| 1.1 SLES-15-010000 | CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT I | Unix | SYSTEM AND INFORMATION INTEGRITY |
| 1.8 CISC-ND-000470 | CIS Cisco IOS XR Router NDM STIG v1.0.0 CAT I | Cisco | CONFIGURATION MANAGEMENT |
| 1.16 CISC-ND-000470 | CIS Cisco IOS XE Switch NDM STIG v1.1.0 CAT I | Cisco | CONFIGURATION MANAGEMENT |
| 1.16 CISC-ND-000470 | CIS Cisco IOS Switch NDM STIG v1.1.0 CAT I | Cisco | CONFIGURATION MANAGEMENT |
| 1.24 CISC-ND-000620 | CIS Cisco IOS XE Switch NDM STIG v1.1.0 CAT I | Cisco | IDENTIFICATION AND AUTHENTICATION |
| 1.44 RHEL-09-214015 | CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT I | Unix | CONFIGURATION MANAGEMENT |
| 1.45 RHEL-09-214020 | CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT I | Unix | CONFIGURATION MANAGEMENT |
| 1.46 RHEL-09-214025 | CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT I | Unix | CONFIGURATION MANAGEMENT |
| 1.54 SLES-15-010430 | CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT I | Unix | CONFIGURATION MANAGEMENT |
| 1.56 WN22-AC-000090 | CIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT I | Windows | IDENTIFICATION AND AUTHENTICATION |
| 1.56 WN22-AC-000090 | CIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT I | Windows | IDENTIFICATION AND AUTHENTICATION |
| 1.59 OL08-00-010371 | CIS Oracle Linux 8 STIG v1.0.0 CAT I | Unix | CONFIGURATION MANAGEMENT |
| 1.89 APPL-14-002060 | CIS Apple macOS 14 Sonoma STIG v1.0.0 CAT I | Unix | CONFIGURATION MANAGEMENT |
| 1.92 APPL-14-002064 | CIS Apple macOS 14 Sonoma STIG v1.0.0 CAT I | Unix | CONFIGURATION MANAGEMENT |
| 1.161 WN22-DC-000150 | CIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT I | Windows | CONFIGURATION MANAGEMENT |
| 1.237 WN22-SO-000300 | CIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT I | Windows | IDENTIFICATION AND AUTHENTICATION |
| 1.237 WN22-SO-000300 | CIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT I | Windows | IDENTIFICATION AND AUTHENTICATION |
| 1.336 RHEL-10-700640 | CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT I | Unix | CONFIGURATION MANAGEMENT |
| 2.2.14 Ensure NIS server is not installed | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| 5.1.20 Ensure sshd PermitEmptyPasswords is disabled | CIS Red Hat Enterprise Linux 8 STIG v2.0.0 L1 Server | Unix | CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION |
| 5.1.20 Ensure sshd PermitEmptyPasswords is disabled | CIS Red Hat Enterprise Linux 8 STIG v2.0.0 L1 Workstation | Unix | CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION |
| 5.1.20 Ensure sshd PermitEmptyPasswords is disabled | CIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIG | Unix | CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION |
| 5.5.8 Ensure Default user umask is 077 | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| 7.1.14 Ensure there are no ".shosts" files on the operating system | CIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIG | Unix | CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION |
| 7.1.15 Ensure there are no "shosts.equiv" files on the operating system | CIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIG | Unix | CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION |
| APPL-14-002060 - The macOS system must apply gatekeeper settings to block applications from unidentified developers. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |
| APPL-14-002064 - The macOS system must enable Gatekeeper. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |
| ESXI-06-000015 - The SSH daemon must not allow authentication using an empty password. | DISA VMware vSphere ESXi 6.0 STIG v1r5 Unix | Unix | IDENTIFICATION AND AUTHENTICATION |
| ESXI-06-000071 - The system must verify the integrity of the installation media before installing ESXi. | DISA VMware vSphere ESXi 6.0 STIG v1r5 | VMware | CONFIGURATION MANAGEMENT |
| ESXI-06-000072 - The system must have all security patches and updates installed. | DISA VMware vSphere ESXi 6.0 STIG v1r5 | VMware | CONFIGURATION MANAGEMENT |
| GEN001100 - Root passwords must never be passed over a network in clear text form - 'root has logged in over a network' | DISA STIG AIX 6.1 v1r14 | Unix | IDENTIFICATION AND AUTHENTICATION |
| GEN001100 - Root passwords must never be passed over a network in clear text form - 'ssh is running' | DISA STIG AIX 6.1 v1r14 | Unix | IDENTIFICATION AND AUTHENTICATION |
| GEN003850 - The telnet daemon must not be running. | DISA STIG AIX 6.1 v1r14 | Unix | IDENTIFICATION AND AUTHENTICATION |
| JUEX-NM-000330 - The Juniper EX switch must be configured to only store cryptographic representations of passwords. | DISA Juniper EX Series Network Device Management v2r4 | Juniper | IDENTIFICATION AND AUTHENTICATION |
| MD7X-00-008500 - MongoDB must implement cryptographic mechanisms to prevent unauthorized modification of organization-defined information at rest (to include, at a minimum, PII and classified information) on organization-defined information system components. | DISA MongoDB Enterprise Advanced 7.x STIG v1r2 Unix | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| MD8X-00-008100 - MongoDB must implement cryptographic mechanisms to prevent unauthorized modification of organization-defined information at rest (to include, at a minimum, PII and classified information) on organization-defined information system components. | DISA MongoDB Enterprise Advanced 8.x STIG v1r1 Unix | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| OL08-00-010370 - YUM must be configured to prevent the installation of patches, service packs, device drivers, or OL 8 system components that have not been digitally signed using a certificate that is recognized and approved by the organization. | DISA Oracle Linux 8 STIG v2r9 | Unix | CONFIGURATION MANAGEMENT |
| OL08-00-010371 - OL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components of local packages without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization. | DISA Oracle Linux 8 STIG v2r9 | Unix | CONFIGURATION MANAGEMENT |
| PHTN-40-000130 - The Photon operating system TDNF package management tool must cryptographically verify the authenticity of all software packages during installation. | DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r2 | Unix | CONFIGURATION MANAGEMENT |
| PHTN-40-000199 - The Photon operating system TDNF package management tool must cryptographically verify the authenticity of all software packages during installation for all repos. | DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-08-010370 - RHEL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components from a repository without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization. | DISA Red Hat Enterprise Linux 8 STIG v2r8 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-08-010371 - RHEL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components of local packages without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization. | DISA Red Hat Enterprise Linux 8 STIG v2r8 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-09-214015 - RHEL 9 must check the GPG signature of software packages originating from external software repositories before installation. | DISA Red Hat Enterprise Linux 9 STIG v2r9 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-09-214020 - RHEL 9 must check the GPG signature of locally installed software packages before installation. | DISA Red Hat Enterprise Linux 9 STIG v2r9 | Unix | CONFIGURATION MANAGEMENT |
| SLES-15-010430 - The SUSE operating system tool zypper must have gpgcheck enabled. | DISA SUSE Linux Enterprise Server 15 STIG v2r8 | Unix | CONFIGURATION MANAGEMENT |
| SPLK-CL-000490 - Splunk Enterprise must accept the DOD CAC or other PKI credential for identity management and personal authentication. | DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST API | Splunk | IDENTIFICATION AND AUTHENTICATION |
| VMCH-06-000005 - The system must disable virtual disk shrinking. | DISA VMware vSphere Virtual Machine Version 6 STIG v1r1 | VMware | CONFIGURATION MANAGEMENT |
| VMCH-06-000007 - The system must not use independent, non-persistent disks. | DISA VMware vSphere Virtual Machine Version 6 STIG v1r1 | VMware | AUDIT AND ACCOUNTABILITY |
| WN11-CC-000315 - The Windows Installer feature 'Always install with elevated privileges' must be disabled. | DISA Microsoft Windows 11 STIG v2r8 | Windows | CONFIGURATION MANAGEMENT |
| WN22-CC-000430 - Windows Server 2022 must disable the Windows Installer Always install with elevated privileges option. | DISA Microsoft Windows Server 2022 STIG v2r8 | Windows | CONFIGURATION MANAGEMENT |