| 4.6.11.1 Ensure 'Hardened UNC Paths' is set to 'Enabled, with 'Require Mutual Authentication', 'Require Integrity', and 'Require Privacy' set for all NETLOGON and SYSVOL shares' | CIS Microsoft Intune for Windows 10 v5.0.0 L1 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 18.8.22.1.2 Ensure 'Turn off handwriting personalization data sharing' is set to 'Enabled' | CIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0 | Windows | ACCESS CONTROL |
| 18.9.7.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled' | CIS Microsoft Windows 10 Stand-alone v5.0.0 L1 | Windows | CONFIGURATION MANAGEMENT |
| 18.9.7.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled' | CIS Microsoft Windows 10 Stand-alone v5.0.0 L1 BL NG | Windows | CONFIGURATION MANAGEMENT |
| 18.9.7.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled' | CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BL NG | Windows | CONFIGURATION MANAGEMENT |
| 18.9.7.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled' | CIS Microsoft Windows 10 Enterprise v5.0.0 L1 NG | Windows | CONFIGURATION MANAGEMENT |
| 18.9.7.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled' | CIS Microsoft Windows 10 Enterprise v5.0.0 L1 | Windows | CONFIGURATION MANAGEMENT |
| 18.9.7.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled' | CIS Microsoft Windows Server 2025 Stand-alone v2.0.0 L1 MS | Windows | CONFIGURATION MANAGEMENT |
| 18.9.7.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled' | CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 | Windows | CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY |
| 18.9.7.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled' | CIS Microsoft Windows Server 2025 v2.1.0 L1 DC | Windows | CONFIGURATION MANAGEMENT |
| 18.9.11.2.1 (BL) Ensure 'Allow enhanced PINs for startup' is set to 'Enabled' | CIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker | Windows | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.9.11.2.7 (BL) Ensure 'Choose how BitLocker-protected operating system drives can be recovered: Omit recovery options from the BitLocker setup wizard' is set to 'Enabled: True' | CIS Microsoft Windows 8.1 v2.4.1 L2 Bitlocker | Windows | ACCESS CONTROL, CONTINGENCY PLANNING |
| 18.9.11.2.7 Ensure 'Choose how BitLocker-protected operating system drives can be recovered: Save BitLocker recovery information to AD DS for operating system drives' is set to 'Enabled: True' | CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0 | Windows | CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.9.59.3.9.1 (L1) Ensure 'Always prompt for password upon connection' is set to 'Enabled' | CIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker | Windows | IDENTIFICATION AND AUTHENTICATION |
| 18.10.9.3.8 (L1) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Configure storage of BitLocker recovery information to AD DS:' is set to 'Enabled: Backup recovery passwords and key packages' | CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1 | Windows | MEDIA PROTECTION |
| 18.10.10.1.8 Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Configure storage of BitLocker recovery information to AD DS' is set to 'Enabled: Backup recovery passwords and key packages' | CIS Microsoft Windows 11 Enterprise v5.1.0 L2 BL | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.10.10.1.8 Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Configure storage of BitLocker recovery information to AD DS' is set to 'Enabled: Backup recovery passwords and key packages' | CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BL | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.10.10.1.8 Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Configure storage of BitLocker recovery information to AD DS' is set to 'Enabled: Backup recovery passwords and key packages' | CIS Microsoft Windows 11 Enterprise v5.1.0 BL | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.10.10.1.8 Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Configure storage of BitLocker recovery information to AD DS' is set to 'Enabled: Backup recovery passwords and key packages' | CIS Microsoft Windows 10 Enterprise v5.0.0 BL | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.10.10.1.8 Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Configure storage of BitLocker recovery information to AD DS' is set to 'Enabled: Backup recovery passwords and key packages' | CIS Microsoft Windows 10 Enterprise v5.0.0 L2 BL | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.10.10.3.8 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Configure storage of BitLocker recovery information to AD DS:' is set to 'Enabled: Backup recovery passwords and key packages' | CIS Microsoft Windows 10 Enterprise v5.0.0 L2 BL | Windows | MEDIA PROTECTION |
| 18.10.10.3.8 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Configure storage of BitLocker recovery information to AD DS:' is set to 'Enabled: Backup recovery passwords and key packages' | CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BL | Windows | MEDIA PROTECTION |
| 18.10.10.3.8 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Configure storage of BitLocker recovery information to AD DS:' is set to 'Enabled: Backup recovery passwords and key packages' | CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BL NG | Windows | MEDIA PROTECTION |
| 18.10.10.3.8 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Configure storage of BitLocker recovery information to AD DS:' is set to 'Enabled: Backup recovery passwords and key packages' | CIS Microsoft Windows 10 Enterprise v5.0.0 BL | Windows | MEDIA PROTECTION |
| 18.10.10.3.8 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Configure storage of BitLocker recovery information to AD DS:' is set to 'Enabled: Backup recovery passwords and key packages' | CIS Microsoft Windows 10 Enterprise v5.0.0 L2 BL NG | Windows | MEDIA PROTECTION |
| 19.1.3.4 Ensure 'Screen saver timeout' is set to 'Enabled: 900 seconds or fewer, but not 0' | CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0 | Windows | ACCESS CONTROL |
| CIS Control 1 (1.4) Maintain Detailed Asset Inventory | CAS Implementation Group 1 Audit File | Unix | CONFIGURATION MANAGEMENT |
| CIS Control 6 (6.2(b)) Activate Audit Logging | CAS Implementation Group 1 Audit File | Unix | AUDIT AND ACCOUNTABILITY |
| CIS Control 10 (10.1) Ensure Regular Automated Backups | CAS Implementation Group 1 Audit File | Unix | CONTINGENCY PLANNING |
| CIS_Apache_Cassandra_3.11_v1.0.0_L1_OS_Unix.audit from CIS Apache Cassandra 3.11 Benchmark v1.0.0 | CIS Apache Cassandra 3.11 L1 Unix Audit v1.0.0 | Unix | |
| CIS_Bottlerocket_v1.0.0_L1.audit from CIS Bottlerocket Benchmark Level 1 | CIS Bottlerocket L1 | Unix | |
| CIS_CentOS_Linux_7_v4.0.0_L1_Workstation.audit from CIS CentOS Linux 7 Benchmark v4.0.0 | CIS CentOS Linux 7 v4.0.0 L1 Workstation | Unix | |
| CIS_Cisco_IOS_15_v4.1.1_Level_2.audit from CIS Cisco IOS 15 Benchmark | CIS Cisco IOS 15 L2 v4.1.1 | Cisco | |
| CIS_Debian_Linux_9_Workstation_v1.0.1_L1.audit from CIS Debian Linux 9 Benchmark | CIS Debian 9 Workstation L1 v1.0.1 | Unix | |
| CIS_Google_Chrome_L2_v3.0.0.audit from CIS Google Chrome Benchmark v3.0.0 | CIS Google Chrome L2 v3.0.0 | Windows | |
| CIS_IBM_DB2_12.1_v1.0.0_Level_1_OS_Windows.audit from CIS IBM DB2 12.1 v1.0.0 Benchmark | CIS IBM DB2 12.1 v1.0.0 Windows OS Level 1 | Windows | |
| CIS_Microsoft_SQL_Server_2022_v1.3.0_L1_AWS_RDS_Windows.audit from CIS Microsoft SQL Server 2022 v1.3.0 | CIS Microsoft SQL Server 2022 v1.3.0 L1 AWS RDS Windows | Windows | |
| CIS_MongoDB_3.2_Benchmark_Level_1_OS_Unix_v1.0.0.audit from CIS MongoDB 3.2 Benchmark v1.0.0 | CIS MongoDB 3.2 L1 Unix Audit v1.0.0 | Unix | |
| CIS_MongoDB_3.2_Benchmark_Level_1_OS_Windows_v1.0.0.audit from CIS MongoDB 3.2 Benchmark v1.0.0 | CIS MongoDB 3.2 L1 Windows Audit v1.0.0 | Windows | |
| CIS_MongoDB_3.2_Benchmark_Level_2_OS_Windows_v1.0.0.audit from CIS MongoDB 3.2 Benchmark v1.0.0 | CIS MongoDB 3.2 L2 Windows Audit v1.0.0 | Windows | |
| CIS_MongoDB_3.4_Benchmark_Level_2_OS_Windows_v1.0.0.audit from CIS MongoDB 3.4 Benchmark v1.0.0 | CIS MongoDB 3.4 L2 Windows Audit v1.0.0 | Windows | |
| CIS_Oracle_Linux_9_STIG_v1.0.0_CAT_I.audit from CIS Oracle Linux 9 STIG v1.0.0 | CIS Oracle Linux 9 STIG v1.0.0 CAT I | Unix | |
| CIS_Oracle_Server_18c_v1.1.0_L1_Windows.audit from CIS Oracle Database 18c Benchmark v1.1.0 | CIS Oracle Server 18c Windows v1.1.0 | Windows | |
| CIS_Solaris_11_X86_STIG_v1.0.0_CAT_I.audit from CIS Solaris 11 X86 STIG v1.0.0 | CIS Solaris 11 X86 STIG v1.0.0 CAT I | Unix | |
| CIS_Solaris_11_X86_STIG_v1.0.0_CAT_II.audit from CIS Solaris 11 X86 STIG v1.0.0 | CIS Solaris 11 X86 STIG v1.0.0 CAT II | Unix | |
| CIS_Ubuntu_Linux_20.04_LTS_v3.0.0_L1_Server.audit from CIS Ubuntu Linux 20.04 LTS v3.0.0 | CIS Ubuntu Linux 20.04 LTS v3.0.0 L1 Server | Unix | |
| CIS_Ubuntu_Linux_22.04_LTS_v3.0.0_L1_Workstation.audit from CIS Ubuntu Linux 22.04 LTS v3.0.0 | CIS Ubuntu Linux 22.04 LTS v3.0.0 L1 Workstation | Unix | |
| CIS_Ubuntu_Linux_22.04_LTS_v3.0.0_L2_Workstation.audit from CIS Ubuntu Linux 22.04 LTS v3.0.0 | CIS Ubuntu Linux 22.04 LTS v3.0.0 L2 Workstation | Unix | |
| CIS_Ubuntu_Linux_24.04_LTS_v2.0.0_L1_Workstation.audit from CIS Ubuntu Linux 24.04 LTS v2.0.0 | CIS Ubuntu Linux 24.04 LTS v2.0.0 L1 Workstation | Unix | |
| CIS_VMware_ESXi_6.5_v1.0.0_L1_Bare_Metal.audit from CIS VMware ESXi 6.5 v1.0.0 benchmark | CIS VMware ESXi 6.5 v1.0.0 Level 1 Bare Metal | Unix | |