| 1.6 Ensure that service accounts use key pair authentication | CIS Snowflake Foundations v1.0.0 L1 | Snowflake | IDENTIFICATION AND AUTHENTICATION |
| 1.7 Ensure authentication key pairs are rotated every 180 days | CIS Snowflake Foundations v1.0.0 L1 | Snowflake | IDENTIFICATION AND AUTHENTICATION |
| 1.13.2.1.2 Ensure 'Missing CRLs' is set to Enabled:Error | CIS Microsoft Office Outlook 2013 v1.1.0 Level 1 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 1.13.2.1.2 Ensure 'Missing CRLs' is set to Enabled:Error | CIS Microsoft Office Outlook 2016 v1.1.0 Level 1 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 1.13.2.1.3 Ensure 'Missing Root Certificates' is set to Enabled:Warning | CIS Microsoft Office Outlook 2013 v1.1.0 Level 1 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 1.13.2.1.5 Ensure 'Retrieving CRLs (Certificate Revocation Lists)' is set to Enabled:When online always retrieve the CRL | CIS Microsoft Office Outlook 2013 v1.1.0 Level 1 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 1.13.2.1.5 Ensure 'Retrieving CRLs (Certificate Revocation Lists)' is set to Enabled:When online always retrieve the CRL | CIS Microsoft Office Outlook 2016 v1.1.0 Level 1 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 1.17 (L1) Ensure 'Enable online OCSP/CRL checks' is set to 'Disabled' | CIS Google Chrome L1 v3.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 2.1 Set 'Retrieving CRLs (Certificate Revocation Lists):' to 'Enabled:When online always retrieve the CRL' | CIS MS Office Outlook 2010 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 2.5 Set 'Do not check e- mail address against address of certificates being used' to 'Disabled' | CIS MS Office Outlook 2010 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 2.5.14.2.1.2 (L1) Ensure 'Missing CRLs' is set to 'Enabled: Error' | CIS Microsoft Intune for Office v1.1.0 L1 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 2.5.14.2.1.2 Ensure 'Missing CRLs' is set to 'Enabled: Error' | CIS Microsoft Office Enterprise v1.2.0 L1 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 2.5.14.2.1.3 (L1) Ensure 'Missing Root Certificates' is set to 'Enabled: Error' | CIS Microsoft Intune for Office v1.1.0 L1 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 2.5.14.2.1.3 Ensure 'Missing Root Certificates' is set to 'Enabled: Error' | CIS Microsoft Office Enterprise v1.2.0 L1 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 2.5.14.2.1.5 Ensure 'Retrieving CRLs (Certificate Revocation Lists)' is set to 'Enabled: When online always retrieve the CRL' | CIS Microsoft Office Enterprise v1.2.0 L1 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 2.5.14.3.27 (L1) Ensure 'Retrieving CRLs (Certificate Revocation Lists)' is set to 'Enabled: When online always retrieve the CRL' | CIS Microsoft Intune for Office v1.1.0 L1 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 2.11 Set 'Indicate a missing CRL as a(n):' to 'Enabled:Error' | CIS MS Office Outlook 2010 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 2.41 (L1) Ensure 'Enable online OCSP/CRL checks' is set to 'Disabled' | CIS Google Chrome Group Policy v1.0.0 L1 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 5.6 Enable OCSP and CRL certificate checking - CRL | CIS Apple OSX 10.9 L2 v1.3.0 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.6 Enable OCSP and CRL certificate checking - CRLStyle | CIS Apple OSX 10.11 El Capitan L2 v1.1.0 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.6 Enable OCSP and CRL certificate checking - OCSPStyle | CIS Apple OSX 10.11 El Capitan L2 v1.1.0 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 6.1 Setup Client-cert Authentication | CIS Apache Tomcat 7 L2 v1.1.0 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 26 - Setup Client-cert Authentication | TNS Best Practice Jetty 9 Linux | Unix | IDENTIFICATION AND AUTHENTICATION |
| Check for server certificate revocation | MSCT Windows 10 1803 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Check for server certificate revocation | MSCT Windows Server 1903 DC v1.19.9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Check for server certificate revocation | MSCT Windows Server 2019 DC v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Check for server certificate revocation | MSCT MSCT Windows Server 2022 DC v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| FireEye - Web interface does not use the system self-signed certificate | TNS FireEye | FireEye | IDENTIFICATION AND AUTHENTICATION |
| Fortigate - Does not use self-signed certificate - 'admin' | TNS Fortigate FortiOS Best Practices v2.0.0 | FortiGate | IDENTIFICATION AND AUTHENTICATION |
| Fortigate - Does not use self-signed certificate - 'user' | TNS Fortigate FortiOS Best Practices v2.0.0 | FortiGate | IDENTIFICATION AND AUTHENTICATION |
| Network security: LDAP client signing requirements | MSCT MSCT Windows Server 2022 DC v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Network security: LDAP client signing requirements | MSCT Windows 11 v22H2 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Network security: LDAP client signing requirements | MSCT Windows 11 v25H2 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Network security: LDAP client signing requirements | MSCT Windows Server 2025 MS v2506 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Network security: LDAP client signing requirements | MSCT Windows 10 v22H2 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Network security: LDAP client signing requirements | MSCT Windows 11 v24H2 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Network security: LDAP client signing requirements | MSCT Windows Server 2022 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Network security: LDAP client signing requirements | MSCT Windows Server 2025 DC v2506 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Network security: LDAP client signing requirements | MSCT Windows 10 v21H1 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Network security: LDAP client signing requirements | MSCT Windows 11 v23H2 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Network security: LDAP client signing requirements | MSCT Windows 11 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Network security: LDAP client signing requirements - LDAPClientIntegrity | MSCT Windows Server 2025 MS v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Network security: LDAP client signing requirements - LDAPClientIntegrity | MSCT Windows Server 2025 DC v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Retrieving CRLs (Certificate Revocation Lists) | Microsoft 365 Apps for Enterprise 2306 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Retrieving CRLs (Certificate Revocation Lists) | MSCT M365 Apps for enterprise 2312 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Retrieving CRLs (Certificate Revocation Lists) | MSCT M365 Apps for enterprise 2412 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Retrieving CRLs (Certificate Revocation Lists) | MSCT Office 2016 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Retrieving CRLs (Certificate Revocation Lists) | MSCT Microsoft 365 Apps for Enterprise 2112 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Retrieving CRLs (Certificate Revocation Lists) | MSCT Microsoft 365 Apps for Enterprise 2206 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
| Retrieving CRLs (Certificate Revocation Lists) | MSCT Office 365 ProPlus 1908 v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |