| 5.1.2 Ensure System Integrity Protection Status (SIP) Is Enabled | CIS Apple macOS 10.15 Catalina v3.0.0 L1 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY |
| 5.19 System Integrity Protection status | CIS Apple macOS 10.13 L1 v1.1.0 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| 8.2 Disable JAR from Opening Unsafe File Types | CIS Mozilla Firefox 38 ESR Linux L1 v1.0.0 | Unix | CONFIGURATION MANAGEMENT |
| 8.7 Secure the permissions of the IBMLDAPSecurity.ini file | CIS IBM DB2 9 Benchmark v3.0.1 Level 1 OS Windows | Windows | |
| 9.7 Secure the permission of the SSLconfig.ini file | CIS IBM DB2 v10 v1.1.0 Windows OS Level 1 | Windows | |
| RHEL-10-000500 - RHEL 10 must enable FIPS mode. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-200020 - RHEL 10 must not have the "telnet-server" package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-200030 - RHEL 10 must not have the "gssproxy" package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-200040 - RHEL 10 must not have the tuned package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-200050 - RHEL 10 must not have a Trivial File Transfer Protocol (TFTP) server package installed unless it is required by the mission, and if required, the TFTP daemon must be configured to operate in secure mode. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-200530 - RHEL 10 must have the "firewalld" package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-200560 - RHEL 10 must have the USBGuard package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-200632 - RHEL 10 must use a file integrity tool that is configured to use FIPS 140-3-approved cryptographic hashes for validating file contents and directories. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-200634 - RHEL 10 must be configured so that the file integrity tool verifies Access Control Lists (ACLs). | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-200640 - RHEL 10 must have the "rsyslog" package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY |
| RHEL-10-200647 - RHEL 10 must monitor all remote access methods. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-200650 - RHEL 10 must have the packages required for encrypting off-loaded audit logs installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-200691 - RHEL 10 must have mail aliases to notify the information system security officer (ISSO) and system administrator (SA) (at a minimum) of an audit processing failure. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY |
| RHEL-10-200700 - RHEL 10 must have the "cronie" package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-200720 - RHEL 10 must have a Secure Shell (SSH) server installed for all networked systems. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-200722 - RHEL 10 must have the "openssh-clients" package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-200740 - RHEL 10 must have the "gnutls-utils" package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-300050 - RHEL 10 must be configured so that Secure Shell (SSH) clients use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL, MAINTENANCE |
| RHEL-10-300060 - RHEL 10 must be configured so that Secure Shell (SSH) servers use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL, MAINTENANCE |
| RHEL-10-300080 - RHEL 10 must implement DOD-approved encryption in the bind package. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-400030 - RHEL 10 must be configured so that the "/etc/gshadow-" file is owned by "root". | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-400040 - RHEL 10 must be configured so that the "/etc/passwd" file is owned by "root". | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-400050 - RHEL 10 must be configured so that the "/etc/passwd-" file is owned by "root". | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-700185 - RHEL 10 must mount "/var/tmp" with the "nodev" option. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-700500 - RHEL 10 must be configured so that Secure Shell (SSH) public host key files have mode "0644" or less permissive. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| RHEL-10-700700 - RHEL 10 must prevent a user from overriding the disabling of the graphical user interface automount function. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-700790 - RHEL 10 must conceal, via the session lock, information previously visible on the display with a publicly viewable image. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-700870 - RHEL 10 must disable wireless network adapters. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-700930 - RHEL 10 must be configured with a timeout interval for the Secure Shell (SSH) daemon. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-700950 - RHEL 10 must disable the systemd Ctrl-Alt-Delete burst key sequence. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-700960 - RHEL 10 must disable the x86 Ctrl-Alt-Delete key sequence. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-701020 - RHEL 10 must enable mitigations against processor-based vulnerabilities. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY |
| RHEL-10-701080 - RHEL 10 must enable kernel parameters to enforce discretionary access control (DAC) on symlinks. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-701130 - RHEL 10 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| RHEL-10-701150 - RHEL 10 must disable core dump backtraces. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-701170 - RHEL 10 must disable core dumps for all users. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-701190 - RHEL 10 must implement nonexecutable data to protect its memory from unauthorized code execution. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| RHEL-10-701220 - RHEL 10 must enable certificate-based smart card authentication. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-800030 - RHEL 10 must disable access to the network bpf system call from nonprivileged processes. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-800040 - RHEL 10 must securely compare internal information system clocks at least every 24 hours. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY |
| RHEL-10-800080 - RHEL 10 must be configured to use Transmission Control Protocol (TCP) syncookies. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-800090 - RHEL 10 must ignore Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-800260 - RHEL 10 must not accept router advertisements on all Internet Protocol version 6 (IPv6) interfaces by default. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-800270 - RHEL 10 must prevent Internet Protocol version 6 (IPv6) Internet Control Message Protocol (ICMP) redirect messages from being accepted. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-900000 - RHEL 10 must enforce mode "0640" or less for the "/etc/audit/auditd.conf" file to prevent unauthorized access. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY |