| 20.13 (L1) Ensure 'Web browser is supported and secured' | CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1 | Windows | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| AIOS-18-015500 - Apple iOS/iPadOS 18 must disable the download of iOS/iPadOS beta updates. | AirWatch - DISA Apple iOS/iPadOS 18 v2r3 | MDM | CONFIGURATION MANAGEMENT |
| OL08-00-030090 - OL 8 audit logs must be group-owned by root to prevent unauthorized read access. | DISA Oracle Linux 8 STIG v2r9 | Unix | AUDIT AND ACCOUNTABILITY |
| OL08-00-030110 - The OL 8 audit log directory must be group-owned by root to prevent unauthorized read access. | DISA Oracle Linux 8 STIG v2r9 | Unix | AUDIT AND ACCOUNTABILITY |
| OL08-00-030122 - The OL 8 audit system must protect logon UIDs from unauthorized change. | DISA Oracle Linux 8 STIG v2r9 | Unix | AUDIT AND ACCOUNTABILITY |
| OL08-00-030130 - OL 8 must generate audit records for all account creation events that affect "/etc/shadow". | DISA Oracle Linux 8 STIG v2r9 | Unix | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| OL08-00-030250 - OL 8 must generate audit records for any use of the "chage" command. | DISA Oracle Linux 8 STIG v2r9 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| OL08-00-030290 - OL 8 must generate audit records for any use of the "passwd" command. | DISA Oracle Linux 8 STIG v2r9 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| OL08-00-030314 - OL 8 must generate audit records for any use of the "setfiles" command. | DISA Oracle Linux 8 STIG v2r9 | Unix | AUDIT AND ACCOUNTABILITY |
| OL08-00-030317 - OL 8 must generate audit records for any use of the "unix_chkpwd" command. | DISA Oracle Linux 8 STIG v2r9 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| OL08-00-030361 - OL 8 must generate audit records for any use of the "rename", "unlink", "rmdir", "renameat", and "unlinkat" system calls. | DISA Oracle Linux 8 STIG v2r9 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| OL08-00-030480 - OL 8 must generate audit records for any use of the "chown", "fchown", "fchownat", and "lchown" system calls. | DISA Oracle Linux 8 STIG v2r9 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| OL08-00-030490 - OL 8 must generate audit records for any use of the "chmod", "fchmod", and "fchmodat" system calls. | DISA Oracle Linux 8 STIG v2r9 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| OL08-00-030600 - OL 8 must generate audit records for any attempted modifications to the "lastlog" file. | DISA Oracle Linux 8 STIG v2r9 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| OL08-00-030650 - OL 8 must use cryptographic mechanisms to protect the integrity of audit tools. | DISA Oracle Linux 8 STIG v2r9 | Unix | AUDIT AND ACCOUNTABILITY |
| OL08-00-030710 - OL 8 must encrypt the transfer of audit records offloaded onto a different system or media from the system being audited. | DISA Oracle Linux 8 STIG v2r9 | Unix | AUDIT AND ACCOUNTABILITY |
| OL08-00-030730 - OL 8 must take action when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity. | DISA Oracle Linux 8 STIG v2r9 | Unix | AUDIT AND ACCOUNTABILITY |
| OL08-00-040001 - OL 8 must not have any automated bug reporting tools installed. | DISA Oracle Linux 8 STIG v2r9 | Unix | CONFIGURATION MANAGEMENT |
| OL08-00-040090 - An OL 8 firewall must employ a deny-all, allow-by-exception policy for allowing connections to other systems. | DISA Oracle Linux 8 STIG v2r9 | Unix | ACCESS CONTROL |
| OL08-00-040110 - OL 8 wireless network adapters must be disabled. | DISA Oracle Linux 8 STIG v2r9 | Unix | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION |
| OL08-00-040122 - OL 8 must mount "/dev/shm" with the "noexec" option. | DISA Oracle Linux 8 STIG v2r9 | Unix | CONFIGURATION MANAGEMENT |
| OL08-00-040123 - OL 8 must mount "/tmp" with the "nodev" option. | DISA Oracle Linux 8 STIG v2r9 | Unix | CONFIGURATION MANAGEMENT |
| OL08-00-040134 - OL 8 must mount "/var/tmp" with the "noexec" option. | DISA Oracle Linux 8 STIG v2r9 | Unix | CONFIGURATION MANAGEMENT |
| OL08-00-040150 - A firewall must be able to protect against or limit the effects of denial-of-service (DoS) attacks by ensuring OL 8 can implement rate-limiting measures on impacted network interfaces. | DISA Oracle Linux 8 STIG v2r9 | Unix | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION |
| OL08-00-040160 - All OL 8 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission. | DISA Oracle Linux 8 STIG v2r9 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| OL08-00-040249 - OL 8 must not forward IPv4 source-routed packets by default. | DISA Oracle Linux 8 STIG v2r9 | Unix | CONFIGURATION MANAGEMENT |
| OL08-00-040270 - OL 8 must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default. | DISA Oracle Linux 8 STIG v2r9 | Unix | CONFIGURATION MANAGEMENT |
| OL08-00-040280 - OL 8 must ignore IPv6 Internet Control Message Protocol (ICMP) redirect messages. | DISA Oracle Linux 8 STIG v2r9 | Unix | CONFIGURATION MANAGEMENT |
| OL08-00-040281 - OL 8 must disable access to the network "bpf" syscall from nonprivileged processes. | DISA Oracle Linux 8 STIG v2r9 | Unix | CONFIGURATION MANAGEMENT |
| WN11-00-000030 - Windows 11 information systems must use BitLocker to encrypt all disks to protect the confidentiality and integrity of all information at rest. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN11-00-000150 - Structured Exception Handling Overwrite Protection (SEHOP) must be enabled. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WN11-00-000160 - The Server Message Block (SMB) v1 protocol must be disabled on the system. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000230 - The system must notify the user when a Bluetooth device attempts to connect. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-AC-000010 - The number of allowed bad logon attempts must be configured to three or less. | DISA Microsoft Windows 11 STIG v2r9 | Windows | ACCESS CONTROL |
| WN11-AC-000045 - Reversible password encryption must be disabled. | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-AU-000005 - The system must be configured to audit Account Logon - Credential Validation failures. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WNDF-AV-000011 - Microsoft Defender AV must be configured to only send safe samples for MAPS telemetry. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000017 - Microsoft Defender AV Group Policy settings must take priority over the local preference settings. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WNDF-AV-000021 - Microsoft Defender AV must be configured to always enable real-time protection. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WNDF-AV-000023 - Microsoft Defender AV must be configured to process scanning when real-time protection is enabled. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WNDF-AV-000029 - Microsoft Defender AV virus definition age must not exceed 7 days. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WNDF-AV-000030 - Microsoft Defender AV must be configured to check for definition updates daily. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WNDF-AV-000032 - Microsoft Defender AV must be configured to block executable content from email client and webmail. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000033 - Microsoft Defender AV must be configured block Office applications from creating child processes. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000035 - Microsoft Defender AV must be configured to block Office applications from injecting into other processes. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000036 - Microsoft Defender AV must be configured to impede JavaScript and VBScript to launch executables. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000040 - Microsoft Defender AV must be configured for automatic remediation action to be taken for threat alert level High. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000051 - Microsoft Defender AV must block abuse of exploited vulnerable signed drivers. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000058 - Microsoft Defender AV must enable extended cloud check. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000072 - Microsoft Defender AV must scan excluded files and directories during quick scans. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |