| 1.2.6 - AirWatch - Disable 'plug-ins' | AirWatch - CIS Google Android 4 v1.0.0 L2 | MDM | ACCESS CONTROL |
| 1.2.6 - MobileIron - Disable 'plug-ins' - 'Samsung SAFE' | MobileIron - CIS Google Android 4 v1.0.0 L2 | MDM | ACCESS CONTROL |
| 1.412 RHEL-10-800110 | CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.2.2 Ensure time set is within appropriate limits | CIS Apple OSX 10.9 L1 v1.3.0 | Unix | CONFIGURATION MANAGEMENT |
| 3.3 Ensure that MongoDB is run using a non-privileged, dedicated service account | CIS MongoDB 8 v1.0.0 L1 Windows | Windows | ACCESS CONTROL |
| 3.3 Ensure that MongoDB is run using a non-privileged, dedicated service account | CIS MongoDB 5 v1.2.0 L1 Unix | Unix | ACCESS CONTROL |
| 5.7 Do not enable the "root" account | CIS Apple OSX 10.9 L1 v1.3.0 | Unix | ACCESS CONTROL |
| 5.18 Install an approved tokend for smartcard authentication | CIS Apple OSX 10.9 L2 v1.3.0 | Unix | IDENTIFICATION AND AUTHENTICATION |
| CIS_Red_Hat_EL7_STIG_v2.0.0_L1_Server.audit from CIS Red Hat Enterprise Linux 7 STIG v2.0.0 | CIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 Server | Unix | |
| CIS_Red_Hat_EL7_STIG_v2.0.0_L2_Server.audit from CIS Red Hat Enterprise Linux 7 STIG v2.0.0 | CIS Red Hat Enterprise Linux 7 STIG v2.0.0 L2 Server | Unix | |
| CIS_Red_Hat_Enterprise_Linux_8_STIG_v2.0.0_L1_Workstation.audit from CIS Red Hat Enterprise Linux 8 STIG v2.0.0 | CIS Red Hat Enterprise Linux 8 STIG v2.0.0 L1 Workstation | Unix | |
| CIS_Red_Hat_Enterprise_Linux_8_STIG_v2.0.0_L2_Server.audit from CIS Red Hat Enterprise Linux 8 STIG v2.0.0 | CIS Red Hat Enterprise Linux 8 STIG v2.0.0 L2 Server | Unix | |
| CIS_Red_Hat_Enterprise_Linux_8_STIG_v2.0.0_L2_Workstation.audit from CIS Red Hat Enterprise Linux 8 STIG v2.0.0 | CIS Red Hat Enterprise Linux 8 STIG v2.0.0 L2 Workstation | Unix | |
| CIS_Red_Hat_Enterprise_Linux_8_STIG_v2.0.0_STIG.audit from CIS Red Hat Enterprise Linux 8 STIG v2.0.0 | CIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIG | Unix | |
| CIS_Red_Hat_Enterprise_Linux_9_STIG_v1.0.0_CAT_I.audit from CIS Red Hat Enterprise Linux 9 STIG v1.0.0 | CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT I | Unix | |
| CIS_Red_Hat_Enterprise_Linux_9_STIG_v1.0.0_CAT_II.audit from CIS Red Hat Enterprise Linux 9 STIG v1.0.0 | CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II | Unix | |
| CIS_Red_Hat_Enterprise_Linux_9_STIG_v1.0.0_CAT_III.audit from CIS Red Hat Enterprise Linux 9 STIG v1.0.0 | CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT III | Unix | |
| CIS_Red_Hat_Enterprise_Linux_10_STIG_v1.0.0_CAT_I.audit from CIS Red Hat Enterprise Linux 10 STIG v1.0.0 | CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT I | Unix | |
| CIS_Red_Hat_Enterprise_Linux_10_STIG_v1.0.0_CAT_II.audit from CIS Red Hat Enterprise Linux 10 STIG v1.0.0 | CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II | Unix | |
| CIS_Red_Hat_Enterprise_Linux_10_STIG_v1.0.0_CAT_III.audit from CIS Red Hat Enterprise Linux 10 STIG v1.0.0 | CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT III | Unix | |
| CIS_SUSE_Linux_Enterprise_Server_15_STIG_v1.0.0_CAT_I.audit from CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 | CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT I | Unix | |
| CIS_SUSE_Linux_Enterprise_Server_15_STIG_v1.0.0_CAT_II.audit from CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 | CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT II | Unix | |
| CIS_SUSE_Linux_Enterprise_Server_15_STIG_v1.0.0_CAT_III.audit from CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 | CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT III | Unix | |
| DISA_STIG_McAfee_VSEL_1.9.x_2.0.x_Managed_Client_v1r5.audit from DISA McAfee VSEL 1.9/2.0 Managed Client v1r5 STIG | McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Managed Client v1r5 | Unix | |
| DISA_STIG_VMware_vSphere_8.0_vCenter_Appliance_User_Interface_UI_v2r2.audit from DISA VMware vSphere 8.0 vCenter Appliance User Interface UI STIG v2r2 | DISA VMware vSphere 8.0 vCenter Appliance User Interface UI STIG v2r2 | Unix | |
| DTAVSEL-017 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x On-Access scanner must be configured to deny access to the file if scanning fails. | McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Managed Client v1r5 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| DTAVSEL-018 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x On-Access scanner must be configured to allow access to files if scanning times out. | McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Managed Client v1r5 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| DTAVSEL-100 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x must be configured to run a scheduled On-Demand scan at least once a week. | McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Local Client v1r6 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| DTAVSEL-113 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x On-Demand scanner must be configured to include all local drives and their sub-directories. | McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Managed Client v1r5 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| EPAS-00-000800 - The EDB Postgres Advanced Server must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies. | EnterpriseDB PostgreSQL Advanced Server OS Linux v2r1 | Unix | ACCESS CONTROL |
| EPAS-00-002400 - The EDB Postgres Advanced Server must be configurable to overwrite audit log records, oldest first (First-In-First-Out [FIFO]), in the event of unavailability of space for more audit log records. | EnterpriseDB PostgreSQL Advanced Server OS Linux v2r1 | Unix | AUDIT AND ACCOUNTABILITY |
| EPAS-00-002700 - The audit information produced by the EDB Postgres Advanced Server must be protected from unauthorized modification. | EnterpriseDB PostgreSQL Advanced Server OS Linux v2r1 | Unix | AUDIT AND ACCOUNTABILITY |
| EPAS-00-004200 - The EDB Postgres Advanced Server must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users). | EnterpriseDB PostgreSQL Advanced Server OS Linux v2r1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| EPAS-00-006100 - Access to database files must be limited to relevant processes and to authorized, administrative users. | EnterpriseDB PostgreSQL Advanced Server OS Linux v2r1 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| EPAS-00-007400 - The EDB Postgres Advanced Server must prevent nonprivileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures. | EnterpriseDB PostgreSQL Advanced Server OS Linux v2r1 | Unix | ACCESS CONTROL |
| O121-C2-012900 - The DBMS must use multifactor authentication for access to user accounts. | DISA Oracle Database 12c STIG v3r5 Unix | Unix | IDENTIFICATION AND AUTHENTICATION |
| O121-C2-012900 - The DBMS must use multifactor authentication for access to user accounts. | DISA Oracle Database 12c STIG v3r5 Windows | Windows | IDENTIFICATION AND AUTHENTICATION |
| PHTN-67-000012 - The Photon operating system must be configured to audit the execution of privileged functions - uid 64 | DISA STIG VMware vSphere 6.7 Photon OS v1r6 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| SLES-12-020240 - The SUSE operating system must generate audit records for all uses of the privileged functions. | DISA SLES 12 STIG v3r5 | Unix | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| SPLK-CL-000060 - Splunk Enterprise must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period. | DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG OS | Unix | ACCESS CONTROL |
| SPLK-CL-000100 - Splunk Enterprise installation directories must be secured. | DISA STIG Splunk Enterprise 7.x for Windows v3r2 OS | Windows | AUDIT AND ACCOUNTABILITY |
| SPLK-CL-000120 - The System Administrator (SA) and Information System Security Manager (ISSM) must configure the retention of the log records based on the defined security plan. | DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG OS | Unix | AUDIT AND ACCOUNTABILITY |
| SPLK-CL-000175 - Splunk Enterprise forwarders must be configured with Indexer Acknowledgement enabled. | DISA STIG Splunk Enterprise 7.x for Windows v3r2 OS | Windows | CONFIGURATION MANAGEMENT |
| SPLK-CL-000190 - Splunk Enterprise installation directories must be secured. | DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG OS | Unix | AUDIT AND ACCOUNTABILITY |
| SPLK-CL-000340 - Splunk Enterprise must be configured to enforce password complexity by requiring that at least one uppercase character be used. | DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG OS | Unix | IDENTIFICATION AND AUTHENTICATION |
| SPLK-CL-000360 - Splunk Enterprise must be configured to enforce password complexity by requiring that at least one numeric character be used. | DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG OS | Unix | IDENTIFICATION AND AUTHENTICATION |
| SPLK-CL-000400 - Splunk Enterprise must be configured to enforce a 60-day maximum password lifetime restriction. | DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG OS | Unix | IDENTIFICATION AND AUTHENTICATION |
| SPLK-CL-000500 - Splunk Enterprise must use a version supported by the vendor. | DISA STIG Splunk Enterprise 7.x for Windows v3r2 OS | Windows | SYSTEM AND INFORMATION INTEGRITY |
| SPLK-CL-000510 - Splunk Enterprise must use a version supported by the vendor. | DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG OS | Unix | SYSTEM AND INFORMATION INTEGRITY |
| WN10-UR-000090 - The Deny log on through Remote Desktop Services user right on Windows 10 workstations must at a minimum be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems. | DISA Microsoft Windows 10 STIG v3r6 | Windows | ACCESS CONTROL |