| 1.1.3.1 Ensure separate partition exists for /var | CIS Debian Linux 10 v2.0.0 L2 Server | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.3.4.2 Configure 'Devices: Restrict floppy access to locally logged-on user only' | CIS Windows 8 L1 v1.0.0 | Windows | MEDIA PROTECTION |
| 1.1.3.4.3 Set 'Devices: Allowed to format and eject removable media' to 'Administrators and Interactive Users' | CIS Windows 8 L1 v1.0.0 | Windows | MEDIA PROTECTION |
| 2.3.4.1 (L1) Ensure 'Devices: Allowed to format and eject removable media' is set to 'Administrators' | CIS Windows Server 2012 DC L1 v3.0.0 | Windows | MEDIA PROTECTION |
| 2.3.4.1 (L1) Ensure 'Devices: Allowed to format and eject removable media' is set to 'Administrators' | CIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 MS | Windows | MEDIA PROTECTION |
| 2.3.4.1 (L1) Ensure 'Devices: Allowed to format and eject removable media' is set to 'Administrators' | CIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 MS | Windows | MEDIA PROTECTION |
| 2.3.4.1 (L1) Ensure 'Devices: Allowed to format and eject removable media' is set to 'Administrators' | CIS Windows Server 2012 R2 DC L1 v3.0.0 | Windows | MEDIA PROTECTION |
| 2.3.4.1 (L1) Ensure 'Devices: Allowed to format and eject removable media' is set to 'Administrators' | CIS Microsoft Windows Server 2008 R2 Member Server Level 1 v3.3.1 | Windows | MEDIA PROTECTION |
| 2.3.4.1 (L1) Ensure 'Devices: Allowed to format and eject removable media' is set to 'Administrators' | CIS Microsoft Windows Server 2008 Domain Controller Level 1 v3.3.1 | Windows | MEDIA PROTECTION |
| 2.3.4.1 (L1) Ensure 'Devices: Allowed to format and eject removable media' is set to 'Administrators' | CIS Microsoft Windows Server 2008 Member Server Level 1 v3.3.1 | Windows | MEDIA PROTECTION |
| 2.3.4.1 (L1) Ensure 'Devices: Allowed to format and eject removable media' is set to 'Administrators' | CIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 DC | Windows | MEDIA PROTECTION |
| 2.3.4.1 (L1) Ensure 'Devices: Allowed to format and eject removable media' is set to 'Administrators' | CIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 DC | Windows | MEDIA PROTECTION |
| 2.3.4.1 (L1) Ensure 'Devices: Allowed to format and eject removable media' is set to 'Administrators' | CIS Windows Server 2012 R2 MS L1 v3.0.0 | Windows | MEDIA PROTECTION |
| 2.3.4.1 (L1) Ensure 'Devices: Allowed to format and eject removable media' is set to 'Administrators' | CIS Microsoft Windows Server 2008 R2 Domain Controller Level 1 v3.3.1 | Windows | MEDIA PROTECTION |
| 2.3.4.1 (L1) Ensure 'Devices: Allowed to format and eject removable media' is set to 'Administrators' | CIS Windows Server 2012 MS L1 v3.0.0 | Windows | MEDIA PROTECTION |
| 2.3.4.1 Ensure 'Devices: Allowed to format and eject removable media' is set to 'Administrators and Interactive Users' | CIS Windows 7 Workstation Level 1 v3.2.0 | Windows | MEDIA PROTECTION |
| 2.3.4.1 Ensure 'Devices: Allowed to format and eject removable media' is set to 'Administrators and Interactive Users' | CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0 | Windows | MEDIA PROTECTION |
| 2.4.1.7 Ensure access to /etc/cron.yearly is configured | CIS AlmaLinux OS 8 v4.0.0 L1 Workstation | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.4.1.7 Ensure access to /etc/cron.yearly is configured | CIS Red Hat Enterprise Linux 10 v1.0.1 L1 Server | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.4.1.7 Ensure access to /etc/cron.yearly is configured | CIS Rocky Linux 10 v1.0.0 L1 Workstation | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.4.1.7 Ensure access to /etc/cron.yearly is configured | CIS Rocky Linux 8 v3.0.0 L1 Server | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.4.1.7 Ensure access to /etc/cron.yearly is configured | CIS Ubuntu Linux 22.04 LTS v3.0.0 L1 Workstation | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.4.1.7 Ensure access to /etc/cron.yearly is configured | CIS Debian Linux 13 v1.0.0 L1 Server | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.4.1.7 Ensure access to /etc/cron.yearly is configured | CIS Ubuntu Linux 20.04 LTS v3.0.0 L1 Workstation | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.4.1.7 Ensure access to /etc/cron.yearly is configured | CIS Oracle Linux 8 v4.0.0 L1 Server | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.4.1.7 Ensure access to /etc/cron.yearly is configured | CIS Red Hat Enterprise Linux 8 v4.0.0 L1 Workstation | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.4.1.7 Ensure access to /etc/cron.yearly is configured | CIS AlmaLinux OS 10 v1.0.0 L1 Workstation | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.4.1.7 Ensure access to /etc/cron.yearly is configured | CIS AlmaLinux OS 8 v4.0.0 L1 Server | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.4.1.7 Ensure access to /etc/cron.yearly is configured | CIS Debian Linux 13 v1.0.0 L1 Workstation | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.4.1.7 Ensure access to /etc/cron.yearly is configured | CIS Oracle Linux 10 v1.0.0 L1 Workstation | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.4.1.7 Ensure access to /etc/cron.yearly is configured | CIS Oracle Linux 8 v4.0.0 L1 Workstation | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.4.1.7 Ensure access to /etc/cron.yearly is configured | CIS Rocky Linux 10 v1.0.0 L1 Server | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.4.1.7 Ensure access to /etc/cron.yearly is configured | CIS Rocky Linux 8 v3.0.0 L1 Workstation | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.4.1.7 Ensure access to /etc/cron.yearly is configured | CIS Ubuntu Linux 20.04 LTS v3.0.0 L1 Server | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.4.1.7 Ensure access to /etc/cron.yearly is configured | CIS Ubuntu Linux 22.04 LTS v3.0.0 L1 Server | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.4.1.7 Ensure access to /etc/cron.yearly is configured | CIS AlmaLinux OS 10 v1.0.0 L1 Server | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.4.1.7 Ensure access to /etc/cron.yearly is configured | CIS Oracle Linux 10 v1.0.0 L1 Server | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.4.1.7 Ensure access to /etc/cron.yearly is configured | CIS Red Hat Enterprise Linux 10 v1.0.1 L1 Workstation | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.4.1.7 Ensure access to /etc/cron.yearly is configured | CIS Red Hat Enterprise Linux 8 v4.0.0 L1 Server | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.5.4 Ensure the usbguard service is enabled and active | CIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIG | Unix | IDENTIFICATION AND AUTHENTICATION, MEDIA PROTECTION |
| 3.2.1.8 Ensure 'Allow USB drive access in Files app' is set to 'Disabled' | MobileIron - CIS Apple iOS 13 and iPadOS 13 Institution Owned L2 | MDM | MEDIA PROTECTION |
| 3.2.1.8 Ensure 'Allow USB drive access in Files app' is set to 'Disabled' | MobileIron - CIS Apple iOS 14 and iPadOS 14 Institution Owned L2 | MDM | MEDIA PROTECTION |
| 3.2.1.8 Ensure 'Allow USB drive access in Files app' is set to 'Disabled' | AirWatch - CIS Apple iOS 13 and iPadOS 13 Institution Owned L2 | MDM | MEDIA PROTECTION |
| 3.2.1.8 Ensure 'Allow USB drive access in Files app' is set to 'Disabled' | AirWatch - CIS Apple iOS 14 and iPadOS 14 Institution Owned L2 | MDM | MEDIA PROTECTION |
| 3.2.1.16 Ensure 'Allow USB accessories while the device is locked' is set to 'Disabled' | AirWatch - CIS Apple iOS 13 and iPadOS 13 Institution Owned L1 | MDM | MEDIA PROTECTION |
| 3.2.1.16 Ensure 'Allow USB accessories while the device is locked' is set to 'Disabled' | MobileIron - CIS Apple iOS 13 and iPadOS 13 Institution Owned L1 | MDM | MEDIA PROTECTION |
| 3.2.1.17 Ensure 'Allow USB accessories while the device is locked' is set to 'Disabled' | MobileIron - CIS Apple iOS 14 and iPadOS 14 Institution Owned L1 | MDM | MEDIA PROTECTION |
| 3.2.1.17 Ensure 'Allow USB accessories while the device is locked' is set to 'Disabled' | AirWatch - CIS Apple iOS 14 and iPadOS 14 Institution Owned L1 | MDM | MEDIA PROTECTION |
| Devices: Allowed to format and eject removable media | MSCT Windows Server 2012 R2 DC v1.0.0 | Windows | MEDIA PROTECTION |
| Devices: Allowed to format and eject removable media | MSCT Windows Server 2012 R2 MS v1.0.0 | Windows | MEDIA PROTECTION |