| 2.1.1 Ensure 'SECURE_CONTROL_<listener_name>' Is Set In 'listener.ora' | CIS Oracle Server 11g R2 Unix v2.2.0 | Unix | ACCESS CONTROL |
| 2.1.9 Enable Global Strong Encryption | CIS Fortigate 7.0.x v1.4.0 L2 | FortiGate | ACCESS CONTROL |
| 4.1 Ensure devices without a compliance policy are marked 'not compliant' | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 5.1.1 Ensure sshd crypto_policy is not set | CIS Rocky Linux 8 v3.0.0 L1 Workstation | Unix | ACCESS CONTROL |
| 5.1.1 Ensure sshd crypto_policy is not set | CIS AlmaLinux OS 8 v4.0.0 L1 Server | Unix | ACCESS CONTROL |
| 5.1.1 Ensure sshd crypto_policy is not set | CIS Oracle Linux 8 v4.0.0 L1 Workstation | Unix | ACCESS CONTROL |
| 5.1.12 Ensure sshd KexAlgorithms is configured | CIS Red Hat Enterprise Linux 10 v1.0.1 L1 Server | Unix | ACCESS CONTROL |
| 5.1.12 Ensure sshd KexAlgorithms is configured | CIS Red Hat Enterprise Linux 10 v1.0.1 L1 Workstation | Unix | ACCESS CONTROL |
| 5.2.2.9 Ensure a managed device is required for authentication | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 5.2.2.9 Ensure a managed device is required for authentication | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 5.2.2.10 Ensure a managed device is required to register security information | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 5.2.2.10 Ensure a managed device is required to register security information | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 6.1.9 Disable SSH root Login - Check if PermitRootLogin is set to no and not commented for the server. | CIS Solaris 10 L1 v5.2 | Unix | ACCESS CONTROL |
| 6.6 Disable root login for SSH - PermitRootLogin = no | CIS Solaris 11 L1 v1.1.0 | Unix | ACCESS CONTROL |
| 9.3.8 Disable SSH Root Login | CIS Debian Linux 7 L1 v1.0.0 | Unix | ACCESS CONTROL |
| 18.9.97.2.2 Ensure 'Allow remote server management through WinRM' is set to 'Disabled' | CIS Windows 7 Workstation Level 2 v3.2.0 | Windows | ACCESS CONTROL |
| 18.9.97.2.2 Ensure 'Allow remote server management through WinRM' is set to 'Disabled' | CIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0 | Windows | ACCESS CONTROL |
| Allow Basic authentication - Client - AllowBasic | MSCT Windows 11 v24H2 v1.0.0 | Windows | ACCESS CONTROL |
| Allow Basic authentication - Client - AllowBasic | MSCT Windows Server 2025 MS v2506 v1.0.0 | Windows | ACCESS CONTROL |
| Allow Basic authentication - Service - AllowBasic | MSCT Windows 11 v23H2 v1.0.0 | Windows | ACCESS CONTROL |
| Allow Basic authentication - Service - AllowBasic | MSCT Windows 11 v1.0.0 | Windows | ACCESS CONTROL |
| Allow Basic authentication - Service - AllowBasic | MSCT Windows Server 2025 DC v2506 v1.0.0 | Windows | ACCESS CONTROL |
| Allow Basic authentication - Service - AllowBasic | MSCT Windows 11 v24H2 v1.0.0 | Windows | ACCESS CONTROL |
| Allow Basic authentication - Service - AllowBasic | MSCT MSCT Windows Server 2022 DC v1.0.0 | Windows | ACCESS CONTROL |
| Allow Basic authentication - Service - AllowBasic | MSCT Windows Server 2022 v1.0.0 | Windows | ACCESS CONTROL |
| Allow unencrypted traffic - Client - AllowUnencryptedTraffic | MSCT Windows 10 v21H1 v1.0.0 | Windows | ACCESS CONTROL |
| Allow unencrypted traffic - Client - AllowUnencryptedTraffic | MSCT Windows Server 2025 DC v2506 v1.0.0 | Windows | ACCESS CONTROL |
| Allow unencrypted traffic - Client - AllowUnencryptedTraffic | MSCT Windows 10 v22H2 v1.0.0 | Windows | ACCESS CONTROL |
| Allow unencrypted traffic - Client - AllowUnencryptedTraffic | MSCT Windows 11 v24H2 v1.0.0 | Windows | ACCESS CONTROL |
| Allow unencrypted traffic - Client - AllowUnencryptedTraffic | MSCT Windows 11 v25H2 v1.0.0 | Windows | ACCESS CONTROL |
| Allow unencrypted traffic - Client - AllowUnencryptedTraffic | MSCT Windows Server 2025 MS v2506 v1.0.0 | Windows | ACCESS CONTROL |
| Allow unencrypted traffic - Service - AllowUnencryptedTraffic | MSCT Windows 11 v23H2 v1.0.0 | Windows | ACCESS CONTROL |
| Allow unencrypted traffic - Service - AllowUnencryptedTraffic | MSCT Windows 10 v21H1 v1.0.0 | Windows | ACCESS CONTROL |
| Allow unencrypted traffic - Service - AllowUnencryptedTraffic | MSCT MSCT Windows Server 2022 DC v1.0.0 | Windows | ACCESS CONTROL |
| Allow unencrypted traffic - Service - AllowUnencryptedTraffic | MSCT Windows Server 2025 MS v1.0.0 | Windows | ACCESS CONTROL |
| Brocade - Set SNMP security level to authentication and privacy | Tenable Best Practices Brocade FabricOS | Brocade | ACCESS CONTROL |
| Configure Solicited Remote Assistance - fAllowToGetHelp | MSCT Windows 11 v23H2 v1.0.0 | Windows | ACCESS CONTROL |
| Disallow Digest authentication | MSCT Windows 11 v22H2 v1.0.0 | Windows | ACCESS CONTROL |
| Disallow Digest authentication | MSCT Windows 11 v1.0.0 | Windows | ACCESS CONTROL |
| Disallow Digest authentication | MSCT MSCT Windows Server 2022 DC v1.0.0 | Windows | ACCESS CONTROL |
| Disallow Digest authentication - Client - AllowDigest | MSCT Windows Server 2025 DC v1.0.0 | Windows | ACCESS CONTROL |
| Disallow Digest authentication - Client - AllowDigest | MSCT Windows Server 2025 MS v1.0.0 | Windows | ACCESS CONTROL |
| FireEye - SNMP v3 uses AES instead of DES | TNS FireEye | FireEye | ACCESS CONTROL |
| Fortigate - VPN SSL cipher suite > than 128 bits | TNS Fortigate FortiOS Best Practices v2.0.0 | FortiGate | ACCESS CONTROL |
| Set client connection encryption level | MSCT Windows 10 v21H1 v1.0.0 | Windows | ACCESS CONTROL |
| Set client connection encryption level | MSCT Windows 11 v1.0.0 | Windows | ACCESS CONTROL |
| Set client connection encryption level | MSCT MSCT Windows Server 2022 DC v1.0.0 | Windows | ACCESS CONTROL |
| Set client connection encryption level | MSCT Windows Server 2025 MS v2506 v1.0.0 | Windows | ACCESS CONTROL |
| Set client connection encryption level - MinEncryptionLevel | MSCT Windows Server 2025 DC v1.0.0 | Windows | ACCESS CONTROL |
| WatchGuard : SNMP Configuration - v3 user has password - auth protocol | TNS Best Practice WatchGuard Audit 1.0.0 | WatchGuard | ACCESS CONTROL |