SRG-OS-000004-GPOS-00004 Controls

STIG IDVersionTitleProduct
ALMA-09-004970V1R2AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.
ALMA-09-005080V1R2AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
ALMA-09-005190V1R2AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
ALMA-09-005300V1R2AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.
ALMA-09-005410V1R2AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
ALMA-09-005960V1R2AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
ALMA-09-006070V1R2AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect the files within /etc/sudoers.d/
APPL-14-001001V2R3The macOS system must be configured to audit all administrative action events.
APPL-15-001001V1R3The macOS system must be configured to audit all administrative action events.
OL07-00-030870V3R2The Oracle Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
OL07-00-030871V3R2The Oracle Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
OL07-00-030872V3R2The Oracle Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
OL07-00-030873V3R2The Oracle Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
OL07-00-030874V3R2The Oracle Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.
OL08-00-030130V2R4OL 8 must generate audit records for all account creation events that affect "/etc/shadow".
OL08-00-030140V2R4OL 8 must generate audit records for all account creation events that affect "/etc/security/opasswd".
OL08-00-030150V2R4OL 8 must generate audit records for all account creation events that affect "/etc/passwd".
OL08-00-030160V2R4OL 8 must generate audit records for all account creation events that affect "/etc/gshadow".
OL08-00-030170V2R4OL 8 must generate audit records for all account creation events that affect "/etc/group".
OL08-00-030171V2R4OL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/sudoers".
OL08-00-030172V2R4OL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/sudoers.d/".
OL09-00-000500V1R1OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.
OL09-00-000505V1R1OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory.
OL09-00-000510V1R1OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
OL09-00-000515V1R1OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
OL09-00-000520V1R1OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
OL09-00-000525V1R1OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
OL09-00-000530V1R1OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
RHEL-07-030870V3R9The Red Hat Enterprise Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
RHEL-07-030871V3R9The Red Hat Enterprise Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
RHEL-07-030872V3R9The Red Hat Enterprise Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
RHEL-07-030873V3R9The Red Hat Enterprise Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
RHEL-07-030874V3R9The Red Hat Enterprise Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.
RHEL-09-654215V2R4RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.
RHEL-09-654220V2R4RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory.
RHEL-09-654225V2R4RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
RHEL-09-654230V2R4RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
RHEL-09-654235V2R4RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
RHEL-09-654240V2R4RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
RHEL-09-654245V2R4RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
SLES-12-020200V3R2The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
SLES-12-020210V3R2The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
SLES-12-020220V3R2The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
SLES-12-020230V3R2The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
SLES-12-020590V3R2The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
SLES-15-030000V2R4The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
SLES-15-030010V2R4The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
SLES-15-030020V2R4The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
SLES-15-030030V2R4The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.
SLES-15-030040V2R4The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
UBTU-20-010100V2R1The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
UBTU-20-010101V2R1The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
UBTU-20-010102V2R1The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
UBTU-20-010103V2R1The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
UBTU-20-010104V2R1The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
UBTU-22-654130V2R4Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
UBTU-22-654135V2R4Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
UBTU-22-654140V2R4Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
UBTU-22-654145V2R4Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
UBTU-22-654150V2R4Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
UBTU-24-200280V1R1Ubuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
UBTU-24-200290V1R1Ubuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
UBTU-24-200300V1R1Ubuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
UBTU-24-200310V1R1Ubuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
UBTU-24-200320V1R1Ubuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
WN10-AU-000030V3R4The system must be configured to audit Account Management - Security Group Management successes.
WN10-AU-000035V3R4The system must be configured to audit Account Management - User Account Management failures.
WN10-AU-000040V3R4The system must be configured to audit Account Management - User Account Management successes.
WN16-AU-000120V2R9Windows Server 2016 must be configured to audit Account Management - Security Group Management successes.
WN16-AU-000140V2R9Windows Server 2016 must be configured to audit Account Management - User Account Management successes.
WN16-AU-000150V2R9Windows Server 2016 must be configured to audit Account Management - User Account Management failures.
WN16-DC-000230V2R9Windows Server 2016 must be configured to audit Account Management - Computer Account Management successes.
WN19-AU-000100V3R4Windows Server 2019 must be configured to audit Account Management - Security Group Management successes.
WN19-AU-000110V3R4Windows Server 2019 must be configured to audit Account Management - User Account Management successes.
WN19-AU-000120V3R4Windows Server 2019 must be configured to audit Account Management - User Account Management failures.
WN19-DC-000230V3R4Windows Server 2019 must be configured to audit Account Management - Computer Account Management successes.
WN22-AU-000100V2R4Windows Server 2022 must be configured to audit Account Management - Security Group Management successes.
WN22-AU-000110V2R4Windows Server 2022 must be configured to audit Account Management - User Account Management successes.
WN22-AU-000120V2R4Windows Server 2022 must be configured to audit Account Management - User Account Management failures.
WN22-DC-000230V2R4Windows Server 2022 must be configured to audit Account Management - Computer Account Management successes.