| 2.3.9.3 Ensure 'Microsoft network server: Digitally sign communications (if client agrees)' is set to 'Enabled' | CIS Microsoft Windows 8.1 v2.4.1 L1 | Windows | CONFIGURATION MANAGEMENT |
| 2.3.10.10 (L1) Ensure 'Network access: Restrict clients allowed to make remote calls to SAM' is set to 'Administrators: Remote Access: Allow' | CIS Microsoft Windows Server 2019 Stand-alone v3.0.0 L1 MS | Windows | ACCESS CONTROL |
| 2.3.10.10 Ensure 'Network access: Restrict clients allowed to make remote calls to SAM' is set to 'Administrators: Remote Access: Allow' | CIS Microsoft Windows Server 2022 Stand-alone v2.0.0 L1 MS | Windows | ACCESS CONTROL |
| 2.3.10.11 (L1) Ensure 'Network access: Restrict clients allowed to make remote calls to SAM' is set to 'Administrators: Remote Access: Allow' (MS only) | CIS Microsoft Windows Server 2016 v4.0.0 L1 MS | Windows | ACCESS CONTROL |
| 2.3.10.11 Ensure 'Network access: Restrict clients allowed to make remote calls to SAM' is set to 'Administrators: Remote Access: Allow' (MS only) | CIS Microsoft Windows Server 2025 v2.1.0 L1 MS | Windows | ACCESS CONTROL |
| 3.076 - The system is not configured to meet the minimum requirement for session security for NTLM SSP based Clients. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 4.11.41.1 Ensure 'Turn off the offer to update to the latest version of Windows' is set to 'Enabled' | CIS Microsoft Intune for Windows 10 v5.0.0 L1 | Windows | CONFIGURATION MANAGEMENT |
| 16 - CIFS SMB Signing and Sealing - SMB encryption is enabled | NetApp Security Hardening Guide for ONTAP 9 v1.7.0 | Netapp_API | |
| 16 - CIFS SMB Signing and Sealing - SMB signing is enabled | NetApp Security Hardening Guide for ONTAP 9 v1.7.0 | Netapp_API | |
| 17.2.1 (L1) Ensure 'Audit Application Group Management' is set to 'Success and Failure' | CIS Windows Server 2012 MS L1 v3.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
| 17.2.1 (L1) Ensure 'Audit Application Group Management' is set to 'Success and Failure' | CIS Microsoft Windows Server 2008 Member Server Level 1 v3.3.1 | Windows | AUDIT AND ACCOUNTABILITY |
| 17.2.1 (L1) Ensure 'Audit Application Group Management' is set to 'Success and Failure' | CIS Windows Server 2012 R2 DC L1 v3.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
| 17.2.1 (L1) Ensure 'Audit Application Group Management' is set to 'Success and Failure' | CIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker | Windows | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 17.2.1 (L1) Ensure 'Audit Application Group Management' is set to 'Success and Failure' | CIS Microsoft Windows Server 2008 Domain Controller Level 1 v3.3.1 | Windows | AUDIT AND ACCOUNTABILITY |
| 17.2.1 (L1) Ensure 'Audit Application Group Management' is set to 'Success and Failure' | CIS Windows Server 2012 DC L1 v3.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
| 17.2.1 (L1) Ensure 'Audit Application Group Management' is set to 'Success and Failure' | CIS Microsoft Windows Server 2008 R2 Member Server Level 1 v3.3.1 | Windows | AUDIT AND ACCOUNTABILITY |
| 17.2.1 Ensure 'Audit Application Group Management' is set to 'Success and Failure' | CIS Windows 7 Workstation Level 1 v3.2.0 | Windows | AUDIT AND ACCOUNTABILITY |
| 18.9.77.14 Ensure 'Turn off Windows Defender AntiVirus' is set to 'Disabled' | CIS Windows 7 Workstation Level 1 v3.2.0 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.10.18.1 Ensure 'Enable App Installer' is set to 'Disabled' | CIS Microsoft Windows Server 2025 v2.1.0 L2 MS | Windows | CONFIGURATION MANAGEMENT |
| 18.10.18.1 Ensure 'Enable App Installer' is set to 'Disabled' | CIS Microsoft Windows Server 2022 Stand-alone v2.0.0 L2 MS | Windows | CONFIGURATION MANAGEMENT |
| 18.10.18.1 Ensure 'Enable App Installer' is set to 'Disabled' | CIS Microsoft Windows 11 Stand-alone v5.0.0 L2 | Windows | CONFIGURATION MANAGEMENT |
| 18.10.18.1 Ensure 'Enable App Installer' is set to 'Disabled' | CIS Microsoft Windows 10 Enterprise v5.0.0 L2 | Windows | CONFIGURATION MANAGEMENT |
| 18.10.18.1 Ensure 'Enable App Installer' is set to 'Disabled' | CIS Microsoft Windows 10 Enterprise v5.0.0 L2 BL | Windows | CONFIGURATION MANAGEMENT |
| 18.10.66.3 (L1) Ensure 'Turn off the offer to update to the latest version of Windows' is set to 'Enabled' | CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 | Windows | CONFIGURATION MANAGEMENT |
| 18.10.66.3 Ensure 'Turn off the offer to update to the latest version of Windows' is set to 'Enabled' | CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 | Windows | CONFIGURATION MANAGEMENT |
| 18.10.66.3 Ensure 'Turn off the offer to update to the latest version of Windows' is set to 'Enabled' | CIS Microsoft Windows 11 Enterprise v5.1.0 L1 | Windows | CONFIGURATION MANAGEMENT |
| 18.10.66.4 Ensure 'Turn off the Store application' is set to 'Enabled' | CIS Microsoft Windows 10 Enterprise v5.0.0 L2 BL NG | Windows | CONFIGURATION MANAGEMENT |
| 18.10.66.4 Ensure 'Turn off the Store application' is set to 'Enabled' | CIS Microsoft Windows 11 Stand-alone v5.0.0 L2 | Windows | CONFIGURATION MANAGEMENT |
| 18.10.66.4 Ensure 'Turn off the Store application' is set to 'Enabled' | CIS Microsoft Windows 11 Enterprise v5.1.0 L2 | Windows | CONFIGURATION MANAGEMENT |
| Allow certificates signed using SHA-1 when issued by local trust anchors (deprecated) | MSCT Edge v89 v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
| Allow certificates signed using SHA-1 when issued by local trust anchors (deprecated) | MSCT Edge v90 v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
| Allow certificates signed using SHA-1 when issued by local trust anchors (deprecated) | MSCT Edge v91 v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
| Allow certificates signed using SHA-1 when issued by local trust anchors (deprecated) | MSCT Edge v88 v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
| Authentication with Exchange Server | Microsoft 365 Apps for Enterprise 2306 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Authentication with Exchange Server | MSCT Office 365 ProPlus 1908 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| CIS_Microsoft_Windows_10_Enterprise_v5.0.0_L1.audit from CIS Microsoft Windows 10 Enterprise v5.0.0 | CIS Microsoft Windows 10 Enterprise v5.0.0 L1 | Windows | |
| CIS_Microsoft_Windows_Server_2016_STIG_v4.0.0_DC_CAT_I.audit from CIS Microsoft Windows Server 2016 STIG v4.0.0 | CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT I | Windows | |
| CIS_Microsoft_Windows_Server_2016_STIG_v4.0.0_MS_CAT_III.audit from CIS Microsoft Windows Server 2016 STIG v4.0.0 | CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT III | Windows | |
| CIS_Microsoft_Windows_Server_2016_v4.0.0_L1_DC.audit from CIS Microsoft Windows Server 2016 Benchmark v4.0.0 | CIS Microsoft Windows Server 2016 v4.0.0 L1 DC | Windows | |
| CIS_Microsoft_Windows_Server_2019_STIG_v4.0.0_DC_CAT_I.audit from CIS Microsoft Windows Server 2019 STIG v4.0.0 | CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT I | Windows | |
| CIS_Microsoft_Windows_Server_2019_STIG_v4.0.0_DC_CAT_II.audit from CIS Microsoft Windows Server 2019 STIG v4.0.0 | CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT II | Windows | |
| CIS_Microsoft_Windows_Server_2022_STIG_v3.0.0_DC_CAT_I.audit from CIS Microsoft Windows Server 2022 STIG v3.0.0 | CIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT I | Windows | |
| CIS_MS_Windows_7_v3.2.0_Bitlocker.audit from CIS Microsoft Windows 7 Workstation Benchmark v3.2.0 | CIS Windows 7 Workstation Bitlocker v3.2.0 | Windows | |
| CIS_MS_Windows_7_v3.2.0_Level_2_Bitlocker.audit from CIS Microsoft Windows 7 Workstation Benchmark v3.2.0 | CIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0 | Windows | |
| Configure Windows SmartScreen | MSCT Windows Server 2016 MS v1.0.0 | Windows | ACCESS CONTROL |
| DISA_STIG_Microsoft_Windows_10_v3r6.audit from DISA Microsoft Windows 10 STIG v3r6 | DISA Microsoft Windows 10 STIG v3r6 | Windows | |
| DTOO280 - Outlook must be configured to force authentication when connecting to an Exchange server. | DISA STIG Microsoft Outlook 2016 v2r4 | Windows | IDENTIFICATION AND AUTHENTICATION |
| O365-OU-000001 - The Exchange client authentication with Exchange servers must be enabled to use Kerberos Password Authentication. | DISA Microsoft Office 365 ProPlus STIG v3r5 | Windows | IDENTIFICATION AND AUTHENTICATION |
| VCENTER-000008 - The vCenter Server must be installed using a service account instead of a built-in Windows account. | DISA STIG VMWare ESXi vCenter 5 STIG v2r1 | VMware | CONFIGURATION MANAGEMENT |
| VM Tools: guest-8.tools-enable-syslog | VMware vSphere Security Configuration and Hardening Guide | VMware | CONFIGURATION MANAGEMENT |