| 1.4.3 SNMP Traps | CIS HPE Aruba Networking CX Switch v1.0.1 L2 | ArubaOS | AUDIT AND ACCOUNTABILITY |
| 1.4.3 SNMP Traps | CIS HPE Aruba Networking CX Switch v1.0.1 Optional Security Recommendations | ArubaOS | AUDIT AND ACCOUNTABILITY |
| 1.10.10 Ensure email logging is configured for critical to emergency | CIS Cisco ASA 9.x Firewall L1 v1.1.0 | Cisco | AUDIT AND ACCOUNTABILITY |
| 2.1 Ensure That Cloud Audit Logging Is Configured Properly | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | AUDIT AND ACCOUNTABILITY |
| 2.12.8 - Miscellaneous Config - enable sar accounting - 'activity reports are generated every 20 minutes or less on weekday 8a-5p' | CIS AIX 5.3/6.1 L2 v1.1.0 | Unix | AUDIT AND ACCOUNTABILITY |
| 2.12.8 - Miscellaneous Config - enable sar accounting - 'activity reports are generated hourly on weekday 6p-7a' | CIS AIX 5.3/6.1 L2 v1.1.0 | Unix | AUDIT AND ACCOUNTABILITY |
| 2.12.8 - Miscellaneous Config - enable sar accounting - 'activity reports are generated hourly on weekends' | CIS AIX 5.3/6.1 L2 v1.1.0 | Unix | AUDIT AND ACCOUNTABILITY |
| 2.12.8 - Miscellaneous Config - enable sar accounting - 'daily summaries are being prepared' | CIS AIX 5.3/6.1 L2 v1.1.0 | Unix | AUDIT AND ACCOUNTABILITY |
| 2.13 Ensure That Cloud DNS Logging Is Enabled for All VPC Networks | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | AUDIT AND ACCOUNTABILITY |
| 2.14 Ensure centralized and remote logging is configured | CIS Docker v1.8.0 L2 OS Linux | Unix | AUDIT AND ACCOUNTABILITY |
| 4.2.1.5 Ensure rsyslog is configured to send logs to a remote log host | CIS Distribution Independent Linux Workstation L1 v2.0.0 | Unix | AUDIT AND ACCOUNTABILITY |
| 4.2.1.5 Ensure rsyslog is configured to send logs to a remote log host | CIS Red Hat 6 Server L1 v3.0.0 | Unix | AUDIT AND ACCOUNTABILITY |
| 4.2.2.4 Ensure syslog-ng is configured to send logs to a remote log host - destination logserver | CIS Debian 8 Workstation L1 v2.0.2 | Unix | AUDIT AND ACCOUNTABILITY |
| 4.2.2.4 Ensure syslog-ng is configured to send logs to a remote log host - destination logserver | CIS Debian 8 Server L1 v2.0.2 | Unix | AUDIT AND ACCOUNTABILITY |
| 4.2.2.4 Ensure syslog-ng is configured to send logs to a remote log host - log src | CIS Debian 8 Server L1 v2.0.2 | Unix | AUDIT AND ACCOUNTABILITY |
| 4.2.2.4 Ensure syslog-ng is configured to send logs to a remote log host - log src | CIS Debian 8 Workstation L1 v2.0.2 | Unix | AUDIT AND ACCOUNTABILITY |
| 4.2.2.5 Ensure remote syslog-ng messages are only accepted on designated log hosts | CIS Debian 8 Server L1 v2.0.2 | Unix | AUDIT AND ACCOUNTABILITY |
| 4.2.2.5 Ensure remote syslog-ng messages are only accepted on designated log hosts | CIS Debian 8 Workstation L1 v2.0.2 | Unix | AUDIT AND ACCOUNTABILITY |
| 4.2.4 Ensure permissions on all logfiles are configured | CIS Debian 9 Server L1 v1.0.1 | Unix | AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| 4.2.4 Ensure permissions on all logfiles are configured | CIS Debian 9 Workstation L1 v1.0.1 | Unix | AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| 5.1 Ensure unauthorized API calls are monitored | CIS Amazon Web Services Foundations v7.0.0 L2 | amazon_aws | AUDIT AND ACCOUNTABILITY |
| 5.1.1.5 Ensure journald is not configured to send logs to rsyslog | CIS Debian Linux 10 v2.0.0 L1 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 5.1.1.5 Ensure journald is not configured to send logs to rsyslog | CIS Ubuntu Linux 18.04 LTS v2.2.0 L1 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 5.1.1.5 Ensure journald is not configured to send logs to rsyslog | CIS Debian Linux 10 v2.0.0 L1 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 5.1.1.5 Ensure journald is not configured to send logs to rsyslog | CIS Ubuntu Linux 18.04 LTS v2.2.0 L1 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 5.1.2.5 Ensure journald is not configured to send logs to rsyslog | CIS Amazon Linux 2023 v1.0.0 L1 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 5.2 Ensure management console sign-in without MFA is monitored | CIS Amazon Web Services Foundations v7.0.0 L1 | amazon_aws | AUDIT AND ACCOUNTABILITY |
| 5.2.2.7 Enable Identity Protection sign-in risk policies | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION |
| 5.3 Ensure usage of the 'root' account is monitored | CIS Amazon Web Services Foundations v7.0.0 L1 | amazon_aws | AUDIT AND ACCOUNTABILITY |
| 5.4 Ensure IAM policy changes are monitored | CIS Amazon Web Services Foundations v7.0.0 L1 | amazon_aws | AUDIT AND ACCOUNTABILITY |
| 5.5 Ensure CloudTrail configuration changes are monitored | CIS Amazon Web Services Foundations v7.0.0 L1 | amazon_aws | AUDIT AND ACCOUNTABILITY |
| 5.6 Ensure AWS Management Console authentication failures are monitored | CIS Amazon Web Services Foundations v7.0.0 L2 | amazon_aws | AUDIT AND ACCOUNTABILITY |
| 5.7 Ensure disabling or scheduled deletion of customer created CMKs is monitored | CIS Amazon Web Services Foundations v7.0.0 L2 | amazon_aws | AUDIT AND ACCOUNTABILITY |
| 5.8 Ensure S3 bucket policy changes are monitored | CIS Amazon Web Services Foundations v7.0.0 L1 | amazon_aws | AUDIT AND ACCOUNTABILITY |
| 5.9 Ensure AWS Config configuration changes are monitored | CIS Amazon Web Services Foundations v7.0.0 L2 | amazon_aws | AUDIT AND ACCOUNTABILITY |
| 5.11 Ensure Network Access Control List (NACL) changes are monitored | CIS Amazon Web Services Foundations v7.0.0 L2 | amazon_aws | AUDIT AND ACCOUNTABILITY |
| 5.12 Ensure changes to network gateways are monitored | CIS Amazon Web Services Foundations v7.0.0 L1 | amazon_aws | AUDIT AND ACCOUNTABILITY |
| 5.13 Ensure route table changes are monitored | CIS Amazon Web Services Foundations v7.0.0 L1 | amazon_aws | AUDIT AND ACCOUNTABILITY |
| 5.14 Ensure VPC changes are monitored | CIS Amazon Web Services Foundations v7.0.0 L1 | amazon_aws | AUDIT AND ACCOUNTABILITY |
| 5.15 Ensure AWS Organizations changes are monitored | CIS Amazon Web Services Foundations v7.0.0 L1 | amazon_aws | AUDIT AND ACCOUNTABILITY |
| 6.2.2.2 Ensure journald ForwardToSyslog is disabled | CIS Oracle Linux 10 v1.0.0 L1 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.2.2 Ensure journald ForwardToSyslog is disabled | CIS Red Hat Enterprise Linux 10 v1.0.1 L1 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.2.2 Ensure journald ForwardToSyslog is disabled | CIS Ubuntu Linux 20.04 LTS v3.0.0 L1 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 7.2.1 Centralized Logging and Reporting | CIS FortiGate 7.4.x v1.0.1 L2 | FortiGate | AUDIT AND ACCOUNTABILITY |
| 7.3.1 Centralized Logging and Reporting | CIS Fortigate 7.0.x v1.4.0 L2 | FortiGate | AUDIT AND ACCOUNTABILITY |
| 9.3 Configure a Logging Syslog Channel | CIS BIND DNS v1.0.0 L1 Authoritative Name Server | Unix | AUDIT AND ACCOUNTABILITY |
| 9.3 Configure a Logging Syslog Channel | CIS BIND DNS v1.0.0 L1 Caching Only Name Server | Unix | AUDIT AND ACCOUNTABILITY |
| FireEye - Greylist URL list | TNS FireEye | FireEye | AUDIT AND ACCOUNTABILITY |
| FireEye - Web-analysis incident list | TNS FireEye | FireEye | AUDIT AND ACCOUNTABILITY |
| FireEye - Workorder stats | TNS FireEye | FireEye | AUDIT AND ACCOUNTABILITY |