| 1.4 AZLX-23-000120 | CIS Amazon Linux 2023 STIG v1.0.0 CAT I | Unix | CONFIGURATION MANAGEMENT |
| 1.5 ESXI-80-000014 | CIS VMware vSphere 8.0 ESXi STIG v1.0.0 CAT I Unix | Unix | ACCESS CONTROL |
| 1.18 CISC-RT-000240 | CIS Cisco IOS XE Router RTR STIG v1.1.0 CAT I | Cisco | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.32 SQLI-22-008300 | CIS Microsoft SQL Server 2022 Instance STIG v1.0.0 CAT I Windows | Windows | IDENTIFICATION AND AUTHENTICATION |
| 1.38 CISC-ND-001370 | CIS Cisco IOS XE Switch NDM STIG v1.1.0 CAT I | Cisco | CONFIGURATION MANAGEMENT |
| 1.72 O19C-00-015200 | CIS Oracle Database 19c STIG v1.1.0 CAT I Windows | Windows | IDENTIFICATION AND AUTHENTICATION |
| 1.85 O19C-00-017700 | CIS Oracle Database 19c STIG v1.1.0 CAT I Windows | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.113 WN16-CC-000250 | CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT I | Windows | CONFIGURATION MANAGEMENT |
| 1.114 WN16-CC-000260 | CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT I | Windows | CONFIGURATION MANAGEMENT |
| 1.115 WN16-CC-000270 | CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT I | Windows | CONFIGURATION MANAGEMENT |
| 1.116 WN22-CC-000230 | CIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT I | Windows | CONFIGURATION MANAGEMENT |
| 1.135 WN16-CC-000460 | CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT I | Windows | CONFIGURATION MANAGEMENT |
| 1.135 WN16-CC-000460 | CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT I | Windows | CONFIGURATION MANAGEMENT |
| 1.156 WN16-DC-000110 | CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT I | Windows | ACCESS CONTROL |
| 1.157 WN22-DC-000110 | CIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT I | Windows | ACCESS CONTROL |
| 1.257 WN16-UR-000090 | CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT I | Windows | ACCESS CONTROL |
| 1.263 WN22-UR-000100 | CIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT I | Windows | ACCESS CONTROL |
| AIOS-01-080006 - Apple iOS must require a valid password be successfully entered before the mobile device data is unencrypted. | AirWatch - DISA Apple iOS 10 v1r3 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |
| ALMA-09-003100 - AlmaLinux OS 9 must implement DOD-approved encryption ciphers to protect the confidentiality of SSH connections. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | ACCESS CONTROL |
| ALMA-09-006730 - The Ctrl-Alt-Delete key sequence must be disabled on AlmaLinux OS 9. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | ACCESS CONTROL |
| ALMA-09-009920 - AlmaLinux OS 9 must check the GPG signature of repository metadata before package installation. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | CONFIGURATION MANAGEMENT |
| ALMA-09-010030 - AlmaLinux OS 9 must have GPG signature verification enabled for all software repositories. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | CONFIGURATION MANAGEMENT |
| ARST-ND-000810 - The network device must be configured to use an authentication server to authenticate users prior to granting administrative access. | DISA STIG Arista MLS EOS 4.2x NDM v2r1 | Arista | CONFIGURATION MANAGEMENT |
| ARST-RT-000330 - The Arista perimeter router must be configured to deny network traffic by default and allow network traffic by exception. | DISA Arista MLS EOS 4.X Router STIG v2r2 | Arista | SYSTEM AND COMMUNICATIONS PROTECTION |
| AZLX-23-000050 - Amazon Linux 2023 must enable FIPS mode. | DISA Amazon Linux 2023 STIG v1r4 | Unix | ACCESS CONTROL |
| AZLX-23-001206 - The Amazon Linux 2023 SSH client must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. | DISA Amazon Linux 2023 STIG v1r4 | Unix | ACCESS CONTROL |
| CASA-VN-000440 - The Cisco ASA remote access VPN server must be configured to enforce certificate-based authentication before granting access to the network. | DISA STIG Cisco ASA VPN v2r2 | Cisco | IDENTIFICATION AND AUTHENTICATION |
| CASA-VN-000550 - The Cisco ASA remote access VPN server must be configured to use TLS 1.2 or higher to protect the confidentiality of remote access connections. | DISA STIG Cisco ASA VPN v2r2 | Cisco | ACCESS CONTROL |
| FGFW-ND-000260 - The FortiGate devices must use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of nonlocal maintenance and diagnostic communications. | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | MAINTENANCE |
| GOOG-15-012500 - Google Android 15 must be configured to disable 'Private Space' use - Private Space use. | MobileIron - DISA Google Android 15 COBO STIG v1r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-16-012500 - Google Android 16 must be configured to disable 'Private Space' use - Private Space use. | AirWatch - DISA Google Android 16 COPE STIG v1r3 | MDM | CONFIGURATION MANAGEMENT |
| MD7X-00-000200 - MongoDB must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals. | DISA MongoDB Enterprise Advanced 7.x STIG v1r2 Unix | Unix | ACCESS CONTROL |
| MD7X-00-002700 MongoDB software installation account must be restricted to authorized users. | DISA MongoDB Enterprise Advanced 7.x STIG v1r1 | Unix | CONFIGURATION MANAGEMENT |
| O19C-00-017700 - Oracle Database must employ cryptographic mechanisms preventing the unauthorized disclosure of information during transmission unless the transmitted data is otherwise protected by alternative physical measures. | DISA Oracle Database 19c STIG v1r3 Unix | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| O19C-00-017700 - Oracle Database must employ cryptographic mechanisms preventing the unauthorized disclosure of information during transmission unless the transmitted data is otherwise protected by alternative physical measures. | DISA Oracle Database 19c STIG v1r3 Windows | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| OL09-00-000261 - OL 9 SSH client must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. | DISA Oracle Linux 9 STIG v1r6 | Unix | ACCESS CONTROL |
| OL09-00-000496 - OL 9 must check the GPG signature of locally installed software packages before installation. | DISA Oracle Linux 9 STIG v1r6 | Unix | CONFIGURATION MANAGEMENT |
| OL09-00-002404 - OL 9 IP tunnels must use 140-3 approved cryptographic algorithms. | DISA Oracle Linux 9 STIG v1r6 | Unix | ACCESS CONTROL |
| OL09-00-002412 - OL 9 must be configured so that the systemd Ctrl-Alt-Delete burst key sequence is disabled. | DISA Oracle Linux 9 STIG v1r6 | Unix | ACCESS CONTROL |
| RHEL-08-010020 - RHEL 8 must implement a FIPS 140-3-compliant systemwide cryptographic policy. | DISA Red Hat Enterprise Linux 8 STIG v2r8 | Unix | ACCESS CONTROL |
| RHEL-08-010297 - The RHEL 8 SSH client must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. | DISA Red Hat Enterprise Linux 8 STIG v2r8 | Unix | ACCESS CONTROL |
| RHEL-09-211050 - The x86 Ctrl-Alt-Delete key sequence must be disabled on RHEL 9. | DISA Red Hat Enterprise Linux 9 STIG v2r9 | Unix | ACCESS CONTROL |
| RHEL-09-255064 - The RHEL 9 SSH client must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. | DISA Red Hat Enterprise Linux 9 STIG v2r9 | Unix | ACCESS CONTROL |
| SHPT-00-000640 - Applications must support organizational requirements to employ cryptographic mechanisms to protect information in storage. | DISA STIG SharePoint 2010 v1r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| SQL2-00-016500 - SQL Server must have the SQL Server Data Tools (SSDT) software component removed from SQL Server if SSDT is unused. | DISA STIG SQL Server 2012 Database OS Audit v1r20 | Windows | CONFIGURATION MANAGEMENT |
| WN22-DC-000080 - Windows Server 2022 Active Directory SYSVOL directory must have the proper access control permissions. | DISA Microsoft Windows Server 2022 STIG v2r8 | Windows | ACCESS CONTROL |
| WN22-DC-000090 - Windows Server 2022 Active Directory Group Policy objects must have proper access control permissions. | DISA Microsoft Windows Server 2022 STIG v2r8 | Windows | ACCESS CONTROL |
| WN25-CC-000430 - Windows Server 2025 must disable the Windows Installer Always install with elevated privileges option. | DISA Microsoft Windows Server 2025 STIG v1r1 | Windows | CONFIGURATION MANAGEMENT |
| WN25-DC-000080 - Windows Server 2025 Active Directory SYSVOL directory must have the proper access control permissions. | DISA Microsoft Windows Server 2025 STIG v1r1 | Windows | ACCESS CONTROL |
| WN25-UR-000020 - The Windows Server 2025 'Act as part of the operating system' user right must not be assigned to any groups or accounts. | DISA Microsoft Windows Server 2025 STIG v1r1 | Windows | ACCESS CONTROL |