| 1.2.3 (L1) Ensure 'Allow Administrator account lockout' is set to 'Enabled' (MS only) | CIS Windows Server 2012 R2 MS L1 v3.0.0 | Windows | ACCESS CONTROL |
| 1.3.6 Apply Security Context to Your Pods and Containers | CIS Kubernetes 1.7.0 Benchmark v1.1.0 L2 | Unix | |
| 1.3.6 Apply Security Context to Your Pods and Containers | CIS Kubernetes 1.8 Benchmark v1.2.0 L2 | Unix | |
| 1.6.6 Apply Security Context to Your Pods and Containers | CIS Kubernetes 1.7.0 Benchmark v1.1.0 L2 | Unix | |
| 1.113 WN11-CC-000037 | CIS Microsoft Windows 11 STIG v1.2.0 CAT II | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.7.3 Apply Security Context to Your Pods and Containers | CIS Kubernetes v1.23 Benchmark v1.0.1 L2 Master | Unix | CONFIGURATION MANAGEMENT |
| 5.7.3 Apply Security Context to Your Pods and Containers | CIS Kubernetes v1.24 Benchmark v1.0.0 L2 Master | Unix | CONFIGURATION MANAGEMENT |
| 5.7.3 Apply Security Context to Your Pods and Containers | CIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShift | OpenShift | RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY |
| 8.6 Enable SSL communication with LDAP server | CIS IBM DB2 9 Benchmark v3.0.1 Level 1 OS Windows | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.9.25.1 (L1) Ensure 'EMET 5.52' or higher is installed | CIS Microsoft Windows Server 2008 Domain Controller Level 1 v3.3.1 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.9.25.1 (L1) Ensure 'EMET 5.52' or higher is installed | CIS Microsoft Windows Server 2008 R2 Member Server Level 1 v3.3.1 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.10.24.1 (L1) Ensure 'EMET 5.52' or higher is installed | CIS Windows Server 2012 R2 DC L1 v3.0.0 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.10.24.1 (L1) Ensure 'EMET 5.52' or higher is installed | CIS Windows Server 2012 MS L1 v3.0.0 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.10.24.1 (L1) Ensure 'EMET 5.52' or higher is installed | CIS Windows Server 2012 DC L1 v3.0.0 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| Apply UAC restrictions to local accounts on network logon | MSCT Windows Server 2016 MS v1.0.0 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows 11 v23H2 v1.0.0 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows 10 1909 v1.0.0 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows 10 v21H1 v1.0.0 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows Server v1909 MS v1.0.0 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows Server v20H2 MS v1.0.0 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows 10 1903 v1.19.9 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows 10 v2004 v1.0.0 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows 10 v20H2 v1.0.0 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows Server v2004 MS v1.0.0 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows Server 2025 MS v1.0.0 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows Server 2025 MS v2506 v1.0.0 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows Server 2019 MS v1.0.0 | Windows | ACCESS CONTROL |
| CIS Microsoft IIS 8 Benchmark v1.5.1 Level 2 | CIS IIS 8.0 v1.5.1 Level 2 | Windows | |
| CIS_Microsoft_Windows_10_Enterprise_v5.0.0_L1.audit from CIS Microsoft Windows 10 Enterprise v5.0.0 | CIS Microsoft Windows 10 Enterprise v5.0.0 L1 | Windows | |
| CIS_Microsoft_Windows_Server_2016_STIG_v4.0.0_DC_CAT_I.audit from CIS Microsoft Windows Server 2016 STIG v4.0.0 | CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT I | Windows | |
| CIS_Microsoft_Windows_Server_2016_STIG_v4.0.0_MS_CAT_III.audit from CIS Microsoft Windows Server 2016 STIG v4.0.0 | CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT III | Windows | |
| CIS_Microsoft_Windows_Server_2016_v4.0.0_L1_DC.audit from CIS Microsoft Windows Server 2016 Benchmark v4.0.0 | CIS Microsoft Windows Server 2016 v4.0.0 L1 DC | Windows | |
| CIS_Microsoft_Windows_Server_2019_STIG_v4.0.0_DC_CAT_I.audit from CIS Microsoft Windows Server 2019 STIG v4.0.0 | CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT I | Windows | |
| CIS_Microsoft_Windows_Server_2019_STIG_v4.0.0_DC_CAT_II.audit from CIS Microsoft Windows Server 2019 STIG v4.0.0 | CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT II | Windows | |
| CIS_Microsoft_Windows_Server_2022_STIG_v3.0.0_DC_CAT_I.audit from CIS Microsoft Windows Server 2022 STIG v3.0.0 | CIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT I | Windows | |
| CIS_MS_Windows_7_v3.2.0_Bitlocker.audit from CIS Microsoft Windows 7 Workstation Benchmark v3.2.0 | CIS Windows 7 Workstation Bitlocker v3.2.0 | Windows | |
| CIS_MS_Windows_7_v3.2.0_Level_2_Bitlocker.audit from CIS Microsoft Windows 7 Workstation Benchmark v3.2.0 | CIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0 | Windows | |
| Configure RPC packet level privacy setting for incoming connections | MSCT Windows 11 v23H2 v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
| Configure RPC packet level privacy setting for incoming connections | MSCT Windows 11 v22H2 v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
| Extended Protection for LDAP Authentication (Domain Controllers only) (DEPRECATED) | MSCT Windows Server v2004 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
| Extended Protection for LDAP Authentication (Domain Controllers only) (DEPRECATED) | MSCT Windows Server 2025 DC v2506 v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
| Extended Protection for LDAP Authentication (Domain Controllers only) (DEPRECATED) | MSCT Windows Server v20H2 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
| Extended Protection for LDAP Authentication (Domain Controllers only) (DEPRECATED) | MSCT Windows Server 2025 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000037 - Local administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain systems. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN12-AD-000009-DC - The directory server supporting (directly or indirectly) system access or resource authorization must run on a machine dedicated to that function - Services | DISA Windows Server 2012 and 2012 R2 DC STIG v3r7 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN19-MS-000020 - Windows Server 2019 local administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain-joined member servers. | DISA Microsoft Windows Server 2019 STIG v3r8 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN22-MS-000020 - Windows Server 2022 local administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain-joined member servers. | DISA Microsoft Windows Server 2022 STIG v2r10 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN22-MS-000140 - Windows Server 2022 must be running Credential Guard on domain-joined member servers. | DISA Microsoft Windows Server 2022 STIG v2r8 | Windows | CONFIGURATION MANAGEMENT |
| WN25-00-000390 - Windows Server 2025 must have the Server Message Block (SMB) v1 protocol disabled on the SMB server. | DISA Microsoft Windows Server 2025 STIG v1r3 | Windows | CONFIGURATION MANAGEMENT |
| WN25-MS-000020 - Windows Server 2025 local administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain-joined member servers. | DISA Microsoft Windows Server 2025 STIG v1r3 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |