| 1.2 O19C-00-000200 | CIS Oracle Database 19c STIG v1.1.0 CAT II Unix | Unix | ACCESS CONTROL |
| 1.10.2 (L2) Ensure 'Configure extension management settings' is set to 'Enabled: { '*': {'installation_mode': 'blocked' }}' | CIS Microsoft Edge v4.0.0 L2 | Windows | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.10.2 (L2) Ensure 'Configure extension management settings' is set to 'Enabled: { '*': {'installation_mode': 'blocked' }}' | CIS Microsoft Intune for Edge v1.0.0 L2 | Windows | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.52 MADB-10-006200 | CIS MariaDB Enterprise 10.x STIG v1.1.0 CAT II MySQLDB | MySQLDB | ACCESS CONTROL |
| 1.53 MADB-10-006300 | CIS MariaDB Enterprise 10.x STIG v1.1.0 CAT II MySQLDB | MySQLDB | ACCESS CONTROL |
| 2.1.3 Ensure Organizations management account is not used for workloads | CIS Amazon Web Services Foundations v7.0.0 L2 | amazon_aws | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.4.4 (L2) Ensure 'Extension management settings' is set to 'Enabled: { '*': {'installation_mode': 'blocked' }}' | CIS Google Chrome Group Policy v1.1.0 L2 | Windows | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.5 Only enable TFTP if absolutely necessary - Uncomment service tftp in /etc/inet/inetd.conf | CIS Solaris 9 v1.3 | Unix | CONFIGURATION MANAGEMENT |
| 4.1 Ensure yearly rekeying is enabled for a Snowflake account | CIS Snowflake Foundations v2.0.0 L2 | Snowflake | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.1.3 Minimize wildcard use in Roles and ClusterRoles | CIS Google Kubernetes Engine GKE Autopilot v2.0.0 L1 | GCP | IDENTIFICATION AND AUTHENTICATION |
| 6.2.3.8 Ensure events that modify the system's network environment are collected | CIS Debian Linux 13 v1.1.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| 6.2.3.8 Ensure events that modify the system's network environment are collected | CIS Debian Linux 13 v1.1.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| 6.2.3.8 Ensure events that modify the system's network environment are collected | CIS Ubuntu Linux 26.04 LTS v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| 6.2.3.8 Ensure events that modify the system's network environment are collected | CIS Ubuntu Linux 26.04 LTS v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| 6.2.3.20 Ensure session initiation information is collected | CIS SUSE Linux Enterprise 16 v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.22 Ensure session initiation information is collected | CIS Debian Linux 13 v1.1.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.22 Ensure session initiation information is collected | CIS Ubuntu Linux 26.04 LTS v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.24 Ensure events that modify the system's Mandatory Access Controls are collected | CIS SUSE Linux Enterprise 16 v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| 6.2.3.24 Ensure unlink file deletion events by users are collected | CIS Debian Linux 13 v1.1.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.24 Ensure unlink file deletion events by users are collected | CIS Ubuntu Linux 26.04 LTS v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.24 Ensure unlink file deletion events by users are collected | CIS Debian Linux 13 v1.1.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.25 Ensure rename file deletion events by users are collected | CIS Ubuntu Linux 26.04 LTS v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.25 Ensure rename file deletion events by users are collected | CIS Debian Linux 13 v1.1.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.27 Ensure successful and unsuccessful attempts to use the chcon command are collected | CIS Debian Linux 13 v1.1.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.27 Ensure successful and unsuccessful attempts to use the chcon command are collected | CIS Debian Linux 13 v1.1.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.27 Ensure successful and unsuccessful attempts to use the chcon command are collected | CIS Ubuntu Linux 26.04 LTS v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.2.3.32 Ensure kernel "init_module" and "finit_module" loading unloading and modification is collected | CIS Ubuntu Linux 26.04 LTS v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.3.3.6 Ensure events that modify /etc/issue and /etc/issue.net are collected | CIS Rocky Linux 10 v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| 6.3.3.7 Ensure events that modify /etc/hosts and /etc/hostname are collected | CIS Oracle Linux 10 v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| 6.3.3.14 Ensure events that modify /etc/shadow and /etc/gshadow are collected | CIS Rocky Linux 10 v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.3.3.17 Ensure events that modify /etc/pam.conf and /etc/pam.d/ information are collected | CIS Rocky Linux 10 v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.3.3.22 Ensure session initiation information is collected | CIS Rocky Linux 10 v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.3.3.22 Ensure session initiation information is collected | CIS AlmaLinux OS 10 v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.3.3.22 Ensure session initiation information is collected | CIS Oracle Linux 10 v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.3.3.22 Ensure session initiation information is collected | CIS Red Hat Enterprise Linux 10 v1.0.1 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.3.3.22 Ensure session initiation information is collected | CIS AlmaLinux OS 10 v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.3.3.24 Ensure unlink file deletion events by users are collected | CIS AlmaLinux OS 10 v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 6.3.3.26 Ensure events that modify the system's Mandatory Access Controls are collected | CIS AlmaLinux OS 10 v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| 6.3.3.30 Ensure successful and unsuccessful attempts to use the usermod command are collected | CIS Rocky Linux 10 v1.0.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
| 6.3.3.30 Ensure successful and unsuccessful attempts to use the usermod command are collected | CIS AlmaLinux OS 10 v1.0.0 L2 Server | Unix | AUDIT AND ACCOUNTABILITY |
| 7.1 Ensure HSTS Header is set | CIS IIS 8.0 v1.5.1 Level 2 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 7.1 Ensure HSTS Header is set | CIS IIS 7 L2 v1.8.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| ALMA-09-002770 - AlmaLinux OS 9 must log SSH connection attempts and failures to the server. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | ACCESS CONTROL |
| BIND-9X-001010 - A BIND 9.x primary name server must limit the number of concurrent zone transfers between authorized secondary name servers. | DISA BIND 9.x STIG v3r3 | Unix | ACCESS CONTROL |
| BIND-9X-001020 - The BIND 9.x secondary name server must limit the number of zones requested from a single primary name server. | DISA BIND 9.x STIG v3r3 | Unix | ACCESS CONTROL |
| BIND-9X-001030 - The BIND 9.x secondary name server must limit the total number of zones the name server can request at any one time. | DISA BIND 9.x STIG v3r3 | Unix | ACCESS CONTROL |
| BIND-9X-001040 - The BIND 9.x server implementation must limit the number of concurrent session client connections. | DISA BIND 9.x STIG v3r3 | Unix | ACCESS CONTROL |
| BIND-9X-002480 - The BIND 9.x server implementation must limit the number of allowed dynamic update clients. | DISA BIND 9.x STIG v3r3 | Unix | ACCESS CONTROL |
| MYS8-00-005100 - If passwords are used for authentication, the MySQL Database Server 8.0 must store only hashed, salted representations of passwords. | DISA Oracle MySQL 8.0 v2r2 DB | MySQLDB | IDENTIFICATION AND AUTHENTICATION |
| Review the list of Database Backups | Tenable Best Practices RackSpace v2.0.0 | Rackspace | CONTINGENCY PLANNING |