| 1.3.6 Ensure the customer lockbox feature is enabled | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 1.3.8 Ensure that Sways cannot be shared with people outside of your organization | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 1.6 O365-CO-000003 | CIS Microsoft Office 365 ProPlus STIG v1.1.0 CAT II | Windows | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.1.4 Ensure Safe Attachments policy is enabled | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.5 Ensure Safe Attachments for SharePoint, OneDrive, and Microsoft Teams is Enabled | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.7 Ensure that an anti-phishing policy has been created | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.11 Ensure comprehensive attachment filtering is applied | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 2.3.23.2 (L1) Ensure 'Block signing into Office' is set to 'Enabled: Org ID only' | CIS Microsoft Intune for Office v1.1.0 L1 | Windows | ACCESS CONTROL |
| 2.3.27.12 Ensure 'Encryption mode for Information Rights Management (IRM)' is set to 'Enabled: Cipher Block Chaining (CBC)' | CIS Microsoft Office Enterprise v1.2.0 L1 | Windows | SYSTEM AND SERVICES ACQUISITION |
| 2.15 Ensure 'Access Transparency' is 'Enabled' | CIS Google Cloud Platform Foundation v5.0.0 L2 | GCP | AUDIT AND ACCOUNTABILITY |
| 4.1 Create CIS Audit Class | CIS Solaris 11.2 L1 v1.1.0 | Unix | ACCESS CONTROL |
| 5.1.2.5 Ensure the option to remain signed in is hidden | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL |
| 5.1.2.6 Ensure 'LinkedIn account connections' is disabled | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 5.1.4.6 Ensure users are restricted from recovering BitLocker keys | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL, MEDIA PROTECTION |
| 5.1.5.1 Ensure user consent to apps accessing company data on their behalf is not allowed | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 5.1.5.3 Ensure password addition is blocked for applications | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.1.6.1 Ensure that collaboration invitations are sent to allowed domains only | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION |
| 5.2.2.8 Ensure 'sign-in risk' is blocked for medium and high risk | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | AUDIT AND ACCOUNTABILITY |
| 5.2.2.14 Ensure trusted 'named locations' are defined | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL, CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 5.2.2.15 Ensure exclusionary geographic access controls are utilized | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL |
| 5.2.4.2 Ensure that 2 methods are required for password reset | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.3.1 Ensure privileged role assignments are activated and not assigned | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION |
| 6.3.1 Ensure users installing Outlook add-ins is not allowed | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 6.5.3 Ensure additional storage providers are restricted in Outlook on the web | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION |
| 6.5.5 Ensure Direct Send submissions are rejected | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 7.2.4 Ensure OneDrive content sharing is restricted | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL, MEDIA PROTECTION |
| 7.2.8 Ensure external sharing is restricted by security group | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION |
| 7.3.1 Ensure Office 365 SharePoint infected files are disallowed for download | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 8.1.1 Ensure external file sharing in Teams is enabled for only approved cloud storage services | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL, MEDIA PROTECTION |
| 8.5.1 Ensure anonymous users can't join a meeting | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL |
| 8.5.5 Ensure meeting chat does not allow anonymous users | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL |
| 8.5.9 Ensure meeting recording is off by default | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 9.1.5 Ensure 'Interact with and share R and Python' visuals is 'Disabled' | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 18.10.43.6 Ensure 'Turn on Microsoft Defender Application Guard in Managed Mode' is set to 'Enabled: 1' | CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BL | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.10.43.6 Ensure 'Turn on Microsoft Defender Application Guard in Managed Mode' is set to 'Enabled: 1' | CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 18.10.43.6 Ensure 'Turn on Microsoft Defender Application Guard in Managed Mode' is set to 'Enabled: 1' | CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BL | Windows | SYSTEM AND INFORMATION INTEGRITY |
| DKER-EE-001800 - The insecure registry capability in the Docker Engine - Enterprise component of Docker Enterprise must be disabled. | DISA STIG Docker Enterprise 2.x Linux/Unix v2r2 | Unix | CONFIGURATION MANAGEMENT |
| DKER-EE-001810 - On Linux, a non-AUFS storage driver in the Docker Engine - Enterprise component of Docker Enterprise must be used. | DISA STIG Docker Enterprise 2.x Linux/Unix v2r2 | Unix | CONFIGURATION MANAGEMENT |
| DKER-EE-001840 - Experimental features in the Docker Engine - Enterprise component of Docker Enterprise must be disabled. | DISA STIG Docker Enterprise 2.x Linux/Unix v2r2 | Unix | CONFIGURATION MANAGEMENT |
| DKER-EE-001870 - The Docker Enterprise self-signed certificates in Universal Control Plane (UCP) must be replaced with DoD trusted, signed certificates. | DISA STIG Docker Enterprise 2.x Linux/Unix UCP v2r2 | Unix | CONFIGURATION MANAGEMENT |
| DKER-EE-001880 - The Docker Enterprise self-signed certificates in Docker Trusted Registry (DTR) must be replaced with DoD trusted, signed certificates. | DISA STIG Docker Enterprise 2.x Linux/Unix DTR v2r2 | Unix | CONFIGURATION MANAGEMENT |
| DKER-EE-001890 - The option in Universal Control Plane (UCP) allowing users and administrators to schedule containers on all nodes, including UCP managers and Docker Trusted Registry (DTR) nodes must be disabled in Docker Enterprise. | DISA STIG Docker Enterprise 2.x Linux/Unix UCP v2r2 | Unix | CONFIGURATION MANAGEMENT |
| DKER-EE-001900 - The Create repository on push option in Docker Trusted Registry (DTR) must be disabled in Docker Enterprise. | DISA STIG Docker Enterprise 2.x Linux/Unix DTR v2r2 | Unix | CONFIGURATION MANAGEMENT |
| DKER-EE-001910 - Periodic data usage and analytics reporting in Universal Control Plane (UCP) must be disabled in Docker Enterprise. | DISA STIG Docker Enterprise 2.x Linux/Unix UCP v2r2 | Unix | CONFIGURATION MANAGEMENT |
| DKER-EE-001920 - Periodic data usage and analytics reporting in Docker Trusted Registry (DTR) must be disabled in Docker Enterprise. | DISA STIG Docker Enterprise 2.x Linux/Unix DTR v2r2 | Unix | CONFIGURATION MANAGEMENT |
| Encryption mode for Information Rights Management (IRM) | Microsoft 365 Apps for Enterprise 2306 v1.0.0 | Windows | |
| Encryption mode for Information Rights Management (IRM) | MSCT M365 Apps for enterprise 2412 v1.0.0 | Windows | |
| Encryption mode for Information Rights Management (IRM) | MSCT M365 Apps for enterprise 2312 v1.0.0 | Windows | |
| MS.DEFENDER.1.1v1 - The standard and strict preset security policies SHALL be enabled. | CISA SCuBA Microsoft 365 Defender v1.5.0 | microsoft_azure | ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| O365-CO-000003 - The Office client must be prevented from polling the SharePoint Server for published links. | DISA Microsoft Office 365 ProPlus STIG v3r5 | Windows | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |