| 1.1.5 Ensure that the scheduler pod specification file permissions are set to 600 or more restrictive | CIS Kubernetes v1.23 Benchmark v1.0.1 L1 Master | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.18 Ensure that the controller-manager.conf file ownership is set to root:root | CIS Kubernetes v1.24 Benchmark v1.0.0 L1 Master | Unix | ACCESS CONTROL |
| 1.1.19 Ensure that the --authorization-mode argument is not set to AlwaysAllow | CIS Kubernetes 1.13 Benchmark v1.4.1 L1 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| 1.2.14 Ensure that the admission control plugin NamespaceLifecycle is set | CIS Kubernetes v1.20 Benchmark v1.0.1 L1 Master | Unix | CONFIGURATION MANAGEMENT |
| 1.2.18 Ensure that the --audit-log-maxbackup argument is set to 10 or as appropriate | CIS Kubernetes v2.0.1 L1 Master Node | Unix | AUDIT AND ACCOUNTABILITY |
| 1.2.30 Ensure that the API Server only makes use of Strong Cryptographic Ciphers | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | CONFIGURATION MANAGEMENT |
| 1.3.1 Ensure that the --terminated-pod-gc-threshold argument is set as appropriate | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 1.3.3 Ensure that the --use-service-account-credentials argument is set to true | CIS Kubernetes v1.23 Benchmark v1.0.1 L1 Master | Unix | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION |
| 1.3.3 Ensure that the --use-service-account-credentials argument is set to true | CIS Kubernetes v1.24 Benchmark v1.0.0 L1 Master | Unix | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION |
| 1.3.7 Ensure that the --bind-address argument is set to 127.0.0.1 | CIS Kubernetes v1.24 Benchmark v1.0.0 L1 Master | Unix | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.4.2 Ensure that the --bind-address argument is set to 127.0.0.1 | CIS Kubernetes v1.20 Benchmark v1.0.1 L1 Master | Unix | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.5.5 Ensure that the --peer-client-cert-auth argument is set to true | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 1.5.6 Ensure that the --peer-auto-tls argument is not set to true | CIS Kubernetes 1.7.0 Benchmark v1.1.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.4.2 Ensure Control Plane Authorized Networks is Enabled | CIS Google Kubernetes Engine GKE Autopilot v1.3.0 L2 | GCP | ACCESS CONTROL, MEDIA PROTECTION |
| 5.5.1.2 Ensure minimum days between password changes is configured - password shadow | CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG | Unix | IDENTIFICATION AND AUTHENTICATION |
| GOOG-14-002800 - Google Android 14 must be configured to enable audit logging. | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | AUDIT AND ACCOUNTABILITY |
| GOOG-14-006000 - Google Android 14 must be configured to enforce a minimum password length of six characters. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | IDENTIFICATION AND AUTHENTICATION |
| GOOG-14-006000 - Google Android 14 must be configured to enforce a minimum password length of six characters. | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | IDENTIFICATION AND AUTHENTICATION |
| GOOG-14-006100 - Google Android 14 must be configured to not allow passwords that include more than four repeating or sequential characters - Complex Characters | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | IDENTIFICATION AND AUTHENTICATION |
| GOOG-14-006300 - Google Android 14 must be configured to lock the display after 15 minutes (or less) of inactivity - or less of inactivity. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | ACCESS CONTROL |
| GOOG-14-006400 - Google Android 14 must be configured to not allow more than 10 consecutive failed authentication attempts. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | ACCESS CONTROL |
| GOOG-14-006600 - Google Android 14 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version]. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-006700 - Google Android 14 allowlist must be configured to not include applications with the following characteristics: | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION |
| GOOG-14-007400 - Google Android 14 must be configured to disable developer modes. | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-007400 - Google Android 14 must be configured to disable developer modes. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-007400 - Google Android 14 must be configured to disable developer modes. | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-007800 - Google Android 14 must be configured to generate audit records for the following auditable events: Detected integrity violations. | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | AUDIT AND ACCOUNTABILITY |
| GOOG-14-008600 - Google Android 14 must be configured to not allow backup of [all applications, configuration data] to remote systems. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |
| GOOG-14-008900 - Google Android 14 must be configured to disable exceptions to the access control policy that prevent [selection: application processes, groups of application processes] from accessing [selection: all, private] data stored by other [selection: application processes, groups of application processes]. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION |
| GOOG-14-009000 - Google Android 14 must be configured to disable multiuser modes. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| GOOG-14-009400 - Google Android 14 must be configured to disable all Bluetooth profiles except for HSP (Headset Profile), HFP (Hands-Free Profile), SPP (Serial Port Profile), A2DP (Advanced Audio Distribution Profile), AVRCP (Audio/Video Remote Control Profile), and PBAP (Phone Book Access Profile) - SPP. | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-009500 - Google Android 14 must be configured to disable ad hoc wireless client-to-client connection capability. | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |
| GOOG-14-009500 - Google Android 14 must be configured to disable ad hoc wireless client-to-client connection capability. | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |
| GOOG-14-009800 - Google Android 14 users must complete required training. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-009900 - Google Android 14 must be configured to enforce that Wi-Fi Sharing is disabled. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-010100 - The Google Android 14 work profile must be configured to prevent users from adding personal email accounts to the work email app. | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-010600 - Google Android 14 must be configured to disallow configuration of date and time. | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-010800 - Android 14 devices must have the latest available Google Android 14 operating system installed. | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-010900 - Android 14 devices must be configured to disable the use of third-party keyboards. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-011000 - Android 14 devices must be configured to enable Common Criteria Mode (CC Mode) - CC Mode. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-012200 - Google Android 14 must be configured to disable all data signaling over [assignment: list of externally accessible hardware ports (for example, USB)] - for example, USB]. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | ACCESS CONTROL |
| GOOG-14-012300 - The Google Android 14 must allow only the administrator (EMM) to install/remove DOD root and intermediate PKI certificates - EMM to install/remove DOD root and intermediate PKI certificates. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-012300 - The Google Android 14 must allow only the administrator (EMM) to install/remove DOD root and intermediate PKI certificates - EMM to install/remove DOD root and intermediate PKI certificates. | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-013000 - Google Android 14 must disable the user's ability to wipe the device. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-013200 - Google Android 14 must disable wireless printing. | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-013300 - Google Android 14 must disable screen capture. | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-013400 - Google Android 14 devices must have a Mobile Threat Detection (MTD) app installed. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-013600 - The Google Android device must be configured to disable Wi-Fi Aware for Work Profile apps. | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| MADB-10-000100 - MariaDB must limit the number of concurrent sessions to an organization-defined number per user for all accounts and/or account types. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | ACCESS CONTROL |
| MADB-10-000300 - MariaDB must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | ACCESS CONTROL |