| 1.1.5 Ensure 'Password must meet complexity requirements' is set to 'Enabled' | CIS Microsoft Windows Server 2022 v5.1.0 L1 DC | Windows | IDENTIFICATION AND AUTHENTICATION |
| 1.1.5 Ensure 'Password must meet complexity requirements' is set to 'Enabled' | CIS Microsoft Windows Server 2019 v5.0.0 L1 MS | Windows | IDENTIFICATION AND AUTHENTICATION |
| 1.1.5 Ensure 'Password Policy' is enabled - minimum-changes | CIS Cisco Firewall v8.x L1 v4.2.0 | Cisco | IDENTIFICATION AND AUTHENTICATION |
| 1.1.6 Ensure 'Relax minimum password length limits' is set to 'Enabled' | CIS Microsoft Windows Server 2025 Stand-alone v2.0.0 L1 MS | Windows | IDENTIFICATION AND AUTHENTICATION |
| 1.4.1.2 Ensure 'local username and password' is set | CIS Cisco Firewall v8.x L1 v4.2.0 | Cisco | IDENTIFICATION AND AUTHENTICATION |
| 1.4.3 Ensure authentication is required when booting into rescue mode | CIS CentOS Linux 8 Server L1 v2.0.0 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 2.3.1.2 Ensure 'Accounts: Limit local account use of blank passwords to console logon only' is set to 'Enabled' | CIS Microsoft Windows Server 2022 v5.1.0 L1 MS | Windows | IDENTIFICATION AND AUTHENTICATION |
| 2.3.1.2 Ensure 'Accounts: Limit local account use of blank passwords to console logon only' is set to 'Enabled' | CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 | Windows | IDENTIFICATION AND AUTHENTICATION |
| 2.3.1.2 Ensure 'Accounts: Limit local account use of blank passwords to console logon only' is set to 'Enabled' | CIS Microsoft Windows Server 2025 v2.1.0 L1 DC | Windows | IDENTIFICATION AND AUTHENTICATION |
| 2.3.1.3 Ensure 'Accounts: Limit local account use of blank passwords to console logon only' is set to 'Enabled' | CIS Microsoft Windows 10 Enterprise v5.0.0 L1 NG | Windows | IDENTIFICATION AND AUTHENTICATION |
| 3.11 (L1) Host must enforce password complexity | CIS VMware ESXi 8.0 v1.3.0 L1 VMware | VMware | IDENTIFICATION AND AUTHENTICATION |
| 4.2.19 Ensure sshd PermitEmptyPasswords is disabled | CIS CentOS Linux 7 v4.0.0 L1 Workstation | Unix | IDENTIFICATION AND AUTHENTICATION |
| 4.3 Ensure 'CHECK_POLICY' Option is set to 'ON' for All SQL Authenticated Logins | CIS Microsoft SQL Server 2019 v1.6.0 L1 Database Engine MS_SQLDB | MS_SQLDB | IDENTIFICATION AND AUTHENTICATION |
| 4.4.2.2.1 Ensure pam_pwquality module is enabled | CIS CentOS Linux 7 v4.0.0 L1 Workstation | Unix | IDENTIFICATION AND AUTHENTICATION |
| 4.4.2.2.3 Ensure password length is configured | CIS CentOS Linux 7 v4.0.0 L1 Server | Unix | IDENTIFICATION AND AUTHENTICATION |
| 4.4.2.2.3 Ensure password length is configured | CIS CentOS Linux 7 v4.0.0 L1 Workstation | Unix | IDENTIFICATION AND AUTHENTICATION |
| 4.4.2.2.5 Ensure password same consecutive characters is configured | CIS CentOS Linux 7 v4.0.0 L1 Workstation | Unix | IDENTIFICATION AND AUTHENTICATION |
| 4.4.2.2.6 Ensure password maximum sequential characters is configured | CIS CentOS Linux 7 v4.0.0 L1 Server | Unix | IDENTIFICATION AND AUTHENTICATION |
| 4.4.2.3.1 Ensure pam_pwhistory module is enabled | CIS CentOS Linux 7 v4.0.0 L1 Workstation | Unix | IDENTIFICATION AND AUTHENTICATION |
| 4.4.2.4.2 Ensure pam_unix does not include remember | CIS CentOS Linux 7 v4.0.0 L1 Workstation | Unix | IDENTIFICATION AND AUTHENTICATION |
| 4.5.1.5 Ensure all users last password change date is in the past | CIS CentOS Linux 7 v4.0.0 L1 Workstation | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.1.5.5 Ensure new application passwords are system-generated | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.3.2 Ensure custom banned passwords lists are used | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.3.1 Ensure password creation requirements are configured - password complexity | CIS Debian Family Server L1 v1.0.0 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.3.1.4 Ensure pam_pwhistory module is enabled | CIS AlmaLinux OS 10 v1.0.0 L1 Server | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.3.2.3 Ensure pam_pwquality module is enabled | CIS AlmaLinux OS 9 v2.0.0 L1 Workstation | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.3.2.3 Ensure pam_pwquality module is enabled | CIS Debian Linux 13 v1.1.0 L1 Server | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.3.2.4 Ensure pam_pwhistory module is enabled | CIS Ubuntu Linux 24.04 LTS v2.0.0 L1 Workstation | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.3.2.4.2 Ensure pam_unix does not include remember | CIS SUSE Linux Enterprise 15 v2.0.1 L1 Server | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.3.3.2.2 Ensure password length is configured | CIS Ubuntu Linux 26.04 LTS v1.0.0 L1 Server | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.3.3.2.2 Ensure password length is configured | CIS Ubuntu Linux 26.04 LTS v1.0.0 L1 Workstation | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.3.3.3.1 Ensure password history remember is configured | CIS Ubuntu Linux 24.04 LTS v2.0.0 L1 Workstation | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.3.3.4.2 Ensure pam_unix does not include remember | CIS AlmaLinux OS 8 v4.0.0 L1 Server | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.3.3.4.2 Ensure pam_unix does not include remember | CIS AlmaLinux OS 8 v4.0.0 L1 Workstation | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.3.3.4.2 Ensure pam_unix does not include remember | CIS AlmaLinux OS 9 v2.0.0 L1 Server | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.3.3.4.2 Ensure pam_unix does not include remember | CIS Ubuntu Linux 26.04 LTS v1.0.0 L1 Server | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.3.3.4.2 Ensure pam_unix does not include remember | CIS Ubuntu Linux 26.04 LTS v1.0.0 L1 Workstation | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.4.1.5 Ensure inactive password lock is configured | CIS Ubuntu Linux 22.04 LTS v3.0.0 L1 Workstation | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.4.1.5 Ensure inactive password lock is configured | CIS Ubuntu Linux 24.04 LTS v2.0.0 L1 Server | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.4.1.5 Ensure inactive password lock is configured | CIS AlmaLinux OS 10 v1.0.0 L1 Workstation | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.4.1.5 Ensure inactive password lock is configured | CIS Ubuntu Linux 26.04 LTS v1.0.0 L1 Server | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.4.1.6 Ensure all users last password change date is in the past | CIS Ubuntu Linux 26.04 LTS v1.0.0 L1 Workstation | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.5.3 Ensure password reuse is limited | CIS CentOS Linux 8 Server L1 v2.0.0 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.6.1.5 Ensure all users last password change date is in the past | CIS CentOS Linux 8 Workstation L1 v2.0.0 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 6.2.2 Ensure /etc/shadow password fields are not empty | CIS CentOS Linux 7 v4.0.0 L1 Workstation | Unix | IDENTIFICATION AND AUTHENTICATION |
| 6.9.1 Ensure a complex Root Password is Set | CIS Juniper OS Benchmark v2.1.0 L1 | Juniper | IDENTIFICATION AND AUTHENTICATION |
| 6.9.2 Ensure Root Password is Unique | CIS Juniper OS Benchmark v2.1.0 L1 | Juniper | IDENTIFICATION AND AUTHENTICATION |
| 7.3 Ensure Passwords are Set for All MySQL Accounts | CIS Oracle MySQL Enterprise Edition 9.7 v1.0.0 L1 MySQL RDBMS on Linux MySQLDB | MySQLDB | IDENTIFICATION AND AUTHENTICATION |
| 7.5 Ensure Password Complexity Policies are in Place | CIS Oracle MySQL Community Server 9.7 v1.0.0 L1 MySQL RDBMS MySQLDB | MySQLDB | IDENTIFICATION AND AUTHENTICATION |
| 18.9.26.4 Ensure 'Password Settings: Password Complexity' is set to 'Enabled: Large letters + small letters + numbers + specials' or higher | CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BL | Windows | IDENTIFICATION AND AUTHENTICATION |