| 4.4.3 Ensure 'Configure SMB v1 server' is set to 'Disabled' | CIS Microsoft Intune for Windows 11 v5.0.0 L1 | Windows | CONFIGURATION MANAGEMENT |
| 8.6 Enable SSL communication with LDAP server | CIS IBM DB2 9 Benchmark v3.0.1 Level 1 OS Windows | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.9.18.1 Ensure 'Turn off desktop gadgets' is set to 'Enabled' | CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0 | Windows | CONFIGURATION MANAGEMENT |
| 18.10.9.3.3 (L1) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Allow data recovery agent' is set to 'Enabled: True' | CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1 | Windows | MEDIA PROTECTION |
| 18.10.10.1.3 Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Allow data recovery agent' is set to 'Enabled: True' | CIS Microsoft Windows 11 Stand-alone v5.0.0 L2 BL | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.10.10.1.3 Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Allow data recovery agent' is set to 'Enabled: True' | CIS Microsoft Windows 10 Enterprise v5.0.0 L2 BL | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.10.10.1.3 Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Allow data recovery agent' is set to 'Enabled: True' | CIS Microsoft Windows 10 Stand-alone v5.0.0 L2 BL NG | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.10.10.1.3 Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Allow data recovery agent' is set to 'Enabled: True' | CIS Microsoft Windows 11 Enterprise v5.1.0 L2 BL | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.10.10.1.3 Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Allow data recovery agent' is set to 'Enabled: True' | CIS Microsoft Windows 10 Enterprise v5.0.0 BL | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.10.10.1.3 Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Allow data recovery agent' is set to 'Enabled: True' | CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BL | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.10.10.1.8 Ensure 'Configure use of passwords for fixed data drives' is set to 'Disabled' | CIS Microsoft Windows 10 Stand-alone v5.0.0 L2 BL NG | Windows | IDENTIFICATION AND AUTHENTICATION |
| 18.10.10.1.8 Ensure 'Configure use of passwords for fixed data drives' is set to 'Disabled' | CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BL | Windows | IDENTIFICATION AND AUTHENTICATION |
| 18.10.10.1.11 Ensure 'Configure use of passwords for fixed data drives' is set to 'Disabled' | CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BL | Windows | IDENTIFICATION AND AUTHENTICATION |
| 18.10.10.1.11 Ensure 'Configure use of passwords for fixed data drives' is set to 'Disabled' | CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BL | Windows | IDENTIFICATION AND AUTHENTICATION |
| 18.10.10.3.3 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Allow data recovery agent' is set to 'Enabled: True' | CIS Microsoft Windows 10 Stand-alone v5.0.0 L2 BL NG | Windows | MEDIA PROTECTION |
| 18.10.10.3.3 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Allow data recovery agent' is set to 'Enabled: True' | CIS Microsoft Windows 11 Enterprise v5.1.0 L2 BL | Windows | MEDIA PROTECTION |
| 18.10.10.3.3 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Allow data recovery agent' is set to 'Enabled: True' | CIS Microsoft Windows 10 Stand-alone v5.0.0 L1 BL | Windows | MEDIA PROTECTION |
| 18.10.10.3.3 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Allow data recovery agent' is set to 'Enabled: True' | CIS Microsoft Windows 11 Stand-alone v5.0.0 BL | Windows | MEDIA PROTECTION |
| 18.10.10.3.3 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Allow data recovery agent' is set to 'Enabled: True' | CIS Microsoft Windows 10 Enterprise v5.0.0 L2 BL NG | Windows | MEDIA PROTECTION |
| 18.10.10.3.3 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Allow data recovery agent' is set to 'Enabled: True' | CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BL | Windows | MEDIA PROTECTION |
| 18.10.10.3.11 Ensure 'Configure use of passwords for removable data drives' is set to 'Disabled' | CIS Microsoft Windows 11 Enterprise v5.1.0 L2 BL | Windows | IDENTIFICATION AND AUTHENTICATION |
| 18.10.10.3.11 Ensure 'Configure use of passwords for removable data drives' is set to 'Disabled' | CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BL | Windows | IDENTIFICATION AND AUTHENTICATION |
| 18.10.10.3.11 Ensure 'Configure use of passwords for removable data drives' is set to 'Disabled' | CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BL NG | Windows | IDENTIFICATION AND AUTHENTICATION |
| 18.10.36.1 Ensure 'Turn off location' is set to 'Enabled' | CIS Microsoft Windows 10 Stand-alone v5.0.0 L2 BL | Windows | CONFIGURATION MANAGEMENT |
| 18.10.36.1 Ensure 'Turn off location' is set to 'Enabled' | CIS Microsoft Windows 10 Stand-alone v5.0.0 L2 BL NG | Windows | CONFIGURATION MANAGEMENT |
| 18.10.36.1 Ensure 'Turn off location' is set to 'Enabled' | CIS Microsoft Windows 10 Stand-alone v5.0.0 L2 NG | Windows | CONFIGURATION MANAGEMENT |
| 18.10.36.1 Ensure 'Turn off location' is set to 'Enabled' | CIS Microsoft Windows 11 Stand-alone v5.0.0 L2 | Windows | CONFIGURATION MANAGEMENT |
| 18.10.36.1 Ensure 'Turn off location' is set to 'Enabled' | CIS Microsoft Windows 10 Enterprise v5.0.0 L2 BL | Windows | CONFIGURATION MANAGEMENT |
| 18.10.36.1 Ensure 'Turn off location' is set to 'Enabled' | CIS Microsoft Windows 11 Stand-alone v5.0.0 L2 BL | Windows | CONFIGURATION MANAGEMENT |
| 18.10.36.1 Ensure 'Turn off location' is set to 'Enabled' | CIS Microsoft Windows 10 Enterprise v5.0.0 L2 | Windows | CONFIGURATION MANAGEMENT |
| 18.10.36.1 Ensure 'Turn off location' is set to 'Enabled' | CIS Microsoft Windows 10 Enterprise v5.0.0 L2 NG | Windows | CONFIGURATION MANAGEMENT |
| Apply UAC restrictions to local accounts on network logon | MSCT Windows Server 2016 MS v1.0.0 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows 11 v24H2 v1.0.0 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows 11 v23H2 v1.0.0 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows 10 1909 v1.0.0 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows 10 v21H1 v1.0.0 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows Server v1909 MS v1.0.0 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows Server v20H2 MS v1.0.0 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows Server 2019 MS v1.0.0 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows 10 1903 v1.19.9 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows 10 v2004 v1.0.0 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows 10 v20H2 v1.0.0 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows Server v2004 MS v1.0.0 | Windows | ACCESS CONTROL |
| Apply UAC restrictions to local accounts on network logons | MSCT Windows Server 2025 MS v1.0.0 | Windows | ACCESS CONTROL |
| Configure RPC packet level privacy setting for incoming connections | MSCT Windows 11 v23H2 v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
| Configure RPC packet level privacy setting for incoming connections | MSCT Windows 11 v22H2 v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
| EX19-MB-000007 - Exchange must use encryption for Outlook Web App (OWA) access. | DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3 | Windows | ACCESS CONTROL |
| Extended Protection for LDAP Authentication (Domain Controllers only) (DEPRECATED) | MSCT Windows Server 2025 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
| PHTN-40-000223 - The Photon operating system must not forward IPv4 or IPv6 source-routed packets. | DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r2 | Unix | CONFIGURATION MANAGEMENT |
| SQL2-00-003200 - SQL Server must not grant users direct access to the View server state permission. | DISA STIG SQL Server 2012 DB Instance Security v1r20 | MS_SQLDB | ACCESS CONTROL |