| AIOS-01-080004 - Apple iOS must enforce a minimum password length of six characters. | MobileIron - DISA Apple iOS 10 v1r3 | MDM | IDENTIFICATION AND AUTHENTICATION |
| AIOS-14-000100 - The mobile operating system must be configured to enforce a minimum password length of six characters. | MobileIron - DISA Apple iOS/iPadOS 14 v1r3 | MDM | IDENTIFICATION AND AUTHENTICATION |
| AIOS-17-706500 - Apple iOS/iPadOS 17 must be configured to enforce a minimum password length of six characters. | MobileIron - DISA Apple iOS/iPadOS BYOAD 17 v1r2 | MDM | IDENTIFICATION AND AUTHENTICATION |
| AIOS-18-006500 - Apple iOS/iPadOS 18 must be configured to enforce a minimum password length of six characters. | MobileIron - DISA Apple iOS/iPadOS 18 v2r3 | MDM | IDENTIFICATION AND AUTHENTICATION |
| ALMA-09-035990 - AlmaLinux OS 9 must ensure the password complexity module in the system-auth file is configured for three retries or less. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | IDENTIFICATION AND AUTHENTICATION |
| APPL-11-003011 - The macOS system must enforce password complexity by requiring that at least one special character be used - minComplexChars | DISA STIG Apple macOS 11 v1r8 | Unix | IDENTIFICATION AND AUTHENTICATION |
| APPL-13-003010 - The macOS system must enforce a minimum 15-character password length. | DISA STIG Apple macOS 13 v1r5 | Unix | IDENTIFICATION AND AUTHENTICATION |
| APPL-26-003007 - The macOS system must require that passwords contain a minimum of one numeric character. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| ARBA-ND-000254 - AOS must enforce password complexity by requiring that at least one uppercase character be used. | DISA HPE Aruba Networking AOS NDM STIG v1r1 | ArubaOS | IDENTIFICATION AND AUTHENTICATION |
| ARBA-ND-000255 - AOS must enforce password complexity by requiring that at least one lowercase character be used. | DISA HPE Aruba Networking AOS NDM STIG v1r1 | ArubaOS | IDENTIFICATION AND AUTHENTICATION |
| ARST-ND-000380 - The Arista network device must enforce a minimum 15-character password length. | DISA STIG Arista MLS EOS 4.2x NDM v2r1 | Arista | IDENTIFICATION AND AUTHENTICATION |
| AZLX-23-002400 - Amazon Linux 2023 must enforce 24 hours/1 day as the minimum password lifetime. | DISA Amazon Linux 2023 STIG v1r4 | Unix | IDENTIFICATION AND AUTHENTICATION |
| EPAS-00-004250 - If DBMS authentication, using passwords, is employed, EDB Postgres Advanced Server must enforce the DOD standards for password complexity and lifetime. | EnterpriseDB PostgreSQL Advanced Server DB v2r1 | PostgreSQLDB | IDENTIFICATION AND AUTHENTICATION |
| F5BI-DM-300050 - The F5 BIG-IP appliance must enforce password complexity by requiring that at least one uppercase character be used. | DISA F5 BIG-IP TMOS NDM STIG v1r2 | F5 | IDENTIFICATION AND AUTHENTICATION |
| FGFW-ND-000230 - The FortiGate device must enforce password complexity by requiring that at least one lowercase character be used. | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | IDENTIFICATION AND AUTHENTICATION |
| FGFW-ND-000235 - The FortiGate device must enforce password complexity by requiring at least one numeric character be used. | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | IDENTIFICATION AND AUTHENTICATION |
| GOOG-13-706000 - Google Android 13 must be configured to enforce a minimum password length of six characters and not allow passwords that include more than four repeating or sequential characters. | MobileIron - DISA Google Android 13 BYOAD v1r3 | MDM | IDENTIFICATION AND AUTHENTICATION |
| GOOG-14-006000 - Google Android 14 must be configured to enforce a minimum password length of six characters. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | IDENTIFICATION AND AUTHENTICATION |
| GOOG-14-006000 - Google Android 14 must be configured to enforce a minimum password length of six characters. | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | IDENTIFICATION AND AUTHENTICATION |
| GOOG-14-006100 - Google Android 14 must be configured to not allow passwords that include more than four repeating or sequential characters - Complex Characters | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | IDENTIFICATION AND AUTHENTICATION |
| GOOG-15-006100 - Google Android 15 must be configured to not allow passwords that include more than four repeating or sequential characters - Alphanumeric | MobileIron - DISA Google Android 15 COBO STIG v1r5 | MDM | IDENTIFICATION AND AUTHENTICATION |
| GOOG-15-006100 - Google Android 15 must be configured to not allow passwords that include more than four repeating or sequential characters - Characters | AirWatch - DISA Google Android 15 COBO STIG v1r5 | MDM | IDENTIFICATION AND AUTHENTICATION |
| GOOG-16-006000 - Google Android 16 must be configured to enforce a minimum password length of six characters. | AirWatch - DISA Google Android 16 COPE STIG v1r1 | MDM | IDENTIFICATION AND AUTHENTICATION |
| GOOG-16-006100 - Google Android 16 must be configured to not allow passwords that include more than four repeating or sequential characters - Numbers | AirWatch - DISA Google Android 16 COBO STIG v1r3 | MDM | IDENTIFICATION AND AUTHENTICATION |
| HONW-13-006000 - Honeywell Android 13 must be configured to enforce a minimum password length of six characters. | AirWatch - DISA Honeywell Android 13 COPE STIG v1r1 | MDM | IDENTIFICATION AND AUTHENTICATION |
| HONW-13-006000 - Honeywell Android 13 must be configured to enforce a minimum password length of six characters. | MobileIron - DISA Honeywell Android 13 COPE STIG v1r1 | MDM | IDENTIFICATION AND AUTHENTICATION |
| HONW-13-006100 - Honeywell Android 13 must be configured to not allow passwords that include more than four repeating or sequential characters - Alphanumeric | MobileIron - DISA Honeywell Android 13 COBO STIG v1r1 | MDM | IDENTIFICATION AND AUTHENTICATION |
| MD4X-00-002950 - If passwords are used for authentication, MongoDB must implement LDAP or Kerberos for authentication to enforce the DoD standards for password complexity and lifetime. | DISA STIG MongoDB Enterprise Advanced 4.x v1r4 OS | Unix | IDENTIFICATION AND AUTHENTICATION |
| MOTO-09-000100 - The Motorola Android Pie must be configured to enforce a minimum password length of six characters. | MobileIron - DISA Motorola Android Pie.x COPE v1r2 | MDM | IDENTIFICATION AND AUTHENTICATION |
| OL09-00-001005 - OL 9 must enforce password complexity by requiring that at least one uppercase character be used. | DISA Oracle Linux 9 STIG v1r6 | Unix | IDENTIFICATION AND AUTHENTICATION |
| OL09-00-001085 - OL 9 passwords for new users or password changes must have a 24-hour minimum password lifetime restriction in /etc/login.defs. | DISA Oracle Linux 9 STIG v1r6 | Unix | IDENTIFICATION AND AUTHENTICATION |
| OS10-NDM-000440 - The Dell OS10 Switch must enforce password complexity by requiring that at least one special character be used. | DISA Dell OS10 Switch NDM STIG v1r1 | Dell_OS10 | IDENTIFICATION AND AUTHENTICATION |
| PHTN-30-000023 - The Photon operating system must enforce password complexity by requiring that at least one numeric character be used. | DISA STIG VMware vSphere 7.0 Photon OS v1r4 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-600220 - RHEL 10 must enforce that passwords be created with a minimum of 15 characters. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-600250 - RHEL 10 must enforce password complexity by requiring that at least one uppercase character be used. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-600260 - RHEL 10 must require the change of at least eight characters when passwords are changed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-600320 - RHEL 10 must prevent the use of dictionary words for passwords. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-600405 - RHEL 10 must enforce password complexity rules for the "root" account. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-600460 - RHEL 10 must not have accounts configured with blank or null passwords. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-600485 - RHEL 10 must ensure the password complexity module in the system-auth file is configured for three or fewer retries. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLEM-05-611010 - SLEM 5 must enforce passwords that contain at least one uppercase character. | DISA SUSE Linux Enterprise Micro SLEM 5 STIG v1r4 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLEM-05-611020 - SLEM 5 must enforce passwords that contain at least one numeric character. | DISA SUSE Linux Enterprise Micro SLEM 5 STIG v1r4 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLEM-05-611025 - SLEM 5 must enforce passwords that contain at least one special character. | DISA SUSE Linux Enterprise Micro SLEM 5 STIG v1r4 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SQLI-22-008000 - Contained databases must use Windows principals. | DISA Microsoft SQL Server 2022 Instance STIG v1r4 MS_SQLDB | MS_SQLDB | IDENTIFICATION AND AUTHENTICATION |
| WN25-00-000020 - Windows Server 2025 passwords for the built-in Administrator account must be changed at least every 60 days. | DISA Microsoft Windows Server 2025 STIG v1r1 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN25-AC-000080 - Windows Server 2025 must have the built-in Windows password complexity policy enabled. | DISA Microsoft Windows Server 2025 STIG v1r1 | Windows | IDENTIFICATION AND AUTHENTICATION |
| ZEBR-10-000100 - Zebra Android 10 must be configured to enforce a minimum password length of six characters. | MobileIron - DISA Zebra Android 10 COPE v1r2 | MDM | IDENTIFICATION AND AUTHENTICATION |
| ZEBR-14-006000 - Zebra Android 14 must be configured to enforce a minimum password length of six characters. | AirWatch - DISA Zebra Android 14 COBO STIG v1r2 | MDM | IDENTIFICATION AND AUTHENTICATION |
| ZEBR-14-006100 - Zebra Android 14 must be configured to not allow passwords that include more than four repeating or sequential characters - Alphanumeric | MobileIron - DISA Zebra Android 14 COPE STIG v1r2 | MDM | IDENTIFICATION AND AUTHENTICATION |
| ZEBR-14-006100 - Zebra Android 14 must be configured to not allow passwords that include more than four repeating or sequential characters - Numbers | AirWatch - DISA Zebra Android 14 COPE STIG v1r2 | MDM | IDENTIFICATION AND AUTHENTICATION |