| 2.14 Ensure centralized and remote logging is configured | CIS Docker v1.8.0 L2 OS Linux | Unix | AUDIT AND ACCOUNTABILITY | 
| 4.1 Ensure unauthorized API calls are monitored | CIS Amazon Web Services Foundations v5.0.0 L2 | amazon_aws | AUDIT AND ACCOUNTABILITY | 
| 4.2.1.3 Ensure journald is configured to send logs to rsyslog | CIS Debian Family Workstation L1 v1.0.0 | Unix | AUDIT AND ACCOUNTABILITY | 
| 4.2.1.3 Ensure journald is configured to send logs to rsyslog | CIS Debian Family Server L1 v1.0.0 | Unix | AUDIT AND ACCOUNTABILITY | 
| 4.2.1.3 Ensure journald is configured to send logs to rsyslog | CIS Fedora 28 Family Linux Server L1 v2.0.0 | Unix | AUDIT AND ACCOUNTABILITY | 
| 4.2.1.3 Ensure journald is configured to send logs to rsyslog | CIS Fedora 28 Family Linux Workstation L1 v2.0.0 | Unix | AUDIT AND ACCOUNTABILITY | 
| 4.2.1.3 Ensure journald is configured to send logs to rsyslog | CIS CentOS Linux 8 Server L1 v2.0.0 | Unix | AUDIT AND ACCOUNTABILITY | 
| 4.2.2.5 Ensure journald is not configured to send logs to rsyslog | CIS CentOS Linux 8 Workstation L1 v2.0.0 | Unix | AUDIT AND ACCOUNTABILITY | 
| 4.2.2.5 Ensure journald is not configured to send logs to rsyslog | CIS Fedora 28 Family Linux Server L1 v2.0.0 | Unix | AUDIT AND ACCOUNTABILITY | 
| 4.8 (L1) Host must store one week of audit records | CIS VMware ESXi 8.0 v1.2.0 L1 | VMware | AUDIT AND ACCOUNTABILITY | 
| 4.9 Ensure AWS Config configuration changes are monitored | CIS Amazon Web Services Foundations v5.0.0 L2 | amazon_aws | AUDIT AND ACCOUNTABILITY | 
| 4.12 Ensure changes to network gateways are monitored | CIS Amazon Web Services Foundations v5.0.0 L1 | amazon_aws | AUDIT AND ACCOUNTABILITY | 
| 4.13 Ensure route table changes are monitored | CIS Amazon Web Services Foundations v5.0.0 L1 | amazon_aws | AUDIT AND ACCOUNTABILITY | 
| 4.15 Ensure AWS Organizations changes are monitored | CIS Amazon Web Services Foundations v5.0.0 L1 | amazon_aws | AUDIT AND ACCOUNTABILITY | 
| 5.1.1.3 Ensure journald is configured to send logs to rsyslog | CIS Oracle Linux 7 v4.0.0 L1 Workstation | Unix | AUDIT AND ACCOUNTABILITY | 
| 5.1.1.3 Ensure journald is configured to send logs to rsyslog | CIS Amazon Linux 2 v3.0.0 L1 | Unix | AUDIT AND ACCOUNTABILITY | 
| 5.1.1.5 Ensure journald is not configured to send logs to rsyslog | CIS Ubuntu Linux 18.04 LTS v2.2.0 L1 Server | Unix | AUDIT AND ACCOUNTABILITY | 
| 5.1.1.5 Ensure journald is not configured to send logs to rsyslog | CIS Ubuntu Linux 18.04 LTS v2.2.0 L1 Workstation | Unix | AUDIT AND ACCOUNTABILITY | 
| 5.1.2.3 Ensure journald is configured to send logs to rsyslog | CIS Ubuntu Linux 18.04 LTS v2.2.0 L1 Workstation | Unix | AUDIT AND ACCOUNTABILITY | 
| 6.1.3.3 Ensure journald is configured to send logs to rsyslog | CIS Ubuntu Linux 24.04 LTS v1.0.0 L1 Server | Unix | AUDIT AND ACCOUNTABILITY | 
| 6.1.3.3 Ensure journald is configured to send logs to rsyslog | CIS Ubuntu Linux 24.04 LTS v1.0.0 L1 Workstation | Unix | AUDIT AND ACCOUNTABILITY | 
| 6.1.3.3 Ensure journald is configured to send logs to rsyslog | CIS Debian Linux 12 v1.1.0 L1 Workstation | Unix | AUDIT AND ACCOUNTABILITY | 
| 6.2.2.3 Ensure journald is configured to send logs to rsyslog | CIS Red Hat Enterprise Linux 8 v4.0.0 L1 Workstation | Unix | AUDIT AND ACCOUNTABILITY | 
| 6.2.2.3 Ensure journald is configured to send logs to rsyslog | CIS Rocky Linux 8 v3.0.0 L1 Workstation | Unix | AUDIT AND ACCOUNTABILITY | 
| 6.2.2.3 Ensure journald is configured to send logs to rsyslog | CIS Oracle Linux 8 v4.0.0 L1 Workstation | Unix | AUDIT AND ACCOUNTABILITY | 
| 6.2.2.3 Ensure journald is configured to send logs to rsyslog | CIS Oracle Linux 8 v4.0.0 L1 Server | Unix | AUDIT AND ACCOUNTABILITY | 
| 6.2.3.3 Ensure journald is configured to send logs to rsyslog | CIS Rocky Linux 9 v2.0.0 L1 Server | Unix | AUDIT AND ACCOUNTABILITY | 
| 6.2.3.3 Ensure journald is configured to send logs to rsyslog | CIS Red Hat Enterprise Linux 9 v2.0.0 L1 Server | Unix | AUDIT AND ACCOUNTABILITY | 
| 6.2.3.3 Ensure journald is configured to send logs to rsyslog | CIS Red Hat Enterprise Linux 9 v2.0.0 L1 Workstation | Unix | AUDIT AND ACCOUNTABILITY | 
| 6.2.3.3 Ensure journald is configured to send logs to rsyslog | CIS AlmaLinux OS 9 v2.0.0 L1 Server | Unix | AUDIT AND ACCOUNTABILITY | 
| 6.2.3.3 Ensure journald is configured to send logs to rsyslog | CIS Red Hat Enterprise Linux 10 v1.0.1 L1 Workstation | Unix | AUDIT AND ACCOUNTABILITY | 
| 6.2.3.3 Ensure journald is configured to send logs to rsyslog | CIS Red Hat Enterprise Linux 10 v1.0.1 L1 Server | Unix | AUDIT AND ACCOUNTABILITY | 
| 6.2.3.4 Ensure journald is configured to send logs to rsyslog | CIS SUSE Linux Enterprise 15 v2.0.1 L1 Server | Unix | AUDIT AND ACCOUNTABILITY | 
| 7.3.1 Centralized Logging and Reporting | CIS Fortigate 7.0.x v1.3.0 L2 | FortiGate | AUDIT AND ACCOUNTABILITY | 
| ALMA-09-054690 - AlmaLinux OS 9 must periodically flush audit records to disk to prevent the loss of audit records. | DISA CloudLinux AlmaLinux OS 9 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY | 
| EX19-ED-000040 - Exchange queue monitoring must be configured with threshold and action. | DISA Microsoft Exchange 2019 Edge Server STIG v2r2 | Windows | AUDIT AND ACCOUNTABILITY | 
| EX19-MB-000048 - Exchange queue monitoring must be configured with threshold and action. | DISA Microsoft Exchange 2019 Mailbox Server STIG v2r2 | Windows | AUDIT AND ACCOUNTABILITY | 
| GOOG-12-002800 - Google Android 12 must be configured to enable audit logging. | AirWatch - DISA Google Android 12 COBO v1r2 | MDM | AUDIT AND ACCOUNTABILITY | 
| GOOG-12-002800 - Google Android 12 must be configured to enable audit logging. | MobileIron - DISA Google Android 12 COPE v1r2 | MDM | AUDIT AND ACCOUNTABILITY | 
| GOOG-13-002800 - Google Android 13 must be configured to enable audit logging. | AirWatch - DISA Google Android 13 COBO v2r2 | MDM | AUDIT AND ACCOUNTABILITY | 
| GOOG-13-002800 - Google Android 13 must be configured to enable audit logging. | MobileIron - DISA Google Android 13 COPE v2r2 | MDM | AUDIT AND ACCOUNTABILITY | 
| GOOG-13-002800 - Google Android 13 must be configured to enable audit logging. | AirWatch - DISA Google Android 13 COPE v2r2 | MDM | AUDIT AND ACCOUNTABILITY | 
| GOOG-14-002800 - Google Android 14 must be configured to enable audit logging. | AirWatch - DISA Google Android 14 COPE v2r2 | MDM | AUDIT AND ACCOUNTABILITY | 
| GOOG-15-002800 - Google Android 15 must be configured to enable audit logging. | MobileIron - DISA Google Android 15 COBO v1r2 | MDM | AUDIT AND ACCOUNTABILITY | 
| GOOG-15-002800 - Google Android 15 must be configured to enable audit logging. | AirWatch - DISA Google Android 15 COBO v1r2 | MDM | AUDIT AND ACCOUNTABILITY | 
| GOOG-15-002800 - Google Android 15 must be configured to enable audit logging. | AirWatch - DISA Google Android 15 COPE v1r2 | MDM | AUDIT AND ACCOUNTABILITY | 
| GOOG-15-002800 - Google Android 15 must be configured to enable audit logging. | MobileIron - DISA Google Android 15 COPE v1r2 | MDM | AUDIT AND ACCOUNTABILITY | 
| HONW-13-002800 - Honeywell Android 13 must be configured to enable audit logging. | MobileIron - DISA Honeywell Android 13 COBO v1r1 | MDM | AUDIT AND ACCOUNTABILITY | 
| OL09-00-000775 - OL 9 must periodically flush audit records to disk to prevent the loss of audit records. | DISA Oracle Linux 9 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY | 
| RHEL-09-653095 - RHEL 9 must periodically flush audit records to disk to prevent the loss of audit records. | DISA Red Hat Enterprise Linux 9 STIG v2r4 | Unix | AUDIT AND ACCOUNTABILITY |