| 1.2 SQLI-22-003700 | CIS Microsoft SQL Server 2022 Instance STIG v1.0.0 CAT I MS_SQLDB | MS_SQLDB | ACCESS CONTROL |
| 1.3 SQLI-22-003800 | CIS Microsoft SQL Server 2022 Instance STIG v1.0.0 CAT I MS_SQLDB | MS_SQLDB | ACCESS CONTROL |
| 1.5 O19C-00-000800 | CIS Oracle Database 19c STIG v1.1.0 CAT I OracleDB | OracleDB | ACCESS CONTROL |
| 1.12 RHEL-10-001040 | CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT I | Unix | CONFIGURATION MANAGEMENT |
| 1.17 CISC-RT-000240 | CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT I | Cisco | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.31 SQLI-22-008200 | CIS Microsoft SQL Server 2022 Instance STIG v1.0.0 CAT I MS_SQLDB | MS_SQLDB | IDENTIFICATION AND AUTHENTICATION |
| 1.34 CISC-ND-001210 | CIS Cisco IOS XE Switch NDM STIG v1.1.0 CAT I | Cisco | MAINTENANCE |
| 1.42 CISC-ND-001450 | CIS Cisco IOS Router NDM STIG v1.1.0 CAT I | Cisco | AUDIT AND ACCOUNTABILITY |
| 1.114 WN16-CC-000260 | CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT I | Windows | CONFIGURATION MANAGEMENT |
| 1.115 WN16-CC-000270 | CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT I | Windows | CONFIGURATION MANAGEMENT |
| 1.115 WN22-CC-000220 | CIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT I | Windows | CONFIGURATION MANAGEMENT |
| 1.154 WN22-DC-000080 | CIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT I | Windows | ACCESS CONTROL |
| 1.189 WN16-MS-000010 | CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT I | Windows | ACCESS CONTROL |
| 1.261 WN16-UR-000130 | CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT I | Windows | ACCESS CONTROL |
| 1.261 WN16-UR-000130 | CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT I | Windows | ACCESS CONTROL |
| 1.263 WN22-UR-000100 | CIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT I | Windows | ACCESS CONTROL |
| 1.291 RHEL-10-600740 | CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT I | Unix | IDENTIFICATION AND AUTHENTICATION |
| 1.367 RHEL-10-700960 | CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT I | Unix | ACCESS CONTROL |
| ALMA-09-003210 - AlmaLinux OS 9 SSH client must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | ACCESS CONTROL |
| ALMA-09-003980 - AlmaLinux OS 9 must implement DOD-approved encryption in the OpenSSL package. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | ACCESS CONTROL |
| ALMA-09-009700 - AlmaLinux OS 9 must ensure cryptographic verification of vendor software packages. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | CONFIGURATION MANAGEMENT |
| ALMA-09-009810 - AlmaLinux OS 9 must check the GPG signature of locally installed software packages before installation. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | CONFIGURATION MANAGEMENT |
| ARST-ND-000700 - The Arista network device must be configured to implement cryptographic mechanisms using a FIPS 140-2 approved algorithm to protect the confidentiality of remote maintenance sessions. | DISA STIG Arista MLS EOS 4.2x NDM v2r1 | Arista | MAINTENANCE |
| AZLX-23-000115 - Amazon Linux 2023 must check the GPG signature of locally installed software packages before installation. | DISA Amazon Linux 2023 STIG v1r4 | Unix | CONFIGURATION MANAGEMENT |
| AZLX-23-001211 - The Amazon Linux 2023 SSH client must be configured to use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. | DISA Amazon Linux 2023 STIG v1r4 | Unix | ACCESS CONTROL |
| EPAS-00-000700 - The EDB Postgres Advanced Server must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals. | EnterpriseDB PostgreSQL Advanced Server OS Linux v2r1 | Unix | ACCESS CONTROL |
| F5BI-VN-300004 - The F5 BIG-IP appliance must be configured to use a Diffie-Hellman (DH) Group of 16 or greater for Internet Key Exchange (IKE) Phase 1. | DISA F5 BIG-IP TMOS VPN STIG v1r1 | F5 | ACCESS CONTROL |
| F5BI-VN-300005 - The F5 BIG-IP appliance IPsec VPN Gateway must use AES256 or higher encryption for the Internet Key Exchange (IKE) proposal to protect confidentiality of remote access sessions. | DISA F5 BIG-IP TMOS VPN STIG v1r1 | F5 | ACCESS CONTROL |
| GOOG-15-012500 - Google Android 15 must be configured to disable 'Private Space' use - Private Space use. | MobileIron - DISA Google Android 15 COPE STIG v1r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-16-012500 - Google Android 16 must be configured to disable 'Private Space' use - Private Space use. | MobileIron - DISA Google Android 16 COBO STIG v1r3 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-16-012500 - Google Android 16 must be configured to disable 'Private Space' use - Private Space use. | MobileIron - DISA Google Android 16 COPE STIG v1r3 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-16-012500 - Google Android 16 must be configured to disable 'Private Space' use - Private Space use. | AirWatch - DISA Google Android 16 COPE STIG v1r1 | MDM | CONFIGURATION MANAGEMENT |
| MADB-10-000200 - MariaDB must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | ACCESS CONTROL |
| MADB-10-008600 - MariaDB must implement cryptographic mechanisms to prevent unauthorized modification of organization-defined information at rest (to include, at a minimum, PII and classified information) on organization-defined information system components. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| O19C-00-008000 - The Oracle Database software installation account must be restricted to authorized users. | DISA Oracle Database 19c STIG v1r3 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| OL08-00-010186 - OL 8 IP tunnels must use FIPS 140-3-approved cryptographic algorithms. | DISA Oracle Linux 8 STIG v2r9 | Unix | ACCESS CONTROL |
| OL09-00-000255 - OL 9 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections. | DISA Oracle Linux 9 STIG v1r6 | Unix | ACCESS CONTROL |
| OL09-00-002413 - OL 9 must be configured so that the x86 Ctrl-Alt-Delete key sequence is disabled. | DISA Oracle Linux 9 STIG v1r6 | Unix | ACCESS CONTROL |
| OS10-NDM-000780 - The Dell OS10 Switch must use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of nonlocal maintenance and diagnostic communications. | DISA Dell OS10 Switch NDM STIG v1r1 | Dell_OS10 | MAINTENANCE |
| OS10-NDM-000970 - The Dell OS10 Switch must be configured to send log data to at least two central log servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO). | DISA Dell OS10 Switch NDM STIG v1r1 | Dell_OS10 | AUDIT AND ACCOUNTABILITY |
| RHEL-08-010296 - The RHEL 8 SSH client must be configured to use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. | DISA Red Hat Enterprise Linux 8 STIG v2r8 | Unix | ACCESS CONTROL |
| RHEL-09-671020 - RHEL 9 IP tunnels must use FIPS 140-3 approved cryptographic algorithms. | DISA Red Hat Enterprise Linux 9 STIG v2r9 | Unix | ACCESS CONTROL |
| SQL2-00-017500 - SQL Server must recover to a known state that is verifiable. | DISA STIG SQL Server 2012 DB Instance Security v1r20 | MS_SQLDB | CONTINGENCY PLANNING |
| SQL2-00-022600 - SQL Server must employ cryptographic mechanisms preventing the unauthorized disclosure of information during transmission. | DISA STIG SQL Server 2012 DB Instance Security v1r20 | MS_SQLDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| VCFL-67-000007 - vSphere Client must be configured to only communicate over TLS 1.2. | DISA STIG VMware vSphere 6.7 Virgo Client v1r2 | Unix | ACCESS CONTROL |
| WN22-CC-000220 - Windows Server 2022 default AutoRun behavior must be configured to prevent AutoRun commands. | DISA Microsoft Windows Server 2022 STIG v2r8 | Windows | CONFIGURATION MANAGEMENT |
| WN22-CC-000230 - Windows Server 2022 AutoPlay must be disabled for all drives. | DISA Microsoft Windows Server 2022 STIG v2r8 | Windows | CONFIGURATION MANAGEMENT |
| WN22-DC-000100 - Windows Server 2022 Active Directory Domain Controllers Organizational Unit (OU) object must have the proper access control permissions. | DISA Microsoft Windows Server 2022 STIG v2r8 | Windows | ACCESS CONTROL |
| WN22-MS-000010 - Windows Server 2022 must only allow administrators responsible for the member server or standalone or nondomain-joined system to have Administrator rights on the system. | DISA Microsoft Windows Server 2022 STIG v2r8 | Windows | ACCESS CONTROL |
| WN22-UR-000100 - Windows Server 2022 debug programs user right must only be assigned to the Administrators group. | DISA Microsoft Windows Server 2022 STIG v2r8 | Windows | ACCESS CONTROL |