| 1.2 Ensure Auto Update Is Enabled | CIS Apple macOS 12.0 Monterey v4.0.0 L1 | Unix | RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY |
| 1.77 RHEL-10-200740 | CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II | Unix | CONFIGURATION MANAGEMENT |
| 1.80 OL09-00-000400 | CIS Oracle Linux 9 STIG v1.0.0 CAT II | Unix | IDENTIFICATION AND AUTHENTICATION |
| 3.121 - The system does not have a backup administrator account | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| AIOS-14-011000 - Apple iOS/iPadOS must implement the management setting: disable paired Apple Watch. | MobileIron - DISA Apple iOS/iPadOS 14 v1r3 | MDM | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| APPNET0048 - Developer certificates used with the .NET Publisher Membership Condition must be approved by the ISSO. | DISA Microsoft DotNet Framework 4.0 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| APPNET0052 - Encryption keys used for the .NET Strong Name Membership Condition must be protected. | DISA Microsoft DotNet Framework 4.0 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| APPNET0071 - Remoting Services TCP channels must utilize authentication and encryption. | DISA Microsoft DotNet Framework 4.0 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| APPNET0075 - Update and configure the .NET Framework to support TLS. | DISA Microsoft DotNet Framework 4.0 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| GOOG-12-007800 - Google Android 12 must be configured to generate audit records for the following auditable events: detected integrity violations. | AirWatch - DISA Google Android 12 COBO v1r2 | MDM | AUDIT AND ACCOUNTABILITY |
| GOOG-12-009800 - Google Android 12 users must complete required training. | MobileIron - DISA Google Android 12 COBO v1r2 | MDM | CONFIGURATION MANAGEMENT |
| SLES-15-010420 - Advanced Intrusion Detection Environment (AIDE) must verify the baseline SUSE operating system configuration at least weekly. | DISA SUSE Linux Enterprise Server 15 STIG v2r8 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY |
| SPLK-CL-000045 - Splunk Enterprise must use an SSO proxy service, F5 device, or SAML implementation to accept the DOD common access card (CAC) or other smart card credential for identity management, personal authentication, and multifactor authentication. | DISA STIG Splunk Enterprise 7.x for Windows v3r2 REST API | Splunk | IDENTIFICATION AND AUTHENTICATION |
| SQL6-D0-004300 - SQL Server must be configured to generate audit records for DoD-defined auditable events within all DBMS/database components. | DISA MS SQL Server 2016 Instance STIG v3r6 MS_SQLDB | MS_SQLDB | AUDIT AND ACCOUNTABILITY |
| UBTU-22-212010 - Ubuntu 22.04 LTS, when booted, must require authentication upon booting into single-user and maintenance modes. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | ACCESS CONTROL |
| UBTU-22-214015 - Ubuntu 22.04 LTS must be configured so that the Advance Package Tool (APT) removes all software components after updated versions have been installed. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| UBTU-22-215015 - Ubuntu 22.04 LTS must have the "chrony" package installed. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | CONFIGURATION MANAGEMENT |
| UBTU-22-215025 - Ubuntu 22.04 LTS must not have the "ntp" package installed. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | CONFIGURATION MANAGEMENT |
| UBTU-22-231010 - Ubuntu 22.04 LTS must implement cryptographic mechanisms to prevent unauthorized disclosure and modification of all information that requires protection at rest. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| UBTU-22-232015 - Ubuntu 22.04 LTS must have system commands set to a mode of "755" or less permissive. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | CONFIGURATION MANAGEMENT |
| UBTU-22-232050 - Ubuntu 22.04 LTS must have system commands owned by "root" or a system account. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | CONFIGURATION MANAGEMENT |
| UBTU-22-232055 - Ubuntu 22.04 LTS must have system commands group-owned by "root" or a system account. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | CONFIGURATION MANAGEMENT |
| UBTU-22-232085 - Ubuntu 22.04 LTS must configure the directories used by the system journal to be group-owned by "systemd-journal". | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| UBTU-22-232100 - Ubuntu 22.04 LTS must be configured so that the "journalctl" command is owned by "root". | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| UBTU-22-232105 - Ubuntu 22.04 LTS must be configured so that the "journalctl" command is group-owned by "root". | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| UBTU-22-232125 - Ubuntu 22.04 LTS must configure the "/var/log" directory to be group-owned by "syslog". | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| UBTU-22-232130 - Ubuntu 22.04 LTS must configure "/var/log/syslog" file to be owned by "syslog". | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| UBTU-22-251020 - Ubuntu 22.04 LTS must have an application firewall enabled. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | CONFIGURATION MANAGEMENT |
| UBTU-22-251025 - Ubuntu 22.04 LTS must configure the Uncomplicated Firewall (ufw) to rate-limit impacted network interfaces. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| UBTU-22-252015 - Ubuntu 22.04 LTS must synchronize internal information system clocks to the authoritative time source when the time difference is greater than one second. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | AUDIT AND ACCOUNTABILITY |
| UBTU-22-254015 - Ubuntu 22.04 LTS must use the "SSSD" package for multifactor authentication services. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | IDENTIFICATION AND AUTHENTICATION |
| UBTU-22-255010 - Ubuntu 22.04 LTS must have SSH installed. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| UBTU-22-255025 - Ubuntu 22.04 LTS must not allow unattended or automatic login via SSH. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | CONFIGURATION MANAGEMENT |
| UBTU-22-255035 - Ubuntu 22.04 LTS must be configured so that all network connections associated with SSH traffic are terminated after 10 minutes of becoming unresponsive. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| UBTU-22-255050 - Ubuntu 22.04 LTS must configure the SSH daemon to use FIPS 140-3-approved ciphers to prevent the unauthorized disclosure of information and/or detect changes to information during transmission. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION |
| UBTU-22-255065 - Ubuntu 22.04 LTS must use strong authenticators in establishing nonlocal maintenance and diagnostic sessions. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | MAINTENANCE |
| UBTU-22-431015 - Ubuntu 22.04 LTS must be configured to use AppArmor. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| UBTU-22-432015 - Ubuntu 22.04 LTS must ensure only users who need access to security functions are part of sudo group. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| UBTU-22-611040 - Ubuntu 22.04 LTS must require the change of at least eight characters when passwords are changed. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | IDENTIFICATION AND AUTHENTICATION |
| UBTU-22-612020 - Ubuntu 22.04 LTS must implement smart card logins for multifactor authentication for local and network access to privileged and nonprivileged accounts. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | IDENTIFICATION AND AUTHENTICATION |
| UBTU-22-631015 - Ubuntu 22.04 LTS must be configured such that Pluggable Authentication Module (PAM) prohibits the use of cached authentications after one day. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | IDENTIFICATION AND AUTHENTICATION |
| UBTU-22-653025 - Ubuntu 22.04 LTS must alert the information system security officer (ISSO) and system administrator (SA) in the event of an audit processing failure. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | AUDIT AND ACCOUNTABILITY |
| UBTU-22-654015 - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the chacl command. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | AUDIT AND ACCOUNTABILITY |
| UBTU-22-654020 - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the chage command. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | AUDIT AND ACCOUNTABILITY |
| UBTU-22-654025 - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the chcon command. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | AUDIT AND ACCOUNTABILITY |
| UBTU-22-654150 - Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| UBTU-22-654165 - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the creat, open, openat, open_by_handle_at, truncate, and ftruncate system calls. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | AUDIT AND ACCOUNTABILITY |
| UBTU-22-654230 - Ubuntu 22.04 LTS must prevent all software from executing at higher privilege levels than users executing the software and the audit system must be configured to audit the execution of privileged functions. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | ACCESS CONTROL |
| UBTU-22-671010 - Ubuntu 22.04 LTS must implement NIST FIPS-validated cryptography to protect classified information and for the following: To provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| VCSA-70-000294 - vCenter Native Key Providers must be backed up with a strong password. | DISA STIG VMware vSphere 7.0 vCenter v1r3 | VMware | CONFIGURATION MANAGEMENT |