| 1.1.2 Ensure that the --basic-auth-file argument is not set | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 1.1.7 Ensure that the --profiling argument is set to false | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 1.1.14 Ensure that the --audit-log-path argument is set as appropriate | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | AUDIT AND ACCOUNTABILITY |
| 1.1.15 Ensure that the --audit-log-maxage argument is set to 30 or as appropriate | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | AUDIT AND ACCOUNTABILITY |
| 1.1.21 Ensure that the --kubelet-certificate-authority argument is set as appropriate | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 1.1.22 Ensure that the --kubelet-client-certificate and --kubelet-client-key arguments are set as appropriate - kubelet-client-key | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 1.1.24 Ensure that the admission control policy is set to PodSecurityPolicy | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | ACCESS CONTROL |
| 1.1.29 Ensure that the --client-ca-file argument is set as appropriate | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 1.1.36 Ensure that the AdvancedAuditing argument is not set to false - AdvancedAuditing | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | AUDIT AND ACCOUNTABILITY |
| 1.3.3 Ensure that the --use-service-account-credentials argument is set to true | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | ACCESS CONTROL |
| 1.3.4 Ensure that the --service-account-private-key-file argument is set as appropriate | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 1.4.16 Ensure that the scheduler.conf file ownership is set to root:root | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 1.5.2 Ensure that the --client-cert-auth argument is set to true | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 1.5.4 Configure Logging Timestamps | CIS Cisco NX-OS v1.2.0 L1 | Cisco | AUDIT AND ACCOUNTABILITY |
| 1.5.5 Ensure that the --peer-client-cert-auth argument is set to true | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 1.6.1 Configure at least 2 external NTP Servers | CIS Cisco NX-OS v1.2.0 L1 | Cisco | AUDIT AND ACCOUNTABILITY |
| 1.9.2 Configure SNMP Traps | CIS Cisco NX-OS v1.2.0 L1 | Cisco | SYSTEM AND INFORMATION INTEGRITY |
| 1.9.4 Ensure Read Write privileges are not configured for SNMP | CIS Cisco NX-OS v1.2.0 L1 | Cisco | CONFIGURATION MANAGEMENT, MAINTENANCE |
| 2.3 Ensure authentication is enabled in the sharded cluster | CIS MongoDB 5 v1.2.0 L2 Unix | Unix | CONFIGURATION MANAGEMENT |
| 3.1.1.2 Configure EIGRP Passive interfaces for interfaces that do not have peers | CIS Cisco NX-OS v1.2.0 L1 | Cisco | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| 3.1.3.1 Set Interfaces with no Peers to Passive-Interface | CIS Cisco NX-OS v1.2.0 L1 | Cisco | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| 3.2.4 Disable IP Directed Broadcasts on all Layer 3 Interfaces | CIS Cisco NX-OS v1.2.0 L1 | Cisco | ACCESS CONTROL, CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 3.3.1 Configure DHCP Trust | CIS Cisco NX-OS v1.2.0 L1 | Cisco | ACCESS CONTROL, CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 3.5.2 Configure FCoE Zoning | CIS Cisco NX-OS v1.2.0 L2 | Cisco | ACCESS CONTROL, CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.1 Configure Local Configuration Backup Schedule | CIS Cisco NX-OS v1.2.0 L1 | Cisco | CONTINGENCY PLANNING |
| 4.2 Ensure Weak Protocols are Disabled | CIS MongoDB 5 v1.2.0 L1 Unix | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.4 Ensure Federal Information Processing Standard (FIPS) is enabled | CIS MongoDB 5 v1.2.0 L2 Unix | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.5 Ensure Encryption of Data at Rest | CIS MongoDB 5 v1.2.0 L2 Unix | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.5.3 Ensure clean_partial_conns is enabled | CIS IBM AIX 7 v1.2.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 4.5.12 Ensure ipsrcroutesend is disabled | CIS IBM AIX 7 v1.2.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 4.5.13 Ensure ip6srcrouteforward is disabled | CIS IBM AIX 7 v1.2.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 4.5.18 Ensure udp_pmtu_discover is disabled | CIS IBM AIX 7 v1.2.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 4.6.1.2 Ensure the cmsd service is not available | CIS IBM AIX 7 v1.2.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 4.6.1.3 Ensure dtlogin service is not available | CIS IBM AIX 7 v1.2.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 4.6.1.5 Ensure CDE daemons have sgid and suid mode disabled | CIS IBM AIX 7 v1.2.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 4.6.1.9 Ensure access to /etc/dt/config/Xconfig is configured | CIS IBM AIX 7 v1.2.0 L1 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 4.6.2.3 Ensure ftpd umask is configured | CIS IBM AIX 7 v1.2.0 L1 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 4.6.3.6 Ensure sshd Ciphers are configured | CIS IBM AIX 7 v1.2.0 L1 | Unix | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.6.3.12 Ensure sshd MaxAuthTries is configured | CIS IBM AIX 7 v1.2.0 L1 | Unix | CONFIGURATION MANAGEMENT, MAINTENANCE |
| 5.1 Ensure that system activity is audited | CIS MongoDB 5 v1.2.0 L1 Unix | Unix | AUDIT AND ACCOUNTABILITY |
| 5.2.6 Ensure password expiration is configured | CIS IBM AIX 7 v1.2.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.2.10 Ensure number of characters changed in new password is configured | CIS IBM AIX 7 v1.2.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.2.11 Ensure minalpha is configured | CIS IBM AIX 7 v1.2.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.3 Ensure that logging captures as much information as possible | CIS MongoDB 5 v1.2.0 L2 Unix | Unix | AUDIT AND ACCOUNTABILITY |
| 5.3.7 Ensure user nuucp is secured | CIS IBM AIX 7 v1.2.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 6.2 Ensure that operating system resource limits are set for MongoDB | CIS MongoDB 5 v1.2.0 L2 Unix | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 7.1 Ensure Fix Level Recommendation Tool Vulnerability Checker Script (FLRTVC) is regularly checked | CIS IBM AIX 7 v1.2.0 L1 | Unix | RISK ASSESSMENT |
| 8.1.1 Ensure /audit filesystem has been created and configured | CIS IBM AIX 7 v1.2.0 L2 | Unix | AUDIT AND ACCOUNTABILITY |
| 8.1.2 Ensure Audit bin(ary) audit event collection is configured | CIS IBM AIX 7 v1.2.0 L2 | Unix | AUDIT AND ACCOUNTABILITY |
| 8.2.1 Ensure syslog local logging is configured | CIS IBM AIX 7 v1.2.0 L1 | Unix | AUDIT AND ACCOUNTABILITY |