| 1.9 VCEM-80-000057 | CIS VMware vSphere 8.0 vCenter Appliance ESX Agent Manager EAM STIG v1.0.0 CAT II | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.9 VCLU-80-000057 | CIS VMware vSphere 8.0 vCenter Appliance Lookup Service STIG v1.0.0 CAT II | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.9 VCPF-80-000057 | CIS VMware vSphere 8.0 vCenter Appliance Perfcharts STIG v1.0.0 CAT II | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.9 VCST-80-000057 | CIS VMware vSphere 8.0 vCenter Appliance Secure Token Service STS STIG v1.0.0 CAT II | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.9 VCUI-80-000057 | CIS VMware vSphere 8.0 vCenter Appliance User Interface UI STIG v1.0.0 CAT II | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.25 VCSA-80-000195 | CIS VMware vSphere 8.0 vCenter STIG v1.0.0 CAT II | VMware | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.31 IIST-SI-000241 | CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT II | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.33 SQLI-22-008700 | CIS Microsoft SQL Server 2022 Instance STIG v1.0.0 CAT I Windows | Windows | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.116 APPL-14-003001 | CIS Apple macOS 14 Sonoma STIG v1.0.0 CAT II | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| ALMA-09-041270 - AlmaLinux OS 9 must only allow the use of DOD PKI-established certificate authorities for authentication in the establishment of protected sessions to the operating system. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| APPL-14-003001 - The macOS system must issue or obtain public key certificates from an approved service provider. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CASA-VN-000610 - The Cisco ASA remote access VPN server must be configured to generate unique session identifiers using a FIPS-validated Random Number Generator (RNG) based on the Deterministic Random Bit Generators (DRBG) algorithm. | DISA STIG Cisco ASA VPN v2r2 | Cisco | SYSTEM AND COMMUNICATIONS PROTECTION |
| CD12-00-010300 - PostgreSQL must only accept end entity certificates issued by DoD PKI or DoD-approved PKI Certification Authorities (CAs) for the establishment of all encrypted sessions. | DISA STIG Crunchy Data PostgreSQL DB v3r1 | PostgreSQLDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| CD12-00-011400 - PostgreSQL must maintain the authenticity of communications sessions by guarding against man-in-the-middle attacks that guess at Session ID values. | DISA STIG Crunchy Data PostgreSQL DB v3r1 | PostgreSQLDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| CD16-00-004700 - PostgreSQL must invalidate session identifiers upon user logout or other session termination. | DISA Crunchy Data Postgres 16 STIG v1r3 PostgreSQLDB | PostgreSQLDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| CD16-00-004900 - PostgreSQL must maintain the authenticity of communications sessions by guarding against man-in-the-middle attacks that guess at Session ID values. | DISA Crunchy Data Postgres 16 STIG v1r3 PostgreSQLDB | PostgreSQLDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| CD16-00-008400 - PostgreSQL must only accept end entity certificates issued by DOD PKI or DOD-approved PKI Certification Authorities (CAs) for the establishment of all encrypted sessions. | DISA Crunchy Data Postgres 16 STIG v1r3 PostgreSQLDB | PostgreSQLDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-001510 - Kubernetes etcd must have the SSL Certificate Authority set. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| EPAS-00-005200 - The EDB Postgres Advanced Server must invalidate session identifiers upon user logout or other session termination. | EnterpriseDB PostgreSQL Advanced Server DB v2r1 | PostgreSQLDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| EPAS-00-009100 - The EDB Postgres Advanced Server must only accept end entity certificates issued by DOD PKI or DOD-approved PKI Certification Authorities (CAs) for the establishment of all encrypted sessions. | EnterpriseDB PostgreSQL Advanced Server OS Linux v2r1 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| F5BI-AP-000235 - The F5 BIG-IP appliance APM Access Policies that grant access to web application resources must allow only client certificates that have the User Persona Name (UPN) value in the User Persona Client Certificates. | DISA F5 BIG-IP Access Policy Manager STIG v2r4 | F5 | SYSTEM AND COMMUNICATIONS PROTECTION |
| F5BI-AP-000236 - The F5 BIG-IP appliance must be configured to limit authenticated client sessions to initial session source IP. | DISA F5 BIG-IP Access Policy Manager STIG v2r4 | F5 | SYSTEM AND COMMUNICATIONS PROTECTION |
| F5BI-AP-000241 - When the Access Profile Type is LTM+APM and it is not using any connectivity resources (such as Network Access, Portal Access, etc.) in the VPE, the F5 BIG-IP appliance must be configured to enable the HTTP Only flag. | DISA F5 BIG-IP Access Policy Manager STIG v2r4 | F5 | SYSTEM AND COMMUNICATIONS PROTECTION |
| F5BI-AP-000242 - The F5 BIG-IP appliance must be configured to enable the 'Secure' cookie flag - Secure cookie flag. | DISA F5 BIG-IP Access Policy Manager STIG v2r4 | F5 | SYSTEM AND COMMUNICATIONS PROTECTION |
| F5BI-AP-000243 - The F5 BIG-IP appliance must be configured to disable the 'Persistent' cookie flag - Persistent cookie flag. | DISA F5 BIG-IP Access Policy Manager STIG v2r4 | F5 | SYSTEM AND COMMUNICATIONS PROTECTION |
| F5BI-AP-300151 - When the Access Profile Type is LTM+APM and it is not using any connectivity resources (such as Network Access, Portal Access, etc.) in the VPE, the F5 BIG-IP appliance must be configured to enable the HTTP Only flag. | DISA F5 BIG-IP TMOS ALG STIG v1r3 | F5 | SYSTEM AND COMMUNICATIONS PROTECTION |
| F5BI-AP-300153 - The F5 BIG-IP appliance must be configured to disable the persistent cookie flag. | DISA F5 BIG-IP TMOS ALG STIG v1r3 | F5 | SYSTEM AND COMMUNICATIONS PROTECTION |
| FGFW-ND-000280 - The FortiGate device must generate unique session identifiers using a FIPS 140-2-approved random number generator. | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | SYSTEM AND COMMUNICATIONS PROTECTION |
| MADB-10-004700 - MariaDB must invalidate session identifiers upon user logout or other session termination. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| MADB-10-004900 - MariaDB must maintain the authenticity of communications sessions by guarding against man-in-the-middle attacks that guess at Session ID values. | DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB | MySQLDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| MD7X-00-004900 - MongoDB must maintain the authenticity of communications sessions by guarding against man-in-the-middle attacks that guess at Session ID values. | DISA MongoDB Enterprise Advanced 7.x STIG v1r2 Unix | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| MD7X-00-008400 - MongoDB must only accept end entity certificates issued by DOD PKI or DOD-approved PKI Certification Authorities (CAs) for the establishment of all encrypted sessions. | DISA MongoDB Enterprise Advanced 7.x STIG v1r2 Unix | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| MD7X-00-008400 MongoDB must only accept end entity certificates issued by DOD PKI or DOD-approved PKI Certification Authorities (CAs) for the establishment of all encrypted sessions. | DISA MongoDB Enterprise Advanced 7.x STIG v1r1 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| MD8X-00-008000 - MongoDB must only accept end entity certificates issued by DOD PKI or DOD-approved PKI Certification Authorities (CAs) for the establishment of all encrypted sessions. | DISA MongoDB Enterprise Advanced 8.x STIG v1r1 Unix | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| MYS8-00-011900 - The MySQL Database Server 8.0 must only accept end entity certificates issued by DoD PKI or DoD-approved PKI Certification Authorities (CAs) for the establishment of all encrypted sessions. | DISA Oracle MySQL 8.0 v2r2 OS Linux | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| OL09-00-900140 - OL 9 must only allow the use of DOD PKI-established certificate authorities for authentication in the establishment of protected sessions to OL 9. | DISA Oracle Linux 9 STIG v1r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| SYMP-AG-000500 - If reverse proxy is used for validating and restricting certs from external entities, and this function is required by the SSP, Symantec ProxySG providing user authentication intermediary services using PKI-based user authentication must only accept end entity certificates issued by DoD PKI or DoD-approved PKI Certification Authorities (CAs) for the establishment of protected sessions. | DISA Symantec ProxySG Benchmark ALG v1r3 | BlueCoat | SYSTEM AND COMMUNICATIONS PROTECTION |
| UBTU-20-010443 - The Ubuntu operating system must use DoD PKI-established certificate authorities for verification of the establishment of protected sessions. | DISA Canonical Ubuntu 20.04 LTS STIG v2r4 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| UBTU-22-631010 - Ubuntu 22.04 LTS must use DOD PKI-established certificate authorities for verification of the establishment of protected sessions. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| UBTU-24-600060 - Ubuntu 24.04 LTS must use DOD PKI-established certificate authorities (CAs) for verification of the establishment of protected sessions. | DISA Canonical Ubuntu 24.04 LTS STIG v1r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| VCEM-80-000057 - The vCenter ESX Agent Manager service must be configured to limit data exposure between applications. | DISA VMware vSphere 8.0 vCenter Appliance ESX Agent Manager EAM STIG v2r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| VCLU-80-000057 - The vCenter Lookup service must be configured to limit data exposure between applications. | DISA VMware vSphere 8.0 vCenter Appliance Lookup Service STIG v2r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| VCPF-80-000057 - The vCenter Perfcharts service must be configured to limit data exposure between applications. | DISA VMware vSphere 8.0 vCenter Appliance Perfcharts STIG v2r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| VCSA-70-000195 - The vCenter Server Machine Secure Sockets Layer (SSL) certificate must be issued by a DOD certificate authority. | DISA STIG VMware vSphere 7.0 vCenter v1r3 | VMware | SYSTEM AND COMMUNICATIONS PROTECTION |
| VCSA-80-000195 - The vCenter Server Machine Secure Sockets Layer (SSL) certificate must be issued by a DOD certificate authority. | DISA VMware vSphere 8.0 vCenter STIG v2r4 VMware | VMware | SYSTEM AND COMMUNICATIONS PROTECTION |
| VCST-80-000057 - The vCenter STS service must be configured to limit data exposure between applications. | DISA VMware vSphere 8.0 vCenter Appliance Secure Token Service STS STIG v2r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| VCUI-67-000032 - vSphere UI must restrict its cookie path. | DISA STIG VMware vSphere 6.7 UI Tomcat v1r3 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| VCUI-70-000018 - vSphere UI must restrict its cookie path. | DISA STIG VMware vSphere 7.0 vCA UI v1r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| VCUI-80-000057 - The vCenter UI service must be configured to limit data exposure between applications. | DISA VMware vSphere 8.0 vCenter Appliance User Interface UI STIG v2r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| VCUI-80-000057 The vCenter UI service must be configured to limit data exposure between applications. | DISA VMware vSphere 8.0 vCenter Appliance User Interface (UI) STIG v2r1 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |