| 1.2 WN19-00-000020 | CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT II | Windows | IDENTIFICATION AND AUTHENTICATION |
| 1.8 VCSA-80-000069 | CIS VMware vSphere 8.0 vCenter STIG v1.0.0 CAT II | VMware | IDENTIFICATION AND AUTHENTICATION |
| 1.10 VCSA-80-000072 | CIS VMware vSphere 8.0 vCenter STIG v1.0.0 CAT II | VMware | IDENTIFICATION AND AUTHENTICATION |
| 1.13 VCSA-80-000074 | CIS VMware vSphere 8.0 vCenter STIG v1.0.0 CAT II | VMware | IDENTIFICATION AND AUTHENTICATION |
| 1.21 CISC-ND-000580 | CIS Cisco IOS Switch NDM STIG v1.1.0 CAT II | Cisco | IDENTIFICATION AND AUTHENTICATION |
| 1.53 WN22-AC-000060 | CIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT II | Windows | IDENTIFICATION AND AUTHENTICATION |
| 1.97 SLES-15-020220 | CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT II | Unix | IDENTIFICATION AND AUTHENTICATION |
| 1.144 AZLX-23-002375 | CIS Amazon Linux 2023 STIG v1.0.0 CAT II | Unix | IDENTIFICATION AND AUTHENTICATION |
| 1.145 AZLX-23-002380 | CIS Amazon Linux 2023 STIG v1.0.0 CAT II | Unix | IDENTIFICATION AND AUTHENTICATION |
| AIOS-17-006500 - Apple iOS/iPadOS 17 must be configured to enforce a minimum password length of six characters. | AirWatch - DISA Apple iOS/iPadOS 17 v2r2 | MDM | IDENTIFICATION AND AUTHENTICATION |
| AIOS-17-006500 - Apple iOS/iPadOS 17 must be configured to enforce a minimum password length of six characters. | MobileIron - DISA Apple iOS/iPadOS 17 v2r2 | MDM | IDENTIFICATION AND AUTHENTICATION |
| APPL-14-003070 - The macOS system must set minimum password lifetime to 24 hours. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | IDENTIFICATION AND AUTHENTICATION |
| APPL-26-003060 - The macOS system must require that passwords contain a minimum of one lowercase character and one uppercase character. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| ARST-ND-000380 - The Arista network device must enforce a minimum 15-character password length. | DISA Arista MLS EOS 4.X NDM STIG v2r2 | Arista | IDENTIFICATION AND AUTHENTICATION |
| CASA-ND-000530 - The Cisco ASA must be configured to enforce password complexity by requiring that at least one lowercase character be used. | DISA STIG Cisco ASA NDM v2r5 | Cisco | IDENTIFICATION AND AUTHENTICATION |
| GOOG-13-006000 - Google Android 13 must be configured to enforce a minimum password length of six characters. | AirWatch - DISA Google Android 13 COBO STIG v2r3 | MDM | IDENTIFICATION AND AUTHENTICATION |
| GOOG-13-006000 - Google Android 13 must be configured to enforce a minimum password length of six characters. | MobileIron - DISA Google Android 13 COBO STIG v2r3 | MDM | IDENTIFICATION AND AUTHENTICATION |
| GOOG-13-006000 - Google Android 13 must be configured to enforce a minimum password length of six characters. | AirWatch - DISA Google Android 13 COPE STIG v2r3 | MDM | IDENTIFICATION AND AUTHENTICATION |
| OL08-00-020200 - OL 8 user account passwords must have a 60-day maximum password lifetime restriction. | DISA Oracle Linux 8 STIG v2r9 | Unix | IDENTIFICATION AND AUTHENTICATION |
| PHTN-40-000041 - The Photon operating system must enforce one day as the minimum password lifetime. | DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-08-020230 - RHEL 8 passwords must have a minimum of 15 characters. | DISA Red Hat Enterprise Linux 8 STIG v2r8 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLES-15-020140 - The SUSE operating system must enforce passwords that contain at least one lowercase character. | DISA SUSE Linux Enterprise Server 15 STIG v2r8 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLES-15-020150 - The SUSE operating system must enforce passwords that contain at least one numeric character. | DISA SUSE Linux Enterprise Server 15 STIG v2r8 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLES-15-020160 - The SUSE operating system must require the change of at least eight of the total number of characters when passwords are changed. | DISA SUSE Linux Enterprise Server 15 STIG v2r8 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLES-15-020200 - The SUSE operating system must be configured to create or update passwords with a minimum lifetime of 24 hours (one day). | DISA SUSE Linux Enterprise Server 15 STIG v2r8 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLES-15-020230 - The SUSE operating system must employ user passwords with a maximum lifetime of 60 days. | DISA SUSE Linux Enterprise Server 15 STIG v2r6 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLES-15-020260 - The SUSE operating system must employ passwords with a minimum of 15 characters. | DISA SUSE Linux Enterprise Server 15 STIG v2r6 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SPLK-CL-000340 - Splunk Enterprise must be configured to enforce password complexity by requiring that at least one uppercase character be used. | DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG OS | Unix | IDENTIFICATION AND AUTHENTICATION |
| SPLK-CL-000360 - Splunk Enterprise must be configured to enforce password complexity by requiring that at least one numeric character be used. | DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG OS | Unix | IDENTIFICATION AND AUTHENTICATION |
| UBTU-20-010050 - The Ubuntu operating system must enforce password complexity by requiring that at least one upper-case character be used. | DISA Canonical Ubuntu 20.04 LTS STIG v2r4 | Unix | IDENTIFICATION AND AUTHENTICATION |
| UBTU-20-010052 - The Ubuntu operating system must enforce password complexity by requiring that at least one numeric character be used. | DISA Canonical Ubuntu 20.04 LTS STIG v2r4 | Unix | IDENTIFICATION AND AUTHENTICATION |
| UBTU-20-010055 - The Ubuntu operating system must enforce password complexity by requiring that at least one special character be used. | DISA Canonical Ubuntu 20.04 LTS STIG v2r4 | Unix | IDENTIFICATION AND AUTHENTICATION |
| UBTU-22-611020 - Ubuntu 22.04 LTS must enforce password complexity by requiring that at least one numeric character be used. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | IDENTIFICATION AND AUTHENTICATION |
| UBTU-22-611025 - Ubuntu 22.04 LTS must enforce password complexity by requiring that at least one special character be used. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | IDENTIFICATION AND AUTHENTICATION |
| UBTU-22-611035 - Ubuntu 22.04 LTS must enforce a minimum 15-character password length. | DISA Canonical Ubuntu 22.04 LTS STIG v2r9 | Unix | IDENTIFICATION AND AUTHENTICATION |
| UBTU-24-400270 - Ubuntu 24.04 LTS must enforce password complexity by requiring that at least one lowercase character be used. | DISA Canonical Ubuntu 24.04 LTS STIG v1r6 | Unix | IDENTIFICATION AND AUTHENTICATION |
| UBTU-24-400290 - Ubuntu 24.04 LTS must require the change of at least eight characters when passwords are changed. | DISA Canonical Ubuntu 24.04 LTS STIG v1r6 | Unix | IDENTIFICATION AND AUTHENTICATION |
| UBTU-24-400300 - Ubuntu 24.04 LTS must enforce 24 hours/1 day as the minimum password lifetime. Passwords for new users must have a 24 hours/1 day minimum password lifetime restriction. | DISA Canonical Ubuntu 24.04 LTS STIG v1r6 | Unix | IDENTIFICATION AND AUTHENTICATION |
| UBTU-24-400310 - Ubuntu 24.04 LTS must enforce a 60-day maximum password lifetime restriction. Passwords for new users must have a 60-day maximum password lifetime restriction. | DISA Canonical Ubuntu 24.04 LTS STIG v1r6 | Unix | IDENTIFICATION AND AUTHENTICATION |
| VCSA-80-000071 - The vCenter Server passwords must contain at least one uppercase character. | DISA VMware vSphere 8.0 vCenter STIG v2r4 VMware | VMware | IDENTIFICATION AND AUTHENTICATION |
| VCSA-80-000072 - The vCenter Server passwords must contain at least one lowercase character. | DISA VMware vSphere 8.0 vCenter STIG v2r4 VMware | VMware | IDENTIFICATION AND AUTHENTICATION |
| VCSA-80-000074 - The vCenter Server passwords must contain at least one special character. | DISA VMware vSphere 8.0 vCenter STIG v2r4 VMware | VMware | IDENTIFICATION AND AUTHENTICATION |
| WN11-00-000090 - Accounts must be configured to require password expiration. | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-AC-000025 - The maximum password age must be configured to 60 days or less. | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-AC-000040 - The built-in Microsoft password complexity filter must be enabled. | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN22-00-000020 - Windows Server 2022 passwords for the built-in Administrator account must be changed at least every 60 days. | DISA Microsoft Windows Server 2022 STIG v2r8 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN22-00-000050 - Windows Server 2022 manually managed application account passwords must be at least 14 characters in length. | DISA Microsoft Windows Server 2022 STIG v2r10 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN22-00-000210 - Windows Server 2022 passwords must be configured to expire. | DISA Microsoft Windows Server 2022 STIG v2r8 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN22-AC-000050 - Windows Server 2022 maximum password age must be configured to 60 days or less. | DISA Microsoft Windows Server 2022 STIG v2r10 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN22-AC-000060 - Windows Server 2022 minimum password age must be configured to at least one day. | DISA Microsoft Windows Server 2022 STIG v2r8 | Windows | IDENTIFICATION AND AUTHENTICATION |