| 1.1.10 Ensure separate partition exists for /var | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| 1.1.19 Ensure nosuid is set on users' home directories. | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| 1.3.1 Ensure AIDE is installed | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| 1.4.5 Ensure version 7.2 or newer booted with a BIOS have a unique name for the grub superusers account | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | ACCESS CONTROL |
| 1.5.7 Ensure kernel core dumps are disabled. | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| 1.8.2 Ensure Standard Mandatory DoD Notice and Consent Banner displayed via a graphical user logon | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 1.8.3 Ensure GDM session lock is enabled | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | ACCESS CONTROL |
| 1.8.14 Ensure unrestricted logon is not allowed | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| 1.11 Ensure anti-virus is installed and running | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | SYSTEM AND INFORMATION INTEGRITY |
| 1.12 Ensure host-based intrusion detection tool is used | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | SYSTEM AND INFORMATION INTEGRITY |
| 2.2.2 Ensure X11 Server components are not installed | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| 2.2.20 Ensure the rsh package has been removed | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| 2.2.23 Ensure default SNMP community strings don't exist | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| 2.2.27 Ensure ldap_id_use_start_tls is set for LDAP. | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | ACCESS CONTROL |
| 3.3.8 Ensure Reverse Path Filtering is enabled | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| 3.4.1 Ensure DCCP is disabled | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | IDENTIFICATION AND AUTHENTICATION |
| 3.5.1.4 Ensure firewalld service enabled and running | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| 3.5.1.5 Ensure firewalld default zone is set | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| 4.1.2.4 Ensure system notification is sent out when volume is 75% full | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | AUDIT AND ACCOUNTABILITY |
| 4.1.2.9 Ensure audit logs on separate system are encrypted. | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | AUDIT AND ACCOUNTABILITY |
| 4.1.3.9 Ensure file deletion events by users are collected | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| 4.1.3.17 Ensure audit of the gpasswd command | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| 4.1.3.18 Ensure audit all uses of chage | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| 4.1.3.21 Ensure audit of postdrop command | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| 4.1.3.31 Ensure audit of the create_module syscall | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | AUDIT AND ACCOUNTABILITY |
| 4.1.3.34 Ensure audit of the setsebool command. | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| 4.1.3.37 Ensure audit of the mount command and syscall | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| 4.2.1.6 Ensure remote rsyslog messages are only accepted on designated log hosts. | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| 5.3.14 Ensure SSH PermitUserEnvironment is disabled | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | CONFIGURATION MANAGEMENT |
| AS24-U2-000090 - The Apache web server must produce log records containing sufficient information to establish what type of events occurred. | DISA STIG Apache Server 2.4 Unix Site v2r6 Middleware | Unix | AUDIT AND ACCOUNTABILITY |
| AS24-U2-000300 - The Apache web server must have Multipurpose Internet Mail Extensions (MIME) that invoke operating system shell programs disabled. | DISA STIG Apache Server 2.4 Unix Site v2r6 | Unix | CONFIGURATION MANAGEMENT |
| AS24-U2-000300 - The Apache web server must have Multipurpose Internet Mail Extensions (MIME) that invoke operating system shell programs disabled. | DISA STIG Apache Server 2.4 Unix Site v2r6 Middleware | Unix | CONFIGURATION MANAGEMENT |
| AS24-U2-000310 - The Apache web server must allow mappings to unused and vulnerable scripts to be removed. | DISA STIG Apache Server 2.4 Unix Site v2r6 Middleware | Unix | CONFIGURATION MANAGEMENT |
| AS24-U2-000320 - The Apache web server must have resource mappings set to disable the serving of certain file types. | DISA STIG Apache Server 2.4 Unix Site v2r6 | Unix | CONFIGURATION MANAGEMENT |
| AS24-U2-000350 - Users and scripts running on behalf of users must be contained to the document root or home directory tree of the Apache web server. | DISA STIG Apache Server 2.4 Unix Site v2r6 Middleware | Unix | CONFIGURATION MANAGEMENT |
| AS24-U2-000360 - The Apache web server must be configured to use a specified IP address and port. | DISA STIG Apache Server 2.4 Unix Site v2r6 Middleware | Unix | CONFIGURATION MANAGEMENT |
| AS24-U2-000390 - Only authenticated system administrators or the designated PKI Sponsor for the Apache web server must have access to the Apache web servers private key. | DISA STIG Apache Server 2.4 Unix Site v2r6 | Unix | IDENTIFICATION AND AUTHENTICATION |
| AS24-U2-000470 - Cookies exchanged between the Apache web server and client, such as session cookies, must have security settings that disallow cookie access outside the originating Apache web server and hosted application. | DISA STIG Apache Server 2.4 Unix Site v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| AS24-U2-000540 - The Apache web server must augment re-creation to a stable and known baseline. | DISA STIG Apache Server 2.4 Unix Site v2r6 Middleware | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| AS24-U2-000640 - Debugging and trace information used to diagnose the Apache web server must be disabled. | DISA STIG Apache Server 2.4 Unix Site v2r6 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| AS24-U2-000700 - Non-privileged accounts on the hosting system must only access Apache web server security-relevant information and functions through a distinct administrative account. | DISA STIG Apache Server 2.4 Unix Site v2r6 Middleware | Unix | ACCESS CONTROL |
| Catalina - Out of Scope Supplemental | NIST macOS Catalina v1.5.0 - All Profiles | Unix | CONFIGURATION MANAGEMENT |
| Monterey - Out of Scope Supplemental | NIST macOS Monterey v1.0.0 - All Profiles | Unix | CONFIGURATION MANAGEMENT |
| WG110 W22 - The number of allowed simultaneous requests must be set. | DISA STIG Apache Site 2.2 Windows v1r13 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WG170 W22 - Each readable web document directory must contain either a default, home, index, or equivalent file. | DISA STIG Apache Site 2.2 Windows v1r13 | Windows | |
| WG205 W22 - The web document (home) directory must be in a separate partition from the web server's system files. - 'CustomLog' | DISA STIG Apache Site 2.2 Windows v1r13 | Windows | AUDIT AND ACCOUNTABILITY |
| WG230 W22 - Web server administration must be performed over a secure path or at the local console. | DISA STIG Apache Site 2.2 Windows v1r13 | Windows | ACCESS CONTROL |
| WG290 W22 - The web client account access to the content and scripts directories must be limited to read and execute. - 'Alias' | DISA STIG Apache Site 2.2 Windows v1r13 | Windows | |
| WG310 W22 - A web site must not contain a robots.txt file. - 'Alias' | DISA STIG Apache Site 2.2 Windows v1r13 | Windows | CONFIGURATION MANAGEMENT |
| WG490 W22 - Java software on production web servers must be limited to class files and the JAVA virtual machine. - 'Alias - *.java' | DISA STIG Apache Site 2.2 Windows v1r13 | Windows | CONFIGURATION MANAGEMENT |