| 1.1.7 Ensure noexec option set on /dev/shm partition | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| 1.20 SOL-11.1-010310 | CIS Solaris 11 SPARC STIG v1.0.0 CAT III | Unix | ACCESS CONTROL |
| 1.28 CISC-RT-000370 | CIS Cisco IOS XE Switch RTR STIG v1.1.0 CAT III | Cisco | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.30 CISC-RT-000370 | CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT III | Cisco | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.33 EX19-MB-000124 | CIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0 CAT III | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.36 EX19-MB-000127 | CIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0 CAT III | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.37 EX19-MB-000128 | CIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0 CAT III | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.39 EX19-MB-000130 | CIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0 CAT III | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.49 EX19-MB-000142 | CIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0 CAT III | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 1.53 CISC-RT-000610 | CIS Cisco IOS XE Switch RTR STIG v1.1.0 CAT III | Cisco | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.63 CISC-RT-000610 | CIS Cisco IOS XE Router RTR STIG v1.1.0 CAT III | Cisco | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.69 CISC-RT-000760 | CIS Cisco IOS XE Switch RTR STIG v1.1.0 CAT III | Cisco | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.70 CISC-RT-000770 | CIS Cisco IOS XE Switch RTR STIG v1.1.0 CAT III | Cisco | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.74 SOL-11.1-040020 | CIS Solaris 11 X86 STIG v1.0.0 CAT III | Unix | ACCESS CONTROL |
| 1.81 OL08-00-010440 | CIS Oracle Linux 8 STIG v1.0.0 CAT III | Unix | SYSTEM AND INFORMATION INTEGRITY |
| 1.87 CISC-RT-000860 | CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT III | Cisco | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.149 SOL-11.1-060150 | CIS Solaris 11 X86 STIG v1.0.0 CAT III | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.152 SOL-11.1-060180 | CIS Solaris 11 X86 STIG v1.0.0 CAT III | Unix | AUDIT AND ACCOUNTABILITY |
| 1.154 SLES-15-030680 | CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT III | Unix | AUDIT AND ACCOUNTABILITY |
| 1.154 SOL-11.1-060180 | CIS Solaris 11 SPARC STIG v1.0.0 CAT III | Unix | AUDIT AND ACCOUNTABILITY |
| 1.156 SLES-15-030690 | CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT III | Unix | AUDIT AND ACCOUNTABILITY |
| AIOS-18-011600 - Apple iOS/iPadOS 18 must implement the management setting: not have any Family Members in Family Sharing. | AirWatch - DISA Apple iOS/iPadOS 18 v2r3 | MDM | IDENTIFICATION AND AUTHENTICATION |
| AIOS-26-010900 - Apple iOS/iPadOS 26 must implement the management setting: require the user to enter a password when connecting to an AirPlay-enabled device. | MobileIron - DISA Apple iOS/iPadOS 26 v1r3 | MDM | ACCESS CONTROL |
| AIOS-26-011600 - Apple iOS/iPadOS 26 must implement the management setting: not have any Family Members in Family Sharing. | AirWatch - DISA Apple iOS/iPadOS 26 v1r3 | MDM | IDENTIFICATION AND AUTHENTICATION |
| ARST-RT-000060 - The Arista BGP router must be configured to reject route advertisements from BGP peers that do not list their autonomous system (AS) number as the first AS in the AS_PATH attribute. | DISA STIG Arista MLS EOS 4.2x Router v2r1 | Arista | ACCESS CONTROL |
| ARST-RT-000100 - The Arista BGP router must be configured to reject route advertisements from CE routers with an originating AS in the AS_PATH attribute that does not belong to that customer. | DISA STIG Arista MLS EOS 4.2x Router v2r1 | Arista | ACCESS CONTROL |
| ARST-RT-000290 - The MPLS router with RSVP-TE enabled must be configured with message pacing or refresh reduction to adjust maximum number of RSVP messages to an output queue based on the link speed and input queue size of adjacent core routers. | DISA Arista MLS EOS 4.X Router STIG v2r2 | Arista | SYSTEM AND COMMUNICATIONS PROTECTION |
| ARST-RT-000320 - The PE router must be configured to enforce a Quality-of-Service (QoS) policy in accordance with the QoS GIG Technical Profile. | DISA Arista MLS EOS 4.X Router STIG v2r2 | Arista | SYSTEM AND COMMUNICATIONS PROTECTION |
| ARST-RT-000630 - The Arista perimeter router must be configured to have Link Layer Discovery Protocols (LLDPs) disabled on all external interfaces. | DISA STIG Arista MLS EOS 4.2x Router v2r1 | Arista | SYSTEM AND COMMUNICATIONS PROTECTION |
| ARST-RT-000660 - The Arista multicast Designated Router (DR) must be configured to filter the Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) Report messages to allow hosts to join only multicast groups that have been approved by the organization. | DISA STIG Arista MLS EOS 4.2x Router v2r1 | Arista | SYSTEM AND COMMUNICATIONS PROTECTION |
| EDGE-00-000004 - The list of domains for which Microsoft Defender SmartScreen will not trigger warnings must be allowlisted if used. | DISA STIG Edge v2r3 | Windows | MAINTENANCE |
| EX19-MB-000124 - Exchange Message size restrictions must be controlled on Receive connectors. | DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| F5BI-AP-000242 - The F5 BIG-IP appliance must be configured to enable the 'Secure' cookie flag - Secure cookie flag. | DISA F5 BIG-IP Access Policy Manager STIG v2r4 | F5 | SYSTEM AND COMMUNICATIONS PROTECTION |
| F5BI-AP-300151 - When the Access Profile Type is LTM+APM and it is not using any connectivity resources (such as Network Access, Portal Access, etc.) in the VPE, the F5 BIG-IP appliance must be configured to enable the HTTP Only flag. | DISA F5 BIG-IP TMOS ALG STIG v1r3 | F5 | SYSTEM AND COMMUNICATIONS PROTECTION |
| JUEX-NM-000490 - The Juniper EX switch must use an an NTP service that is hosted by a trusted source or a DOD-compliant enterprise or local NTP server. | DISA Juniper EX Series Switches Network Device Management STIG v2r5 | Juniper | IDENTIFICATION AND AUTHENTICATION |
| JUEX-RT-000320 - The Juniper MPLS router with RSVP-TE enabled must be configured to enable refresh reduction features. | DISA Juniper EX Series Switches Router STIG v2r1 | Juniper | SYSTEM AND COMMUNICATIONS PROTECTION |
| JUEX-RT-000750 - The Juniper perimeter router must be configured to have Link Layer Discovery Protocols (LLDPs) disabled on all external interfaces. | DISA Juniper EX Series Switches Router STIG v2r1 | Juniper | SYSTEM AND COMMUNICATIONS PROTECTION |
| OL08-00-010440 - YUM must remove all software components after updated versions have been installed on OL 8. | DISA Oracle Linux 8 STIG v2r9 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| OL09-00-000495 - OL 9 must remove all software components after updated versions have been installed. | DISA Oracle Linux 9 STIG v1r6 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| OS10-RTR-000800 - The Dell OS10 multicast Designated Router (DR) must be configured to filter the Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) Report messages to allow hosts to join only multicast groups that have been approved by the organization. | DISA Dell OS10 Switch Router STIG v1r2 | Dell_OS10 | SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-200662 - RHEL 10 must have the "audispd-plugins" package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY |
| SHPT-00-000165 - SharePoint must enable IRM to bind attributes to information to facilitate the organization's established information flow policy as needed. | DISA STIG SharePoint 2010 v1r9 | Windows | ACCESS CONTROL |
| SLES-15-010140 - The SUSE operating system must conceal, via the session lock, information previously visible on the display with a publicly viewable image in the graphical user interface (GUI). | DISA SUSE Linux Enterprise Server 15 STIG v2r8 | Unix | ACCESS CONTROL |
| SLES-15-030680 - The SUSE operating system audit event multiplexor must be configured to use Kerberos. | DISA SUSE Linux Enterprise Server 15 STIG v2r8 | Unix | AUDIT AND ACCOUNTABILITY |
| SPLK-CL-000120 - The System Administrator (SA) and Information System Security Manager (ISSM) must configure the retention of the log records based on the defined security plan. | DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG OS | Unix | AUDIT AND ACCOUNTABILITY |
| SPLK-CL-000170 - Splunk Enterprise must notify the System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) of all audit failure events, such as loss of communications with hosts and devices, or if log records are no longer being received. | DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST API | Splunk | AUDIT AND ACCOUNTABILITY |
| UBTU-20-010216 - The Ubuntu operating system audit event multiplexor must be configured to off-load audit logs onto a different system or storage media from the system being audited. | DISA Canonical Ubuntu 20.04 LTS STIG v2r4 | Unix | AUDIT AND ACCOUNTABILITY |
| UBTU-20-010410 - The Ubuntu operating system must automatically expire temporary accounts within 72 hours. | DISA Canonical Ubuntu 20.04 LTS STIG v2r4 | Unix | ACCESS CONTROL |
| UBTU-22-631015 - Ubuntu 22.04 LTS must be configured such that Pluggable Authentication Module (PAM) prohibits the use of cached authentications after one day. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | IDENTIFICATION AND AUTHENTICATION |
| UBTU-22-653020 - Ubuntu 22.04 LTS audit event multiplexor must be configured to offload audit logs onto a different system from the system being audited. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | AUDIT AND ACCOUNTABILITY |