| 1.6.8 Ensure system-wide crypto policy is FIPS | CIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIG | Unix | ACCESS CONTROL |
| 2.022 - Disallow AutoPlay/Autorun from Autorun.inf | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 2.023 - Standard user accounts must only have Read permissions to the Winlogon registry key. | DISA Windows Vista STIG v6r41 | Windows | ACCESS CONTROL |
| 3.030 - Anonymous access to the registry must be restricted. | DISA Windows Vista STIG v6r41 | Windows | ACCESS CONTROL |
| 3.059 - The system is configured to autoplay removable media. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| 3.061 - Unencrypted remote access is permitted to system services. | DISA Windows Vista STIG v6r41 | Windows | ACCESS CONTROL |
| 4.005 - Unapproved Users have access to Debug programs. | DISA Windows Vista STIG v6r41 | Windows | ACCESS CONTROL |
| 4.009 - Unauthorized users are granted right to Act as part of the operating system. | DISA Windows Vista STIG v6r41 | Windows | ACCESS CONTROL |
| 4.027 - Only administrators responsible for the system must have Administrator rights on the system. | DISA Windows Vista STIG v6r41 | Windows | ACCESS CONTROL |
| APPL-15-002062 - The macOS system must disable Bluetooth when no approved device is connected. | DISA Apple macOS 15 Sequoia STIG v1r7 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| APPL-26-006000 - The macOS system must be a version supported by the vendor. | DISA Apple macOS 26 Tahoe STIG v1r2 | Unix | SYSTEM AND SERVICES ACQUISITION |
| APPL-26-999999 - The macOS system must install security-relevant software updates within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, STIGs). | DISA Apple macOS 26 Tahoe STIG v1r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| DTAVSEL-001 - The anti-virus signature file age must not exceed 7 days - avvclean.dat | McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Managed Client v1r5 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| DTAVSEL-001 - The anti-virus signature file age must not exceed 7 days - avvclean.dat | McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Local Client v1r6 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| DTAVSEL-001 - The anti-virus signature file age must not exceed 7 days - avvnames.dat | McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Local Client v1r6 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| DTAVSEL-001 - The anti-virus signature file age must not exceed 7 days - avvnames.dat | McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Managed Client v1r5 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| DTAVSEL-001 - The anti-virus signature file age must not exceed 7 days - avvscan.dat | McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Managed Client v1r5 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| DTAVSEL-001 - The anti-virus signature file age must not exceed 7 days - avvscan.dat | McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Local Client v1r6 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| DTBI999-IE11 - The version of Internet Explorer running on the system must be a supported version. | DISA STIG IE 11 v2r7 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| DTO-OneNote999 - The version of OneNote running on the system must be a supported version. | DISA STIG Microsoft OneNote 2016 v2r1 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| DTO-Outlook999 - The version of Outlook running on the system must be a supported version. | DISA STIG Microsoft Outlook 2016 v2r4 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| DTO-PP999 - The version of PowerPoint running on the system must be a supported version. | DISA STIG Microsoft PowerPoint 2016 v2r1 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| DTO-Pub999 - The version of Publisher running on the system must be a supported version. | DISA STIG Microsoft Publisher 2016 v2r1 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| DTO-Vis999 - The version of Visio running on the system must be a supported version. | DISA STIG Microsoft Visio 2016 v2r1 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| DTO-Word999 - The version of Word running on the system must be a supported version. | DISA STIG Microsoft Word 2016 v2r1 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| DTOO425 - Outlook - The version of Outlook running on the system must be a supported version. | DISA Microsoft Outlook 2010 STIG v1r14 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| DTOO999-Lync13 - The version of Lync running on the system must be a supported version. | DISA STIG Microsoft Lync 2013 v1r5 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| DTOO999-PP13 - The version of PowerPoint running on the system must be a supported version. | DISA STIG Microsoft PowerPoint 2013 v1r7 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| DTOO999-Word13 - The version of Microsoft Word running on the system must be a supported version. | DISA STIG Microsoft Word 2013 v1r7 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| FNFG-FW-000110 - The FortiGate firewall must employ filters that prevent or limit the effects of all types of commonly known denial-of-service (DoS) attacks, including flooding, packet sweeps, and unauthorized port scanning. | DISA Fortigate Firewall STIG v1r4 | FortiGate | SYSTEM AND COMMUNICATIONS PROTECTION |
| GEN000560 - The system must not have accounts configured with blank or null passwords. | DISA AIX 5.3 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| GEN008600 - The system must be configured to only boot from the system boot device. | DISA AIX 5.3 STIG v1r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| GEN008640 - The system must not use removable media as the boot loader - 'both' | DISA AIX 5.3 STIG v1r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| GEN008640 - The system must not use removable media as the boot loader - 'normal' | DISA AIX 5.3 STIG v1r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| GEN008640 - The system must not use removable media as the boot loader - 'prevboot' | DISA AIX 5.3 STIG v1r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| GEN008640 - The system must not use removable media as the boot loader - 'service' | DISA AIX 5.3 STIG v1r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| JUEX-NM-000230 - The Juniper EX switch must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services. | DISA Juniper EX Series Network Device Management v2r4 | Juniper | CONFIGURATION MANAGEMENT |
| JUEX-NM-000340 - The Juniper EX switch must be configured to use FIPS 140-2/140-3-validated algorithms for authentication to a cryptographic module. | DISA Juniper EX Series Network Device Management v2r4 | Juniper | IDENTIFICATION AND AUTHENTICATION |
| JUEX-NM-000370 - The Juniper device must be configured to only allow authorized administrators to view or change the device configuration, system files, and other files stored either in the device or on removable media (such as a flash drive). | DISA Juniper EX Series Network Device Management v2r4 | Juniper | SYSTEM AND COMMUNICATIONS PROTECTION |
| MD8X-00-004200 - MongoDB must use NIST FIPS 140-2/140-3 validated cryptographic modules for cryptographic operations. | DISA MongoDB Enterprise Advanced 8.x STIG v1r1 Unix | Unix | IDENTIFICATION AND AUTHENTICATION |
| MD8X-00-005000 - MongoDB must protect the confidentiality and integrity of all information at rest. | DISA MongoDB Enterprise Advanced 8.x STIG v1r1 Unix | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| MD8X-00-007900 - MongoDB must use NSA-approved cryptography to protect classified information in accordance with the data owner's requirements. | DISA MongoDB Enterprise Advanced 8.x STIG v1r1 MongoDB | MongoDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| O19C-00-009900 - The Oracle Listener must be configured to require administration authentication. | DISA Oracle Database 19c STIG v1r5 Windows | Windows | CONFIGURATION MANAGEMENT |
| O19C-00-011800 - Database administrator (DBA) OS accounts must be granted only those host system privileges necessary for the administration of the Oracle Database. | DISA Oracle Database 19c STIG v1r5 Windows | Windows | CONFIGURATION MANAGEMENT |
| O19C-00-011900 - Oracle Database default accounts must be assigned custom passwords. | DISA Oracle Database 19c STIG v1r5 OracleDB | OracleDB | CONFIGURATION MANAGEMENT |
| O19C-00-018600 - Oracle Database software must be evaluated and patched against newly found vulnerabilities. | DISA Oracle Database 19c STIG v1r5 OracleDB | OracleDB | SYSTEM AND INFORMATION INTEGRITY |
| VCENTER-000099 - The version of vCenter running on the server must be a supported version. | DISA STIG VMWare ESXi vCenter 5 STIG v2r1 | VMware | SYSTEM AND INFORMATION INTEGRITY |
| WINGE-000100 - EMET v5.5 or later must be installed on the system. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| ZEBR-11-999999 - All Zebra Android 11 installations must be removed. | AirWatch - DISA Zebra Android 11 COBO STIG v1r4 | MDM | CONFIGURATION MANAGEMENT |
| ZEBR-11-999999 - All Zebra Android 11 installations must be removed. | MobileIron - DISA Zebra Android 11 COBO STIG v1r4 | MDM | CONFIGURATION MANAGEMENT |