| 1.2.1.3 Configure 'Prohibit connection to non-domain networks when connected to domain authenticated network' | CIS Windows 8 L1 v1.0.0 | Windows | ACCESS CONTROL |
| 1.4 Use Secure Upstream Caching DNS Servers | CIS BIND DNS v1.0.0 L2 Caching Only Name Server | Unix | ACCESS CONTROL |
| 3.8 Ensure 'security-level' is set to '0' for Internet-facing interface | CIS Cisco Firewall v8.x L1 v4.2.0 | Cisco | ACCESS CONTROL |
| 4.4.1 Create a Web Filtering Profile | CIS FortiGate 7.4.x v1.0.1 L1 | FortiGate | ACCESS CONTROL |
| 6.31 Don't use the default VPC | CIS Amazon Web Services Three-tier Web Architecture L2 1.0.0 | amazon_aws | ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.1.27 Set 'Navigate windows and frames across different domains' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | ACCESS CONTROL |
| 8.1.33 Set 'Web sites in less privileged Web content zones can navigate into this zone' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | ACCESS CONTROL |
| 8.3.32 Set 'Navigate windows and frames across different domains' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | ACCESS CONTROL |
| 8.3.38 Set 'Web sites in less privileged Web content zones can navigate into this zone' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | ACCESS CONTROL |
| 18.5.11.2 Ensure 'Prohibit installation and configuration of Network Bridge on your DNS domain network' is set to 'Enabled' | CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0 | Windows | ACCESS CONTROL |
| 18.5.11.2 Ensure 'Prohibit installation and configuration of Network Bridge on your DNS domain network' is set to 'Enabled' | CIS Windows 7 Workstation Level 1 v3.2.0 | Windows | ACCESS CONTROL |
| 18.8.22.1.6 (L1) Ensure 'Turn off Internet download for Web publishing and online ordering wizards' is set to 'Enabled' | CIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker | Windows | ACCESS CONTROL |
| 18.8.22.1.6 Ensure 'Turn off Internet download for Web publishing and online ordering wizards' is set to 'Enabled' | CIS Microsoft Windows 8.1 v2.4.1 L1 | Windows | ACCESS CONTROL |
| 18.8.22.1.8 (L2) Ensure 'Turn off Registration if URL connection is referring to Microsoft.com' is set to 'Enabled' | CIS Microsoft Windows 8.1 v2.4.1 L2 Bitlocker | Windows | ACCESS CONTROL |
| 18.8.22.1.8 (L2) Ensure 'Turn off Registration if URL connection is referring to Microsoft.com' is set to 'Enabled' | CIS Microsoft Windows 8.1 v2.4.1 L2 | Windows | ACCESS CONTROL |
| BGP: Authenticate peers | TNS Alcatel-Lucent TiMOS/Nokia SR-OS Best Practice Audit | Alcatel | ACCESS CONTROL |
| Big Sur - Control Connections to Other Systems via a Deny-All and Allow-by-Exception Firewall Policy | NIST macOS Big Sur v1.4.0 - All Profiles | Unix | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION |
| Big Sur - Control Connections to Other Systems via a Deny-All and Allow-by-Exception Firewall Policy | NIST macOS Big Sur v1.4.0 - CNSSI 1253 | Unix | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION |
| Big Sur - Control Connections to Other Systems via a Deny-All and Allow-by-Exception Firewall Policy | NIST macOS Big Sur v1.4.0 - 800-53r5 High | Unix | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION |
| Big Sur - Control Connections to Other Systems via a Deny-All and Allow-by-Exception Firewall Policy | NIST macOS Big Sur v1.4.0 - 800-171 | Unix | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION |
| Configure IPsec Tunnel Parameters - cipher-suite | Tenable Cisco Viptela SD-WAN - vEdge | Cisco_Viptela | ACCESS CONTROL |
| Configure IPsec Tunnel Parameters - replay-window | Tenable Cisco Viptela SD-WAN - vEdge | Cisco_Viptela | ACCESS CONTROL |
| Ensure 'Unused Interfaces' is disable | Tenable Cisco Firepower Best Practices Audit | Cisco | ACCESS CONTROL |
| Ensure 'Unused Interfaces' is disable | Tenable Cisco Firepower Threat Defense Best Practices Audit | Cisco_Firepower | ACCESS CONTROL |
| Navigate windows and frames across different domains - Internet Zone | MSCT Windows Server 2025 MS v2506 v1.0.0 | Windows | ACCESS CONTROL |
| Navigate windows and frames across different domains - Restricted Sites Zone | MSCT Windows Server 2016 MS v1.0.0 | Windows | ACCESS CONTROL |
| Navigate windows and frames across different domains - Restricted Sites Zone | MSCT Windows Server 2019 DC v1.0.0 | Windows | ACCESS CONTROL |
| Navigate windows and frames across different domains - Restricted Sites Zone | MSCT Windows Server 2025 DC v2506 v1.0.0 | Windows | ACCESS CONTROL |
| Navigate windows and frames across different domains - Restricted Sites Zone | MSCT Windows Server 2025 MS v1.0.0 | Windows | ACCESS CONTROL |
| Navigate windows and frames across different domains - Restricted Sites Zone | MSCT Windows Server v20H2 MS v1.0.0 | Windows | ACCESS CONTROL |
| Prohibit connection to non-domain networks when connected to domain authenticated network | MSCT Windows 11 v24H2 v1.0.0 | Windows | ACCESS CONTROL |
| Prohibit connection to non-domain networks when connected to domain authenticated network | MSCT Windows 11 v23H2 v1.0.0 | Windows | ACCESS CONTROL |
| Prohibit connection to non-domain networks when connected to domain authenticated network | MSCT Windows 11 v25H2 v1.0.0 | Windows | ACCESS CONTROL |
| Prohibit connection to non-domain networks when connected to domain authenticated network | MSCT Windows 10 v21H1 v1.0.0 | Windows | ACCESS CONTROL |
| Prohibit connection to non-domain networks when connected to domain authenticated network | MSCT Windows 11 v1.0.0 | Windows | ACCESS CONTROL |
| Prohibit connection to non-domain networks when connected to domain authenticated network | MSCT Windows 10 v22H2 v1.0.0 | Windows | ACCESS CONTROL |
| Prohibit connection to non-domain networks when connected to domain authenticated network | MSCT Windows 11 v22H2 v1.0.0 | Windows | ACCESS CONTROL |
| Prohibit connection to non-domain networks when connected to domain authenticated network | MSCT Windows 10 1909 v1.0.0 | Windows | ACCESS CONTROL |
| Prohibit connection to non-domain networks when connected to domain authenticated network | MSCT Windows 10 v2004 v1.0.0 | Windows | ACCESS CONTROL |
| Prohibit connection to non-domain networks when connected to domain authenticated network | MSCT Windows 10 v20H2 v1.0.0 | Windows | ACCESS CONTROL |
| Prohibit connection to non-domain networks when connected to domain authenticated network | MSCT Windows 10 v1507 v1.0.0 | Windows | ACCESS CONTROL |
| Prohibit connection to non-domain networks when connected to domain authenticated network | MSCT Windows 10 1903 v1.19.9 | Windows | ACCESS CONTROL |
| Prohibit connection to non-domain networks when connected to domain authenticated network | MSCT Windows 10 v21H2 v1.0.0 | Windows | ACCESS CONTROL |
| Prohibit connection to non-domain networks when connected to domain authenticated network | MSCT Windows 10 1803 v1.0.0 | Windows | ACCESS CONTROL |
| Prohibit connection to non-domain networks when connected to domain authenticated network | MSCT Windows 10 1809 v1.0.0 | Windows | ACCESS CONTROL |
| Salesforce.com : Object Permissions - 'DefaultCampaignAccess should not be Public Full Access or Public Read/Write' | TNS Salesforce Best Practices Audit v1.2.0 | Salesforce.com | ACCESS CONTROL |
| Security Zones: Use only machine settings | MSCT Windows Server 2019 MS v1.0.0 | Windows | ACCESS CONTROL |
| Web sites in less privileged Web content zones can navigate into this zone - Internet Zone | MSCT Windows Server 2019 DC v1.0.0 | Windows | ACCESS CONTROL |
| Web sites in less privileged Web content zones can navigate into this zone - Restricted Sites Zone | MSCT Windows Server 2025 MS v1.0.0 | Windows | ACCESS CONTROL |
| Web sites in less privileged Web content zones can navigate into this zone - Restricted Sites Zone | MSCT Windows Server v20H2 DC v1.0.0 | Windows | ACCESS CONTROL |