| 1.1 CISC-L2-000020 | CIS Cisco NX OS Switch L2S STIG v1.0.0 CAT I | Cisco | IDENTIFICATION AND AUTHENTICATION |
| 1.1.10 - /etc/security/user - 'maxexpired <= 2' | CIS AIX 5.3/6.1 L1 v1.1.0 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 1.1.26 Ensure all world-writable directories are group-owned. | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| 1.5 CISC-L2-000080 | CIS Cisco NX OS Switch L2S STIG v1.0.0 CAT II | Cisco | IDENTIFICATION AND AUTHENTICATION |
| 1.5.6 Ensure the Ctrl-Alt-Delete key sequence is disabled. | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| 1.5.8 Ensure DNS is servers are configured | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| 1.6.1.5 Ensure the SELinux mode is enforcing | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY |
| 1.6.1.10 Ensure system device files are labeled. | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| 1.7.3 Ensure the Standard Mandatory DoD Notice and Consent Banner are configured | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| 1.8.1 Ensure GDM login banner is configured | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 1.8.5 Ensure users must authenticate users using MFA via a graphical user logon | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | IDENTIFICATION AND AUTHENTICATION |
| 1.8.9 Ensure session idle-delay settings is enforced | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | ACCESS CONTROL |
| 1.31 SQLI-22-008200 | CIS Microsoft SQL Server 2022 Instance STIG v1.0.0 CAT I MS_SQLDB | MS_SQLDB | IDENTIFICATION AND AUTHENTICATION |
| 1.75 O19C-00-015500 | CIS Oracle Database 19c STIG v1.1.0 CAT I Unix | Unix | IDENTIFICATION AND AUTHENTICATION |
| 2.2.26 Ensure ldap_tls_cacert is set for LDAP. | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | ACCESS CONTROL |
| 2.2.37 Ensure 'Manage auditing and security log' is set to 'Administrators' (DC only) | CIS Microsoft Windows Server 2025 v2.1.0 L1 DC | Windows | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 2.3.10.7 (L1) Ensure 'Network access: Remotely accessible registry paths' is configured | CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1 | Windows | ACCESS CONTROL |
| 2.3.10.8 (L1) Ensure 'Network access: Remotely accessible registry paths' is configured | CIS Microsoft Windows Server 2016 v4.0.0 L1 MS | Windows | ACCESS CONTROL |
| 2.3.10.11 (L1) Ensure 'Network access: Restrict clients allowed to make remote calls to SAM' is set to 'Administrators: Remote Access: Allow' (MS only) | CIS Microsoft Windows Server 2008 R2 Member Server Level 1 v3.3.1 | Windows | ACCESS CONTROL |
| 2.63 (L1) Ensure 'Enable network prediction' is set to 'Enabled: Do not predict actions on any network connection' | CIS Google Chrome Group Policy v1.1.0 L1 | Windows | CONFIGURATION MANAGEMENT |
| 3.3.3.4 Set 'ip rip authentication key-chain' | CIS Cisco IOS 12 L2 v4.0.0 | Cisco | SYSTEM AND COMMUNICATIONS PROTECTION |
| 3.10 (L1) Ensure 'Enable predict network actions` is set to 'Enabled: Do not predict actions on any network connection' | CIS Google Chrome L1 v3.0.0 | Windows | CONFIGURATION MANAGEMENT |
| 5.3.17 Ensure only strong MAC algorithms are used - MACs employing FIPS 140-2 approved cryptographic hash algorithms. | CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG | Unix | ACCESS CONTROL |
| 6 - Storage Encryption | NetApp Security Hardening Guide for ONTAP 9 v1.7.0 | Netapp_API | |
| 18.10.93.4.3 (L1) Ensure 'Select when Quality Updates are received' is set to 'Enabled: 0 days' | CIS Microsoft Windows Server 2016 v4.0.0 L1 DC | Windows | RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY |
| ALMA-09-041160 - AlmaLinux OS 9 must prevent kernel profiling by nonprivileged users. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| AZLX-23-002495 - Amazon Linux 2023 system-auth must be configured to use a sufficient number of hashing rounds. | DISA Amazon Linux 2023 STIG v1r4 | Unix | IDENTIFICATION AND AUTHENTICATION |
| CIS Amazon Linux Benchmark Level 2 | CIS Amazon Linux v2.1.0 L2 | Unix | |
| CIS_Amazon_Linux_2_v4.0.0_L1_Server.audit from CIS Amazon Linux 2 v4.0.0 | CIS Amazon Linux 2 v4.0.0 L1 Server | Unix | |
| CISC-L2-000020 - The Cisco switch must uniquely identify all network-connected endpoint devices before establishing any connection. | DISA Cisco NX OS Switch L2S STIG v3r4 | Cisco | IDENTIFICATION AND AUTHENTICATION |
| CISC-L2-000080 - The Cisco switch must authenticate all endpoint devices before establishing any connection. | DISA Cisco NX OS Switch L2S STIG v3r4 | Cisco | IDENTIFICATION AND AUTHENTICATION |
| GEN000500-2 - The graphical desktop environment must set the idle timeout to no more than 15 minutes. | DISA STIG for Oracle Linux 5 v2r1 | Unix | ACCESS CONTROL |
| GEN000500-2 - The graphical desktop environment must set the idle timeout to no more than 15 minutes. | DISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit | Unix | ACCESS CONTROL |
| GEN002820-2 - The audit system must be configured to audit all discretionary access control permission modifications - 'fchmod' | DISA STIG for Oracle Linux 5 v2r1 | Unix | AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| GEN006575 - The file integrity tool must use FIPS 140-2 approved cryptographic hashes for validating file contents. | DISA AIX 5.3 STIG v1r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| JUNI-RT-000690 - The Juniper PE router must be configured to implement Protocol Independent Multicast (PIM) snooping for each Virtual Private LAN Services (VPLS) bridge domain. | DISA STIG Juniper Router RTR v3r2 | Juniper | SYSTEM AND COMMUNICATIONS PROTECTION |
| MD8X-00-004200 - MongoDB must use NIST FIPS 140-2/140-3 validated cryptographic modules for cryptographic operations. | DISA MongoDB Enterprise Advanced 8.x STIG v1r1 Unix | Unix | IDENTIFICATION AND AUTHENTICATION |
| MYS8-00-011800 - The MySQL Database Server 8.0 must implement NIST FIPS 140-2 or 140-3 validated cryptographic modules to protect unclassified information requiring confidentiality and cryptographic protection, in accordance with the data owner's requirements. | DISA Oracle MySQL 8.0 v2r2 DB | MySQLDB | SYSTEM AND COMMUNICATIONS PROTECTION |
| Number of changes allowed within the change interval (changes) | Tenable Cisco ACI | Cisco_ACI | IDENTIFICATION AND AUTHENTICATION |
| SOL-11.1-060010 - The operating system must use mechanisms for authentication to a cryptographic module meeting the requirements of applicable federal laws, Executive orders, directives, policies, regulations, standards, and guidance for such authentication. | DISA Solaris 11 SPARC STIG v3r6 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SOL-11.1-060010 - The operating system must use mechanisms for authentication to a cryptographic module meeting the requirements of applicable federal laws, Executive orders, directives, policies, regulations, standards, and guidance for such authentication. | DISA Solaris 11 X86 STIG v3r6 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SQL6-D0-000100 - SQL Server databases must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals. | DISA MS SQL Server 2016 Database STIG v3r5 | MS_SQLDB | ACCESS CONTROL |
| SQLD-22-000100 - SQL Server must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals. | DISA Microsoft SQL Server 2022 Database STIG v1r3 | MS_SQLDB | ACCESS CONTROL |
| SQLI-22-003700 - SQL Server must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals. | DISA Microsoft SQL Server 2022 Instance STIG v1r4 MS_SQLDB | MS_SQLDB | ACCESS CONTROL |
| WBLC-02-000062 - Oracle WebLogic must protect against an individual falsely denying having performed a particular action. | Oracle WebLogic Server 12c Linux v2r2 Middleware | Unix | AUDIT AND ACCOUNTABILITY |
| WBLC-02-000062 - Oracle WebLogic must protect against an individual falsely denying having performed a particular action. | Oracle WebLogic Server 12c Windows v2r2 | Windows | AUDIT AND ACCOUNTABILITY |
| WBLC-02-000062 - Oracle WebLogic must protect against an individual falsely denying having performed a particular action. | Oracle WebLogic Server 12c Linux v2r2 | Unix | AUDIT AND ACCOUNTABILITY |
| WBLC-02-000069 - Oracle WebLogic must generate audit records for the DoD-selected list of auditable events - HTTP Access Log | Oracle WebLogic Server 12c Linux v2r2 | Unix | AUDIT AND ACCOUNTABILITY |
| WBLC-02-000069 - Oracle WebLogic must generate audit records for the DoD-selected list of auditable events - HTTP Access Log | Oracle WebLogic Server 12c Linux v2r2 Middleware | Unix | AUDIT AND ACCOUNTABILITY |
| WBLC-02-000069 - Oracle WebLogic must generate audit records for the DoD-selected list of auditable events. | Oracle WebLogic Server 12c Windows v2r2 | Windows | AUDIT AND ACCOUNTABILITY |