| 1.1 Ensure the appropriate MongoDB software version/patches are installed | CIS MongoDB Database Audit L1 v1.0.0 | MongoDB | CONFIGURATION MANAGEMENT |
| 1.1 Ensure the appropriate MongoDB software version/patches are installed | CIS MongoDB 3.4 Database Audit L1 v1.0.0 | MongoDB | CONFIGURATION MANAGEMENT |
| 1.1 Ensure the appropriate MongoDB software version/patches are installed | CIS MongoDB 3.2 Database Audit L1 v1.0.0 | MongoDB | CONFIGURATION MANAGEMENT |
| 2.1 Ensure Authentication is configured | CIS MongoDB 4 v1.0.0 L1 Windows | Windows | IDENTIFICATION AND AUTHENTICATION |
| 2.1 Ensure Authentication is configured | CIS MongoDB 5 v1.2.0 L1 Windows | Windows | IDENTIFICATION AND AUTHENTICATION |
| 2.1 Ensure Authentication is configured | CIS MongoDB 7 v1.2.0 L1 Unix | Unix | IDENTIFICATION AND AUTHENTICATION |
| 2.1 Ensure Authentication is configured | CIS MongoDB 7 v1.2.0 L1 Windows | Windows | IDENTIFICATION AND AUTHENTICATION |
| 2.1 Ensure Authentication is configured | CIS MongoDB 6 v1.2.0 L1 MongoDB | Unix | IDENTIFICATION AND AUTHENTICATION |
| 2.1 Ensure Authentication is configured | CIS MongoDB 6 v1.2.0 L1 MongoDB | Windows | IDENTIFICATION AND AUTHENTICATION |
| 2.1 Ensure Authentication is configured | CIS MongoDB 8 v1.0.0 L1 Windows | Windows | IDENTIFICATION AND AUTHENTICATION |
| 2.1 Ensure Authentication is configured | CIS MongoDB 8 v1.0.0 L1 Unix | Unix | IDENTIFICATION AND AUTHENTICATION |
| 2.7.2 iCloud keychain | CIS Apple OSX 10.11 El Capitan L2 v1.1.0 | Unix | |
| 2.7.2 iCloud keychain | CIS Apple OSX 10.9 L2 v1.3.0 | Unix | |
| 3.1 Ensure least privilege for database accounts | CIS MongoDB 4 v1.0.0 L1 MongoDB | MongoDB | ACCESS CONTROL |
| 3.2 Ensure that role-based access control is enabled and configured appropriately | CIS MongoDB 4 v1.0.0 L1 MongoDB | MongoDB | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 3.4 Control access to audit records - /etc/security/audit_control | CIS Apple macOS 10.12 L1 v1.2.0 | Unix | |
| 3.4 Control access to audit records - /var/audit | CIS Apple macOS 10.12 L1 v1.2.0 | Unix | AUDIT AND ACCOUNTABILITY |
| 3.4 Ensure that each role for each MongoDB database is needed and grants only the necessary privileges | CIS MongoDB 4 v1.0.0 L1 MongoDB | MongoDB | ACCESS CONTROL |
| 3.5 Review Superuser/Admin Roles | CIS MongoDB 4 v1.0.0 L2 MongoDB | MongoDB | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.4.7 Ensure minimum and maximum requirements are set for password changes - maxrepeat | CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.5.1.2 Ensure minimum days between password changes is configured - login.defs | CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.5.1.2 Ensure minimum days between password changes is configured - password shadow | CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG | Unix | IDENTIFICATION AND AUTHENTICATION |
| AOSX-15-100001 - The macOS system must be a supported release. | DISA STIG Apple Mac OSX 10.15 v1r10 | Unix | CONFIGURATION MANAGEMENT |
| APPNET0064 - .Net applications that invoke NetFx40_LegacySecurityPolicy must apply previous versions of .NET STIG guidance. | DISA Microsoft DotNet Framework 4.0 STIG v2r8 | Windows | CONFIGURATION MANAGEMENT |
| BIND-9X-001360 - The BIND 9.x server implementation must prohibit the forwarding of queries to servers controlled by organizations outside of the U.S. government. | DISA BIND 9.x STIG v3r2 | Unix | CONFIGURATION MANAGEMENT |
| CIS_MariaDB_Enterprise_10.x_STIG_v1.1.0_CAT_I_Unix.audit from CIS MariaDB Enterprise 10.x STIG v1.1.0 | CIS MariaDB Enterprise 10.x STIG v1.1.0 CAT I Unix | Unix | |
| CIS_MariaDB_Enterprise_10.x_STIG_v1.1.0_CAT_II_Unix.audit from CIS MariaDB Enterprise 10.x STIG v1.1.0 | CIS MariaDB Enterprise 10.x STIG v1.1.0 CAT II Unix | Unix | |
| DISA_F5_BIG-IP_AFM_v2r2.audit from DISA F5 BIG-IP Advanced Firewall Manager v2r2 STIG | DISA F5 BIG-IP Advanced Firewall Manager STIG v2r2 | F5 | |
| DISA_STIG_BIND_9.x_v3r2.audit from DISA BIND 9.x STIG v3r2 | DISA BIND 9.x STIG v3r2 | Unix | |
| DISA_STIG_Cloud_Linux_AlmaLinux_OS_9_v1r7.audit from DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | |
| DISA_STIG_EDB_PostgreSQL_Advanced_Server_v11_Windows_v2r4_OS.audit from DISA EDB Postgres Advanced Server v11 on Windows v2r4 STIG | EDB PostgreSQL Advanced Server v11 Windows OS Audit v2r4 | Windows | |
| DISA_STIG_IBM_AIX_7.x_v3r3.audit from DISA IBM AIX 7.x STIG v3r3 | DISA IBM AIX 7.x STIG v3r3 | Unix | |
| DISA_STIG_IBM_WebSphere_Traditional_9_v2r1_Middleware.audit from DISA IBM WebSphere Traditional V9.x v2r1 STIG | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | |
| DISA_STIG_IBM_WebSphere_Traditional_9_Windows_v2r1.audit from DISA IBM WebSphere Traditional V9.x v2r1 STIG | DISA IBM WebSphere Traditional 9 Windows STIG v2r1 | Windows | |
| DISA_STIG_JBoss_EAP_6.3_v2r6.audit from DISA JBoss Enterprise Application Platform 6.3 v2r6 STIG | DISA JBoss Enterprise Application Platform 6.3 STIG v2r6 | Unix | |
| DISA_STIG_Red_Hat_Enterprise_Linux_7_v3r15.audit from DISA Red Hat Enterprise Linux 7 v3r15 STIG | DISA Red Hat Enterprise Linux 7 STIG v3r15 | Unix | |
| DISA_STIG_Red_Hat_Enterprise_Linux_8_v2r8.audit from DISA Red Hat Enterprise Linux 8 STIG v2r8 | DISA Red Hat Enterprise Linux 8 STIG v2r8 | Unix | |
| DISA_STIG_Red_Hat_Enterprise_Linux_9_v2r9.audit from DISA Red Hat Enterprise Linux 9 STIG v2r9 | DISA Red Hat Enterprise Linux 9 STIG v2r9 | Unix | |
| DISA_STIG_RHEL_5_v1r18.audit from DISA Red Hat Enterprise Linux 5 STIG v1r18 | DISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit | Unix | |
| DISA_STIG_RHEL_6_v2r2.audit from DISA Red Hat Enterprise Linux 6 v2r2 STIG | DISA Red Hat Enterprise Linux 6 STIG v2r2 | Unix | |
| DISA_STIG_SLES_12_v3r5.audit from DISA SUSE Linux Enterprise Server 12 v3r5 STIG | DISA SLES 12 STIG v3r5 | Unix | |
| DISA_STIG_SUSE_Linux_Enterprise_Micro_SLEM_5_v1r4.audit from DISA SUSE Linux Enterprise Micro SLEM 5 STIG v1r4 | DISA SUSE Linux Enterprise Micro SLEM 5 STIG v1r4 | Unix | |
| DISA_STIG_SUSE_Linux_Enterprise_Server_15_v2r6.audit from DISA SUSE Linux Enterprise Server 15 STIG v2r6 | DISA SUSE Linux Enterprise Server 15 STIG v2r6 | Unix | |
| DISA_STIG_SUSE_Linux_Enterprise_Server_15_v2r8.audit from DISA SUSE Linux Enterprise Server 15 STIG v2r8 | DISA SUSE Linux Enterprise Server 15 STIG v2r8 | Unix | |
| DISA_STIG_VMware_vSphere_6.7_Photon_OS_v1r6.audit from DISA VMware vSphere 6.7 Photon OS v1r6 STIG | DISA STIG VMware vSphere 6.7 Photon OS v1r6 | Unix | |
| DISA_STIG_Windows_Firewall_v2r2.audit from DISA Microsoft Windows Defender Firewall with Advanced Security v2r2 STIG | DISA Microsoft Windows Defender Firewall with Advanced Security STIG v2r2 | Windows | |
| EP11-00-002300 - The EDB Postgres Advanced Server must by default shut down upon audit failure, to include the unavailability of space for more audit log records; or must be configurable to shut down upon audit failure. | EDB PostgreSQL Advanced Server v11 Windows OS Audit v2r4 | Windows | AUDIT AND ACCOUNTABILITY |
| OL6-00-000010 - The Oracle Linux operating system must be a vendor-supported release. | DISA STIG Oracle Linux 6 v2r7 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-060010 - The operating system must use mechanisms for authentication to a cryptographic module meeting the requirements of applicable federal laws, Executive orders, directives, policies, regulations, standards, and guidance for such authentication. | DISA Solaris 11 SPARC STIG v3r6 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SOL-11.1-060010 - The operating system must use mechanisms for authentication to a cryptographic module meeting the requirements of applicable federal laws, Executive orders, directives, policies, regulations, standards, and guidance for such authentication. | DISA Solaris 11 X86 STIG v3r6 | Unix | IDENTIFICATION AND AUTHENTICATION |