| 1.1.3.10.10 Set 'Network access: Remotely accessible registry paths' to the following list | CIS Windows 8 L1 v1.0.0 | Windows | ACCESS CONTROL |
| 2.3.7.2 Ensure 'Interactive logon: Do not require CTRL+ALT+DEL' is set to 'Disabled' | CIS Microsoft Windows 8.1 v2.4.1 L1 | Windows | CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION |
| 2.62 (L1) Ensure 'Enable reporting of usage and crash-related data' is set to 'Disabled' | CIS Google Chrome Group Policy v1.1.0 L1 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 4.10.5.2 Ensure 'Remote host allows delegation of non-exportable credentials' is set to 'Enabled' | CIS Microsoft Intune for Windows 11 v5.0.0 L1 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 5.3 (L1) Ensure 'Computer Browser (Browser)' is set to 'Disabled' or 'Not Installed' | CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1 | Windows | CONFIGURATION MANAGEMENT |
| 9.1.4 Ensure 'Windows Firewall: Domain: Logging: Name' is configured | CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BL NG | Windows | AUDIT AND ACCOUNTABILITY |
| 9.1.4 Ensure 'Windows Firewall: Domain: Logging: Name' is configured | CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BL | Windows | AUDIT AND ACCOUNTABILITY |
| 9.1.4 Ensure 'Windows Firewall: Domain: Logging: Name' is configured | CIS Microsoft Windows Server 2019 v5.0.0 L1 MS | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 9.2.4 Ensure 'Windows Firewall: Private: Logging: Name' is configured | CIS Microsoft Windows Server 2019 Stand-alone v4.0.0 L1 MS | Windows | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 9.2.4 Ensure 'Windows Firewall: Private: Logging: Name' is configured | CIS Microsoft Windows Server 2022 v5.1.0 L1 MS | Windows | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 9.2.4 Ensure 'Windows Firewall: Private: Logging: Name' is configured | CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BL NG | Windows | AUDIT AND ACCOUNTABILITY |
| 9.2.4 Ensure 'Windows Firewall: Private: Logging: Name' is configured | CIS Microsoft Windows Server 2025 v2.1.0 L1 DC | Windows | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 9.2.4 Ensure 'Windows Firewall: Private: Logging: Name' is configured | CIS Microsoft Windows 10 Stand-alone v5.0.0 L1 BL | Windows | AUDIT AND ACCOUNTABILITY |
| 9.2.4 Ensure 'Windows Firewall: Private: Logging: Name' is configured | CIS Microsoft Windows 10 Stand-alone v5.0.0 L1 NG | Windows | AUDIT AND ACCOUNTABILITY |
| 9.3.4 Ensure 'Windows Firewall: Public: Logging: Name' is configured | CIS Microsoft Windows 10 Stand-alone v5.0.0 L1 BL | Windows | AUDIT AND ACCOUNTABILITY |
| 9.3.6 Ensure 'Windows Firewall: Public: Logging: Name' is configured | CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BL | Windows | AUDIT AND ACCOUNTABILITY |
| 9.3.6 Ensure 'Windows Firewall: Public: Logging: Name' is configured | CIS Microsoft Windows 10 Enterprise v5.0.0 L1 NG | Windows | AUDIT AND ACCOUNTABILITY |
| 18.3.2 Ensure 'Configure SMB v1 client driver' is set to 'Enabled: Disable driver (recommended)' | CIS Microsoft Windows 8.1 v2.4.1 L1 | Windows | CONFIGURATION MANAGEMENT, RISK ASSESSMENT |
| 18.6.7.3 Ensure 'Audit insecure guest logon' is set to 'Enabled' | CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BL | Windows | AUDIT AND ACCOUNTABILITY |
| 18.6.7.3 Ensure 'Audit insecure guest logon' is set to 'Enabled' | CIS Microsoft Windows Server 2025 v2.1.0 L1 DC | Windows | AUDIT AND ACCOUNTABILITY |
| 18.6.7.3 Ensure 'Audit insecure guest logon' is set to 'Enabled' | CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 | Windows | AUDIT AND ACCOUNTABILITY |
| 18.6.7.3 Ensure 'Audit insecure guest logon' is set to 'Enabled' | CIS Microsoft Windows Server 2025 Stand-alone v2.0.0 L1 MS | Windows | AUDIT AND ACCOUNTABILITY |
| 18.6.7.3 Ensure 'Audit insecure guest logon' is set to 'Enabled' | CIS Microsoft Windows Server 2025 v2.1.0 L1 MS | Windows | AUDIT AND ACCOUNTABILITY |
| 18.6.8.1 Ensure 'Audit insecure guest logon' is set to 'Enabled' | CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 | Windows | AUDIT AND ACCOUNTABILITY |
| 18.6.8.1 Ensure 'Audit insecure guest logon' is set to 'Enabled' | CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BL | Windows | AUDIT AND ACCOUNTABILITY |
| 18.8.4.2 (L1) Ensure 'Remote host allows delegation of non-exportable credentials' is set to 'Enabled' | CIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 DC | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.8.4.2 (L1) Ensure 'Remote host allows delegation of non-exportable credentials' is set to 'Enabled' | CIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 MS | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.8.4.2 Ensure 'Remote host allows delegation of non-exportable credentials' is set to 'Enabled' | CIS Microsoft Windows 8.1 v2.4.1 L1 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 18.8.5.1 (NG) Ensure 'Turn On Virtualization Based Security' is set to 'Enabled' | CIS Azure Compute Microsoft Windows Server 2022 v1.0.0 NG MS | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.9.4.2 (L1) Ensure 'Remote host allows delegation of non-exportable credentials' is set to 'Enabled' | CIS Microsoft Windows Server 2016 v4.0.0 L1 MS | Windows | IDENTIFICATION AND AUTHENTICATION |
| 18.9.5.1 (NG) Ensure 'Turn On Virtualization Based Security' is set to 'Enabled' | CIS Microsoft Windows Server 2016 v4.0.0 NG DC | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.9.5.1 (NG) Ensure 'Turn On Virtualization Based Security' is set to 'Enabled' | CIS Microsoft Windows Server 2016 v4.0.0 NG MS | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.9.5.1 Ensure 'Turn On Virtualization Based Security' is set to 'Enabled' | CIS Microsoft Windows Server 2022 v5.1.0 NG DC | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.9.5.1 Ensure 'Turn On Virtualization Based Security' is set to 'Enabled' | CIS Microsoft Windows Server 2019 v5.0.0 NG MS | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.9.5.1 Ensure 'Turn On Virtualization Based Security' is set to 'Enabled' | CIS Microsoft Windows Server 2025 Stand-alone v2.0.0 NG MS | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.9.5.1 Ensure 'Turn On Virtualization Based Security' is set to 'Enabled' | CIS Microsoft Windows Server 2025 v2.1.0 NG DC | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.9.5.1 Ensure 'Turn On Virtualization Based Security' is set to 'Enabled' | CIS Microsoft Windows Server 2019 Stand-alone v4.0.0 NG MS | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.9.5.1 Ensure 'Turn On Virtualization Based Security' is set to 'Enabled' | CIS Microsoft Windows Server 2019 v5.0.0 NG DC | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.9.5.1 Ensure 'Turn On Virtualization Based Security' is set to 'Enabled' | CIS Microsoft Windows Server 2022 v5.1.0 NG MS | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.9.17.1 (L1) Ensure 'Allow Diagnostic Data' is set to 'Enabled: Send required diagnostic data' | CIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 MS | Windows | CONFIGURATION MANAGEMENT |
| 18.9.17.1 (L1) Ensure 'Allow Diagnostic Data' is set to 'Enabled: Send required diagnostic data' | CIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 MS | Windows | CONFIGURATION MANAGEMENT |
| 18.9.17.1 (L1) Ensure 'Allow Diagnostic Data' is set to 'Enabled: Send required diagnostic data' | CIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 DC | Windows | CONFIGURATION MANAGEMENT |
| 18.9.29.4 Ensure 'Turn on convenience PIN sign-in' is set to 'Disabled' | CIS Microsoft Windows Server 2022 Stand-alone v2.0.0 L1 MS | Windows | CONFIGURATION MANAGEMENT |
| 18.10.16.1 (L1) Ensure 'Allow Diagnostic Data' is set to 'Enabled: Diagnostic data off (not recommended)' or 'Enabled: Send required diagnostic data' | CIS Microsoft Windows Server 2016 v4.0.0 L1 DC | Windows | CONFIGURATION MANAGEMENT |
| 18.10.16.1 (L1) Ensure 'Allow Diagnostic Data' is set to 'Enabled: Diagnostic data off (not recommended)' or 'Enabled: Send required diagnostic data' | CIS Microsoft Windows Server 2016 v4.0.0 L1 MS | Windows | CONFIGURATION MANAGEMENT |
| 23.3 Ensure 'Enable Virtualization Based Security' is set to 'Enable virtualization based security' | CIS Microsoft Intune for Windows 11 v5.0.0 L1 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 23.3 Ensure 'Enable Virtualization Based Security' is set to 'Enable virtualization based security' | CIS Microsoft Intune for Windows 10 v5.0.0 NG | Windows | SYSTEM AND INFORMATION INTEGRITY |
| CIS_Microsoft_Windows_10_EMS_Gateway_v3.0.0_L1.audit from CIS Microsoft Windows 10 EMS Gateway Benchmark v3.0.0 | CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1 | Windows | |
| CIS_Microsoft_Windows_Server_2022_Stand-alone_v2.0.0_L2_MS.audit from CIS Microsoft Windows Server 2022 Stand-alone 2.0.0 | CIS Microsoft Windows Server 2022 Stand-alone v2.0.0 L2 MS | Windows | |
| CIS_Microsoft_Windows_Server_2022_Stand-alone_v2.0.0_NG_MS.audit from CIS Microsoft Windows Server 2022 Stand-alone 2.0.0 | CIS Microsoft Windows Server 2022 Stand-alone v2.0.0 NG MS | Windows | |