| 1.114 SLES-15-030110 | CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT II | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| 1.122 SLES-15-030330 | CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT II | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| 1.129 SLES-15-030400 | CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT II | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| 1.130 SLES-15-030410 | CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT II | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| 1.159 OL09-00-000840 | CIS Oracle Linux 9 STIG v1.0.0 CAT II | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| 1.160 OL09-00-000845 | CIS Oracle Linux 9 STIG v1.0.0 CAT II | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| 1.364 ALMA-09-047760 | CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT II | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| 1.365 ALMA-09-047870 | CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT II | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| 6.2.3.10 Ensure unsuccessful file access attempts are collected | CIS SUSE Linux Enterprise 16 v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.10 Ensure unsuccessful file access attempts are collected | CIS SUSE Linux Enterprise 16 v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.11 Ensure events that modify /etc/group information are collected | CIS Ubuntu Linux 24.04 LTS v2.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.11 Ensure events that modify /etc/group information are collected | CIS SUSE Linux Enterprise 16 v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.11 Ensure events that modify /etc/group information are collected | CIS Ubuntu Linux 24.04 LTS v2.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.11 Ensure events that modify /etc/group information are collected | CIS Debian Linux 12 v2.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.11 Ensure events that modify /etc/group information are collected | CIS Debian Linux 12 v2.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.11 Ensure events that modify /etc/group information are collected | CIS SUSE Linux Enterprise 16 v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.12 Ensure events that modify /etc/group information are collected | CIS Debian Linux 13 v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.12 Ensure events that modify /etc/group information are collected | CIS Debian Linux 13 v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.12 Ensure events that modify /etc/passwd information are collected | CIS Debian Linux 12 v2.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.12 Ensure events that modify /etc/passwd information are collected | CIS SUSE Linux Enterprise 16 v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.12 Ensure events that modify /etc/passwd information are collected | CIS Ubuntu Linux 24.04 LTS v2.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.13 Ensure events that modify /etc/passwd information are collected | CIS Debian Linux 13 v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.13 Ensure events that modify /etc/passwd information are collected | CIS Debian Linux 13 v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.14 Ensure events that modify /etc/security/opasswd are collected | CIS Debian Linux 12 v2.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.14 Ensure events that modify /etc/security/opasswd are collected | CIS Ubuntu Linux 24.04 LTS v2.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.14 Ensure events that modify /etc/security/opasswd are collected | CIS Ubuntu Linux 24.04 LTS v2.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.14 Ensure events that modify /etc/security/opasswd are collected | CIS SUSE Linux Enterprise 16 v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.15 Ensure events that modify /etc/security/opasswd are collected | CIS Debian Linux 13 v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.15 Ensure events that modify /etc/security/opasswd are collected | CIS Debian Linux 13 v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.22 Ensure unlink file deletion events by users are collected | CIS SUSE Linux Enterprise 16 v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.22 Ensure unlink file deletion events by users are collected | CIS SUSE Linux Enterprise 16 v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.23 Ensure rename file deletion events by users are collected | CIS SUSE Linux Enterprise 16 v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.23 Ensure rename file deletion events by users are collected | CIS SUSE Linux Enterprise 16 v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.24 Ensure unlink file deletion events by users are collected | CIS Debian Linux 13 v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.24 Ensure unlink file deletion events by users are collected | CIS Debian Linux 13 v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.25 Ensure rename file deletion events by users are collected | CIS Debian Linux 13 v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.25 Ensure rename file deletion events by users are collected | CIS Debian Linux 13 v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.30 Ensure kernel "init_module" and "finit_module" loading unloading and modification is collected | CIS SUSE Linux Enterprise 16 v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.30 Ensure kernel "init_module" and "finit_module" loading unloading and modification is collected | CIS SUSE Linux Enterprise 16 v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.31 Ensure kernel "delete_module" loading unloading and modification is collected | CIS SUSE Linux Enterprise 16 v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.31 Ensure kernel "delete_module" loading unloading and modification is collected | CIS SUSE Linux Enterprise 16 v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.32 Ensure kernel "init_module" and "finit_module" loading unloading and modification is collected | CIS Debian Linux 13 v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.32 Ensure kernel "init_module" and "finit_module" loading unloading and modification is collected | CIS Debian Linux 13 v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.33 Ensure kernel "delete_module" loading unloading and modification is collected | CIS Debian Linux 13 v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.33 Ensure kernel "delete_module" loading unloading and modification is collected | CIS Debian Linux 13 v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.3.3.1 Ensure changes to system administration scope (sudoers) is collected | CIS Red Hat Enterprise Linux 8 STIG v2.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| 6.3.3.1 Ensure changes to system administration scope (sudoers) is collected | CIS Red Hat Enterprise Linux 8 STIG v2.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| 6.3.3.12 Ensure login and logout events are collected | CIS Red Hat Enterprise Linux 8 STIG v2.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| SLEM-05-654050 - SLEM 5 must generate audit records for all uses of the "insmod" command. | DISA SUSE Linux Enterprise Micro SLEM 5 STIG v1r4 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| SLEM-05-654180 - SLEM 5 must generate audit records for all uses of the "setxattr", "fsetxattr", "lsetxattr", "removexattr", "fremovexattr", and "lremovexattr" system calls. | DISA SUSE Linux Enterprise Micro SLEM 5 STIG v1r4 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |