| 1.2 Ensure 'Screen Lock' is set to 'Enabled' | AirWatch - CIS Google Android v1.6.0 L1 | MDM | ACCESS CONTROL |
| 1.2 Ensure 'Screen Lock' is set to 'Enabled' | MobileIron - CIS Google Android v1.6.0 L1 | MDM | ACCESS CONTROL |
| 1.3 Ensure 'Make pattern visible' is set to 'Disabled' (if using a pattern as device lock mechanism) | MobileIron - CIS Google Android v1.6.0 L1 | MDM | CONFIGURATION MANAGEMENT |
| 1.4 Ensure 'Automatically Lock' is set to 'Immediately' | AirWatch - CIS Google Android v1.6.0 L1 | MDM | IDENTIFICATION AND AUTHENTICATION |
| 1.5 Ensure 'Power button instantly locks' is set to 'Enabled' | MobileIron - CIS Google Android v1.6.0 L1 | MDM | IDENTIFICATION AND AUTHENTICATION |
| 1.6 Ensure 'Lock Screen Message' is configured | AirWatch - CIS Google Android v1.6.0 L1 | MDM | ACCESS CONTROL |
| 1.6 Ensure 'Lock Screen Message' is configured | MobileIron - CIS Google Android v1.6.0 L1 | MDM | ACCESS CONTROL |
| 1.10 Ensure 'Install unknown apps' is set to 'Disabled' | AirWatch - CIS Google Android v1.6.0 L1 | MDM | CONFIGURATION MANAGEMENT |
| 1.11 Do not root a user device | MobileIron - CIS Google Android v1.6.0 L1 | MDM | CONFIGURATION MANAGEMENT |
| 1.11 Do not root a user device | AirWatch - CIS Google Android v1.6.0 L1 | MDM | CONFIGURATION MANAGEMENT |
| 1.14 Ensure 'Use network-provided time' and 'Use network-provided time zone' are set to 'Enabled' | AirWatch - CIS Google Android v1.6.0 L1 | MDM | AUDIT AND ACCOUNTABILITY |
| 1.15 Ensure 'Remotely locate this device' is set to 'Enabled' | AirWatch - CIS Google Android v1.6.0 L1 | MDM | ACCESS CONTROL |
| 1.17 Ensure 'Scan device for security threats' is set to 'Enabled' | AirWatch - CIS Google Android v1.6.0 L1 | MDM | SYSTEM AND INFORMATION INTEGRITY |
| 1.17 Ensure 'Scan device for security threats' is set to 'Enabled' | MobileIron - CIS Google Android v1.6.0 L1 | MDM | SYSTEM AND INFORMATION INTEGRITY |
| 1.18 Ensure 'Improve harmful app detection' is set to 'Enabled' | MobileIron - CIS Google Android v1.6.0 L1 | MDM | SYSTEM AND INFORMATION INTEGRITY |
| 1.19 Ensure 'Ask for unlock pattern/PIN/password before unpinning' is set to 'Enabled' | AirWatch - CIS Google Android v1.6.0 L1 | MDM | IDENTIFICATION AND AUTHENTICATION |
| 1.20 Ensure 'Screen timeout' is set to '2 minutes' | MobileIron - CIS Google Android v1.6.0 L1 | MDM | ACCESS CONTROL |
| 1.21 Ensure 'Wi-Fi assistant' is set to 'Disabled' | AirWatch - CIS Google Android v1.6.0 L1 | MDM | CONFIGURATION MANAGEMENT |
| 1.22 Keep device Apps up to date | AirWatch - CIS Google Android v1.6.0 L1 | MDM | SYSTEM AND INFORMATION INTEGRITY |
| 1.23 Ensure 'Add users from lock screen' is set to 'Disabled' | MobileIron - CIS Google Android v1.6.0 L1 | MDM | CONFIGURATION MANAGEMENT |
| 1.28 Review existing user profiles periodically | AirWatch - CIS Google Android v1.6.0 L1 | MDM | ACCESS CONTROL |
| 1.28 Review existing user profiles periodically | MobileIron - CIS Google Android v1.6.0 L1 | MDM | ACCESS CONTROL |
| 2.1 Ensure 'Lock screen' is set to 'Don't show notifications at all' | AirWatch - CIS Google Android v1.6.0 L1 | MDM | ACCESS CONTROL |
| 2.1 Ensure 'Lock screen' is set to 'Don't show notifications at all' | MobileIron - CIS Google Android v1.6.0 L1 | MDM | ACCESS CONTROL |
| 2.2 Secure the database container directory | CIS IBM DB2 v10 v1.1.0 Linux OS Level 2 | Unix | |
| 2.2 Secure the database container directory | CIS IBM DB2 9 Benchmark v3.0.1 Level 1 OS Linux | Unix | |
| 2.2 Secure the database container directory | CIS IBM DB2 9 Benchmark v3.0.1 Level 1 OS Windows | Windows | |
| 2.3 Ensure 'Web and App Activity' is set to 'Disabled' | MobileIron - CIS Google Android v1.6.0 L1 | MDM | CONFIGURATION MANAGEMENT |
| 2.5 Ensure 'Voice & Audio Activity' is set to 'Disabled' | MobileIron - CIS Google Android v1.6.0 L1 | MDM | CONFIGURATION MANAGEMENT |
| 2.5 Ensure 'Voice & Audio Activity' is set to 'Disabled' | AirWatch - CIS Google Android v1.6.0 L1 | MDM | CONFIGURATION MANAGEMENT |
| 2.6 Ensure 'YouTube Search History' is set to 'Disabled' | MobileIron - CIS Google Android v1.6.0 L1 | MDM | CONFIGURATION MANAGEMENT |
| 2.7 Ensure 'YouTube Watch History' is set to 'Disabled' | AirWatch - CIS Google Android v1.6.0 L1 | MDM | CONFIGURATION MANAGEMENT |
| 2.7 Ensure 'YouTube Watch History' is set to 'Disabled' | MobileIron - CIS Google Android v1.6.0 L1 | MDM | CONFIGURATION MANAGEMENT |
| 2.8 Ensure 'Google Location History' is set to 'Disabled' | MobileIron - CIS Google Android v1.6.0 L1 | MDM | CONFIGURATION MANAGEMENT |
| 2.8 Enable user namespace support | CIS Docker 1.13.0 v1.0.0 L2 Docker | Unix | |
| 2.9 Ensure 'Opt out of Ads Personalization' is set to 'Enabled' | MobileIron - CIS Google Android v1.6.0 L1 | MDM | ACCESS CONTROL |
| 2.10 Ensure 'Wi-Fi scanning' Is 'Disabled' | MobileIron - CIS Google Android v1.6.0 L1 | MDM | CONFIGURATION MANAGEMENT |
| 3.1 Ensure 'Microphone' is set to 'Enabled' | MobileIron - CIS Google Android v1.6.0 L1 | MDM | ACCESS CONTROL |
| 3.2 Ensure 'Location' is set to 'Enabled' | MobileIron - CIS Google Android v1.6.0 L1 | MDM | ACCESS CONTROL |
| 3.2 Ensure 'Location' is set to 'Enabled' | AirWatch - CIS Google Android v1.6.0 L1 | MDM | ACCESS CONTROL |
| 3.3 Ensure 'Allow third-party cookies' is set to 'Disabled' | MobileIron - CIS Google Android v1.6.0 L1 | MDM | CONFIGURATION MANAGEMENT |
| 3.3 Ensure 'Allow third-party cookies' is set to 'Disabled' | AirWatch - CIS Google Android v1.6.0 L1 | MDM | CONFIGURATION MANAGEMENT |
| 3.4 Ensure 'Safe Browsing' is set to 'Enabled' | MobileIron - CIS Google Android v1.6.0 L1 | MDM | SYSTEM AND INFORMATION INTEGRITY |
| 3.4 Ensure 'Safe Browsing' is set to 'Enabled' | AirWatch - CIS Google Android v1.6.0 L1 | MDM | SYSTEM AND INFORMATION INTEGRITY |
| 5.5 Do not use privileged containers | CIS Docker 1.6 v1.0.0 L1 Docker | Unix | |
| 5.11 Set container CPU priority appropriately | CIS Docker 1.13.0 v1.0.0 L1 Docker | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.12 Set container CPU priority appropriately | CIS Docker 1.6 v1.0.0 L1 Docker | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| DKER-EE-002020 - Docker Enterprise CPU priority must be set appropriately on all containers. | DISA STIG Docker Enterprise 2.x Linux/Unix v2r2 | Unix | CONFIGURATION MANAGEMENT |
| KNOX-07-912200 - The Samsung Android 7 with Knox must be configured to lock the container after 15 minutes (or less) of inactivity. | MobileIron - DISA Samsung Android 7 with Knox 2.x v1r1 | MDM | CONFIGURATION MANAGEMENT |
| PPS9-00-012800 - The EDB Postgres Advanced Server must implement NIST FIPS 140-2 or 140-3 validated cryptographic modules to generate and validate cryptographic hashes. | EDB PostgreSQL Advanced Server OS Linux Audit v2r3 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |