| DTBI032-IE11 - Accessing data sources across domains must be disallowed (Internet zone). | DISA STIG IE 11 v2r7 | Windows | ACCESS CONTROL |
| DTBI038-IE11 - Launching programs and files in IFRAME must be disallowed (Internet zone). | DISA STIG IE 11 v2r7 | Windows | CONFIGURATION MANAGEMENT |
| DTBI061-IE11 - Java permissions must be configured with High Safety (Intranet zone). | DISA STIG IE 11 v2r7 | Windows | CONFIGURATION MANAGEMENT |
| DTBI114-IE11 - The Initialize and script ActiveX controls not marked as safe property must be disallowed (Restricted Sites zone). | DISA STIG IE 11 v2r7 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| DTBI115-IE11 - ActiveX controls and plug-ins must be disallowed (Restricted Sites zone). | DISA STIG IE 11 v2r7 | Windows | CONFIGURATION MANAGEMENT |
| DTBI318-IE11 - Internet Explorer must be set to disallow users to add/delete sites. | DISA STIG IE 11 v2r7 | Windows | CONFIGURATION MANAGEMENT |
| DTBI390-IE11 - Script-initiated windows without size or position constraints must be disallowed (Restricted Sites zone). | DISA STIG IE 11 v2r7 | Windows | CONFIGURATION MANAGEMENT |
| DTBI426-IE11 - Anti-Malware programs against ActiveX controls must be run for the Local Machine zone. | DISA STIG IE 11 v2r7 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| DTBI435-IE11 - Java permissions must be disallowed (Locked Down Intranet zone). | DISA STIG IE 11 v2r7 | Windows | CONFIGURATION MANAGEMENT |
| DTBI485-IE11 - Protected Mode must be enforced (Internet zone). | DISA STIG IE 11 v2r7 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| DTBI490-IE11 - Protected Mode must be enforced (Restricted Sites zone). | DISA STIG IE 11 v2r7 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| DTBI580-IE11 - Automatic prompting for file downloads must be disallowed (Restricted Sites zone). | DISA STIG IE 11 v2r7 | Windows | CONFIGURATION MANAGEMENT |
| DTBI590-IE11 - Internet Explorer Processes for MIME handling must be enforced. (Reserved) | DISA STIG IE 11 v2r7 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| DTBI600-IE11 - Internet Explorer Processes for MK protocol must be enforced (Explorer). | DISA STIG IE 11 v2r7 | Windows | CONFIGURATION MANAGEMENT |
| DTBI614-IE11 - Internet Explorer Processes for Zone Elevation must be enforced (iexplore). | DISA STIG IE 11 v2r7 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| DTBI635-IE11 - Internet Explorer Processes for Restrict File Download must be enforced (Explorer). | DISA STIG IE 11 v2r7 | Windows | CONFIGURATION MANAGEMENT |
| DTBI760-IE11 - Browser must retain history on exit. | DISA STIG IE 11 v2r7 | Windows | AUDIT AND ACCOUNTABILITY |
| DTBI770-IE11 - Deleting websites that the user has visited must be disallowed. | DISA STIG IE 11 v2r7 | Windows | AUDIT AND ACCOUNTABILITY |
| DTBI835-IE11 - Internet Explorer Processes for Notification Bars must be enforced (iexplore). | DISA STIG IE 11 v2r7 | Windows | CONFIGURATION MANAGEMENT |
| DTBI930-IE11 - .NET Framework-reliant components signed with Authenticode must be disallowed to run (Internet zone). | DISA STIG IE 11 v2r7 | Windows | CONFIGURATION MANAGEMENT |
| DTBI1005-IE11 - Dragging of content from different domains across windows must be disallowed (Restricted Sites zone). | DISA STIG IE 11 v2r7 | Windows | ACCESS CONTROL |
| DTBI1010-IE11 - Internet Explorer Processes Restrict ActiveX Install must be enforced (Explorer). | DISA STIG IE 11 v2r7 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| DTBI1060-IE11 - Prevent bypassing SmartScreen Filter warnings must be enabled. | DISA STIG IE 11 v2r7 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| DTBI1070-IE11 - Prevent per-user installation of ActiveX controls must be enabled. | DISA STIG IE 11 v2r7 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| DTBI1115-IE11 - Use of the Tabular Data Control (TDC) ActiveX control must be disabled for the Internet Zone. | DISA STIG IE 11 v2r7 | Windows | CONFIGURATION MANAGEMENT |
| DTBI1120-IE11 - Use of the Tabular Data Control (TDC) ActiveX control must be disabled for the Restricted Sites Zone. | DISA STIG IE 11 v2r7 | Windows | CONFIGURATION MANAGEMENT |
| DTBI1125-IE11 - VBScript must not be allowed to run in Internet Explorer (Internet zone) - Internet zone | DISA STIG IE 11 v2r7 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| DTBI1130-IE11 - VBScript must not be allowed to run in Internet Explorer (Restricted Sites zone) - Restricted Sites zone | DISA STIG IE 11 v2r7 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| FNFG-FW-000015 - The FortiGate firewall must use organization-defined filtering rules that apply to the monitoring of remote access traffic for the traffic from the VPN access points. | DISA Fortigate Firewall STIG v1r4 | FortiGate | ACCESS CONTROL |
| FNFG-FW-000020 - The FortiGate firewall must generate traffic log entries containing information to establish what type of events occurred. | DISA Fortigate Firewall STIG v1r4 | FortiGate | AUDIT AND ACCOUNTABILITY |
| FNFG-FW-000035 - The FortiGate firewall must generate traffic log entries containing information to establish the source of the events, such as the source IP address at a minimum. | DISA Fortigate Firewall STIG v1r4 | FortiGate | AUDIT AND ACCOUNTABILITY |
| FNFG-FW-000040 - The FortiGate firewall must generate traffic log entries containing information to establish the outcome of the events, such as, at a minimum, the success or failure of the application of the firewall rule. | DISA Fortigate Firewall STIG v1r4 | FortiGate | AUDIT AND ACCOUNTABILITY |
| FNFG-FW-000045 - In the event that communication with the central audit server is lost, the FortiGate firewall must continue to queue traffic log records locally. | DISA Fortigate Firewall STIG v1r4 | FortiGate | AUDIT AND ACCOUNTABILITY |
| FNFG-FW-000055 - The FortiGate firewall must protect the traffic log from unauthorized modification of local log records. | DISA Fortigate Firewall STIG v1r4 | FortiGate | AUDIT AND ACCOUNTABILITY |
| FNFG-FW-000070 - The FortiGate firewall must block outbound traffic containing denial-of-service (DoS) attacks to protect against the use of internal information systems to launch any DoS attacks against other networks or endpoints. | DISA Fortigate Firewall STIG v1r4 | FortiGate | SYSTEM AND COMMUNICATIONS PROTECTION |
| FNFG-FW-000100 - The FortiGate firewall must send traffic log entries to a central audit server for management and configuration of the traffic log entries. | DISA Fortigate Firewall STIG v1r4 | FortiGate | AUDIT AND ACCOUNTABILITY |
| SLES-12-010020 - The SUSE operating system must display the Standard Mandatory DoD Notice and Consent Banner until users acknowledge the usage conditions and take explicit actions to log on for further access to the local graphical user interface. | DISA SLES 12 STIG v3r5 | Unix | ACCESS CONTROL |
| SLES-12-010050 - The SUSE operating system must display the approved Standard Mandatory DoD Notice before granting local or remote access to the system via a graphical user logon. | DISA SLES 12 STIG v3r5 | Unix | ACCESS CONTROL |
| SLES-12-010070 - The SUSE operating system must utilize vlock to allow for session locking. | DISA SLES 12 STIG v3r5 | Unix | ACCESS CONTROL |
| SLES-12-010100 - The SUSE operating system must conceal, via the session lock, information previously visible on the display with a publicly viewable image in the graphical user interface. | DISA SLES 12 STIG v3r5 | Unix | ACCESS CONTROL |
| SLES-12-010110 - The SUSE operating system must reauthenticate users when changing authenticators, roles, or escalating privileges. | DISA SLES 12 STIG v3r5 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLES-12-010111 - The SUSE operating system must restrict privilege elevation to authorized personnel. | DISA SLES 12 STIG v3r5 | Unix | CONFIGURATION MANAGEMENT |
| SLES-12-010113 - The SUSE operating system must require re-authentication when using the 'sudo' command - sudo command. | DISA SLES 12 STIG v3r5 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLES-12-010114 - The SUSE operating system must not be configured to bypass password requirements for privilege escalation. | DISA SLES 12 STIG v3r5 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLES-12-010120 - The SUSE operating system must limit the number of concurrent sessions to 10 for all accounts and/or account types. | DISA SLES 12 STIG v3r5 | Unix | ACCESS CONTROL |
| SLES-12-010140 - The SUSE operating system must enforce a delay of at least four (4) seconds between logon prompts following a failed logon attempt. | DISA SLES 12 STIG v3r5 | Unix | CONFIGURATION MANAGEMENT |
| SLES-12-010220 - The SUSE operating system must employ FIPS 140-2-approved cryptographic hashing algorithms for all stored passwords. | DISA SLES 12 STIG v3r5 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLES-12-010221 - The SUSE operating system must not have accounts configured with blank or null passwords. | DISA SLES 12 STIG v3r5 | Unix | CONFIGURATION MANAGEMENT |
| SLES-12-010280 - The SUSE operating system must be configured to create or update passwords with a maximum lifetime of 60 days. | DISA SLES 12 STIG v3r5 | Unix | IDENTIFICATION AND AUTHENTICATION |
| WPAW-00-000400 - Administrative accounts of all high-value IT resources must be assigned to a specific administrative tier in Active Directory to separate highly privileged administrative accounts from less privileged administrative accounts. | DISA Microsoft Windows PAW STIG v3r2 | Windows | ACCESS CONTROL, CONFIGURATION MANAGEMENT |