| 1.2.2.4 Ensure the operating system removes all software components after updated versions have been installed | CIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIG | Unix | SYSTEM AND INFORMATION INTEGRITY |
| 1.016 - Security configuration tools or equivalent processes must be used to configure and maintain platforms for security compliance. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 3.003 - System pagefile is cleared upon shutdown. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 3.006 - Floppy media devices are not allocated upon user logon. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 3.013 - Caching of logon credentials must be limited. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 3.044 - The computer account password is prevented from being reset. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 3.048 - The Recovery Console SET command must be disabled. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 3.054 - Users are not warned in advance that their passwords will expire. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 3.055 - The default permissions of Global system objects are not increased. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 3.094 - The system is configured to allow IP source routing. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 3.095 - The system is configured to redirect ICMP. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 3.097 - The system is configured for a greater keep-alive time than recommended. | DISA Windows Vista STIG v6r41 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 3.101 - The system must be configured to ignore NetBIOS name release requests except from WINS servers. | DISA Windows Vista STIG v6r41 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 3.104 - The system is configured to detect and configure default gateway addresses. | DISA Windows Vista STIG v6r41 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 3.119 - The system is configured to allow the display of the last user name on the logon screen. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 3.127 - IPSec Exemptions are limited. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 3.141 - User Account Control - Executable Elevation | DISA Windows Vista STIG v6r41 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.006 - Users must be forcibly disconnected when their logon hours expire. | DISA Windows Vista STIG v6r41 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.019 - Outdated or unused accounts must be removed from the system. | DISA Windows Vista STIG v6r41 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 4.024 - Local users must not exist on a system in a domain. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 4.043 - The maximum age for machine account passwords is not set to requirements. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 4.045 - Domain Controller authentication is not required to unlock the workstation. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 5.098 - The system must limit how many times unacknowledged TCP data is retransmitted. | DISA Windows Vista STIG v6r41 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.102 - This check verifies that Windows is configured to have password protection take effect within a limited time frame. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 5.216 - Internet Connection Wizard ISP Downloads | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 5.223 - The classic logon screen must be required for user logons. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 5.228 - Game Explorer Information Downloads | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 5.233 - Indexing of mail items in Exchange folders when Outlook is running in uncached mode must be turned off. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 5.244 - Users must be notified if the logon server was inaccessible and cached credentials were used. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| GEN000450 - The system must limit users to 10 simultaneous system logins in accordance with operational requirements. | DISA AIX 5.3 STIG v1r2 | Unix | ACCESS CONTROL |
| GEN001540 - All files and directories contained in interactive user's home directories must be owned by the home directory's owner. | DISA AIX 5.3 STIG v1r2 | Unix | ACCESS CONTROL |
| GEN002260 - The system must be checked for extraneous device files at least weekly. | DISA AIX 5.3 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| GEN002752 - The audit system must be configured to audit account disabling - '/etc/security/audit/config USER_Change exists' | DISA AIX 5.3 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY |
| GEN002752 - The audit system must be configured to audit account disabling - '/etc/security/audit/config USER_Locked exists' | DISA AIX 5.3 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY |
| GEN003520 - The kernel core dump data directory must be owned by root. | DISA AIX 5.3 STIG v1r2 | Unix | ACCESS CONTROL |
| GEN003522 - The kernel core dump data directory must have mode 0700 or less permissive. | DISA AIX 5.3 STIG v1r2 | Unix | ACCESS CONTROL |
| GEN003523 - The kernel core dump data directory must not have an extended ACL. | DISA AIX 5.3 STIG v1r2 | Unix | ACCESS CONTROL |
| GEN003602 - The system must not process ICMP timestamp requests. | DISA AIX 5.3 STIG v1r2 | Unix | ACCESS CONTROL |
| GEN003623 - The system must use a separate file system for the system audit data path. | DISA AIX 5.3 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY |
| GEN003624 - The system must use a separate file system for /tmp (or equivalent). | DISA AIX 5.3 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| GEN003800 - Inetd or xinetd logging/tracing must be enabled. | DISA AIX 5.3 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY |
| GEN004440 - Sendmail logging must not be set to less than nine in the sendmail.cf file. | DISA AIX 5.3 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY |
| GEN004700 - The Sendmail service must not have the wizard backdoor active. | DISA AIX 5.3 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| GEN004980 - The FTP daemon must be configured for logging or verbose mode - '/etc/syslog.conf contains daemon.info or *.info' | DISA AIX 5.3 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY |
| GEN005533 - The SSH daemon must limit connections to a single session. | DISA AIX 5.3 STIG v1r2 | Unix | ACCESS CONTROL |
| GEN006571 - The file integrity tool must be configured to verify extended attributes. | DISA AIX 5.3 STIG v1r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| GEN006575 - The file integrity tool must use FIPS 140-2 approved cryptographic hashes for validating file contents. | DISA AIX 5.3 STIG v1r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| GEN008420 - The system must use available memory address randomization techniques. | DISA AIX 5.3 STIG v1r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| GEN008440 - Automated file system mounting tools must not be enabled unless needed. | DISA AIX 5.3 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| GEN008460 - The system must have USB disabled unless needed - 'lsdev' | DISA AIX 5.3 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |