| 1.4 Ensure 'application pool identity' is configured for all application pools | CIS IIS 10 v1.2.1 Level 1 | Windows | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 1.4 Ensure 'application pool identity' is configured for all application pools | CIS IIS 8.0 v1.5.1 Level 1 | Windows | ACCESS CONTROL |
| 2.2.6 Ensure 'Allow log on through Remote Desktop Services' is set to 'Administrators, Remote Desktop Users' | CIS Microsoft Windows Server 2019 Stand-alone v4.0.0 L1 MS | Windows | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 2.2.8 (L1) Ensure 'Allow log on through Remote Desktop Services' is set to 'Administrators' (DC only) | CIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 DC | Windows | ACCESS CONTROL |
| 2.2.8 (L1) Ensure 'Allow log on through Remote Desktop Services' is set to 'Administrators' (DC only) | CIS Windows Server 2012 R2 DC L1 v3.0.0 | Windows | ACCESS CONTROL |
| 2.2.9 (L1) Ensure 'Allow log on through Remote Desktop Services' is set to 'Administrators, Remote Desktop Users' (MS only) | CIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 MS | Windows | ACCESS CONTROL |
| 2.2.9 (L1) Ensure 'Allow log on through Remote Desktop Services' is set to 'Administrators, Remote Desktop Users' (MS only) | CIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 MS | Windows | ACCESS CONTROL |
| 2.2.10 Ensure 'Allow log on through Remote Desktop Services' is set to 'Administrators, Remote Desktop Users' (MS only) | CIS Microsoft Windows Server 2025 v2.1.0 L1 MS | Windows | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 2.2.10 Ensure 'Allow log on through Remote Desktop Services' is set to 'Administrators, Remote Desktop Users' (MS only) | CIS Microsoft Windows Server 2022 v5.1.0 L1 MS | Windows | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.3.2.2.4 Ensure password complexity is configured | CIS SUSE Linux Enterprise 16 v1.0.0 L1 Server | Unix | IDENTIFICATION AND AUTHENTICATION |
| 7.2.10 Ensure reauthentication with verification code is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 7.2.10 Ensure reauthentication with verification code is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 18.9.11.1.2 (BL) Ensure 'Choose how BitLocker-protected fixed drives can be recovered' is set to 'Enabled' | CIS Microsoft Windows 8.1 v2.4.1 L2 Bitlocker | Windows | ACCESS CONTROL, CONTINGENCY PLANNING |
| 18.9.11.1.2 Ensure 'Choose how BitLocker-protected fixed drives can be recovered' is set to 'Enabled' | CIS Windows 7 Workstation Bitlocker v3.2.0 | Windows | CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.9.11.1.2 Ensure 'Choose how BitLocker-protected fixed drives can be recovered' is set to 'Enabled' | CIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0 | Windows | CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.9.11.1.12 Ensure 'Configure use of smart cards on fixed data drives: Require use of smart cards on fixed data drives' is set to 'Enabled: True' | CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0 | Windows | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.9.11.1.12 Ensure 'Configure use of smart cards on fixed data drives: Require use of smart cards on fixed data drives' is set to 'Enabled: True' | CIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0 | Windows | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.9.11.2.22 (BL) Ensure 'Require additional authentication at startup: Configure TPM startup key and PIN:' is set to 'Enabled: Do not allow startup key and PIN with TPM' | CIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker | Windows | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.9.11.3.2 Ensure 'Choose how BitLocker-protected removable drives can be recovered' is set to 'Enabled' | CIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0 | Windows | CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.9.11.3.12 Ensure 'Configure use of smart cards on removable data drives: Require use of smart cards on removable data drives' is set to 'Enabled: True' | CIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0 | Windows | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.9.35.1 (L1) Ensure 'Prevent the computer from joining a homegroup' is set to 'Enabled' | CIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker | Windows | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 18.9.59.3.2.1 (L2) Ensure 'Allow users to connect remotely by using Remote Desktop Services' is set to 'Disabled' | CIS Microsoft Windows 8.1 v2.4.1 L2 | Windows | CONFIGURATION MANAGEMENT |
| 18.9.59.3.2.1 Ensure 'Allow users to connect remotely by using Remote Desktop Services' is set to 'Disabled' | CIS Windows 7 Workstation Level 2 v3.2.0 | Windows | CONFIGURATION MANAGEMENT |
| CIS_Apache_Tomcat_10.1_v1.1.0_L2.audit from CIS Apache Tomcat 10.1 Benchmark v1.1.0 | CIS Apache Tomcat 10.1 v1.1.0 L2 | Unix | |
| CIS_Apache_Tomcat_11_v1.0.0_L1.audit from CIS Apache Tomcat 11 Benchmark v1.0.0 | CIS Apache Tomcat 11 v1.0.0 L1 | Unix | |
| CIS_Apple_macOS_10.14_v2.0.0_L1.audit from CIS Apple macOS 10.14 Benchmark v2.0.0 | CIS Apple macOS 10.14 v2.0.0 L1 | Unix | |
| CIS_Apple_macOS_14.0_Sonoma_v3.1.0_L1.audit from CIS Apple macOS 14.0 Sonoma v3.1.0 | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | |
| CIS_Apple_macOS_14.0_Sonoma_v3.1.0_L2.audit from CIS Apple macOS 14.0 Sonoma v3.1.0 | CIS Apple macOS 14.0 Sonoma v3.1.0 L2 | Unix | |
| CIS_Apple_macOS_15_Sequoia_STIG_v1.0.0_CAT_I.audit from CIS Apple macOS 15 Sequoia STIG v1.0.0 | CIS Apple macOS 15 Sequoia STIG v1.0.0 CAT I | Unix | |
| CIS_Apple_macOS_15_Sequoia_STIG_v1.0.0_CAT_III.audit from CIS Apple macOS 15 Sequoia STIG v1.0.0 | CIS Apple macOS 15 Sequoia STIG v1.0.0 CAT III | Unix | |
| CIS_Apple_macOS_15.0_Sequoia_v2.1.0_L2.audit from CIS Apple macOS 15.0 Sequoia v2.1.0 | CIS Apple macOS 15.0 Sequoia v2.1.0 L2 | Unix | |
| CIS_Apple_macOS_26_Tahoe_v1.1.0_L2.audit from CIS Apple macOS 26 Tahoe v1.1.0 | CIS Apple macOS 26 Tahoe v1.1.0 L2 | Unix | |
| CIS_CentOS_8_Server_L2_v2.0.0.audit from CIS CentOS Linux 8 Benchmark v2.0.0 | CIS CentOS Linux 8 Server L2 v2.0.0 | Unix | |
| CIS_Google_Chrome_Group_Policy_v1.1.0_L2.audit from CIS Google Chrome Group Policy v1.1.0 | CIS Google Chrome Group Policy v1.1.0 L2 | Windows | |
| CIS_Microsoft_Exchange_Server_2019_v1.0.0_Level_1_Edge.audit from CIS Microsoft Exchange Server 2019 Benchmark v1.0.0 | CIS Microsoft Exchange Server 2019 L1 Edge v1.0.0 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| CIS_Microsoft_Intune_for_Edge_v1.0.0_L1.audit from CIS Microsoft Intune for Edge 1.0.0 | CIS Microsoft Intune for Edge v1.0.0 L1 | Windows | |
| CIS_Microsoft_Office_365_ProPlus_STIG_v1.1.0_CAT_II.audit from CIS Microsoft Office 365 ProPlus STIG v1.1.0 | CIS Microsoft Office 365 ProPlus STIG v1.1.0 CAT II | Windows | |
| CIS_MS_IIS_10_v1.2.1_Level_1.audit from CIS Microsoft IIS 10 Benchmark v1.2.1 | CIS IIS 10 v1.2.1 Level 1 | Windows | |
| CIS_MySQL_5.7_Community_Benchmark_v2.0.0_Level_2_DB.audit from CIS Oracle MySQL 5.7 Community Edition Benchmark | CIS MySQL 5.7 Community Database L2 v2.0.0 | MySQLDB | |
| CIS_MySQL_5.7_Enterprise_Benchmark_v2.0.0_Level_1_OS_MS.audit from CIS Oracle MySQL 5.7 Enterprise Edition Benchmark | CIS MySQL 5.7 Enterprise Windows OS L1 v2.0.0 | Windows | |
| CIS_MySQL_5.7_Enterprise_Benchmark_v2.0.0_Level_2_OS_Linux.audit from CIS Oracle MySQL 5.7 Enterprise Edition Benchmark | CIS MySQL 5.7 Enterprise Linux OS L2 v2.0.0 | Unix | |
| CIS_Oracle_MySQL_Community_Server_8.4_v1.1.0_L1_MySQL_RDBMS_on_Linux_MySQLDB.audit from CIS Oracle MySQL Community Server 8.4 v1.1.0 | CIS Oracle MySQL Community Server 8.4 v1.1.0 L1 MySQL RDBMS on Linux MySQLDB | MySQLDB | |
| CIS_Oracle_MySQL_Community_Server_8.4_v1.1.0_L2_MySQL_RDBMS_MySQLDB.audit from CIS Oracle MySQL Community Server 8.4 v1.1.0 | CIS Oracle MySQL Community Server 8.4 v1.1.0 L2 MySQL RDBMS MySQLDB | MySQLDB | |
| CIS_Oracle_MySQL_Community_Server_9.7_v1.0.0_L1_MySQL_RDBMS_Unix.audit from CIS Oracle MySQL Community Server 9.7 v1.0.0 | CIS Oracle MySQL Community Server 9.7 v1.0.0 L1 MySQL RDBMS Unix | Unix | |
| CIS_Oracle_MySQL_Enterprise_Edition_9.7_v1.0.0_L1_MySQL_RDBMS_Unix.audit from CIS Oracle MySQL Enterprise Edition 9.7 v1.0.0 | CIS Oracle MySQL Enterprise Edition 9.7 v1.0.0 L1 MySQL RDBMS Unix | Unix | |
| CIS_Red_Hat_Enterprise_Linux_7_v4.0.0_L1_Server.audit from CIS Red Hat Enterprise Linux 7 v4.0.0 | CIS Red Hat Enterprise Linux 7 v4.0.0 L1 Server | Unix | |
| CIS_Red_Hat_Enterprise_Linux_8_v4.0.0_L1_Server.audit from CIS Red Hat Enterprise Linux 8 v4.0.0 | CIS Red Hat Enterprise Linux 8 v4.0.0 L1 Server | Unix | |
| CIS_Red_Hat_Enterprise_Linux_8_v4.0.0_L1_Workstation.audit from CIS Red Hat Enterprise Linux 8 v4.0.0 | CIS Red Hat Enterprise Linux 8 v4.0.0 L1 Workstation | Unix | |
| CIS_Red_Hat_Enterprise_Linux_9_v2.0.0_L2_Workstation.audit from CIS Red Hat Enterprise Linux 9 v2.0.0 | CIS Red Hat Enterprise Linux 9 v2.0.0 L2 Workstation | Unix | |
| WN16-CC-000330 - Windows Server 2016 Windows SmartScreen must be enabled. | DISA Microsoft Windows Server 2016 STIG v2r10 | Windows | CONFIGURATION MANAGEMENT |