| 1.86 PHTN-40-000223 | CIS VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v1.0.0 CAT II | Unix | CONFIGURATION MANAGEMENT |
| 2.5 Set 'Do not allow ActiveX controls to run in Protected Mode when Enhanced Protected Mode is enabled' to 'Enabled' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.2 Set 'Check for server certificate revocation' to 'Enabled' | CIS IE 10 v1.1.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 5.017 - The user is allowed to launch Windows Messenger (MSN Messenger, .NET Messenger). | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 7.5 Set 'MK Protocol Security Restriction' to 'Enabled' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
| 7.8 Set 'Protection From Zone Elevation' to 'Enabled' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.1.2 Set 'Allow paste operations via script' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
| 8.1.6 Set 'Use Pop-up Blocker' to 'Enabled:Enable' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
| 8.1.8 Set 'Only allow approved domains to use ActiveX controls without prompt' to 'Enabled:Enable' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.1.9 Set 'Allow drag and drop or copy and paste files' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
| 8.1.25 Set 'Userdata persistence' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.1.26 Set 'Enable dragging of content from different domains within a window' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.1.27 Set 'Navigate windows and frames across different domains' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | ACCESS CONTROL |
| 8.1.32 Configure 'First-Run Opt-In' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
| 8.1.33 Set 'Web sites in less privileged Web content zones can navigate into this zone' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | ACCESS CONTROL |
| 8.2.2 Set 'Initialize and script ActiveX controls not marked as safe' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.3.3 Set 'Download signed ActiveX controls' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.3.5 Set 'Allow active scripting' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.3.7 Set 'Initialize and script ActiveX controls not marked as safe' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.3.10 Set 'Protected Mode' to 'Enabled:Enable' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.3.12 Set 'Launching programs and unsafe files' to 'Enabled:Prompt' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 8.3.13 Set 'Automatic prompting for file downloads' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
| 8.3.15 Set 'Allow font downloads' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.3.17 Set 'Internet Explorer web browser control' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
| 8.3.21 Set 'Download unsigned ActiveX controls' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.3.22 Set 'Scriptlets' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
| 8.3.23 Set 'Allow file downloads' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
| 8.3.25 Set 'Use SmartScreen Filter' to 'Enabled:Enable' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 8.3.26 Set 'Run ActiveX controls and plugins' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.3.27 Set 'Run .NET Framework-reliant components not signed with Authenticode' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.3.29 Set 'Allow script-initiated windows without size or position constraints' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
| 8.3.30 Set 'Allow META REFRESH' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
| 8.3.32 Set 'Navigate windows and frames across different domains' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | ACCESS CONTROL |
| 8.3.35 Set 'Enable dragging of content from different domains within a window' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.3.36 Set 'Status bar updates via script' to 'Enabled:Enable' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
| 8.3.38 Set 'Web sites in less privileged Web content zones can navigate into this zone' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | ACCESS CONTROL |
| 8.3.39 Configure 'First-Run Opt-In' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
| 8.3.40 Set 'Enable dragging of content from different domains across windows' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.3.41 Set 'Launching applications and files in an IFRAME' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
| 8.4.2 Set 'Use SmartScreen Filter' to 'Enabled:Enable' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 8.8.2 Set 'Only allow approved domains to use ActiveX controls without prompt' to 'Enabled:Enable' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.11 Set 'Security Zones: Do not allow users to change policies' to 'Enabled' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
| 9.1 Set 'Disable the Security page' to 'Enabled' | CIS IE 10 v1.1.0 | Windows | ACCESS CONTROL |
| 9.4 Set 'Turn on Basic feed authentication over HTTP' to 'Not Configured' | CIS IE 10 v1.1.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 9.8 Configure 'Disable changing Automatic Configuration settings' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| CIS Internet Explorer 10 Benchmark Version 1.1.0 | CIS IE 10 v1.1.0 | Windows | |
| DTOO129 - Project - Links that invoke instances of IE from within an Office product must be blocked. | DISA STIG Office 2010 Project v1r10 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| DTOO129 - Publisher - Links that invoke instances of IE from within an Office product must be blocked. | DISA STIG Office 2010 Publisher v1r12 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| PHTN-40-000226 - The Photon operating system must prevent IPv4 Internet Control Message Protocol (ICMP) secure redirect messages from being accepted. | DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r2 | Unix | CONFIGURATION MANAGEMENT |
| PHTN-40-000229 - The Photon operating system must use a reverse-path filter for IPv4 network traffic. | DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r2 | Unix | CONFIGURATION MANAGEMENT |