| 1.1.2 Ensure Super Admin Account Is Not Used For Google Cloud Administration | CIS Google Cloud Platform Foundation v5.0.0 L1 | GCP | ACCESS CONTROL |
| 1.1.4 Ensure that the controller manager pod specification file ownership is set to root:root | CIS Kubernetes v2.0.1 L1 Master Node | Unix | ACCESS CONTROL |
| 1.8.2 Set username secret for all local users | CIS Cisco IOS XR 7.x v1.0.1 L1 | Cisco | ACCESS CONTROL |
| 2.1 Run BIND as a non-root User - process -u named | CIS BIND DNS v3.0.1 Authoritative Name Server | Unix | ACCESS CONTROL |
| 2.1 Run BIND as a non-root User - process -u named | CIS BIND DNS v3.0.1 Caching Only Name Server | Unix | ACCESS CONTROL |
| 2.1 Run BIND as a non-root User - UID | CIS BIND DNS v3.0.1 Caching Only Name Server | Unix | ACCESS CONTROL |
| 2.1 Run BIND as a non-root User - UID | CIS BIND DNS v3.0.1 Authoritative Name Server | Unix | ACCESS CONTROL |
| 2.1.4 Verify root login is disabled | CIS Arista EOS benchmark v1.0.0 L1 | Arista | ACCESS CONTROL |
| 2.2.1 Ensure that NGINX is run using a non-privileged, dedicated service account | CIS NGINX v3.0.0 L1 Webserver | Unix | ACCESS CONTROL |
| 3.5 Ensure the SQL Server's MSSQL Service Account is Not an Administrator | CIS Microsoft SQL Server 2022 v1.3.0 L1 AWS RDS Windows | Windows | ACCESS CONTROL |
| 3.6.1.2 OpenSSH - PermitRootLogin | CIS IBM AIX 7.1 L2 v2.1.0 | Unix | ACCESS CONTROL |
| 3.7 Ensure the SQL Server's Full-Text Service Account is Not an Administrator | CIS Microsoft SQL Server 2025 v1.0.0 L1 AWS RDS MS_SQLDB | MS_SQLDB | ACCESS CONTROL |
| 3.7 Ensure the SQL Server's Full-Text Service Account is Not an Administrator | CIS Microsoft SQL Server 2025 v1.0.0 L1 Database Engine MS_SQLDB | MS_SQLDB | ACCESS CONTROL |
| 3.7 Ensure the SQL Server's Full-Text Service Account is Not an Administrator | CIS Microsoft SQL Server 2022 v1.3.0 L1 AWS RDS MS_SQLDB | MS_SQLDB | ACCESS CONTROL |
| 3.7 Ensure the SQL Server's Full-Text Service Account is Not an Administrator | CIS Microsoft SQL Server 2022 v1.3.0 L1 AWS RDS Windows | Windows | ACCESS CONTROL |
| 3.7 Ensure the SQL Server's Full-Text Service Account is Not an Administrator | CIS Microsoft SQL Server 2022 v1.3.0 L1 Database Engine MS_SQLDB | MS_SQLDB | ACCESS CONTROL |
| 4.1 Ensure Interactive Login is Disabled | CIS PostgreSQL 14 OS v 1.3.0 | Unix | ACCESS CONTROL |
| 4.1 Ensure Interactive Login is Disabled | CIS PostgreSQL 13 v1.3.0 L1 Database Unix | Unix | ACCESS CONTROL |
| 4.1 Ensure Interactive Login is Disabled | CIS PostgreSQL 15 v1.2.0 L1 OS Linux Unix | Unix | ACCESS CONTROL |
| 4.1 Ensure Interactive Login is Disabled | CIS PostgreSQL 16 v1.1.0 L1 OS Linux Unix | Unix | ACCESS CONTROL |
| 4.1 Ensure Interactive Login is Disabled | CIS PostgreSQL 18 v1.0.0 L1 Database Unix | Unix | ACCESS CONTROL |
| 4.1.2 Ensure that the kubelet service file ownership is set to root:root | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 4.1.2 Ensure that the kubelet service file ownership is set to root:root | CIS Kubernetes v2.0.1 L1 Worker Node | Unix | ACCESS CONTROL |
| 4.1.6 Ensure that the --kubeconfig kubelet.conf file ownership is set to root:root | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 4.1.10 If the kubelet config.yaml configuration file is being used validate file ownership is set to root:root | CIS Kubernetes v2.0.1 L1 Worker Node | Unix | ACCESS CONTROL |
| 4.3.6 Ensure sudo authentication timeout is configured correctly | CIS FreeBSD 14 v1.0.1 L1 | Unix | ACCESS CONTROL |
| 4.8 Ensure the set_user extension is installed | CIS PostgreSQL 18 v1.0.0 L1 Database PostgreSQLDB | PostgreSQLDB | ACCESS CONTROL |
| 5.2.2 Minimize the admission of containers wishing to share the host process ID namespace | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 5.2.7 Minimize the admission of root containers | CIS Kubernetes v2.0.1 L2 Master Node | Unix | ACCESS CONTROL |
| 5.3 Ensure Options for Other Directories Are Minimized | CIS Apache HTTP Server 2.4 v2.3.0 L2 | Unix | ACCESS CONTROL |
| 5.5 Ensure the 'root' Account Is Disabled | CIS Apple macOS 10.15 Catalina v3.0.0 L1 | Unix | ACCESS CONTROL |
| 5.6 Ensure 'CREATE USER' is Not Granted to Non-Administrative Users | CIS MariaDB 10.11 v1.0.0 L1 MariaDB RDBMS MySQLDB | MySQLDB | ACCESS CONTROL |
| 5.6 Ensure the "root" Account Is Disabled | CIS Apple macOS 13.0 Ventura v4.0.0 L1 | Unix | ACCESS CONTROL |
| 6.1.1 Ensure sudo is installed | CIS IBM AIX 7 v1.2.0 L2 | Unix | ACCESS CONTROL |
| 6.1.4 Ensure 'CREATE EXTERNAL JOB' Is Revoked From Unauthorized 'GRANTEE' | CIS Oracle Database 26ai v1.0.0 L1 RDBMS On Windows Server Host OS OracleDB | OracleDB | ACCESS CONTROL |
| 6.1.11 Ensure All `SYSTEM` Privileges Are Revoked from Unauthorized 'GRANTEE' | CIS Oracle Database 26ai v1.0.0 L1 RDBMS On Windows Server Host OS OracleDB | OracleDB | ACCESS CONTROL |
| 6.5 Restrict FTP Use - Audit the list of users in /etc/ftpd/ftpusers. | CIS Solaris 10 L1 v5.2 | Unix | ACCESS CONTROL |
| 6.9 Restrict FTP Use | CIS Solaris 11 L1 v1.1.0 | Unix | ACCESS CONTROL |
| 6.9 Restrict FTP Use | CIS Solaris 11.1 L1 v1.0.0 | Unix | ACCESS CONTROL |
| 6.9 Restrict FTP Use - /etc/ftpd/ftpusers | CIS Solaris 11.2 L1 v1.1.0 | Unix | ACCESS CONTROL |
| 10.3 Restrict manager application | CIS Apache Tomcat 7 L2 v1.1.0 | Unix | ACCESS CONTROL |
| 10.3 Restrict manager application | CIS Apache Tomcat 7 L2 v1.1.0 Middleware | Unix | ACCESS CONTROL |
| 10.13 Do not run applications as privileged | CIS Apache Tomcat 10 L1 v1.1.0 | Unix | ACCESS CONTROL |
| 10.17 Setting Security Lifecycle Listener | CIS Apache Tomcat 11 v1.0.0 L1 | Unix | ACCESS CONTROL |
| 10.17 Setting Security Lifecycle Listener - check for umask present in startup | CIS Apache Tomcat 10 L1 v1.1.0 Middleware | Unix | ACCESS CONTROL |
| 10.17 Setting Security Lifecycle Listener - check for umask present in startup | CIS Apache Tomcat 9 L1 v1.2.0 | Unix | ACCESS CONTROL |
| 10.17 Setting Security Lifecycle Listener - check for umask uncommented in startup | CIS Apache Tomcat 10 L1 v1.1.0 | Unix | ACCESS CONTROL |
| 18.9.90.2 (L1) Ensure 'Always install with elevated privileges' is set to 'Disabled' | CIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 MS | Windows | ACCESS CONTROL |
| 18.9.90.2 (L1) Ensure 'Always install with elevated privileges' is set to 'Disabled' | CIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 DC | Windows | ACCESS CONTROL |
| Access Security - SSH - Deny Root logins | Juniper Hardening JunOS 12 Devices Checklist | Juniper | ACCESS CONTROL |