| 1.1.3 Ensure that the controller manager pod specification file permissions are set to 600 or more restrictive | CIS Kubernetes v1.23 Benchmark v1.0.1 L1 Master | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.4 Ensure that the controller manager pod specification file ownership is set to root:root | CIS Kubernetes v1.23 Benchmark v1.0.1 L1 Master | Unix | ACCESS CONTROL |
| 1.3.7 Ensure that the --bind-address argument is set to 127.0.0.1 | CIS Kubernetes v1.23 Benchmark v1.0.1 L1 Master | Unix | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.5.5 Ensure that the --peer-client-cert-auth argument is set to true | CIS Kubernetes 1.11 Benchmark v1.3.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 2.1.3 Ensure that the --authorization-mode argument is not set to AlwaysAllow | CIS Kubernetes 1.7.0 Benchmark v1.1.0 L1 | Unix | ACCESS CONTROL |
| 4.2.12 Ensure that the Kubelet only makes use of Strong Cryptographic Ciphers | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | IDENTIFICATION AND AUTHENTICATION |
| 5.3.1 Ensure Kubernetes Secrets are encrypted using keys managed in Cloud KMS | CIS Google Kubernetes Engine GKE Autopilot v1.3.0 L2 | GCP | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.5.1.2 Ensure minimum days between password changes is configured - /etc/shadow | CIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 Workstation | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| GOOG-14-006100 - Google Android 14 must be configured to not allow passwords that include more than four repeating or sequential characters - Alphanumeric | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | IDENTIFICATION AND AUTHENTICATION |
| GOOG-14-006300 - Google Android 14 must be configured to lock the display after 15 minutes (or less) of inactivity - or less of inactivity. | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | ACCESS CONTROL |
| GOOG-14-006300 - Google Android 14 must be configured to lock the display after 15 minutes (or less) of inactivity - or less of inactivity. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | ACCESS CONTROL |
| GOOG-14-006500 - Google Android 14 must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including [selection: DOD-approved commercial app repository, MDM server, mobile application store]. | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-006700 - Google Android 14 allowlist must be configured to not include applications with the following characteristics: | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION |
| GOOG-14-007400 - Google Android 14 must be configured to disable developer modes. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-008500 - Google Android 14 must be configured to not allow backup of [all applications, configuration data] to locally connected systems. | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |
| GOOG-14-011000 - Android 14 devices must be configured to enable Common Criteria Mode (CC Mode) - CC Mode. | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| JUEX-NM-000490 - The Juniper EX switch must use an an NTP service that is hosted by a trusted source or a DOD-compliant enterprise or local NTP server. | DISA Juniper EX Series Network Device Management v2r4 | Juniper | IDENTIFICATION AND AUTHENTICATION |
| MADB-10-000400 - MariaDB must protect against a user falsely repudiating having performed organization-defined actions. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-000700 - MariaDB must be able to generate audit records when privileges/permissions are retrieved. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-001000 - MariaDB must produce audit records containing sufficient information to establish what type of events occurred. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-002200 - The audit information produced by MariaDB must be protected from unauthorized deletion. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-002400 - MariaDB must protect its audit configuration from unauthorized modification. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-002700 - The MariaDB software installation account must be restricted to authorized users. | DISA MariaDB Enterprise 10.x STIG v2r5 Unix | Unix | CONFIGURATION MANAGEMENT |
| MADB-10-003000 - The role(s)/group(s) used to modify database structure (including but not necessarily limited to tables, indexes, storage, etc.) and logic modules (stored procedures, functions, triggers, links to software external to the MariaDB, etc.) must be restricted to authorized users. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | CONFIGURATION MANAGEMENT |
| MADB-10-003700 - If MariaDB authentication, using passwords, is employed, then MariaDB must enforce the DOD standards for password complexity. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | IDENTIFICATION AND AUTHENTICATION |
| MADB-10-003750 - If MariaDB authentication using passwords is employed, MariaDB must enforce the DOD standards for password lifetime. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | IDENTIFICATION AND AUTHENTICATION |
| MADB-10-004300 - MariaDB must obscure feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals. | DISA MariaDB Enterprise 10.x STIG v2r5 Unix | Unix | IDENTIFICATION AND AUTHENTICATION |
| MADB-10-004400 - MariaDB must use NIST FIPS 140-2/140-3 validated cryptographic modules for cryptographic operations. | DISA MariaDB Enterprise 10.x STIG v2r5 Unix | Unix | IDENTIFICATION AND AUTHENTICATION |
| MADB-10-006200 - MariaDB must automatically terminate a user's session after organization-defined conditions or trigger events requiring session disconnect. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | ACCESS CONTROL |
| MADB-10-006700 - MariaDB must enforce discretionary access control policies, as defined by the data owner, over defined subjects, and objects. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | ACCESS CONTROL |
| MADB-10-006800 - MariaDB must prevent nonprivileged users from executing privileged functions, to include disabling, circumventing, or altering implemented security safeguards/countermeasures. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | ACCESS CONTROL |
| MADB-10-007300 - MariaDB must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-007400 - MariaDB must provide a warning to appropriate support staff when allocated audit record storage volume reaches 75 percent of maximum audit record storage capacity. | DISA MariaDB Enterprise 10.x STIG v2r5 Unix | Unix | AUDIT AND ACCOUNTABILITY |
| MADB-10-007800 - MariaDB must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | CONFIGURATION MANAGEMENT |
| MADB-10-007900 - MariaDB must enforce access restrictions associated with changes to the configuration of MariaDB or database(s). | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | CONFIGURATION MANAGEMENT |
| MADB-10-008000 - MariaDB must produce audit records of its enforcement of access restrictions associated with changes to the configuration of the DBMS or database(s). | DISA MariaDB Enterprise 10.x STIG v2r5 Unix | Unix | CONFIGURATION MANAGEMENT |
| MADB-10-008300 - MariaDB must prohibit the use of cached authenticators after an organization-defined time period. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | IDENTIFICATION AND AUTHENTICATION |
| MADB-10-008400 - MariaDB must use NSA-approved cryptography to protect classified information in accordance with the data owner's requirements. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| MADB-10-008700 - MariaDB must implement cryptographic mechanisms preventing the unauthorized disclosure of organization-defined information at rest on organization-defined information system components. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| MADB-10-008900 - MariaDB must maintain the confidentiality and integrity of information during preparation for transmission. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| MADB-10-009100 - When invalid inputs are received, MariaDB must behave in a predictable and documented manner that reflects organizational and system objectives. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | SYSTEM AND INFORMATION INTEGRITY |
| MADB-10-009400 - MariaDB must be able to generate audit records when security objects are accessed. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-009700 - MariaDB must generate audit records when unsuccessful attempts to access categories of information (e.g., classification levels/security levels) occur. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-009800 - MariaDB must generate audit records when privileges/permissions are added. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-010000 - MariaDB must generate audit records when privileges/permissions are modified. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-010600 - MariaDB must generate audit records when privileges/permissions are deleted. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-010700 - MariaDB must generate audit records when unsuccessful attempts to delete privileges/permissions occur. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-011000 - MariaDB must generate audit records when categories of information (e.g., classification levels/security levels) are deleted. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-011400 - MariaDB must generate audit records for all privileged activities or other system-level access. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-011800 - MariaDB must be able to generate audit records when successful accesses to objects occur. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |