| 1.11 UBTU-24-100300 | CIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.12 UBTU-24-100310 | CIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.20 IBMW-LS-000770 | CIS IBM WebSphere Liberty Server STIG v1.0.0 CAT I | Unix | ACCESS CONTROL |
| 1.46 UBTU-22-251010 | CIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.47 UBTU-22-251015 | CIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.250 WN10-UR-000090 | CIS Microsoft Windows 10 STIG v1.0.0 CAT II | Windows | ACCESS CONTROL |
| 3.5.3.2.3 Ensure iptables rules exist for all open ports - PPSM CLSA and vulnerability assessments. | CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| 4.1.1 Ensure ufw is installed | CIS Ubuntu Linux 22.04 LTS v3.0.0 L1 Workstation | Unix | ACCESS CONTROL |
| 4.1.1 Ensure ufw is installed | CIS Ubuntu Linux 22.04 LTS v3.0.0 L1 Server | Unix | ACCESS CONTROL |
| AIOS-17-011000 - Apple iOS/iPadOS 17 must implement the management setting: Disable Allow MailDrop. | MobileIron - DISA Apple iOS/iPadOS 17 v2r2 | MDM | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| AIOS-17-011000 - Apple iOS/iPadOS 17 must implement the management setting: Disable Allow MailDrop. | AirWatch - DISA Apple iOS/iPadOS 17 v2r2 | MDM | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| AIOS-18-011000 - Apple iOS/iPadOS 18 must implement the management setting: disable Allow MailDrop. | AirWatch - DISA Apple iOS/iPadOS 18 v2r3 | MDM | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| AIOS-18-011000 - Apple iOS/iPadOS 18 must implement the management setting: disable Allow MailDrop. | MobileIron - DISA Apple iOS/iPadOS 18 v2r3 | MDM | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| AIOS-26-011000 - Apple iOS/iPadOS 26 must implement the management setting: disable Allow MailDrop. | AirWatch - DISA Apple iOS/iPadOS 26 v1r3 | MDM | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| AIOS-26-011000 - Apple iOS/iPadOS 26 must implement the management setting: disable Allow MailDrop. | MobileIron - DISA Apple iOS/iPadOS 26 v1r3 | MDM | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| AS24-U1-000670 - The Apache web server must restrict inbound connections from nonsecure zones. | DISA STIG Apache Server 2.4 Unix Server v3r2 | Unix | ACCESS CONTROL |
| AS24-W1-000670 - The Apache web server must restrict inbound connections from nonsecure zones. | DISA STIG Apache Server 2.4 Windows Server v3r4 | Windows | ACCESS CONTROL |
| AS24-W1-000670 - The Apache web server must restrict inbound connections from nonsecure zones. | DISA STIG Apache Server 2.4 Windows Server v2r3 | Windows | ACCESS CONTROL |
| ESXI-06-200035 - The VMM must provide the capability to immediately disconnect or disable remote access to the information system by disabling SSH. | DISA VMware vSphere ESXi 6.0 STIG v1r5 | VMware | CONFIGURATION MANAGEMENT |
| ESXi: esxi-8.deactivate-ssh | VMware vSphere Security Configuration and Hardening Guide | VMware | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| F5BI-LT-000153 - The BIG-IP Core implementation providing intermediary services for remote access communications traffic must control remote access methods to virtual servers. | DISA F5 BIG-IP Local Traffic Manager STIG v2r4 | F5 | ACCESS CONTROL |
| GEN001000 - Remote consoles must be disabled or protected from unauthorized access. | DISA STIG Solaris 10 X86 v2r4 | Unix | ACCESS CONTROL |
| GEN001000 - Remote consoles must be disabled or protected from unauthorized access. | DISA STIG Solaris 10 SPARC v2r4 | Unix | ACCESS CONTROL |
| GEN008540 - The system's local firewall must implement a deny-all, allow-by-exception policy. | DISA STIG Solaris 10 SPARC v2r4 | Unix | ACCESS CONTROL |
| GEN008540 - The system's local firewall must implement a deny-all, allow-by-exception policy. | DISA STIG Solaris 10 X86 v2r4 | Unix | ACCESS CONTROL |
| GOOG-15-008700 - Google Android 15 must be configured to enable authentication of personal hotspot connections to the device using a preshared key. | AirWatch - DISA Google Android 15 COPE STIG v1r5 | MDM | ACCESS CONTROL |
| GOOG-15-008700 - Google Android 15 must be configured to enable authentication of personal hotspot connections to the device using a preshared key. | MobileIron - DISA Google Android 15 COPE STIG v1r5 | MDM | ACCESS CONTROL |
| GOOG-16-008700 - Google Android 16 must be configured to enable authentication of personal hotspot connections to the device using a preshared key. | AirWatch - DISA Google Android 16 COBO STIG v1r3 | MDM | ACCESS CONTROL |
| GOOG-16-008700 - Google Android 16 must be configured to enable authentication of personal hotspot connections to the device using a preshared key. | MobileIron - DISA Google Android 16 COPE STIG v1r3 | MDM | ACCESS CONTROL |
| GOOG-16-008700 - Google Android 16 must be configured to enable authentication of personal hotspot connections to the device using a preshared key. | MobileIron - DISA Google Android 16 COBO STIG v1r1 | MDM | ACCESS CONTROL |
| GOOG-16-008700 - Google Android 16 must be configured to enable authentication of personal hotspot connections to the device using a preshared key. | MobileIron - DISA Google Android 16 COBO STIG v1r3 | MDM | ACCESS CONTROL |
| HONW-13-008700 - Honeywell Android 13 must be configured to enable authentication of personal hotspot connections to the device using a preshared key. | AirWatch - DISA Honeywell Android 13 COBO STIG v1r1 | MDM | ACCESS CONTROL |
| HONW-13-008700 - Honeywell Android 13 must be configured to enable authentication of personal hotspot connections to the device using a preshared key. | MobileIron - DISA Honeywell Android 13 COBO STIG v1r1 | MDM | ACCESS CONTROL |
| HONW-13-008700 - Honeywell Android 13 must be configured to enable authentication of personal hotspot connections to the device using a preshared key. | MobileIron - DISA Honeywell Android 13 COPE STIG v1r1 | MDM | ACCESS CONTROL |
| OH12-1X-000031 - OHS must have the Order, Allow, and Deny directives set within the Directory directives set to restrict inbound connections from nonsecure zones. | DISA STIG Oracle HTTP Server 12.1.3 v2r3 | Unix | ACCESS CONTROL |
| OH12-1X-000032 - OHS must have the Order, Allow, and Deny directives set within the Files directives set to restrict inbound connections from nonsecure zones. | DISA STIG Oracle HTTP Server 12.1.3 v2r3 | Unix | ACCESS CONTROL |
| OL09-00-000221 - OL 9 must be configured so that the firewalld service is active. | DISA Oracle Linux 9 STIG v1r5 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| OL09-00-000223 - OL 9 must control remote access methods. | DISA Oracle Linux 9 STIG v1r5 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| RHEL-09-251015 - The firewalld service on RHEL 9 must be active. | DISA Red Hat Enterprise Linux 9 STIG v2r8 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| RHEL-10-200531 - RHEL 10 must have the "firewalld" service set to active. | DISA Red Hat Enterprise Linux 10 STIG v1r1 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| RHEL-10-800000 - RHEL 10 must control remote access methods. | DISA Red Hat Enterprise Linux 10 STIG v1r1 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| SLES-15-010220 - The SUSE operating system must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments. | DISA SUSE Linux Enterprise Server 15 STIG v2r6 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| WBSP-AS-000130 - The WebSphere Application Server administrative security must be enabled. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | ACCESS CONTROL |
| WN11-UR-000090 - The 'Deny log on through Remote Desktop Services' user right on Windows 11 workstations must be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems. | DISA Microsoft Windows 11 STIG v2r7 | Windows | ACCESS CONTROL |
| WN12-CC-000134 - The system must be configured to ensure smart card devices can be redirected to the Remote Desktop session. (Remote Desktop Services Role). | DISA Windows Server 2012 and 2012 R2 DC STIG v3r7 | Windows | ACCESS CONTROL |
| WN16-MS-000410 - The 'Deny log on through Remote Desktop Services' user right on member servers must be configured to prevent access from highly privileged domain accounts and all local accounts on domain systems and from unauthenticated access on all systems. | DISA Microsoft Windows Server 2016 STIG v2r10 | Windows | ACCESS CONTROL |
| WN19-DC-000410 - Windows Server 2019 Deny log on through Remote Desktop Services user right on domain controllers must be configured to prevent unauthenticated access. | DISA Microsoft Windows Server 2019 STIG v3r8 | Windows | ACCESS CONTROL |
| WN19-MS-000120 - Windows Server 2019 'Deny log on through Remote Desktop Services' user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and all local accounts and from unauthenticated access on all systems. | DISA Microsoft Windows Server 2019 STIG v3r8 | Windows | ACCESS CONTROL |
| ZEBR-14-008700 - Zebra Android 14 must be configured to enable authentication of personal hotspot connections to the device using a preshared key. | AirWatch - DISA Zebra Android 14 COPE STIG v1r2 | MDM | ACCESS CONTROL |
| ZEBR-14-008700 - Zebra Android 14 must be configured to enable authentication of personal hotspot connections to the device using a preshared key. | MobileIron - DISA Zebra Android 14 COPE STIG v1r2 | MDM | ACCESS CONTROL |