| 1.12 Ensure 'Smart Lock' is set to 'Disabled' | MobileIron - CIS Google Android v1.6.0 L2 | MDM | ACCESS CONTROL |
| 1.12 Ensure 'Smart Lock' is set to 'Disabled' | AirWatch - CIS Google Android v1.6.0 L2 | MDM | ACCESS CONTROL |
| 1.20 Ensure an account-level authentication policy has been configured to restrict allowed provider accounts for Workload Identify Federation (WIF) | CIS Snowflake Foundations v2.0.0 L2 | Snowflake | IDENTIFICATION AND AUTHENTICATION |
| 1.24 CISC-ND-001410 | CIS Cisco IOS XR Router NDM STIG v1.0.0 CAT II | Cisco | CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING |
| 1.24 EX19-ED-000113 | CIS Microsoft Exchange 2019 Edge Server STIG v1.0.0 CAT II | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.37 EX19-MB-000128 | CIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0 CAT III | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.39 CISC-ND-001410 | CIS Cisco NX OS Switch NDM STIG v1.1.0 CAT II | Cisco | CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING |
| 1.161 SOL-11.1-070060 | CIS Solaris 11 SPARC STIG v1.0.0 CAT II | Unix | CONFIGURATION MANAGEMENT |
| 2.1.3 Ensure Organizations management account is not used for workloads | CIS Amazon Web Services Foundations v7.0.0 L2 | amazon_aws | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.3.3.9 Ensure Media Sharing Is Disabled | CIS Apple macOS 26 Tahoe v1.1.0 L2 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 2.7 Lock Out Accounts if Not Currently in Use | CIS MariaDB 10.11 v1.0.0 L2 MariaDB RDBMS on Linux MySQLDB | MySQLDB | ACCESS CONTROL |
| 2.7 Lock Out Accounts if Not Currently in Use | CIS MariaDB 10.11 v1.0.0 L2 MariaDB RDBMS MySQLDB | MySQLDB | ACCESS CONTROL |
| 2.8 Ensure IAM password policy requires minimum length of 14 or greater | CIS Amazon Web Services Foundations v7.0.0 L1 | amazon_aws | IDENTIFICATION AND AUTHENTICATION |
| 2.11 Lock Out Accounts if Not Currently in Use | CIS Oracle MySQL Enterprise Edition 9.7 v1.0.0 L2 MySQL RDBMS MySQLDB | MySQLDB | ACCESS CONTROL |
| 2.11 Lock Out Accounts if Not Currently in Use | CIS Oracle MySQL Enterprise Edition 9.7 v1.0.0 L2 MySQL RDBMS on Linux MySQLDB | MySQLDB | ACCESS CONTROL |
| 2.11 Lock Out Accounts if Not Currently in Use | CIS Oracle MySQL Enterprise Edition 8.0 v1.5.0 L2 MySQL RDBMS MySQLDB | MySQLDB | ACCESS CONTROL |
| 2.11 Lock Out Accounts if Not Currently in Use | CIS Oracle MySQL Community Server 8.0 v1.2.0 L2 MySQL RDBMS MySQLDB | MySQLDB | ACCESS CONTROL |
| 2.11 Lock Out Accounts if Not Currently in Use | CIS Oracle MySQL Community Server 8.0 v1.2.0 L2 MySQL RDBMS on Linux MySQLDB | MySQLDB | ACCESS CONTROL |
| 2.11 Lock Out Accounts if Not Currently in Use | CIS Oracle MySQL Community Server 8.4 v1.1.0 L2 MySQL RDBMS MySQLDB | MySQLDB | ACCESS CONTROL |
| 2.11 Lock Out Accounts if Not Currently in Use | CIS Oracle MySQL Enterprise Edition 8.0 v1.5.0 L2 MySQL RDBMS on Linux MySQLDB | MySQLDB | ACCESS CONTROL |
| 2.11 Lock Out Accounts if Not Currently in Use | CIS Oracle MySQL Enterprise Edition 8.4 v1.1.0 L2 MySQL RDBMS on Linux MySQLDB | MySQLDB | ACCESS CONTROL |
| 2.11 Lock Out Accounts if Not Currently in Use | CIS Oracle MySQL Community Server 9.7 v1.0.0 L2 MySQL RDBMS on Linux MySQLDB | MySQLDB | ACCESS CONTROL |
| 2.11 Lock Out Accounts if Not Currently in Use | CIS Oracle MySQL Enterprise Edition 8.4 v1.1.0 L2 MySQL RDBMS MySQLDB | MySQLDB | ACCESS CONTROL |
| 2.16 Ensure 'AUTO_CLOSE' is set to 'OFF' on contained databases | CIS SQL Server 2012 Database L1 AWS RDS v1.6.0 | MS_SQLDB | CONFIGURATION MANAGEMENT |
| 2.18 Ensure that IAM External Access Analyzer is enabled for all regions | CIS Amazon Web Services Foundations v7.0.0 L1 | amazon_aws | ACCESS CONTROL, MEDIA PROTECTION |
| 3.2.1 Ensure that encryption-at-rest is enabled for RDS instances | CIS Amazon Web Services Foundations v7.0.0 L1 | amazon_aws | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.2 Ensure CloudTrail log file validation is enabled | CIS Amazon Web Services Foundations v7.0.0 L2 | amazon_aws | AUDIT AND ACCOUNTABILITY |
| 5.7 Ensure disabling or scheduled deletion of customer created CMKs is monitored | CIS Amazon Web Services Foundations v7.0.0 L2 | amazon_aws | AUDIT AND ACCOUNTABILITY |
| 5.11 Ensure Network Access Control List (NACL) changes are monitored | CIS Amazon Web Services Foundations v7.0.0 L2 | amazon_aws | AUDIT AND ACCOUNTABILITY |
| 6.1 Ensure Root Domain Alias Record Points to ELB | CIS Amazon Web Services Three-tier Web Architecture L2 1.0.0 | amazon_aws | SYSTEM AND COMMUNICATIONS PROTECTION |
| 6.17 Ensure that all zones have Zone Protection Profiles with all Reconnaissance Protection settings enabled, tuned, and set to appropriate actions | CIS Palo Alto Firewall 10 v1.3.0 L1 | Palo_Alto | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 6.18 Ensure that all zones have Zone Protection Profiles with all Reconnaissance Protection settings enabled, tuned, and set to appropriate actions | CIS Palo Alto Firewall 9 v1.1.0 L1 | Palo_Alto | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| 6.27 Ensure EC2 instances within Web Tier have no Elastic / Public IP addresses associated | CIS Amazon Web Services Three-tier Web Architecture L1 1.0.0 | amazon_aws | SYSTEM AND COMMUNICATIONS PROTECTION |
| 6.29 Ensure EC2 instances within Data Tier have no Elastic / Public IP addresses associated | CIS Amazon Web Services Three-tier Web Architecture L1 1.0.0 | amazon_aws | SYSTEM AND COMMUNICATIONS PROTECTION |
| 9.23 Find Un-owned Files and Directories | CIS Solaris 11.2 L1 v1.1.0 | Unix | ACCESS CONTROL |
| 9.24 Find Files and Directories with Extended Attributes | CIS Solaris 11.2 L1 v1.1.0 | Unix | |
| 9.24 Find Un-owned Files and Directories | CIS Solaris 11.1 L1 v1.0.0 | Unix | ACCESS CONTROL |
| 9.24 Find Un-owned Files and Directories | CIS Solaris 11 L1 v1.1.0 | Unix | ACCESS CONTROL |
| DTAM100 - McAfee VirusScan On-Access Default Processes Policies must be configured to use only one scanning policy for all processes, unless the use of Low-Risk Processes/High-Risk Processes has been documented with, and approved by, the IAO/IAM. | DISA McAfee VirusScan 8.8 Managed Client STIG v6r1 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| DTAM100 - McAfee VirusScan On-Access Scanner All Processes settings must be configured to use only one scanning policy for all processes, unless the use of Low-Risk Processes/High-Risk Processes has been documented with, and approved by, the IAO/IAM. | DISA McAfee VirusScan 8.8 Local Client STIG v6r1 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| Maximum password age | MSCT Windows 10 v1507 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Maximum password age | MSCT Windows 10 1803 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Maximum password age | MSCT Windows 10 1809 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Maximum password age | MSCT Windows Server 2012 R2 DC v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Maximum password age | MSCT Windows Server 2019 DC v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Maximum password age | MSCT Windows Server 2019 MS v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Maximum password age | MSCT Windows Server 2012 R2 MS v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Maximum password age | MSCT Windows Server 2016 DC v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Maximum password age | MSCT Windows Server 2016 MS v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| SOL-11.1-070060 - Groups assigned to users must exist in the /etc/group file. | DISA Solaris 11 X86 STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |