| 1.2 Password Security Policy - b) The password must include either three of 'number', 'capital', 'lowercase', 'special-character' or set the 'character-set-num' value to 3-4 | Tenable ZTE JINOS | ZTE_JINOS | IDENTIFICATION AND AUTHENTICATION |
| 1.4 SNMP Security - a) SNMP Community Security | Tenable ZTE JINOS | ZTE_JINOS | IDENTIFICATION AND AUTHENTICATION |
| 1.6 Support Web Access Security - b) ssl-context field | Tenable ZTE JINOS | ZTE_JINOS | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.8 SSH Strong Algorithm - i) Disable diffie-hellman group-exchange-sha1 | Tenable ZTE JINOS | ZTE_JINOS | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.2.23 Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE, RESTRICTED SERVICES\PrintSpoolerService' | CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 | Windows | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 2.2.23 Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE, RESTRICTED SERVICES\PrintSpoolerService' | CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BL | Windows | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 2.2.23 Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE, RESTRICTED SERVICES\PrintSpoolerService' | CIS Microsoft Windows 11 Enterprise v5.1.0 L1 | Windows | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 2.2.23 Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE' | CIS Microsoft Windows 10 Enterprise v5.0.0 L1 NG | Windows | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 2.2.24 (L1) Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE' | CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 | Windows | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 2.2.24 Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE' | CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0 | Windows | ACCESS CONTROL |
| 2.2.31 (L1) Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE' and (when the Web Server (IIS) Role with Web Services Role Service is installed) 'IIS_IUSRS' (MS only) | CIS Microsoft Windows Server 2008 Member Server Level 1 v3.3.1 | Windows | ACCESS CONTROL |
| 2.2.31 Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE, RESTRICTED SERVICES\PrintSpoolerService' (DC only) | CIS Microsoft Windows Server 2025 v2.1.0 L1 DC | Windows | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 2.2.31 Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE' (DC only) | CIS Microsoft Windows Server 2022 v5.1.0 L1 DC | Windows | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 2.2.31 Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE' (DC only) | CIS Microsoft Windows Server 2019 v5.0.0 L1 DC | Windows | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 2.2.32 (L1) Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE' (DC only) | CIS Microsoft Windows Server 2016 v4.0.0 L1 DC | Windows | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 2.2.32 (L1) Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE' and (when the Web Server (IIS) Role with Web Services Role Service is installed) 'IIS_IUSRS' (MS only) | CIS Microsoft Windows Server 2008 R2 Member Server Level 1 v3.3.1 | Windows | ACCESS CONTROL |
| 3.1 Ensure detailed logging is enabled | CIS NGINX v3.0.0 L1 Webserver | Unix | AUDIT AND ACCOUNTABILITY |
| 3.1 Ensure detailed logging is enabled | CIS NGINX v3.0.0 L1 Proxy | Unix | AUDIT AND ACCOUNTABILITY |
| 3.1 Ensure detailed logging is enabled | CIS NGINX v3.0.0 L1 Loadbalancer | Unix | AUDIT AND ACCOUNTABILITY |
| 5.1.1 Ensure that 'security defaults' is Enabled in Microsoft Entra ID | CIS Microsoft Azure Foundations v6.0.0 L1 | microsoft_azure | CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION |
| 6.1.2 Configuring syslog - remote logging - *.info;auth.none in /etc/syslog.conf | CIS IBM AIX 7.1 L2 v2.1.0 | Unix | AUDIT AND ACCOUNTABILITY |
| 6.1.2 Configuring syslog - remote logging - auth.info in /etc/syslog.conf | CIS IBM AIX 7.1 L2 v2.1.0 | Unix | AUDIT AND ACCOUNTABILITY |
| 8.2.2 Ensure syslog is configured to send logs to a remote log host | CIS IBM AIX 7 v1.2.0 L2 | Unix | AUDIT AND ACCOUNTABILITY |
| CIS Amazon Linux Benchmark Level 1 | CIS Amazon Linux v2.1.0 L1 | Unix | |
| CIS Amazon Linux Benchmark Level 2 | CIS Amazon Linux v2.1.0 L2 | Unix | |
| CIS Control 10 (10.4) Protect Backups | CAS Implementation Group 1 Audit File | Unix | CONTINGENCY PLANNING |
| CIS DNS BIND 9.0 - 9.5 v2.0.0 | CIS ISC BIND 9.0/9.5 v2.0.0 | Unix | |
| CIS_Docker_v1.8.0_L1_Docker_Swarm.audit from CIS Docker Benchmark v1.8.0 | CIS Docker v1.8.0 L1 Docker Swarm | Unix | |
| CIS_Docker_v1.8.0_L1_OS_Linux.audit from CIS Docker Benchmark v1.8.0 | CIS Docker v1.8.0 L1 OS Linux | Unix | |
| CIS_Docker_v1.8.0_L2_OS_Linux.audit from CIS Docker Benchmark v1.8.0 | CIS Docker v1.8.0 L2 OS Linux | Unix | |
| CIS_IBM_DB2_9_v3.0.1_Level_2_OS_Linux.audit from CIS DB2 9 Linux | CIS IBM DB2 9 Benchmark v3.0.1 Level 2 OS Linux | Unix | |
| CIS_MariaDB_10.6_Benchmark_v1.1.0_L1_Linux_OS.audit from CIS MariaDB 10.6 Benchmark | CIS MariaDB 10.6 on Linux L1 v1.1.0 | Unix | |
| CIS_MariaDB_10.11_v1.0.0_L1_MariaDB_RDBMS_MySQLDB.audit from CIS MariaDB 10.11 1.0.0 | CIS MariaDB 10.11 v1.0.0 L1 MariaDB RDBMS MySQLDB | MySQLDB | |
| CIS_MariaDB_10.11_v1.0.0_L1_MariaDB_RDBMS_on_Linux_MySQLDB.audit from CIS MariaDB 10.11 1.0.0 | CIS MariaDB 10.11 v1.0.0 L1 MariaDB RDBMS on Linux MySQLDB | MySQLDB | |
| CIS_MariaDB_10.11_v1.0.0_L2_MariaDB_RDBMS_MySQLDB.audit from CIS MariaDB 10.11 1.0.0 | CIS MariaDB 10.11 v1.0.0 L2 MariaDB RDBMS MySQLDB | MySQLDB | |
| CIS_MariaDB_10.11_v1.0.0_L2_MariaDB_RDBMS_on_Linux_MySQLDB.audit from CIS MariaDB 10.11 1.0.0 | CIS MariaDB 10.11 v1.0.0 L2 MariaDB RDBMS on Linux MySQLDB | MySQLDB | |
| CIS_MongoDB_5_v1.2.0_L1_Unix.audit from CIS MongoDB 5 v1.2.0 | CIS MongoDB 5 v1.2.0 L1 Unix | Unix | |
| CIS_MongoDB_5_v1.2.0_L1_Windows.audit from CIS MongoDB 5 v1.2.0 | CIS MongoDB 5 v1.2.0 L1 Windows | Windows | |
| CIS_MongoDB_5_v1.2.0_L2_Unix.audit from CIS MongoDB 5 v1.2.0 | CIS MongoDB 5 v1.2.0 L2 Unix | Unix | |
| CIS_MongoDB_5_v1.2.0_L2_Windows.audit from CIS MongoDB 5 v1.2.0 | CIS MongoDB 5 v1.2.0 L2 Windows | Windows | |
| CIS_PostgreSQL_13_v1.3.0_L1_Database_PostgreSQLDB.audit from CIS PostgreSQL 13 v1.3.0 | CIS PostgreSQL 13 v1.3.0 L1 Database PostgreSQLDB | PostgreSQLDB | |
| CIS_PostgreSQL_13_v1.3.0_L1_Database_Unix.audit from CIS PostgreSQL 13 v1.3.0 | CIS PostgreSQL 13 v1.3.0 L1 Database Unix | Unix | |
| CIS_PostgreSQL_13_v1.3.0_L1_OS_Linux_Unix.audit from CIS PostgreSQL 13 v1.3.0 | CIS PostgreSQL 13 v1.3.0 L1 OS Linux Unix | Unix | |
| CIS_PostgreSQL_17_v1.1.0_L1_Database_Unix.audit from CIS PostgreSQL 17 v1.1.0 | CIS PostgreSQL 17 v1.1.0 L1 Database Unix | Unix | |
| CIS_PostgreSQL_17_v1.1.0_L1_OS_Linux_PostgreSQLDB.audit from CIS PostgreSQL 17 v1.1.0 | CIS PostgreSQL 17 v1.1.0 L1 OS Linux PostgreSQLDB | PostgreSQLDB | |
| CIS_PostgreSQL_17_v1.1.0_L1_OS_Linux_Unix.audit from CIS PostgreSQL 17 v1.1.0 | CIS PostgreSQL 17 v1.1.0 L1 OS Linux Unix | Unix | |
| SP13-00-000015 - SharePoint must utilize approved cryptography to protect the confidentiality of remote access sessions. | DISA Microsoft SharePoint 2013 STIG v2r4 | Windows | ACCESS CONTROL |
| SP13-00-000120 - SharePoint must maintain the confidentiality of information during aggregation, packaging, and transformation in preparation for transmission. When transmitting data, applications need to leverage transmission protection mechanisms such as TLS, SSL VPNs, or IPSec. | DISA Microsoft SharePoint 2013 STIG v2r4 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN16-00-000360 - The Microsoft FTP service must not be installed unless required. | DISA Microsoft Windows Server 2016 STIG v2r10 | Windows | CONFIGURATION MANAGEMENT |
| WN25-00-000330 - Windows Server 2025 must not have the Microsoft FTP service installed unless required by the organization. | DISA Microsoft Windows Server 2025 STIG v1r3 | Windows | CONFIGURATION MANAGEMENT |