| 1.1.1 Ensure that the API server pod specification file permissions are set to 600 or more restrictive | CIS Kubernetes v1.24 Benchmark v1.0.0 L1 Master | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.9 Ensure that the --profiling argument is set to false | CIS Kubernetes 1.7.0 Benchmark v1.1.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 1.1.19 Ensure that the --audit-log-maxsize argument is set to 100 or as appropriate | CIS Kubernetes 1.7.0 Benchmark v1.1.0 L1 | Unix | AUDIT AND ACCOUNTABILITY |
| 1.1.23 Ensure that the --service-account-lookup argument is set to true | CIS Kubernetes 1.13 Benchmark v1.4.1 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 1.2.11 Ensure that the admission control plugin AlwaysPullImages is set | CIS Kubernetes v1.20 Benchmark v1.0.1 L1 Master | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 1.2.20 Ensure that the --audit-log-maxbackup argument is set to 10 or as appropriate | CIS Kubernetes v1.23 Benchmark v1.0.1 L1 Master | Unix | AUDIT AND ACCOUNTABILITY |
| 1.3.5 Ensure that the --root-ca-file argument is set as appropriate | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 1.3.5 Ensure that the --root-ca-file argument is set as appropriate | CIS Kubernetes 1.11 Benchmark v1.3.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 1.7.6 Do not admit root containers | CIS Kubernetes 1.11 Benchmark v1.3.0 L2 | Unix | CONFIGURATION MANAGEMENT |
| 2.4 Ensure that the --peer-cert-file and --peer-key-file arguments are set as appropriate - cert | CIS Kubernetes v1.23 Benchmark v1.0.1 L1 Master | Unix | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.4 Ensure that the --peer-cert-file and --peer-key-file arguments are set as appropriate - cert | CIS Kubernetes v1.24 Benchmark v1.0.0 L1 Master | Unix | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 3.1.18 Ensure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriate - etcd-keyfile | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 3.1.19 Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate - tls-cert-file | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 4.1.6 Ensure that the --kubeconfig kubelet.conf file ownership is set to root:root | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 4.6.3 Apply Security Context to Pods and Containers | CIS Google Kubernetes Engine GKE Autopilot v1.3.0 L2 | GCP | CONFIGURATION MANAGEMENT |
| 4.6.3 Apply Security Context to Pods and Containers | CIS Google Kubernetes Engine GKE v1.9.0 L2 GCP | GCP | CONFIGURATION MANAGEMENT |
| 5.5.1.2 Ensure minimum days between password changes is configured - /etc/login.defs | CIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 Server | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 5.5.1.2 Ensure minimum days between password changes is configured - /etc/shadow | CIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 Server | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 5.6.3 Apply Security Context to Your Pods and Containers | CIS Kubernetes v2.0.1 L2 Master Node | Unix | CONFIGURATION MANAGEMENT |
| 5.6.3 Ensure Control Plane Authorized Networks is Enabled | CIS Google Kubernetes Engine GKE v1.9.0 L2 GCP | GCP | ACCESS CONTROL, MEDIA PROTECTION |
| GOOG-14-002800 - Google Android 14 must be configured to enable audit logging. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | AUDIT AND ACCOUNTABILITY |
| GOOG-14-006100 - Google Android 14 must be configured to not allow passwords that include more than four repeating or sequential characters - Numbers | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | IDENTIFICATION AND AUTHENTICATION |
| GOOG-14-006500 - Google Android 14 must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including [selection: DOD-approved commercial app repository, MDM server, mobile application store]. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-006500 - Google Android 14 must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including [selection: DOD-approved commercial app repository, MDM server, mobile application store]. | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-006600 - Google Android 14 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version]. | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-007200 - Google Android 14 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation. | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | IDENTIFICATION AND AUTHENTICATION |
| GOOG-14-007700 - Google Android 14 must be configured to display the DOD advisory warning message at startup or each time the user unlocks the device. | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | ACCESS CONTROL |
| GOOG-14-007800 - Google Android 14 must be configured to generate audit records for the following auditable events: Detected integrity violations. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | AUDIT AND ACCOUNTABILITY |
| GOOG-14-008400 - Google Android 14 must be configured to disable USB mass storage mode. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |
| GOOG-14-008500 - Google Android 14 must be configured to not allow backup of [all applications, configuration data] to locally connected systems. | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |
| GOOG-14-008600 - Google Android 14 must be configured to not allow backup of [all applications, configuration data] to remote systems. | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |
| GOOG-14-009000 - Google Android 14 must be configured to disable multiuser modes. | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| GOOG-14-009400 - Google Android 14 must be configured to disable all Bluetooth profiles except for HSP (Headset Profile), HFP (Hands-Free Profile), SPP (Serial Port Profile), A2DP (Advanced Audio Distribution Profile), AVRCP (Audio/Video Remote Control Profile), and PBAP (Phone Book Access Profile) - SPP. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-009400 - Google Android 14 must be configured to disable all Bluetooth profiles except for HSP (Headset Profile), HFP (Hands-Free Profile), SPP (Serial Port Profile), A2DP (Advanced Audio Distribution Profile), AVRCP (Audio/Video Remote Control Profile), and PBAP (Phone Book Access Profile) - SPP. | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-009500 - Google Android 14 must be configured to disable ad hoc wireless client-to-client connection capability. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |
| GOOG-14-009900 - Google Android 14 must be configured to enforce that Wi-Fi Sharing is disabled. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-010200 - The Google Android 14 work profile must be configured to enforce the system application disable list. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-010200 - The Google Android 14 work profile must be configured to enforce the system application disable list. | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-010500 - The Google Android 14 work profile must be configured to disable the autofill services. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-010800 - Android 14 devices must have the latest available Google Android 14 operating system installed. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-012200 - Google Android 14 must be configured to disable all data signaling over [assignment: list of externally accessible hardware ports (for example, USB)] - for example, USB]. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | ACCESS CONTROL |
| GOOG-14-012400 - Google Android 14 must allow only the administrator (MDM) to perform the following management function: Disable Phone Hub - MDM to perform the following management function: Disable Phone Hub. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |
| GOOG-14-012400 - Google Android 14 must allow only the administrator (MDM) to perform the following management function: Disable Phone Hub - MDM to perform the following management function: Disable Phone Hub. | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |
| GOOG-14-013000 - Google Android 14 must disable the user's ability to wipe the device. | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-013200 - Google Android 14 must disable wireless printing. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-013500 - Google Android 14 must implement the management setting: disable Camera. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-013500 - Google Android 14 must implement the management setting: disable Camera. | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-013600 - The Google Android device must be configured to disable Wi-Fi Aware for Work Profile apps. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-013600 - The Google Android device must be configured to disable Wi-Fi Aware for Work Profile apps. | MobileIron - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| SHPT-00-000760 - SharePoint must implement security functions as largely independent modules to avoid unnecessary interactions between modules - Internet & Extranet assigned to diff App Pools | DISA STIG SharePoint 2010 v1r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |