| 1.1 Ensure Latest SQL Server Service Packs and Hotfixes are Installed | CIS SQL Server 2008 R2 DB Engine L1 v1.7.0 | MS_SQLDB | CONFIGURATION MANAGEMENT |
| 3.1.2 Secure Ppermissions for Default Database File Path (DFTDBPATH) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, MEDIA PROTECTION |
| 3.1.4 Secure Permissions for All Diagnostic Logs (DIAGPATH) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, MEDIA PROTECTION |
| 3.1.5 Secure Permissions for Alternate Diagnostic Log Path (ALT_DIAGPATH) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, MEDIA PROTECTION |
| 3.1.6 Disable Client Discovery Requests (DISCOVER) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | CONFIGURATION MANAGEMENT |
| 3.1.7 Disable Instance Discoverability (DISCOVER_INST) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | CONFIGURATION MANAGEMENT |
| 3.1.8 Set Maximum Connection Limits (MAX_CONNECTIONS and MAX_COORDAGENTS) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, MEDIA PROTECTION |
| 3.1.11 Secure the Python Runtime Path (PYTHON_PATH) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, MEDIA PROTECTION |
| 3.1.12 Secure the R Runtime Path (R_PATH) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, MEDIA PROTECTION |
| 3.2.2 Turn Off Remote Command Legacy Mode (DB2RCMD_LEGACY_MODE) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | CONFIGURATION MANAGEMENT |
| 3.2.5 Limit OS Privileges of Fenced Mode Process (DB2_LIMIT_FENCED_GROUP) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, MEDIA PROTECTION |
| 3.3.1 Secure Db2 Runtime Library | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, MEDIA PROTECTION |
| 3.6 Implement DNSSEC 'INCLUDE' | CIS ISC BIND 9.0/9.5 v2.0.0 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.1.2 Set Failed Archive Retry Delay (ARCHRETRYDELAY) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | AUDIT AND ACCOUNTABILITY |
| 4.1.4 Disable Database Discovery (DISCOVER_DB) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | CONFIGURATION MANAGEMENT |
| 4.1.6 Secure Permissions for the Secondary Archive Log Location (LOGARCHMETH2) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, MEDIA PROTECTION |
| 4.1.7 Secure Permissions for the Tertiary Archive Log Location (FAILARCHPATH) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, MEDIA PROTECTION |
| 4.1.8 Secure Permissions for the Log Mirror Location (MIRRORLOGPATH) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, MEDIA PROTECTION |
| 4.1.9 Secure Permissions for the Log Overflow Location (OVERFLOWLOGPATH) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, MEDIA PROTECTION |
| 4.1.10 Establish Retention Set Size for Backups (NUM_DB_BACKUPS) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | CONTINGENCY PLANNING |
| 4.1.11 Set Archive Log Failover Retry Limit (NUMARCHRETRY) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | AUDIT AND ACCOUNTABILITY |
| 4.1.12 Set Maximum Number of Applications (MAXAPPLS) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.1.14 Specify a Secure Location for External Tables (EXTBL_LOCATION) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, MEDIA PROTECTION |
| 5.1 Specify a Secure Connection Authentication Type (SRVCON_AUTH) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL |
| 5.2 Specify a Secure Authentication Type (AUTHENTICATION) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL |
| 5.3 Database Manager Configuration Parameter: ALTERNATE_AUTH_ENC | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.4 Database Manager Configuration Parameter: TRUST_ALLCLNTS | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL |
| 5.6 Database Manager Configuration Parameter: FED_NOAUTH | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL |
| 5.8 DB2_GRP_LOOKUP Registry Variable (Windows only) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, MEDIA PROTECTION |
| 5.9 DB2DOMAINLIST Registry Variable (Windows only) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL |
| 5.10 DB2AUTH Registry Variable | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.11 DB2CHGPWD_EEE Registry Variable | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL |
| 6.1.1 Secure SYSADM Authority | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, MEDIA PROTECTION |
| 6.1.2 Secure SYSCTRL Authority | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, MEDIA PROTECTION |
| 6.1.4 Secure SYSMON Authority | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, MEDIA PROTECTION |
| 7.1.1 Disable the Audit Buffer | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | AUDIT AND ACCOUNTABILITY |
| 7.1.2 Disable Limited Audit of Applications (DB2_LIMIT_AUDIT_APPS) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | AUDIT AND ACCOUNTABILITY |
| 8.1.1 Configure a Server-side Key Store for TLS (SSL_SVR_KEYDB) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.1.2 Configure a Server-side Stash File for TLS (SSL_SVR_STASH) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.1.4 Configure the Service Name for TLS (SSL_SVCENAME) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | PLANNING, SYSTEM AND SERVICES ACQUISITION |
| 8.1.5 Configure a Secure TLS Version (SSL_VERSIONS) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.1.6 Configure Secure TLS Cipher Suites (SSL_CIPHERSPECS) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.1.8 Configure a Client-side Key Store for TLS (SSL_CLNT_KEYDB) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.1.9 Configure a Client-side Stash File for TLS (SSL_CLNT_STASH) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.1.10 Enable TLS Communication Between HADR Primary and Standby Instances (HADR_SSL_LABEL) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 8.1.11 Enable Remote TLS Connections to Db2 (DB2COMM) | CIS IBM DB2 11 v1.2.0 Windows OS Level 1 | Windows | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 18.9.19.1 (L1) Ensure 'Turn off desktop gadgets' is set to 'Enabled' | CIS Microsoft Windows Server 2008 Domain Controller Level 1 v3.3.1 | Windows | CONFIGURATION MANAGEMENT |
| 18.9.47.11.1 (L2) Ensure 'Enable/Disable PerfTrack' is set to 'Disabled' | CIS Microsoft Windows Server 2016 v4.0.0 L2 DC | Windows | CONFIGURATION MANAGEMENT |
| 18.9.49.11.1 Ensure 'Enable/Disable PerfTrack' is set to 'Disabled' | CIS Microsoft Windows Server 2022 Stand-alone v2.0.0 L2 MS | Windows | CONFIGURATION MANAGEMENT |
| CIS_MS_SERVER_2012_Level_2_v3.0.0.audit from CIS Security Benchmark For Microsoft Windows Server 2012 MS Level 2 | CIS Windows Server 2012 MS L2 v3.0.0 | Windows | |