| 1.2.28 Ensure that the --etcd-cafile argument is set as appropriate | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.6.4 Ensure that the seccomp profile is set to docker/default in your pod definitions | CIS Kubernetes 1.13 Benchmark v1.4.1 L2 | Unix | |
| GOOG-14-002800 - Google Android 14 must be configured to enable audit logging. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | AUDIT AND ACCOUNTABILITY |
| GOOG-14-006600 - Google Android 14 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version]. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-006800 - Google Android 14 must be configured to not display the following (work profile) notifications when the device is locked: [selection: | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | ACCESS CONTROL |
| GOOG-14-007200 - Google Android 14 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation. | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | IDENTIFICATION AND AUTHENTICATION |
| GOOG-14-007200 - Google Android 14 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | IDENTIFICATION AND AUTHENTICATION |
| GOOG-14-007700 - Google Android 14 must be configured to display the DOD advisory warning message at startup or each time the user unlocks the device. | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | ACCESS CONTROL |
| GOOG-14-007700 - Google Android 14 must be configured to display the DOD advisory warning message at startup or each time the user unlocks the device. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | ACCESS CONTROL |
| GOOG-14-007700 - Google Android 14 must be configured to display the DOD advisory warning message at startup or each time the user unlocks the device. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | ACCESS CONTROL |
| GOOG-14-008500 - Google Android 14 must be configured to not allow backup of [all applications, configuration data] to locally connected systems. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |
| GOOG-14-008500 - Google Android 14 must be configured to not allow backup of [all applications, configuration data] to locally connected systems. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |
| GOOG-14-008600 - Google Android 14 must be configured to not allow backup of [all applications, configuration data] to remote systems. | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |
| GOOG-14-009000 - Google Android 14 must be configured to disable multiuser modes. | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| GOOG-14-009000 - Google Android 14 must be configured to disable multiuser modes. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| GOOG-14-009500 - Google Android 14 must be configured to disable ad hoc wireless client-to-client connection capability. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |
| GOOG-14-009800 - Google Android 14 users must complete required training. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-010000 - Google Android 14 must have the DOD root and intermediate PKI certificates installed. | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-010900 - Android 14 devices must be configured to disable the use of third-party keyboards. | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-010900 - Android 14 devices must be configured to disable the use of third-party keyboards. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-012300 - The Google Android 14 must allow only the administrator (EMM) to install/remove DOD root and intermediate PKI certificates - EMM to install/remove DOD root and intermediate PKI certificates. | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-012400 - Google Android 14 must allow only the administrator (MDM) to perform the following management function: Disable Phone Hub - MDM to perform the following management function: Disable Phone Hub. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | SYSTEM AND COMMUNICATIONS PROTECTION |
| GOOG-14-013000 - Google Android 14 must disable the user's ability to wipe the device. | MobileIron - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| GOOG-14-013400 - Google Android 14 devices must have a Mobile Threat Detection (MTD) app installed. | AirWatch - DISA Google Android 14 COBO STIG v2r5 | MDM | CONFIGURATION MANAGEMENT |
| MADB-10-000200 - MariaDB must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | ACCESS CONTROL |
| MADB-10-000500 - MariaDB must provide audit record generation capability for DoD-defined auditable events within all DBMS/database components. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-000600 - MariaDB must allow only the ISSM (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-000800 - MariaDB must be able to generate audit records when unsuccessful attempts to retrieve privileges/permissions occur. | DISA MariaDB Enterprise 10.x STIG v2r5 Unix | Unix | AUDIT AND ACCOUNTABILITY |
| MADB-10-000900 - MariaDB must initiate session auditing upon startup. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-001800 - MariaDB must be configurable to overwrite audit log records, oldest first (First-In-First-Out - FIFO), in the event of unavailability of space for more audit log records. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-002000 - The audit information produced by MariaDB must be protected from unauthorized read access. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-002100 - The audit information produced by MariaDB must be protected from unauthorized modification. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-002300 - MariaDB must protect its audit features from unauthorized access. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-003500 - MariaDB must be configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | CONFIGURATION MANAGEMENT |
| MADB-10-003600 - MariaDB must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users). | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | IDENTIFICATION AND AUTHENTICATION |
| MADB-10-004200 - MariaDB must map PKI ID to an associated user account. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | IDENTIFICATION AND AUTHENTICATION |
| MADB-10-005000 - MariaDB must fail to a secure state if system initialization fails, shutdown fails, or aborts fail. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| MADB-10-005400 - Database contents must be protected from unauthorized and unintended information transfer by enforcement of a data-transfer policy. | DISA MariaDB Enterprise 10.x STIG v2r5 Unix | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| MADB-10-005800 - MariaDB and associated applications must reserve the use of dynamic code execution for situations that require it. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | SYSTEM AND INFORMATION INTEGRITY |
| MADB-10-006400 - MariaDB must associate organization-defined types of security labels having organization-defined security label values with information in storage. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | ACCESS CONTROL |
| MADB-10-007600 - MariaDB must record time stamps, in audit records and application data, that can be mapped to Coordinated Universal Time (UTC, formerly GMT). | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-008600 - MariaDB must implement cryptographic mechanisms to prevent unauthorized modification of organization-defined information at rest (to include, at a minimum, PII and classified information) on organization-defined information system components. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| MADB-10-009600 - MariaDB must generate audit records when categories of information (e.g., classification levels/security levels) are accessed. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-010300 - MariaDB must generate audit records when unsuccessful attempts to modify security objects occur. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-011100 - MariaDB must generate audit records when unsuccessful attempts to delete categories of information (e.g., classification levels/security levels) occur. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-011500 - MariaDB must generate audit records when unsuccessful attempts to execute privileged activities or other system-level access occur. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-011600 - MariaDB must generate audit records showing starting and ending time for user access to the database(s). | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-011900 - MariaDB must generate audit records when unsuccessful accesses to objects occur. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-012400 - MariaDB must off-load audit data to a separate log management facility; this must be continuous and in near real time for systems with a network connection to the storage facility and weekly or more often for stand-alone systems. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | AUDIT AND ACCOUNTABILITY |
| MADB-10-012600 - MariaDB products must be an enterprise version supported by the vendor. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | SYSTEM AND SERVICES ACQUISITION |