| 1.1.2 Ensure Super Admin Account Is Not Used For Google Cloud Administration | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | ACCESS CONTROL |
| 1.2 Ensure that Corporate Login Credentials are Used | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | ACCESS CONTROL |
| 1.2.3 Set 'seconds' for 'ssh timeout' for 60 seconds or less | CIS Cisco IOS XR 7.x v1.0.1 L1 | Cisco | IDENTIFICATION AND AUTHENTICATION |
| 1.5 Ensure That There Are Only GCP-Managed Service Account Keys for Each Service Account | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | IDENTIFICATION AND AUTHENTICATION |
| 1.6.7 Configure Image Provenance using ImagePolicyWebhook admission controller | CIS Kubernetes 1.8 Benchmark v1.2.0 L2 | Unix | |
| 1.7 Ensure That IAM Users Are Not Assigned the Service Account User or Service Account Token Creator Roles at Project Level | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | ACCESS CONTROL, MEDIA PROTECTION |
| 1.10 Ensure That Cloud KMS Cryptokeys Are Not Anonymously or Publicly Accessible | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | ACCESS CONTROL, MEDIA PROTECTION |
| 1.11 Ensure KMS Encryption Keys Are Rotated Within a Period of 90 Days | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.18 Ensure Secrets are Not Stored in Cloud Functions Environment Variables by Using Secret Manager | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.1 Ensure That Cloud Audit Logging Is Configured Properly | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | AUDIT AND ACCOUNTABILITY |
| 2.2 Ensure Google Workspace/Cloud Identity Data Sharing with Google Cloud is Enabled for Admin Audit Logging | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | AUDIT AND ACCOUNTABILITY |
| 2.6 Ensure That the Log Metric Filter and Alerts Exist for Audit Configuration Changes | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | AUDIT AND ACCOUNTABILITY |
| 2.7 Ensure That the Log Metric Filter and Alerts Exist for Custom Role Changes | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | AUDIT AND ACCOUNTABILITY |
| 3.2 Ensure Legacy Networks Do Not Exist for Older Projects | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| 3.3 Ensure That DNSSEC Is Enabled for Cloud DNS | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| 3.4 Ensure That RSASHA1 Is Not Used for the Key-Signing Key in Cloud DNS DNSSEC | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| 3.5 Ensure That RSASHA1 Is Not Used for the Zone-Signing Key in Cloud DNS DNSSEC | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| 3.11 Ensure No HTTPS or SSL Proxy Load Balancers Permit SSL Policies With Weak Cipher Suites | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.1 Ensure That Instances Are Not Configured To Use the Default Service Account | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | IDENTIFICATION AND AUTHENTICATION |
| 4.2 Ensure That Instances Are Not Configured To Use the Default Service Account With Full Access to All Cloud APIs | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | IDENTIFICATION AND AUTHENTICATION |
| 4.5 Ensure 'Enable Connecting to Serial Ports' Is Not Enabled for VM Instance | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | CONFIGURATION MANAGEMENT |
| 4.6 Ensure That IP Forwarding Is Not Enabled on Instances | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.1 Ensure That Cloud Storage Bucket Is Not Anonymously or Publicly Accessible | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | ACCESS CONTROL, MEDIA PROTECTION |
| 5.1.4.5 Ensure Local Administrator Password Solution is enabled | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION |
| 5.2 Ensure SELinux security options are set, if applicable | CIS Docker Community Edition v1.1.0 L2 Docker | Unix | ACCESS CONTROL |
| 5.23 Do not docker exec commands with user option | CIS Docker 1.11.0 v1.0.0 L2 Docker | Unix | |
| 6.1.2 Ensure 'Skip_show_database' Database Flag for Cloud SQL MySQL Instance Is Set to 'On' | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | ACCESS CONTROL, MEDIA PROTECTION |
| 6.1.3 Ensure That the 'Local_infile' Database Flag for a Cloud SQL MySQL Instance Is Set to 'Off' | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | CONFIGURATION MANAGEMENT |
| 6.2.2 Ensure That the 'Log_connections' Database Flag for Cloud SQL PostgreSQL Instance Is Set to 'On' | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | AUDIT AND ACCOUNTABILITY |
| 6.2.3 Ensure That the 'Log_disconnections' Database Flag for Cloud SQL PostgreSQL Instance Is Set to 'On' | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | AUDIT AND ACCOUNTABILITY |
| 6.2.5 Ensure that the 'Log_min_messages' Flag for a Cloud SQL PostgreSQL Instance is set at minimum to 'Warning' | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | AUDIT AND ACCOUNTABILITY |
| 6.3.1 Ensure 'external scripts enabled' Database Flag for Cloud SQL SQL Server Instance Is Set to 'off' | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY |
| 6.3.2 Ensure 'cross db ownership chaining' Database Flag for Cloud SQL SQL Server Instance Is Set to 'off' | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | ACCESS CONTROL, MEDIA PROTECTION |
| 6.3.3 Ensure 'user Connections' Database Flag for Cloud SQL SQL Server Instance Is Set to a Non-limiting Value | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | SYSTEM AND COMMUNICATIONS PROTECTION |
| 6.3.5 Ensure 'remote access' Database Flag for Cloud SQL SQL Server Instance Is Set to 'off' | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | CONFIGURATION MANAGEMENT |
| 6.3.7 Ensure 'contained database authentication' Database Flag for Cloud SQL SQL Server Instance Is Set to 'off' | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | ACCESS CONTROL, MEDIA PROTECTION |
| 6.5 Ensure That Cloud SQL Database Instances Do Not Implicitly Whitelist All Public IP Addresses | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | ACCESS CONTROL, MEDIA PROTECTION |
| 6.5 Use a centralized and remote log collection service | CIS Docker 1.6 v1.0.0 L1 Docker | Unix | AUDIT AND ACCOUNTABILITY |
| 6.6 Ensure Cloud SQL Database Instances Have IAM Database Authentication Enabled | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | ACCESS CONTROL, MEDIA PROTECTION |
| 6.8 Ensure That Cloud SQL Database Instances Are Configured With Automated Backups | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | CONTINGENCY PLANNING |
| 18.9.5.1 Ensure 'Turn On Virtualization Based Security' is set to 'Enabled' | CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.9.5.1 Ensure 'Turn On Virtualization Based Security' is set to 'Enabled' | CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BL | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.9.5.4 Ensure 'Turn On Virtualization Based Security: Require UEFI Memory Attributes Table' is set to 'True (checked)' | CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.9.5.4 Ensure 'Turn On Virtualization Based Security: Require UEFI Memory Attributes Table' is set to 'True (checked)' | CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BL | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.9.5.6 Ensure 'Turn On Virtualization Based Security: Secure Launch Configuration' is set to 'Enabled' | CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BL | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.11.1 Ensure 'Disable HTTP proxy features: Disable WPAD' is set to 'Enabled: Checked' | CIS Microsoft Windows Server 2022 v5.1.0 L1 MS | Windows | CONFIGURATION MANAGEMENT |
| 18.11.1 Ensure 'Disable HTTP proxy features: Disable WPAD' is set to 'Enabled: Checked' | CIS Microsoft Windows Server 2025 v2.1.0 L1 DC | Windows | CONFIGURATION MANAGEMENT |
| 18.11.1 Ensure 'Disable HTTP proxy features: Disable WPAD' is set to 'Enabled: Checked' | CIS Microsoft Windows Server 2019 v5.0.0 L1 MS | Windows | CONFIGURATION MANAGEMENT |
| 18.11.1 Ensure 'Disable HTTP proxy features: Disable WPAD' is set to 'Enabled: Checked' | CIS Microsoft Windows Server 2025 Stand-alone v2.0.0 L1 MS | Windows | CONFIGURATION MANAGEMENT |
| OL08-00-010141 - OL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must have a unique name for the grub superusers account when booting into single-user mode and maintenance. | DISA Oracle Linux 8 STIG v2r9 | Unix | ACCESS CONTROL |