| 2.3.8.2 (L1) Ensure 'Microsoft network client: Digitally sign communications (if server agrees)' is set to 'Enabled' | CIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker | Windows | CONFIGURATION MANAGEMENT |
| 2.3.9.3 Ensure 'Microsoft network server: Digitally sign communications (if client agrees)' is set to 'Enabled' | CIS Windows 7 Workstation Level 1 v3.2.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 3.1.6 Disable Client Discovery Requests (DISCOVER) | CIS IBM DB2 11 v1.2.0 Linux OS Level 1 | Unix | CONFIGURATION MANAGEMENT |
| 3.1.10 Secure the Java Development Kit Installation Path (JDK_PATH) | CIS IBM DB2 11 v1.2.0 Linux OS Level 1 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 3.2.4 Enable Extended Security (DB2_EXTSECURITY) | CIS IBM DB2 11 v1.2.0 Linux OS Level 1 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 3.9 Ensure Windows BUILTIN groups are not SQL Logins | CIS Microsoft SQL Server 2022 v1.2.1 L1 AWS RDS | MS_SQLDB | ACCESS CONTROL, MEDIA PROTECTION |
| 4.1.4 Disable Database Discovery (DISCOVER_DB) | CIS IBM DB2 11 v1.2.0 Linux OS Level 1 | Unix | CONFIGURATION MANAGEMENT |
| 4.1.5 Secure Permissions for the Primary Archive Log Location (LOGARCHMETH1) | CIS IBM DB2 11 v1.2.0 Linux OS Level 1 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 4.1.7 Secure Permissions for the Tertiary Archive Log Location (FAILARCHPATH) | CIS IBM DB2 11 v1.2.0 Linux OS Level 1 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 4.1.8 Secure Permissions for the Log Mirror Location (MIRRORLOGPATH) | CIS IBM DB2 11 v1.2.0 Linux OS Level 1 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 4.1.10 Establish Retention Set Size for Backups (NUM_DB_BACKUPS) | CIS IBM DB2 11 v1.2.0 Linux OS Level 1 | Unix | CONTINGENCY PLANNING |
| 4.1.11 Set Archive Log Failover Retry Limit (NUMARCHRETRY) | CIS IBM DB2 11 v1.2.0 Linux OS Level 1 | Unix | AUDIT AND ACCOUNTABILITY |
| 4.1.12 Set Maximum Number of Applications (MAXAPPLS) | CIS IBM DB2 11 v1.2.0 Linux OS Level 1 | Unix | ACCESS CONTROL |
| 5.1 Specify a Secure Connection Authentication Type (SRVCON_AUTH) | CIS IBM DB2 11 v1.2.0 Linux OS Level 1 | Unix | ACCESS CONTROL |
| 5.10 DB2AUTH Registry Variable | CIS IBM DB2 11 v1.2.0 Linux OS Level 1 | Unix | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 6.1.2 Secure SYSCTRL Authority | CIS IBM DB2 11 v1.2.0 Linux OS Level 1 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 6.1.4 Secure SYSMON Authority | CIS IBM DB2 11 v1.2.0 Linux OS Level 1 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 7.1.2 Disable Limited Audit of Applications (DB2_LIMIT_AUDIT_APPS) | CIS IBM DB2 11 v1.2.0 Linux OS Level 1 | Unix | AUDIT AND ACCOUNTABILITY |
| 8.1.2 Configure a Server-side Stash File for TLS (SSL_SVR_STASH) | CIS IBM DB2 11 v1.2.0 Linux OS Level 1 | Unix | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.1.3 Configure an Endpoint Certificate (SSL_SVR_LABEL) | CIS IBM DB2 11 v1.2.0 Linux OS Level 1 | Unix | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.1.5 Configure a Secure TLS Version (SSL_VERSIONS) | CIS IBM DB2 11 v1.2.0 Linux OS Level 1 | Unix | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.1.6 Configure Secure TLS Cipher Suites (SSL_CIPHERSPECS) | CIS IBM DB2 11 v1.2.0 Linux OS Level 1 | Unix | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.1.7 Unset the Service Name for Plaintext Communication (SVCENAME) | CIS IBM DB2 11 v1.2.0 Linux OS Level 1 | Unix | PLANNING, SYSTEM AND SERVICES ACQUISITION |
| 18.9.11.2.3 Ensure 'Choose how BitLocker-protected operating system drives can be recovered: Allow data recovery agent' is set to 'Enabled: False' | CIS Windows 7 Workstation Bitlocker v3.2.0 | Windows | CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.10.10.1.10 Ensure 'Configure use of smart cards on fixed data drives: Require use of smart cards on fixed data drives' is set to 'Enabled: True' | CIS Microsoft Windows 11 Stand-alone v5.0.0 BL | Windows | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.10.10.2.10 Ensure 'Choose how BitLocker-protected operating system drives can be recovered: Do not enable BitLocker until recovery information is stored to AD DS for operating system drives' is set to 'Enabled: True' | CIS Microsoft Windows 11 Enterprise v5.0.1 L2 BL | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.10.10.3.10 Ensure 'Configure use of smart cards on removable data drives: Require use of smart cards on removable data drives' is set to 'Enabled: True' | CIS Microsoft Windows 11 Stand-alone v5.0.0 BL | Windows | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| CIS_AlmaLinux_OS_9_v2.0.0_L2_Server.audit from CIS AlmaLinux OS 9 v2.0.0 | CIS AlmaLinux OS 9 v2.0.0 L2 Server | Unix | |
| CIS_AlmaLinux_OS_9_v2.0.0_L2_Workstation.audit from CIS AlmaLinux OS 9 v2.0.0 | CIS AlmaLinux OS 9 v2.0.0 L2 Workstation | Unix | |
| CIS_Apache_Tomcat_7_L1_v1.1.0_Middleware.audit from CIS Apach Tomcat 7 Benchmark | CIS Apache Tomcat 7 L1 v1.1.0 Middleware | Unix | |
| CIS_Apache_Tomcat_7_L2_v1.1.0_Middleware.audit from CIS Apach Tomcat 7 Benchmark | CIS Apache Tomcat 7 L2 v1.1.0 Middleware | Unix | |
| CIS_Apache_Tomcat_8_L2_v1.1.0_Middleware.audit from CIS Apache Tomcat 8 Benchmark | CIS Apache Tomcat 8 L2 v1.1.0 Middleware | Unix | |
| CIS_Apache_Tomcat_10_L2_v1.1.0_Middleware.audit from CIS Apache Tomcat 10 Benchmark | CIS Apache Tomcat 10 L2 v1.1.0 Middleware | Unix | |
| CIS_Debian_Family_Linux_v1.0.0_L2_Workstation.audit from CIS Debian Family Linux Benchmark | CIS Debian Family Workstation L2 v1.0.0 | Unix | |
| CIS_Debian_Linux_11_v2.0.0_L1_Workstation.audit from CIS Debian Linux 11 v2.0.0 | CIS Debian Linux 11 v2.0.0 L1 Workstation | Unix | |
| CIS_Debian_Linux_12_v1.1.0_L2_Workstation.audit from CIS Debian Linux 12 v1.1.0 | CIS Debian Linux 12 v1.1.0 L2 Workstation | Unix | |
| CIS_IBM_DB2_10_v1.1.0_Level_2_OS_Linux.audit from CIS DB2 10.x Linux | CIS IBM DB2 v10 v1.1.0 Linux OS Level 2 | Unix | |
| CIS_Microsoft_Defender_Antivirus_v1.0.0_L2_Server.audit from CIS Microsoft Defender Antivirus 1.0.0 | CIS Microsoft Defender Antivirus v1.0.0 L2 Server | Windows | |
| CIS_Microsoft_Edge_v4.0.0_L1.audit from CIS Microsoft Edge v4.0.0 | CIS Microsoft Edge v4.0.0 L1 | Windows | |
| CIS_Microsoft_Edge_v4.0.0_L2.audit from CIS Microsoft Edge v4.0.0 | CIS Microsoft Edge v4.0.0 L2 | Windows | |
| CIS_MongoDB_3.4_Benchmark_Level_1_OS_Unix_v1.0.0.audit from CIS MongoDB 3.4 Benchmark | CIS MongoDB 3.4 L1 Unix Audit v1.0.0 | Unix | |
| CIS_MongoDB_4_Benchmark_Level_1_OS_Linux_v1.0.0.audit from CIS MongoDB 4 Benchmark | CIS MongoDB 4 L1 OS Linux v1.0.0 | Unix | |
| CIS_MongoDB_4_Benchmark_Level_2_OS_Windows_v1.0.0.audit from CIS MongoDB 4 Benchmark | CIS MongoDB 4 L2 OS Windows v1.0.0 | Windows | |
| CIS_MongoDB_Benchmark_Level_1_OS_Windows_v1.0.0.audit from CIS MongoDB Benchmark v1.0.0 | CIS MongoDB L1 Windows Audit v1.0.0 | Windows | |
| CIS_MongoDB_Benchmark_Level_2_OS_Unix_v1.0.0.audit from CIS MongoDB Benchmark v1.0.0 | CIS MongoDB L2 Unix Audit v1.0.0 | Unix | |
| CIS_Oracle_Linux_9_v2.0.0_L2_Server.audit from CIS Oracle Linux 9 v2.0.0 | CIS Oracle Linux 9 v2.0.0 L2 Server | Unix | |
| CIS_Oracle_Linux_10_v1.0.0_L1_Workstation.audit from CIS Oracle Linux 10 1.0.0 | CIS Oracle Linux 10 v1.0.0 L1 Workstation | Unix | |
| CIS_PostgreSQL_12_v1.1.0_L1_OS_Linux.audit from CIS PostgreSQL 12 Benchmark v1.1.0 | CIS PostgreSQL 12 OS v1.1.0 | Unix | |
| CIS_Rocky_Linux_8_v3.0.0_L1_Workstation.audit from CIS Rocky Linux 8 3.0.0 | CIS Rocky Linux 8 v3.0.0 L1 Workstation | Unix | |
| CIS_VMware_ESXi_8.0_v1.2.0_L1_Unix.audit from CIS VMware ESXi 8.0 1.2.0 | CIS VMware ESXi 8.0 v1.2.0 L1 Unix | Unix | |