| 1.10 SQLI-22-004400 | CIS Microsoft SQL Server 2022 Instance STIG v1.0.0 CAT II MS_SQLDB | MS_SQLDB | AUDIT AND ACCOUNTABILITY |
| 1.193 WN19-MS-000030 | CIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT II | Windows | CONFIGURATION MANAGEMENT |
| 1.193 WN22-MS-000030 | CIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT II | Windows | CONFIGURATION MANAGEMENT |
| 1.194 WN16-MS-000120 | CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT I | Windows | CONFIGURATION MANAGEMENT |
| 1.204 WN19-MS-000140 | CIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT I | Windows | CONFIGURATION MANAGEMENT |
| 1.204 WN22-MS-000140 | CIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT I | Windows | CONFIGURATION MANAGEMENT |
| 2.3.9.2 Ensure 'Microsoft network server: Digitally sign communications (always)' is set to 'Enabled' | CIS Microsoft Windows 8.1 v2.4.1 L1 | Windows | CONFIGURATION MANAGEMENT |
| 2.5 Ensure that the User-ID Agent has minimal permissions if User-ID is enabled | CIS Palo Alto Firewall 8 Benchmark L1 v1.0.0 | Palo_Alto | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| 5.1 Set 'Turn off Encryption Support' to 'Use TLS 1.1 and TLS 1.2' | CIS IE 11 v1.0.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.244 - Users must be notified if the logon server was inaccessible and cached credentials were used. | DISA Windows Vista STIG v6r41 | Windows | CONFIGURATION MANAGEMENT |
| Audit Audit Policy Change: MSFT Windows Server 2025 v2602 - Member Server | MSCT Windows Server 2025 MS v2602 v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
| Audit Authentication Policy Change: MSFT Windows Server 2025 v2602 - Member Server | MSCT Windows Server 2025 MS v2602 v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
| Audit Authorization Policy Change: MSFT Windows Server 2025 v2602 - Member Server | MSCT Windows Server 2025 MS v2602 v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
| Audit Detailed File Share: MSFT Windows Server 2025 v2602 - Member Server | MSCT Windows Server 2025 MS v2602 v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
| Audit Other System Events: MSFT Windows Server 2025 v2602 - Member Server | MSCT Windows Server 2025 MS v2602 v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
| Audit PNP Activity: MSFT Windows Server 2025 v2602 - Member Server | MSCT Windows Server 2025 MS v2602 v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
| Audit Process Creation: MSFT Windows Server 2025 v2602 - Member Server | MSCT Windows Server 2025 MS v2602 v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
| Audit Removable Storage: MSFT Windows Server 2025 v2602 - Member Server | MSCT Windows Server 2025 MS v2602 v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
| Audit Security Group Management: MSFT Windows Server 2025 v2602 - Member Server | MSCT Windows Server 2025 MS v2602 v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
| Audit Security State Change: MSFT Windows Server 2025 v2602 - Member Server | MSCT Windows Server 2025 MS v2602 v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
| Audit Security System Extension: MSFT Windows Server 2025 v2602 - Member Server | MSCT Windows Server 2025 MS v2602 v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
| Audit Sensitive Privilege Use: MSFT Windows Server 2025 v2602 - Member Server | MSCT Windows Server 2025 MS v2602 v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
| Audit System Integrity: MSFT Windows Server 2025 v2602 - Member Server | MSCT Windows Server 2025 MS v2602 v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
| Audit User Account Management: MSFT Windows Server 2025 v2602 - Member Server | MSCT Windows Server 2025 MS v2602 v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
| IIST-SI-000206 - Both the log file and Event Tracing for Windows (ETW) for each IIS 10.0 website must be enabled. | DISA IIS 10.0 Site v2r14 | Windows | AUDIT AND ACCOUNTABILITY |
| IIST-SI-000206 - Both the log file and Event Tracing for Windows (ETW) for each IIS 10.0 website must be enabled. | DISA Microsoft IIS 10.0 Site STIG v2r16 | Windows | AUDIT AND ACCOUNTABILITY |
| IISW-SI-000206 - Both the log file and Event Tracing for Windows (ETW) for each IIS 8.5 website must be enabled. | DISA IIS 8.5 Site v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| SQL2-00-002200 - SQL Server must enforce non-DAC policies over users and resources where the policy rule set for each policy specifies access control information (i.e., position, nationality, age, project, time of day) - 'server permissions' | DISA STIG SQL Server 2012 DB Instance Security v1r20 | MS_SQLDB | ACCESS CONTROL |
| SQL2-00-008500 - SQL Server must enforce DAC policy allowing users to specify and control sharing by named individuals, groups of individuals, or by both; limiting propagation of access rights; and including or excluding access to the granularity of a single user - 'server permissions' | DISA STIG SQL Server 2012 DB Instance Security v1r20 | MS_SQLDB | ACCESS CONTROL |
| SQL2-00-008500 - SQL Server must enforce DAC policy allowing users to specify and control sharing by named individuals, groups of individuals, or by both; limiting propagation of access rights; and including or excluding access to the granularity of a single user - 'user defined roles' | DISA STIG SQL Server 2012 DB Instance Security v1r20 | MS_SQLDB | ACCESS CONTROL |
| SQL6-D0-004400 - SQL Server must allow only the ISSM (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited. | DISA MS SQL Server 2016 Instance STIG v3r6 MS_SQLDB | MS_SQLDB | AUDIT AND ACCOUNTABILITY |
| VCTR-67-000072 - The vCenter Server services must be ran using a service account instead of a built-in Windows account. | DISA STIG VMware vSphere 6.7 vCenter v1r4 | VMware | CONFIGURATION MANAGEMENT |
| VCWN-06-000022 - The vCenter Server services must be ran using a service account instead of a built-in Windows account. | DISA VMware vSphere vCenter Server Version 6 STIG v1r4 | VMware | CONFIGURATION MANAGEMENT |
| VCWN-65-000022 - The vCenter Server for Windows services must be ran using a service account instead of a built-in Windows account. | DISA VMware vSphere 6.5 vCenter Server for Windows STIG v2r3 | VMware | CONFIGURATION MANAGEMENT |
| WDNS-AC-000001 - The Windows 2012 DNS Server must restrict incoming dynamic update requests to known clients. | DISA Microsoft Windows 2012 Server Domain Name System STIG v2r7 | Windows | ACCESS CONTROL |
| WDNS-SC-000012 - Trust anchors must be exported from authoritative Windows 2012 DNS Servers and distributed to validating Windows 2012 DNS Servers. | DISA Microsoft Windows 2012 Server Domain Name System STIG v2r7 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WDNS-SC-000020 - The Windows 2012 DNS Server must protect the authenticity of dynamic updates via transaction signing. | DISA Microsoft Windows 2012 Server Domain Name System STIG v2r7 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WDNS-SC-000021 - The Windows 2012 DNS Server must protect the authenticity of query responses via DNSSEC. | DISA Microsoft Windows 2012 Server Domain Name System STIG v2r7 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WDNS-SC-000024 - The Windows 2012 DNS Server must protect secret/private cryptographic keys while at rest. | DISA Microsoft Windows 2012 Server Domain Name System STIG v2r7 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WDNS-SC-000029 - The Windows 2012 DNS Server must maintain the integrity of information during preparation for transmission. | DISA Microsoft Windows 2012 Server Domain Name System STIG v2r7 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN12-00-000160 - The Server Message Block (SMB) v1 protocol must be disabled on Windows 2012 R2. | DISA Windows Server 2012 and 2012 R2 DC STIG v3r7 | Windows | CONFIGURATION MANAGEMENT |
| WN12-00-000160 - The Server Message Block (SMB) v1 protocol must be disabled on Windows 2012 R2. | DISA Windows Server 2012 and 2012 R2 MS STIG v3r7 | Windows | CONFIGURATION MANAGEMENT |
| WN12-00-000190 - Orphaned security identifiers (SIDs) must be removed from user rights on Windows 2012 / 2012 R2. | DISA Windows Server 2012 and 2012 R2 DC STIG v3r7 | Windows | CONFIGURATION MANAGEMENT |
| WN12-00-000190 - Orphaned security identifiers (SIDs) must be removed from user rights on Windows 2012 / 2012 R2. | DISA Windows Server 2012 and 2012 R2 MS STIG v3r7 | Windows | CONFIGURATION MANAGEMENT |
| WN12-CC-000142 - The Windows Explorer Preview pane must be disabled for Windows 2012 | DISA Windows Server 2012 and 2012 R2 MS STIG v3r7 | Windows | CONFIGURATION MANAGEMENT |
| WN12-CC-000142 - The Windows Explorer Preview pane must be disabled for Windows 2012 | DISA Windows Server 2012 and 2012 R2 DC STIG v3r7 | Windows | CONFIGURATION MANAGEMENT |
| WN12-CC-000145 - Automatically signing in the last interactive user after a system-initiated restart must be disabled (Windows 2012 R2). | DISA Windows Server 2012 and 2012 R2 MS STIG v3r7 | Windows | CONFIGURATION MANAGEMENT |
| WN12-CC-000145 - Automatically signing in the last interactive user after a system-initiated restart must be disabled (Windows 2012 R2). | DISA Windows Server 2012 and 2012 R2 DC STIG v3r7 | Windows | CONFIGURATION MANAGEMENT |
| WN12-GE-000056 - Windows 2012 / 2012 R2 must automatically remove or disable temporary user accounts after 72 hours. | DISA Windows Server 2012 and 2012 R2 DC STIG v3r7 | Windows | ACCESS CONTROL |
| WN12-GE-000056 - Windows 2012 / 2012 R2 must automatically remove or disable temporary user accounts after 72 hours. | DISA Windows Server 2012 and 2012 R2 MS STIG v3r7 | Windows | ACCESS CONTROL |