| 1.5.2.3 Remote Authentication - RADIUS/RadSec/TACACS+ | CIS HPE Aruba Networking CX Switch v1.0.1 L2 | ArubaOS | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 2.8 Ensure TLS authentication for Docker daemon is configured | CIS Docker v1.8.0 L1 OS Linux | Unix | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 2.8.2 (L1) Ensure 'Allow remote users to interact with elevated windows in remote assistance sessions' is set to 'Disabled' | CIS Google Chrome L1 v3.0.0 | Windows | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 2.8.4 (L1) Ensure 'Enable curtaining of remote access hosts' is set to 'Disabled' | CIS Google Chrome L1 v3.0.0 | Windows | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 2.8.5 (L1) Ensure 'Enable firewall traversal from remote access host' is set to 'Disabled' | CIS Google Chrome L1 v3.0.0 | Windows | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 2.8.6 (L1) Ensure 'Enable or disable PIN-less authentication for remote access hosts' is set to 'Disabled' | CIS Google Chrome L1 v3.0.0 | Windows | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 2.13.5 (L1) Ensure 'Configure the required domain names for remote access clients' is set to 'Enabled' with a domain defined | CIS Google Chrome Group Policy v1.0.0 L1 | Windows | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 2.13.6 (L1) Ensure 'Enable firewall traversal from remote access host' is set to 'Disabled' | CIS Google Chrome Group Policy v1.0.0 L1 | Windows | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 2.13.7 (L1) Ensure 'Enable curtaining of remote access hosts' is set to 'Disabled' | CIS Google Chrome Group Policy v1.0.0 L1 | Windows | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 3.2.1.29 Ensure 'Allow proximity based password sharing requests' is set to 'Disabled' | AirWatch - CIS Apple iPadOS 26 v1.0.0 L1 Institutionally Owned | MDM | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 3.2.1.29 Ensure 'Allow proximity based password sharing requests' is set to 'Disabled' | MobileIron - CIS Apple iPadOS 26 v1.0.0 L1 Institutionally Owned | MDM | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 3.2.1.29 Ensure 'Allow proximity based password sharing requests' is set to 'Disabled' | MobileIron - CIS Apple iPadOS 17 Institutionally Owned L1 | MDM | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 3.9 Ensure 'Require encryption on device' is set to 'True' | CIS Microsoft Exchange Server 2019 L1 MDM v1.0.0 | Windows | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 4.1 Ensure devices without a compliance policy are marked 'not compliant' | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 5.1.1 Ensure sshd crypto_policy is not set | CIS Red Hat Enterprise Linux 8 v4.0.0 L1 Workstation | Unix | ACCESS CONTROL |
| 5.1.1 Ensure sshd crypto_policy is not set | CIS Rocky Linux 8 v3.0.0 L1 Server | Unix | ACCESS CONTROL |
| 5.1.1 Ensure sshd crypto_policy is not set | CIS AlmaLinux OS 8 v4.0.0 L1 Workstation | Unix | ACCESS CONTROL |
| 5.1.1 Ensure sshd crypto_policy is not set | CIS Oracle Linux 8 v4.0.0 L1 Server | Unix | ACCESS CONTROL |
| 5.1.1 Ensure sshd crypto_policy is not set | CIS Red Hat Enterprise Linux 8 v4.0.0 L1 Server | Unix | ACCESS CONTROL |
| 5.1.12 Ensure sshd KexAlgorithms is configured | CIS AlmaLinux OS 10 v1.0.0 L1 Workstation | Unix | ACCESS CONTROL |
| 5.1.12 Ensure sshd KexAlgorithms is configured | CIS Oracle Linux 10 v1.0.0 L1 Server | Unix | ACCESS CONTROL |
| 5.1.12 Ensure sshd KexAlgorithms is configured | CIS AlmaLinux OS 10 v1.0.0 L1 Server | Unix | ACCESS CONTROL |
| 5.1.12 Ensure sshd KexAlgorithms is configured | CIS Oracle Linux 10 v1.0.0 L1 Workstation | Unix | ACCESS CONTROL |
| 5.2.8 Ensure SSH root login is disabled | CIS Ubuntu Linux 14.04 LTS Server L1 v2.1.0 | Unix | ACCESS CONTROL |
| 5.8 Set DCUI.Access to allow trusted users to override lockdown mode | CIS VMware ESXi 5.1 v1.0.1 Level 1 | VMware | ACCESS CONTROL |
| 18.8.36.2 Ensure 'Configure Solicited Remote Assistance' is set to 'Disabled' | CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0 | Windows | ACCESS CONTROL |
| 18.9.59.3.9.5 Ensure 'Set client connection encryption level' is set to 'Enabled: High Level' | CIS Windows 7 Workstation Level 1 v3.2.0 | Windows | ACCESS CONTROL |
| 18.9.97.1.1 Ensure 'Allow Basic authentication' is set to 'Disabled' - Client | CIS Windows 7 Workstation Level 1 v3.2.0 | Windows | ACCESS CONTROL |
| 18.9.97.1.3 Ensure 'Disallow Digest authentication' is set to 'Enabled' | CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0 | Windows | ACCESS CONTROL |
| 18.9.97.1.3 Ensure 'Disallow Digest authentication' is set to 'Enabled' | CIS Windows 7 Workstation Level 1 v3.2.0 | Windows | ACCESS CONTROL |
| Allow Basic authentication - Client - AllowBasic | MSCT Windows 10 v20H2 v1.0.0 | Windows | ACCESS CONTROL |
| Allow Basic authentication - Client - AllowBasic | MSCT Windows Server 2016 DC v1.0.0 | Windows | ACCESS CONTROL |
| Allow Basic authentication - Client - AllowBasic | MSCT Windows Server v20H2 DC v1.0.0 | Windows | ACCESS CONTROL |
| Allow Basic authentication - Service - AllowBasic | MSCT Windows 10 1909 v1.0.0 | Windows | ACCESS CONTROL |
| Allow Basic authentication - Service - AllowBasic | MSCT Windows Server 1903 MS v1.19.9 | Windows | ACCESS CONTROL |
| Allow Basic authentication - Service - AllowBasic | MSCT Windows Server v20H2 DC v1.0.0 | Windows | ACCESS CONTROL |
| Allow Basic authentication - WinRM Client | MSCT Windows 10 1803 v1.0.0 | Windows | ACCESS CONTROL |
| Allow unencrypted traffic - Client - AllowUnencryptedTraffic | MSCT Windows 10 v21H2 v1.0.0 | Windows | ACCESS CONTROL |
| Allow unencrypted traffic - Service - AllowUnencryptedTraffic | MSCT Windows Server v2004 MS v1.0.0 | Windows | ACCESS CONTROL |
| Allow unencrypted traffic - Service - AllowUnencryptedTraffic | MSCT Windows Server 2016 DC v1.0.0 | Windows | ACCESS CONTROL |
| Allow unencrypted traffic - WinRM Service | MSCT Windows Server 2019 DC v1.0.0 | Windows | ACCESS CONTROL |
| Allow unencrypted traffic - WinRM Service | MSCT Windows Server 2019 MS v1.0.0 | Windows | ACCESS CONTROL |
| Configure Solicited Remote Assistance - fAllowToGetHelp | MSCT Windows 10 1809 v1.0.0 | Windows | ACCESS CONTROL |
| Configure Solicited Remote Assistance - fAllowToGetHelp | MSCT Windows 10 1909 v1.0.0 | Windows | ACCESS CONTROL |
| Disallow Digest authentication | MSCT Windows 10 v1507 v1.0.0 | Windows | ACCESS CONTROL |
| Disallow Digest authentication | MSCT Windows 10 1809 v1.0.0 | Windows | ACCESS CONTROL |
| Disallow Digest authentication | MSCT Windows Server 2019 DC v1.0.0 | Windows | ACCESS CONTROL |
| Set client connection encryption level | MSCT Windows 10 v20H2 v1.0.0 | Windows | ACCESS CONTROL |
| Set client connection encryption level | MSCT Windows Server 2016 DC v1.0.0 | Windows | ACCESS CONTROL |
| Set client connection encryption level | MSCT Windows Server v20H2 DC v1.0.0 | Windows | ACCESS CONTROL |