| 1.2.1.5 Ensure DNF is configured to perform a signature check on local packages | CIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIG | Unix | CONFIGURATION MANAGEMENT |
| 1.5 O365-CO-000002 | CIS Microsoft Office 365 ProPlus STIG v1.1.0 CAT I | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.8.14 Ensure unrestricted logon is not allowed | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| 1.11 Ensure anti-virus is installed and running | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | SYSTEM AND INFORMATION INTEGRITY |
| 1.68 UBTU-24-300025 | CIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT I | Unix | CONFIGURATION MANAGEMENT |
| 1.99 UBTU-22-611060 | CIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT I | Unix | CONFIGURATION MANAGEMENT |
| 1.105 UBTU-24-600130 | CIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT I | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.2.20 Ensure the rsh package has been removed | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| 2.2.23 Ensure default SNMP community strings don't exist | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| AIOS-17-706950 - Apple iOS/iPadOS 17 must be configured to enforce a passcode reuse prohibition of at least two generations. | AirWatch - DISA Apple iOS/iPadOS 17 BYOAD v1r2 | MDM | IDENTIFICATION AND AUTHENTICATION |
| AIOS-17-706950 - Apple iOS/iPadOS 17 must be configured to enforce a passcode reuse prohibition of at least two generations. | MobileIron - DISA Apple iOS/iPadOS BYOAD 17 v1r2 | MDM | IDENTIFICATION AND AUTHENTICATION |
| ALMA-09-002990 - AlmaLinux OS 9 SSH client must be configured to use only encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | ACCESS CONTROL |
| ALMA-09-003870 - AlmaLinux OS 9 IP tunnels must use FIPS 140-3 approved cryptographic algorithms. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | ACCESS CONTROL |
| ALMA-09-009590 - AlmaLinux OS 9 must check the GPG signature of software packages originating from external software repositories before installation. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | CONFIGURATION MANAGEMENT |
| APPL-11-002031 - The macOS system must be configured to disable the system preference pane for Apple ID. | DISA STIG Apple macOS 11 v1r5 | Unix | CONFIGURATION MANAGEMENT |
| APPL-11-002038 - Apple macOS must be configured to disable the tftp service. | DISA STIG Apple macOS 11 v1r5 | Unix | IDENTIFICATION AND AUTHENTICATION |
| ARBA-VN-002430 - AOS, when used as a VPN Gateway, must not accept certificates that have been revoked when using PKI for authentication. | DISA HPE Aruba Networking AOS VPN STIG v1r1 | ArubaOS | IDENTIFICATION AND AUTHENTICATION |
| ARST-RT-000450 - The Arista perimeter router must be configured to restrict it from accepting outbound IP packets that contain an illegitimate address in the source address field via egress filter or by enabling Unicast Reverse Path Forwarding (uRPF). | DISA STIG Arista MLS EOS 4.2x Router v2r1 | Arista | SYSTEM AND COMMUNICATIONS PROTECTION |
| AZLX-23-001205 - Amazon Linux 2023 server must be configured to use only DOD-approved encryption ciphers employing FIPS 140-2/140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections. | DISA Amazon Linux 2023 STIG v1r4 | Unix | ACCESS CONTROL |
| CD12-00-000800 - If passwords are used for authentication, PostgreSQL must transmit only encrypted representations of passwords. | DISA STIG Crunchy Data PostgreSQL OS v3r1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| CD16-00-000200 - PostgreSQL must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals. | DISA Crunchy Data Postgres 16 STIG v1r3 PostgreSQLDB | PostgreSQLDB | ACCESS CONTROL |
| CD16-00-008500 - PostgreSQL must implement cryptographic mechanisms to prevent unauthorized modification of organization-defined information at rest (to include, at a minimum, PII and classified information) on organization-defined information system components. | DISA Crunchy Data Postgres 16 STIG v1r3 PostgreSQLDB | PostgreSQLDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| ESXI-80-000014 - The ESXi host Secure Shell (SSH) daemon must use FIPS 140-2 validated cryptographic modules to protect the confidentiality of remote access sessions. | DISA VMware vSphere 8.0 ESXi STIG v2r4 Unix | Unix | ACCESS CONTROL |
| F5BI-FW-300020 - The F5 BIG-IP appliance must deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception). | DISA F5 BIG-IP TMOS Firewall STIG v1r1 | F5 | SYSTEM AND COMMUNICATIONS PROTECTION |
| F5BI-VN-300006 - The F5 BIG-IP appliance IPsec VPN must use AES256 or greater encryption for the IPsec proposal. | DISA F5 BIG-IP TMOS VPN STIG v1r1 | F5 | ACCESS CONTROL |
| FGFW-ND-000245 - The FortiGate device must use LDAPS for the LDAP connection. | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | IDENTIFICATION AND AUTHENTICATION |
| GEN000000-AIX00080 - The SYSTEM attribute must not be set to NONE for any account. | DISA AIX 5.3 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| GEN002220 - All shell files must have mode 0755 or less permissive. | DISA STIG AIX 6.1 v1r14 | Unix | ACCESS CONTROL |
| GEN005100 - The TFTP daemon must have mode 0755 or less permissive. | DISA STIG AIX 6.1 v1r14 | Unix | ACCESS CONTROL |
| GEN008640 - The system must not use removable media as the boot loader - 'prevboot' | DISA STIG AIX 6.1 v1r14 | Unix | CONFIGURATION MANAGEMENT |
| GEN008640 - The system must not use removable media as the boot loader - 'service' | DISA STIG AIX 6.1 v1r14 | Unix | CONFIGURATION MANAGEMENT |
| GOOG-16-012500 - Google Android 16 must be configured to disable 'Private Space' use - Private Space use. | AirWatch - DISA Google Android 16 COBO STIG v1r1 | MDM | CONFIGURATION MANAGEMENT |
| MADB-10-003900 - If passwords are used for authentication, MariaDB must transmit only encrypted representations of passwords. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | IDENTIFICATION AND AUTHENTICATION |
| MD7X-00-002700 - MongoDB software installation account must be restricted to authorized users. | DISA MongoDB Enterprise Advanced 7.x STIG v1r2 Unix | Unix | CONFIGURATION MANAGEMENT |
| MD8X-00-003600 - MongoDB must, for password-based authentication, store passwords using an approved salted key derivation function, preferably using a keyed hash. | DISA MongoDB Enterprise Advanced 8.x STIG v1r1 MongoDB | MongoDB | IDENTIFICATION AND AUTHENTICATION |
| RHEL-08-010291 - The RHEL 8 SSH server must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections. | DISA Red Hat Enterprise Linux 8 STIG v2r8 | Unix | ACCESS CONTROL |
| RHEL-09-211045 - The systemd Ctrl-Alt-Delete burst key sequence in RHEL 9 must be disabled. | DISA Red Hat Enterprise Linux 9 STIG v2r9 | Unix | ACCESS CONTROL |
| RHEL-09-255070 - The RHEL 9 SSH client must be configured to use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. | DISA Red Hat Enterprise Linux 9 STIG v2r9 | Unix | ACCESS CONTROL |
| RHEL-09-255075 - The RHEL 9 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections. | DISA Red Hat Enterprise Linux 9 STIG v2r9 | Unix | ACCESS CONTROL |
| RHEL-10-001050 - RHEL 10 must have GNU Privacy Guard (GPG) signature verification enabled for all software repositories. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-200631 - RHEL 10 must use cryptographic mechanisms to protect the integrity of audit tools. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY |
| RHEL-10-701050 - RHEL 10 must prevent the loading of a new kernel for later execution. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| SHPT-00-000683 - SharePoint-specific malware (i.e., anti-virus) software must be integrated and configured - 'Scan Documents on Upload is enabled' | DISA STIG SharePoint 2010 v1r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| SQL2-00-015700 - Vendor-supported software and patches must be evaluated and patched against newly found vulnerabilities. | DISA STIG SQL Server 2012 DB Instance Security v1r20 | MS_SQLDB | CONFIGURATION MANAGEMENT |
| SYMP-AG-000030 - Symantec ProxySG providing forward proxy intermediary services for TLS must be configured to comply with the required TLS settings in NIST SP 800-52 - client.connection.negotiated_cipher | DISA Symantec ProxySG Benchmark ALG v1r3 | BlueCoat | ACCESS CONTROL |
| SYMP-AG-000030 - Symantec ProxySG providing forward proxy intermediary services for TLS must be configured to comply with the required TLS settings in NIST SP 800-52 - client.connection.negotiated_ssl_version | DISA Symantec ProxySG Benchmark ALG v1r3 | BlueCoat | ACCESS CONTROL |
| SYMP-NM-000290 - The Symantec ProxySG Web Management Console and SSH sessions must implement cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications. | DISA Symantec ProxySG Benchmark NDM v1r2 | BlueCoat | MAINTENANCE |
| WN11-CC-000180 - Autoplay must be turned off for non-volume devices. | DISA Microsoft Windows 11 STIG v2r8 | Windows | CONFIGURATION MANAGEMENT |
| WN11-UR-000045 - The 'Create a token object' user right must not be assigned to any groups or accounts. | DISA Microsoft Windows 11 STIG v2r8 | Windows | ACCESS CONTROL |
| WN22-DC-000290 - Windows Server 2022 domain controller PKI certificates must be issued by the DOD PKI or an approved External Certificate Authority (ECA). | DISA Microsoft Windows Server 2022 STIG v2r8 | Windows | IDENTIFICATION AND AUTHENTICATION |