SRG-OS-000004-GPOS-00004 Controls

STIG IDVersionTitleProduct
ALMA-09-004970V1R4AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.AlmaLinux OS 9
ALMA-09-005080V1R4AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.AlmaLinux OS 9
ALMA-09-005190V1R4AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.AlmaLinux OS 9
ALMA-09-005300V1R4AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.AlmaLinux OS 9
ALMA-09-005410V1R4AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.AlmaLinux OS 9
ALMA-09-005960V1R4AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.AlmaLinux OS 9
ALMA-09-006070V1R4AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect the files within /etc/sudoers.d/AlmaLinux OS 9
APPL-13-001001V1R5The macOS system must generate audit records for all account creations, modifications, disabling, and termination events; privileged activities or other system-level access; all kernel module load, unload, and restart actions; all program initiations; and organizationally defined events for all nonlocal maintenance and diagnostic sessions.macOS 13 - Ventura
APPL-14-001001V2R4The macOS system must be configured to audit all administrative action events.macOS 14 - Sonoma
APPL-15-001001V1R5The macOS system must be configured to audit all administrative action events.macOS 15 - Sequoia
OL07-00-030870V3R3The Oracle Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.Oracle Linux 7
OL07-00-030871V3R3The Oracle Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.Oracle Linux 7
OL07-00-030872V3R3The Oracle Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.Oracle Linux 7
OL07-00-030873V3R3The Oracle Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.Oracle Linux 7
OL07-00-030874V3R3The Oracle Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.Oracle Linux 7
OL08-00-030130V2R6OL 8 must generate audit records for all account creation events that affect "/etc/shadow".Oracle Linux 8
OL08-00-030140V2R6OL 8 must generate audit records for all account creation events that affect "/etc/security/opasswd".Oracle Linux 8
OL08-00-030150V2R6OL 8 must generate audit records for all account creation events that affect "/etc/passwd".Oracle Linux 8
OL08-00-030160V2R6OL 8 must generate audit records for all account creation events that affect "/etc/gshadow".Oracle Linux 8
OL08-00-030170V2R6OL 8 must generate audit records for all account creation events that affect "/etc/group".Oracle Linux 8
OL08-00-030171V2R6OL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/sudoers".Oracle Linux 8
OL08-00-030172V2R6OL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/sudoers.d/".Oracle Linux 8
OL09-00-000500V1R3OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.Oracle Linux 9
OL09-00-000505V1R3OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory.Oracle Linux 9
OL09-00-000510V1R3OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.Oracle Linux 9
OL09-00-000515V1R3OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.Oracle Linux 9
OL09-00-000520V1R3OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.Oracle Linux 9
OL09-00-000525V1R3OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.Oracle Linux 9
OL09-00-000530V1R3OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.Oracle Linux 9
RHEL-07-030870V3R9The Red Hat Enterprise Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.Red Hat Enterprise Linux 7
RHEL-07-030871V3R9The Red Hat Enterprise Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.Red Hat Enterprise Linux 7
RHEL-07-030872V3R9The Red Hat Enterprise Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.Red Hat Enterprise Linux 7
RHEL-07-030873V3R9The Red Hat Enterprise Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.Red Hat Enterprise Linux 7
RHEL-07-030874V3R9The Red Hat Enterprise Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.Red Hat Enterprise Linux 7
RHEL-09-654215V2R6RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.Red Hat Enterprise Linux 9
RHEL-09-654220V2R6RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory.Red Hat Enterprise Linux 9
RHEL-09-654225V2R6RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.Red Hat Enterprise Linux 9
RHEL-09-654230V2R6RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.Red Hat Enterprise Linux 9
RHEL-09-654235V2R6RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.Red Hat Enterprise Linux 9
RHEL-09-654240V2R6RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.Red Hat Enterprise Linux 9
RHEL-09-654245V2R6RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.Red Hat Enterprise Linux 9
SLES-12-020200V3R2The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.SUSE Linux Enterprise 12
SLES-12-020210V3R2The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.SUSE Linux Enterprise 12
SLES-12-020220V3R2The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.SUSE Linux Enterprise 12
SLES-12-020230V3R2The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.SUSE Linux Enterprise 12
SLES-12-020590V3R2The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.SUSE Linux Enterprise 12
SLES-15-030000V2R4The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.SUSE Linux Enterprise 15
SLES-15-030010V2R4The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.SUSE Linux Enterprise 15
SLES-15-030020V2R4The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.SUSE Linux Enterprise 15
SLES-15-030030V2R4The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.SUSE Linux Enterprise 15
SLES-15-030040V2R4The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.SUSE Linux Enterprise 15
TOSS-04-030000V2R3TOSS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.Tri-Lab Operating System Stack
UBTU-20-010100V2R3The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.Ubuntu 20.04
UBTU-20-010101V2R3The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.Ubuntu 20.04
UBTU-20-010102V2R3The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.Ubuntu 20.04
UBTU-20-010103V2R3The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.Ubuntu 20.04
UBTU-20-010104V2R3The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.Ubuntu 20.04
UBTU-22-654130V2R6Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.Ubuntu 22.04
UBTU-22-654135V2R6Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.Ubuntu 22.04
UBTU-22-654140V2R6Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.Ubuntu 22.04
UBTU-22-654145V2R6Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.Ubuntu 22.04
UBTU-22-654150V2R6Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.Ubuntu 22.04
UBTU-24-200280V1R1Ubuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.Ubuntu 24.04
UBTU-24-200290V1R1Ubuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.Ubuntu 24.04
UBTU-24-200300V1R1Ubuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.Ubuntu 24.04
UBTU-24-200310V1R1Ubuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.Ubuntu 24.04
UBTU-24-200320V1R1Ubuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.Ubuntu 24.04
WN10-AU-000030V3R4The system must be configured to audit Account Management - Security Group Management successes.Microsoft Windows 10
WN10-AU-000035V3R4The system must be configured to audit Account Management - User Account Management failures.Microsoft Windows 10
WN10-AU-000040V3R4The system must be configured to audit Account Management - User Account Management successes.Microsoft Windows 10
WN16-AU-000120V2R9Windows Server 2016 must be configured to audit Account Management - Security Group Management successes.Microsoft Windows Server 2016
WN16-AU-000140V2R9Windows Server 2016 must be configured to audit Account Management - User Account Management successes.Microsoft Windows Server 2016
WN16-AU-000150V2R9Windows Server 2016 must be configured to audit Account Management - User Account Management failures.Microsoft Windows Server 2016
WN16-DC-000230V2R9Windows Server 2016 must be configured to audit Account Management - Computer Account Management successes.Microsoft Windows Server 2016
WN19-AU-000100V3R6Windows Server 2019 must be configured to audit Account Management - Security Group Management successes.Microsoft Windows Server 2019
WN19-AU-000110V3R6Windows Server 2019 must be configured to audit Account Management - User Account Management successes.Microsoft Windows Server 2019
WN19-AU-000120V3R6Windows Server 2019 must be configured to audit Account Management - User Account Management failures.Microsoft Windows Server 2019
WN19-DC-000230V3R6Windows Server 2019 must be configured to audit Account Management - Computer Account Management successes.Microsoft Windows Server 2019
WN22-AU-000100V2R6Windows Server 2022 must be configured to audit Account Management - Security Group Management successes.Microsoft Windows Server 2022
WN22-AU-000110V2R6Windows Server 2022 must be configured to audit Account Management - User Account Management successes.Microsoft Windows Server 2022
WN22-AU-000120V2R6Windows Server 2022 must be configured to audit Account Management - User Account Management failures.Microsoft Windows Server 2022
WN22-DC-000230V2R6Windows Server 2022 must be configured to audit Account Management - Computer Account Management successes.Microsoft Windows Server 2022