{
    "control": "CM-7",
    "title": "Least Functionality",
    "ccis": [
        {
            "cci": "CCI-000380",
            "definition": "Defines prohibited or restricted functions, system ports, protocols, software and/or services for the system."
        },
        {
            "cci": "CCI-000381",
            "definition": "Configure the system to provide only organization-defined mission essential capabilities."
        },
        {
            "cci": "CCI-000382",
            "definition": "Configure the system to prohibit or restrict the use of organization-defined prohibited or restricted functions, system ports, protocols, software, and/or services."
        },
        {
            "cci": "CCI-000384",
            "definition": "Review the system per organization-defined frequency to identify unnecessary and nonsecure functions, ports, protocols, software, and services."
        },
        {
            "cci": "CCI-000387",
            "definition": "Defines registration requirements for functions, ports, protocols, and services."
        },
        {
            "cci": "CCI-000388",
            "definition": "Ensure compliance with organization-defined registration requirements for functions, ports, protocols, and services."
        },
        {
            "cci": "CCI-001592",
            "definition": "Defines the rules authorizing the terms and conditions of software program usage on the system."
        },
        {
            "cci": "CCI-001760",
            "definition": "Defines the frequency of system reviews to identify unnecessary and/or nonsecure functions, ports, protocols, software, and services."
        },
        {
            "cci": "CCI-001761",
            "definition": "Defines the functions, ports, protocols, software, and services within the information system that are to be disabled or removed when deemed unnecessary and/or nonsecure."
        },
        {
            "cci": "CCI-001762",
            "definition": "Disable or remove organization-defined functions, ports, protocols, software, and services within the system deemed to be unnecessary and/or nonsecure."
        },
        {
            "cci": "CCI-001763",
            "definition": "Defines the policies regarding software program usage and restrictions."
        },
        {
            "cci": "CCI-001764",
            "definition": "Prevent program execution in accordance with organization-defined policies, rules of behavior, and/or access agreements regarding software program usage and restrictions; rules authorizing the terms and conditions of software program usage."
        },
        {
            "cci": "CCI-001765",
            "definition": "Defines the software programs not authorized to execute on the system."
        },
        {
            "cci": "CCI-001766",
            "definition": "Identify the organization-defined software programs not authorized to execute on the system."
        },
        {
            "cci": "CCI-001767",
            "definition": "Employ an allow-all, deny-by-exception policy to prohibit the execution of unauthorized software programs on the system."
        },
        {
            "cci": "CCI-001768",
            "definition": "Defines the frequency on which the list of unauthorized software programs will be reviewed and updated."
        },
        {
            "cci": "CCI-001769",
            "definition": "The organization defines the frequency on which it will update the list of unauthorized software programs."
        },
        {
            "cci": "CCI-001770",
            "definition": "Review and update the list of unauthorized software programs per organization-defined frequency."
        },
        {
            "cci": "CCI-001771",
            "definition": "The organization updates the list of unauthorized software programs per organization-defined frequency."
        },
        {
            "cci": "CCI-001772",
            "definition": "Defines the software programs authorized to execute on the system."
        },
        {
            "cci": "CCI-001773",
            "definition": "Identify the organization-defined software programs authorized to execute on the system."
        },
        {
            "cci": "CCI-001774",
            "definition": "Employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs on the system."
        },
        {
            "cci": "CCI-001775",
            "definition": "Defines the frequency on which the list of authorized software programs will be reviewed and updated."
        },
        {
            "cci": "CCI-001776",
            "definition": "The organization defines the frequency on which it will update the list of authorized software programs."
        },
        {
            "cci": "CCI-001777",
            "definition": "Review and update the list of authorized software programs per organization-defined frequency."
        },
        {
            "cci": "CCI-001778",
            "definition": "The organization updates the list of authorized software programs per organization-defined frequency."
        }
    ],
    "rules_mapped": 231,
    "rules": [
        {
            "rule": "V-221561",
            "stig_id": "DTBC-0004",
            "title": "Sites ability to show pop-ups must be disabled.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-221564",
            "stig_id": "DTBC-0007",
            "title": "The default search providers name must be set.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-221565",
            "stig_id": "DTBC-0008",
            "title": "The default search provider URL must be set to perform encrypted searches.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-221566",
            "stig_id": "DTBC-0009",
            "title": "Default search provider must be enabled.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-221567",
            "stig_id": "DTBC-0011",
            "title": "The Password Manager must be disabled.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-221572",
            "stig_id": "DTBC-0021",
            "title": "The URL protocol schema javascript must be disabled.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-221575",
            "stig_id": "DTBC-0026",
            "title": "Metrics reporting to Google must be disabled.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-221576",
            "stig_id": "DTBC-0027",
            "title": "Search suggestions must be disabled.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-221577",
            "stig_id": "DTBC-0029",
            "title": "Importing of saved passwords must be disabled.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-221591",
            "stig_id": "DTBC-0058",
            "title": "WebUSB must be disabled.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-221594",
            "stig_id": "DTBC-0063",
            "title": "Google Cast must be disabled.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-221595",
            "stig_id": "DTBC-0064",
            "title": "Autoplay must be disabled.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-241787",
            "stig_id": "DTBC-0073",
            "title": "Web Bluetooth API must be disabled.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-245538",
            "stig_id": "DTBC-0074",
            "title": "Use of the QUIC protocol must be disabled.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-001762"
            ]
        },
        {
            "rule": "V-242409",
            "stig_id": "CNTR-K8-000910",
            "title": "Kubernetes Controller Manager must disable profiling.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-242410",
            "stig_id": "CNTR-K8-000920",
            "title": "The Kubernetes API Server must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL).",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000382"
            ]
        },
        {
            "rule": "V-242411",
            "stig_id": "CNTR-K8-000930",
            "title": "The Kubernetes Scheduler must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL).",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000382"
            ]
        },
        {
            "rule": "V-242412",
            "stig_id": "CNTR-K8-000940",
            "title": "The Kubernetes Controllers must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL).",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000382"
            ]
        },
        {
            "rule": "V-242413",
            "stig_id": "CNTR-K8-000950",
            "title": "The Kubernetes etcd must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL).",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000382"
            ]
        },
        {
            "rule": "V-242414",
            "stig_id": "CNTR-K8-000960",
            "title": "The Kubernetes cluster must use non-privileged host ports for user pods.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000382"
            ]
        },
        {
            "rule": "V-220705",
            "stig_id": "WN10-00-000035",
            "title": "The operating system must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-001774"
            ]
        },
        {
            "rule": "V-220714",
            "stig_id": "WN10-00-000080",
            "title": "Only authorized user accounts must be allowed to create or run virtual machines on Windows 10 systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220718",
            "stig_id": "WN10-00-000100",
            "title": "Internet Information System (IIS) or its subcomponents must not be installed on a workstation.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220719",
            "stig_id": "WN10-00-000105",
            "title": "Simple Network Management Protocol (SNMP) must not be installed on the system.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000382"
            ]
        },
        {
            "rule": "V-220720",
            "stig_id": "WN10-00-000110",
            "title": "Simple TCP/IP Services must not be installed on the system.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220721",
            "stig_id": "WN10-00-000115",
            "title": "The Telnet Client must not be installed on the system.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000382"
            ]
        },
        {
            "rule": "V-220722",
            "stig_id": "WN10-00-000120",
            "title": "The TFTP Client must not be installed on the system.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000382"
            ]
        },
        {
            "rule": "V-220728",
            "stig_id": "WN10-00-000155",
            "title": "The Windows PowerShell 2.0 feature must be disabled on the system.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220729",
            "stig_id": "WN10-00-000160",
            "title": "The Server Message Block (SMB) v1 protocol must be disabled on the system.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220730",
            "stig_id": "WN10-00-000165",
            "title": "The Server Message Block (SMB) v1 protocol must be disabled on the SMB server.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220731",
            "stig_id": "WN10-00-000170",
            "title": "The Server Message Block (SMB) v1 protocol must be disabled on the SMB client.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220732",
            "stig_id": "WN10-00-000175",
            "title": "The Secondary Logon service must be disabled on Windows 10.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220734",
            "stig_id": "WN10-00-000210",
            "title": "Bluetooth must be turned off unless approved by the organization.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220735",
            "stig_id": "WN10-00-000220",
            "title": "Bluetooth must be turned off when not in use.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220792",
            "stig_id": "WN10-CC-000005",
            "title": "Camera access from the lock screen must be disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220793",
            "stig_id": "WN10-CC-000007",
            "title": "Windows 10 must cover or disable the built-in or attached camera when not in use.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220794",
            "stig_id": "WN10-CC-000010",
            "title": "The display of slide shows on the lock screen must be disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220800",
            "stig_id": "WN10-CC-000038",
            "title": "WDigest Authentication must be disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220801",
            "stig_id": "WN10-CC-000039",
            "title": "Run as different user must be removed from context menus.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220803",
            "stig_id": "WN10-CC-000044",
            "title": "Internet connection sharing must be disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220815",
            "stig_id": "WN10-CC-000100",
            "title": "Downloading print driver packages over HTTP must be prevented.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220816",
            "stig_id": "WN10-CC-000105",
            "title": "Web publishing and online ordering wizards must be prevented from downloading a list of providers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220817",
            "stig_id": "WN10-CC-000110",
            "title": "Printing over HTTP must be prevented.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220819",
            "stig_id": "WN10-CC-000120",
            "title": "The network selection user interface (UI) must not be displayed on the logon screen.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220820",
            "stig_id": "WN10-CC-000130",
            "title": "Local users on domain-joined computers must not be enumerated.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220826",
            "stig_id": "WN10-CC-000175",
            "title": "The Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft.",
            "severity": "low",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220827",
            "stig_id": "WN10-CC-000180",
            "title": "Autoplay must be turned off for non-volume devices.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-220828",
            "stig_id": "WN10-CC-000185",
            "title": "The default autorun behavior must be configured to prevent autorun commands.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-220829",
            "stig_id": "WN10-CC-000190",
            "title": "Autoplay must be disabled for all drives.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-220831",
            "stig_id": "WN10-CC-000197",
            "title": "Microsoft consumer experiences must be turned off.",
            "severity": "low",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220836",
            "stig_id": "WN10-CC-000210",
            "title": "The Windows Defender SmartScreen for Explorer must be enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220845",
            "stig_id": "WN10-CC-000252",
            "title": "Windows 10 must be configured to disable Windows Game Recording and Broadcasting.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220854",
            "stig_id": "WN10-CC-000300",
            "title": "Basic authentication for RSS feeds over HTTP must not be used.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220855",
            "stig_id": "WN10-CC-000305",
            "title": "Indexing of encrypted files must be turned off.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220870",
            "stig_id": "WN10-CC-000370",
            "title": "The convenience PIN for Windows 10 must be disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220871",
            "stig_id": "WN10-CC-000385",
            "title": "Windows Ink Workspace must be configured to disallow access above the lock.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220872",
            "stig_id": "WN10-CC-000390",
            "title": "Windows 10 should be configured to prevent users from receiving suggestions for third-party or additional applications.",
            "severity": "low",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-220954",
            "stig_id": "WN10-UC-000015",
            "title": "Toast notifications to the lock screen must be turned off.",
            "severity": "low",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-257593",
            "stig_id": "WN10-00-000395",
            "title": "Windows 10 must not have portproxy enabled or in use.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-268315",
            "stig_id": "WN10-00-000107",
            "title": "Copilot in Windows must be disabled for Windows 10.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000382"
            ]
        },
        {
            "rule": "V-253262",
            "stig_id": "WN11-00-000035",
            "title": "The operating system must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-001774"
            ]
        },
        {
            "rule": "V-253275",
            "stig_id": "WN11-00-000100",
            "title": "Internet Information System (IIS) or its subcomponents must not be installed on a workstation.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253276",
            "stig_id": "WN11-00-000105",
            "title": "Simple Network Management Protocol (SNMP) must not be installed on the system.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000382"
            ]
        },
        {
            "rule": "V-253277",
            "stig_id": "WN11-00-000110",
            "title": "Simple TCP/IP Services must not be installed on the system.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253278",
            "stig_id": "WN11-00-000115",
            "title": "The Telnet Client must not be installed on the system.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000382"
            ]
        },
        {
            "rule": "V-253279",
            "stig_id": "WN11-00-000120",
            "title": "The TFTP Client must not be installed on the system.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000382"
            ]
        },
        {
            "rule": "V-253285",
            "stig_id": "WN11-00-000155",
            "title": "The Windows PowerShell 2.0 feature must be disabled on the system.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253286",
            "stig_id": "WN11-00-000160",
            "title": "The Server Message Block (SMB) v1 protocol must be disabled on the system.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253287",
            "stig_id": "WN11-00-000165",
            "title": "The Server Message Block (SMB) v1 protocol must be disabled on the SMB server.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253288",
            "stig_id": "WN11-00-000170",
            "title": "The Server Message Block (SMB) v1 protocol must be disabled on the SMB client.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253289",
            "stig_id": "WN11-00-000175",
            "title": "The Secondary Logon service must be disabled on Windows 11.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253291",
            "stig_id": "WN11-00-000210",
            "title": "Bluetooth must be turned off unless approved by the organization.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253292",
            "stig_id": "WN11-00-000220",
            "title": "Bluetooth must be turned off when not in use.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253350",
            "stig_id": "WN11-CC-000005",
            "title": "Camera access from the lock screen must be disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253351",
            "stig_id": "WN11-CC-000007",
            "title": "Windows 11 must cover or disable the built-in or attached camera when not in use.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253352",
            "stig_id": "WN11-CC-000010",
            "title": "The display of slide shows on the lock screen must be disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253358",
            "stig_id": "WN11-CC-000038",
            "title": "WDigest Authentication must be disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253359",
            "stig_id": "WN11-CC-000039",
            "title": "Run as different user must be removed from context menus.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253361",
            "stig_id": "WN11-CC-000044",
            "title": "Internet connection sharing must be disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253374",
            "stig_id": "WN11-CC-000100",
            "title": "Downloading print driver packages over HTTP must be prevented.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253375",
            "stig_id": "WN11-CC-000105",
            "title": "Web publishing and online ordering wizards must be prevented from downloading a list of providers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253376",
            "stig_id": "WN11-CC-000110",
            "title": "Printing over HTTP must be prevented.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253378",
            "stig_id": "WN11-CC-000120",
            "title": "The network selection user interface (UI) must not be displayed on the logon screen.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253379",
            "stig_id": "WN11-CC-000130",
            "title": "Local users on domain-joined computers must not be enumerated.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253385",
            "stig_id": "WN11-CC-000175",
            "title": "The Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft.",
            "severity": "low",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253386",
            "stig_id": "WN11-CC-000180",
            "title": "Autoplay must be turned off for non-volume devices.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-253387",
            "stig_id": "WN11-CC-000185",
            "title": "The default autorun behavior must be configured to prevent autorun commands.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-253388",
            "stig_id": "WN11-CC-000190",
            "title": "Autoplay must be disabled for all drives.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-253390",
            "stig_id": "WN11-CC-000197",
            "title": "Microsoft consumer experiences must be turned off.",
            "severity": "low",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253395",
            "stig_id": "WN11-CC-000210",
            "title": "The Microsoft Defender SmartScreen for Explorer must be enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253399",
            "stig_id": "WN11-CC-000252",
            "title": "Windows 11 must be configured to disable Windows Game Recording and Broadcasting.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253408",
            "stig_id": "WN11-CC-000300",
            "title": "Basic authentication for RSS feeds over HTTP must not be used.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253409",
            "stig_id": "WN11-CC-000305",
            "title": "Indexing of encrypted files must be turned off.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253423",
            "stig_id": "WN11-CC-000370",
            "title": "The convenience PIN for Windows 11 must be disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253425",
            "stig_id": "WN11-CC-000390",
            "title": "Windows 11 must be configured to prevent users from receiving suggestions for third-party or additional applications.",
            "severity": "low",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-253477",
            "stig_id": "WN11-UC-000015",
            "title": "Toast notifications to the lock screen must be turned off.",
            "severity": "low",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-257592",
            "stig_id": "WN11-00-000395",
            "title": "Windows 11 must not have portproxy enabled or in use.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-268317",
            "stig_id": "WN11-00-000125",
            "title": "Copilot in Windows must be disabled for Windows 11",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000382"
            ]
        },
        {
            "rule": "V-205677",
            "stig_id": "WN19-00-000270",
            "title": "Windows Server 2019 must have the roles and features required by the system documented.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-205678",
            "stig_id": "WN19-00-000320",
            "title": "Windows Server 2019 must not have the Fax Server role installed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-205679",
            "stig_id": "WN19-00-000340",
            "title": "Windows Server 2019 must not have the Peer Name Resolution Protocol installed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-205680",
            "stig_id": "WN19-00-000350",
            "title": "Windows Server 2019 must not have Simple TCP/IP Services installed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-205681",
            "stig_id": "WN19-00-000370",
            "title": "Windows Server 2019 must not have the TFTP Client installed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-205682",
            "stig_id": "WN19-00-000380",
            "title": "Windows Server 2019 must not have the Server Message Block (SMB) v1 protocol installed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-205683",
            "stig_id": "WN19-00-000390",
            "title": "Windows Server 2019 must have the Server Message Block (SMB) v1 protocol disabled on the SMB server.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-205684",
            "stig_id": "WN19-00-000400",
            "title": "Windows Server 2019 must have the Server Message Block (SMB) v1 protocol disabled on the SMB client.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-205685",
            "stig_id": "WN19-00-000410",
            "title": "Windows Server 2019 must not have Windows PowerShell 2.0 installed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-205686",
            "stig_id": "WN19-CC-000010",
            "title": "Windows Server 2019 must prevent the display of slide shows on the lock screen.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-205687",
            "stig_id": "WN19-CC-000020",
            "title": "Windows Server 2019 must have WDigest Authentication disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-205688",
            "stig_id": "WN19-CC-000150",
            "title": "Windows Server 2019 downloading print driver packages over HTTP must be turned off.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-205689",
            "stig_id": "WN19-CC-000160",
            "title": "Windows Server 2019 printing over HTTP must be turned off.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-205690",
            "stig_id": "WN19-CC-000170",
            "title": "Windows Server 2019 network selection user interface (UI) must not be displayed on the logon screen.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-205691",
            "stig_id": "WN19-CC-000200",
            "title": "Windows Server 2019 Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft.",
            "severity": "low",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-205692",
            "stig_id": "WN19-CC-000300",
            "title": "Windows Server 2019 Windows Defender SmartScreen must be enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-205693",
            "stig_id": "WN19-CC-000400",
            "title": "Windows Server 2019 must disable Basic authentication for RSS feeds over HTTP.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-205694",
            "stig_id": "WN19-CC-000410",
            "title": "Windows Server 2019 must prevent Indexing of encrypted files.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-205695",
            "stig_id": "WN19-DC-000130",
            "title": "Windows Server 2019 domain controllers must run on a machine dedicated to that function.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-205696",
            "stig_id": "WN19-MS-000030",
            "title": "Windows Server 2019 local users on domain-joined member servers must not be enumerated.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-205697",
            "stig_id": "WN19-00-000330",
            "title": "Windows Server 2019 must not have the Microsoft FTP service installed unless required by the organization.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000382"
            ]
        },
        {
            "rule": "V-205698",
            "stig_id": "WN19-00-000360",
            "title": "Windows Server 2019 must not have the Telnet Client installed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000382"
            ]
        },
        {
            "rule": "V-205804",
            "stig_id": "WN19-CC-000210",
            "title": "Windows Server 2019 Autoplay must be turned off for non-volume devices.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-205805",
            "stig_id": "WN19-CC-000220",
            "title": "Windows Server 2019 default AutoRun behavior must be configured to prevent AutoRun commands.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-205806",
            "stig_id": "WN19-CC-000230",
            "title": "Windows Server 2019 AutoPlay must be disabled for all drives.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-205807",
            "stig_id": "WN19-00-000080",
            "title": "Windows Server 2019 must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-001774"
            ]
        },
        {
            "rule": "V-254245",
            "stig_id": "WN22-00-000080",
            "title": "Windows Server 2022 must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-001774"
            ]
        },
        {
            "rule": "V-254264",
            "stig_id": "WN22-00-000270",
            "title": "Windows Server 2022 must have the roles and features required by the system documented.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-254269",
            "stig_id": "WN22-00-000320",
            "title": "Windows Server 2022 must not have the Fax Server role installed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-254270",
            "stig_id": "WN22-00-000330",
            "title": "Windows Server 2022 must not have the Microsoft FTP service installed unless required by the organization.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000382"
            ]
        },
        {
            "rule": "V-254271",
            "stig_id": "WN22-00-000340",
            "title": "Windows Server 2022 must not have the Peer Name Resolution Protocol installed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-254272",
            "stig_id": "WN22-00-000350",
            "title": "Windows Server 2022 must not have Simple TCP/IP Services installed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-254273",
            "stig_id": "WN22-00-000360",
            "title": "Windows Server 2022 must not have the Telnet Client installed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000382"
            ]
        },
        {
            "rule": "V-254274",
            "stig_id": "WN22-00-000370",
            "title": "Windows Server 2022 must not have the TFTP Client installed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-254275",
            "stig_id": "WN22-00-000380",
            "title": "Windows Server 2022 must not the Server Message Block (SMB) v1 protocol installed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-254276",
            "stig_id": "WN22-00-000390",
            "title": "Windows Server 2022 must have the Server Message Block (SMB) v1 protocol disabled on the SMB server.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-254277",
            "stig_id": "WN22-00-000400",
            "title": "Windows Server 2022 must have the Server Message Block (SMB) v1 protocol disabled on the SMB client.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-254278",
            "stig_id": "WN22-00-000410",
            "title": "Windows Server 2022 must not have Windows PowerShell 2.0 installed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-254333",
            "stig_id": "WN22-CC-000010",
            "title": "Windows Server 2022 must prevent the display of slide shows on the lock screen.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-254334",
            "stig_id": "WN22-CC-000020",
            "title": "Windows Server 2022 must have WDigest Authentication disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-254346",
            "stig_id": "WN22-CC-000150",
            "title": "Windows Server 2022 downloading print driver packages over HTTP must be turned off.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-254347",
            "stig_id": "WN22-CC-000160",
            "title": "Windows Server 2022 printing over HTTP must be turned off.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-254348",
            "stig_id": "WN22-CC-000170",
            "title": "Windows Server 2022 network selection user interface (UI) must not be displayed on the logon screen.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-254351",
            "stig_id": "WN22-CC-000200",
            "title": "Windows Server 2022 Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft.",
            "severity": "low",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-254352",
            "stig_id": "WN22-CC-000210",
            "title": "Windows Server 2022 Autoplay must be turned off for nonvolume devices.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-254353",
            "stig_id": "WN22-CC-000220",
            "title": "Windows Server 2022 default AutoRun behavior must be configured to prevent AutoRun commands.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-254354",
            "stig_id": "WN22-CC-000230",
            "title": "Windows Server 2022 AutoPlay must be disabled for all drives.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-254361",
            "stig_id": "WN22-CC-000300",
            "title": "Windows Server 2022 Microsoft Defender antivirus SmartScreen must be enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-254371",
            "stig_id": "WN22-CC-000400",
            "title": "Windows Server 2022 must disable Basic authentication for RSS feeds over HTTP.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-254372",
            "stig_id": "WN22-CC-000410",
            "title": "Windows Server 2022 must prevent Indexing of encrypted files.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-254397",
            "stig_id": "WN22-DC-000130",
            "title": "Windows Server 2022 domain controllers must run on a machine dedicated to that function.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-254430",
            "stig_id": "WN22-MS-000030",
            "title": "Windows Server 2022 local users on domain-joined member servers must not be enumerated.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-230485",
            "stig_id": "RHEL-08-030741",
            "title": "RHEL 8 must disable the chrony daemon from acting as a server.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-230486",
            "stig_id": "RHEL-08-030742",
            "title": "RHEL 8 must disable network management of the chrony daemon.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-230487",
            "stig_id": "RHEL-08-040000",
            "title": "RHEL 8 must not have the telnet-server package installed.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-230488",
            "stig_id": "RHEL-08-040001",
            "title": "RHEL 8 must not have any automated bug reporting tools installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-230489",
            "stig_id": "RHEL-08-040002",
            "title": "RHEL 8 must not have the sendmail package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-230491",
            "stig_id": "RHEL-08-040004",
            "title": "RHEL 8 must enable mitigations against processor-based vulnerabilities.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-230492",
            "stig_id": "RHEL-08-040010",
            "title": "RHEL 8 must not have the rsh-server package installed.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-230493",
            "stig_id": "RHEL-08-040020",
            "title": "RHEL 8 must cover or disable the built-in or attached camera when not in use.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-230494",
            "stig_id": "RHEL-08-040021",
            "title": "RHEL 8 must disable the asynchronous transfer mode (ATM) protocol.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-230495",
            "stig_id": "RHEL-08-040022",
            "title": "RHEL 8 must disable the controller area network (CAN) protocol.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-230496",
            "stig_id": "RHEL-08-040023",
            "title": "RHEL 8 must disable the stream control transmission protocol (SCTP).",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-230497",
            "stig_id": "RHEL-08-040024",
            "title": "RHEL 8 must disable the transparent inter-process communication (TIPC) protocol.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-230498",
            "stig_id": "RHEL-08-040025",
            "title": "RHEL 8 must disable mounting of cramfs.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-230499",
            "stig_id": "RHEL-08-040026",
            "title": "RHEL 8 must disable IEEE 1394 (FireWire) Support.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-230500",
            "stig_id": "RHEL-08-040030",
            "title": "RHEL 8 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000382"
            ]
        },
        {
            "rule": "V-230508",
            "stig_id": "RHEL-08-040120",
            "title": "RHEL 8 must mount /dev/shm with the nodev option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-230509",
            "stig_id": "RHEL-08-040121",
            "title": "RHEL 8 must mount /dev/shm with the nosuid option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-230510",
            "stig_id": "RHEL-08-040122",
            "title": "RHEL 8 must mount /dev/shm with the noexec option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-230511",
            "stig_id": "RHEL-08-040123",
            "title": "RHEL 8 must mount /tmp with the nodev option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-230512",
            "stig_id": "RHEL-08-040124",
            "title": "RHEL 8 must mount /tmp with the nosuid option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-230513",
            "stig_id": "RHEL-08-040125",
            "title": "RHEL 8 must mount /tmp with the noexec option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-230514",
            "stig_id": "RHEL-08-040126",
            "title": "RHEL 8 must mount /var/log with the nodev option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-230515",
            "stig_id": "RHEL-08-040127",
            "title": "RHEL 8 must mount /var/log with the nosuid option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-230516",
            "stig_id": "RHEL-08-040128",
            "title": "RHEL 8 must mount /var/log with the noexec option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-230517",
            "stig_id": "RHEL-08-040129",
            "title": "RHEL 8 must mount /var/log/audit with the nodev option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-230518",
            "stig_id": "RHEL-08-040130",
            "title": "RHEL 8 must mount /var/log/audit with the nosuid option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-230519",
            "stig_id": "RHEL-08-040131",
            "title": "RHEL 8 must mount /var/log/audit with the noexec option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-230520",
            "stig_id": "RHEL-08-040132",
            "title": "RHEL 8 must mount /var/tmp with the nodev option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-230521",
            "stig_id": "RHEL-08-040133",
            "title": "RHEL 8 must mount /var/tmp with the nosuid option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-230522",
            "stig_id": "RHEL-08-040134",
            "title": "RHEL 8 must mount /var/tmp with the noexec option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-230523",
            "stig_id": "RHEL-08-040135",
            "title": "The RHEL 8 fapolicy module must be installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-230559",
            "stig_id": "RHEL-08-040370",
            "title": "The gssproxy package must not be installed unless mission essential on RHEL 8.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-244545",
            "stig_id": "RHEL-08-040136",
            "title": "The RHEL 8 fapolicy module must be enabled.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-244546",
            "stig_id": "RHEL-08-040137",
            "title": "The RHEL 8 fapolicy module must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-257795",
            "stig_id": "RHEL-09-212050",
            "title": "RHEL 9 must enable mitigations against processor-based vulnerabilities.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000381",
                "CCI-002824"
            ]
        },
        {
            "rule": "V-257804",
            "stig_id": "RHEL-09-213045",
            "title": "RHEL 9 must be configured to disable the Asynchronous Transfer Mode kernel module.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-257805",
            "stig_id": "RHEL-09-213050",
            "title": "RHEL 9 must be configured to disable the Controller Area Network kernel module.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-257806",
            "stig_id": "RHEL-09-213055",
            "title": "RHEL 9 must be configured to disable the FireWire kernel module.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-257807",
            "stig_id": "RHEL-09-213060",
            "title": "RHEL 9 must disable the Stream Control Transmission Protocol (SCTP) kernel module.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-257808",
            "stig_id": "RHEL-09-213065",
            "title": "RHEL 9 must disable the Transparent Inter Process Communication (TIPC) kernel module.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-257826",
            "stig_id": "RHEL-09-215015",
            "title": "RHEL 9 must not have a File Transfer Protocol (FTP) server package installed.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000197",
                "CCI-000381"
            ]
        },
        {
            "rule": "V-257827",
            "stig_id": "RHEL-09-215020",
            "title": "RHEL 9 must not have the sendmail package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-257828",
            "stig_id": "RHEL-09-215025",
            "title": "RHEL 9 must not have the nfs-utils package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-257829",
            "stig_id": "RHEL-09-215030",
            "title": "RHEL 9 must not have the ypserv package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-257830",
            "stig_id": "RHEL-09-215035",
            "title": "RHEL 9 must not have the rsh-server package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-257831",
            "stig_id": "RHEL-09-215040",
            "title": "RHEL 9 must not have the telnet-server package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-257832",
            "stig_id": "RHEL-09-215045",
            "title": "RHEL 9 must not have the gssproxy package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-257833",
            "stig_id": "RHEL-09-215050",
            "title": "RHEL 9 must not have the iprutils package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-257834",
            "stig_id": "RHEL-09-215055",
            "title": "RHEL 9 must not have the tuned package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-257850",
            "stig_id": "RHEL-09-231045",
            "title": "RHEL 9 must prevent device files from being interpreted on file systems that contain user home directories.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-257851",
            "stig_id": "RHEL-09-231050",
            "title": "RHEL 9 must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-257860",
            "stig_id": "RHEL-09-231095",
            "title": "RHEL 9 must mount /boot with the nodev option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-257861",
            "stig_id": "RHEL-09-231100",
            "title": "RHEL 9 must prevent files with the setuid and setgid bit set from being executed on the /boot directory.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-257862",
            "stig_id": "RHEL-09-231105",
            "title": "RHEL 9 must prevent files with the setuid and setgid bit set from being executed on the /boot/efi directory.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-257863",
            "stig_id": "RHEL-09-231110",
            "title": "RHEL 9 must mount /dev/shm with the nodev option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-257864",
            "stig_id": "RHEL-09-231115",
            "title": "RHEL 9 must mount /dev/shm with the noexec option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-257865",
            "stig_id": "RHEL-09-231120",
            "title": "RHEL 9 must mount /dev/shm with the nosuid option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-257866",
            "stig_id": "RHEL-09-231125",
            "title": "RHEL 9 must mount /tmp with the nodev option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-257867",
            "stig_id": "RHEL-09-231130",
            "title": "RHEL 9 must mount /tmp with the noexec option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-257868",
            "stig_id": "RHEL-09-231135",
            "title": "RHEL 9 must mount /tmp with the nosuid option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-257869",
            "stig_id": "RHEL-09-231140",
            "title": "RHEL 9 must mount /var with the nodev option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-257870",
            "stig_id": "RHEL-09-231145",
            "title": "RHEL 9 must mount /var/log with the nodev option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-257871",
            "stig_id": "RHEL-09-231150",
            "title": "RHEL 9 must mount /var/log with the noexec option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-257872",
            "stig_id": "RHEL-09-231155",
            "title": "RHEL 9 must mount /var/log with the nosuid option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-257873",
            "stig_id": "RHEL-09-231160",
            "title": "RHEL 9 must mount /var/log/audit with the nodev option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-257874",
            "stig_id": "RHEL-09-231165",
            "title": "RHEL 9 must mount /var/log/audit with the noexec option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-257875",
            "stig_id": "RHEL-09-231170",
            "title": "RHEL 9 must mount /var/log/audit with the nosuid option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-257876",
            "stig_id": "RHEL-09-231175",
            "title": "RHEL 9 must mount /var/tmp with the nodev option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-257877",
            "stig_id": "RHEL-09-231180",
            "title": "RHEL 9 must mount /var/tmp with the noexec option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-257878",
            "stig_id": "RHEL-09-231185",
            "title": "RHEL 9 must mount /var/tmp with the nosuid option.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-257880",
            "stig_id": "RHEL-09-231195",
            "title": "RHEL 9 must disable mounting of cramfs.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000381"
            ]
        },
        {
            "rule": "V-257935",
            "stig_id": "RHEL-09-251010",
            "title": "RHEL 9 must have the firewalld package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000382",
                "CCI-002314",
                "CCI-002322"
            ]
        },
        {
            "rule": "V-257936",
            "stig_id": "RHEL-09-251015",
            "title": "The firewalld service on RHEL 9 must be active.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000382",
                "CCI-002314"
            ]
        },
        {
            "rule": "V-257940",
            "stig_id": "RHEL-09-251035",
            "title": "RHEL 9 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000382"
            ]
        },
        {
            "rule": "V-257946",
            "stig_id": "RHEL-09-252025",
            "title": "RHEL 9 must disable the chrony daemon from acting as a server.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000381",
                "CCI-000382"
            ]
        },
        {
            "rule": "V-257947",
            "stig_id": "RHEL-09-252030",
            "title": "RHEL 9 must disable network management of the chrony daemon.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000381",
                "CCI-000382"
            ]
        },
        {
            "rule": "V-258016",
            "stig_id": "RHEL-09-271030",
            "title": "RHEL 9 must disable the graphical user interface autorun function unless required.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        },
        {
            "rule": "V-258039",
            "stig_id": "RHEL-09-291035",
            "title": "RHEL 9 Bluetooth must be disabled.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000381",
                "CCI-001443"
            ]
        },
        {
            "rule": "V-258089",
            "stig_id": "RHEL-09-433010",
            "title": "RHEL 9 fapolicy module must be installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764",
                "CCI-001774"
            ]
        },
        {
            "rule": "V-258090",
            "stig_id": "RHEL-09-433015",
            "title": "RHEL 9 fapolicy module must be enabled.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764",
                "CCI-001774"
            ]
        },
        {
            "rule": "V-270180",
            "stig_id": "RHEL-09-433016",
            "title": "The RHEL 9 fapolicy module must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001764"
            ]
        }
    ]
}