SRG-OS-000062-GPOS-00031 Controls

STIG IDVersionTitleProduct
ALMA-09-045670V1R2AlmaLinux OS 9 audit system must audit local events.
OL08-00-030313V2R4OL 8 must generate audit records for any use of the "semanage" command.
OL08-00-030314V2R4OL 8 must generate audit records for any use of the "setfiles" command.
OL08-00-030315V2R4OL 8 must generate audit records for any use of the "userhelper" command.
OL09-00-000440V1R1OL 9 must have the audit package installed.
OL09-00-000441V1R1OL 9 audit service must be enabled.
OL09-00-000760V1R1OL 9 audit system must take appropriate action when an error writing to the audit storage volume occurs.
OL09-00-000765V1R1OL 9 audit system must take appropriate action when the audit storage volume is full.
OL09-00-000770V1R1OL 9 audit system must take appropriate action when the audit files have reached maximum size.
OL09-00-000800V1R1OL 9 audit system must audit local events.
OL09-00-002330V1R1OL 9 must enable Linux audit logging for the USBGuard daemon.
RHEL-08-030130V2R3RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
RHEL-08-030140V2R3RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.
RHEL-08-030150V2R3RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
RHEL-08-030160V2R3RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
RHEL-08-030170V2R3RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
RHEL-08-030171V2R3RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.
RHEL-08-030172V2R3RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/.
RHEL-08-030180V2R3The RHEL 8 audit package must be installed.
RHEL-08-030190V2R3Successful/unsuccessful uses of the su command in RHEL 8 must generate an audit record.
RHEL-08-030200V2R3The RHEL 8 audit system must be configured to audit any usage of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls.
RHEL-08-030250V2R3Successful/unsuccessful uses of the chage command in RHEL 8 must generate an audit record.
RHEL-08-030260V2R3Successful/unsuccessful uses of the chcon command in RHEL 8 must generate an audit record.
RHEL-08-030280V2R3Successful/unsuccessful uses of the ssh-agent in RHEL 8 must generate an audit record.
RHEL-08-030290V2R3Successful/unsuccessful uses of the passwd command in RHEL 8 must generate an audit record.
RHEL-08-030300V2R3Successful/unsuccessful uses of the mount command in RHEL 8 must generate an audit record.
RHEL-08-030301V2R3Successful/unsuccessful uses of the umount command in RHEL 8 must generate an audit record.
RHEL-08-030302V2R3Successful/unsuccessful uses of the mount syscall in RHEL 8 must generate an audit record.
RHEL-08-030310V2R3Successful/unsuccessful uses of the unix_update in RHEL 8 must generate an audit record.
RHEL-08-030311V2R3Successful/unsuccessful uses of postdrop in RHEL 8 must generate an audit record.
RHEL-08-030312V2R3Successful/unsuccessful uses of postqueue in RHEL 8 must generate an audit record.
RHEL-08-030313V2R3Successful/unsuccessful uses of semanage in RHEL 8 must generate an audit record.
RHEL-08-030314V2R3Successful/unsuccessful uses of setfiles in RHEL 8 must generate an audit record.
RHEL-08-030315V2R3Successful/unsuccessful uses of userhelper in RHEL 8 must generate an audit record.
RHEL-08-030316V2R3Successful/unsuccessful uses of setsebool in RHEL 8 must generate an audit record.
RHEL-08-030317V2R3Successful/unsuccessful uses of unix_chkpwd in RHEL 8 must generate an audit record.
RHEL-08-030320V2R3Successful/unsuccessful uses of the ssh-keysign in RHEL 8 must generate an audit record.
RHEL-08-030330V2R3Successful/unsuccessful uses of the setfacl command in RHEL 8 must generate an audit record.
RHEL-08-030340V2R3Successful/unsuccessful uses of the pam_timestamp_check command in RHEL 8 must generate an audit record.
RHEL-08-030350V2R3Successful/unsuccessful uses of the newgrp command in RHEL 8 must generate an audit record.
RHEL-08-030360V2R3Successful/unsuccessful uses of the init_module and finit_module system calls in RHEL 8 must generate an audit record.
RHEL-08-030361V2R3Successful/unsuccessful uses of the rename, unlink, rmdir, renameat, and unlinkat system calls in RHEL 8 must generate an audit record.
RHEL-08-030370V2R3Successful/unsuccessful uses of the gpasswd command in RHEL 8 must generate an audit record.
RHEL-08-030390V2R3Successful/unsuccessful uses of the delete_module command in RHEL 8 must generate an audit record.
RHEL-08-030400V2R3Successful/unsuccessful uses of the crontab command in RHEL 8 must generate an audit record.
RHEL-08-030410V2R3Successful/unsuccessful uses of the chsh command in RHEL 8 must generate an audit record.
RHEL-08-030420V2R3Successful/unsuccessful uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls in RHEL 8 must generate an audit record.
RHEL-08-030480V2R3Successful/unsuccessful uses of the chown, fchown, fchownat, and lchown system calls in RHEL 8 must generate an audit record.
RHEL-08-030490V2R3Successful/unsuccessful uses of the chmod, fchmod, and fchmodat system calls in RHEL 8 must generate an audit record.
RHEL-08-030550V2R3Successful/unsuccessful uses of the sudo command in RHEL 8 must generate an audit record.
RHEL-08-030560V2R3Successful/unsuccessful uses of the usermod command in RHEL 8 must generate an audit record.
RHEL-08-030570V2R3Successful/unsuccessful uses of the chacl command in RHEL 8 must generate an audit record.
RHEL-08-030580V2R3Successful/unsuccessful uses of the kmod command in RHEL 8 must generate an audit record.
RHEL-08-030590V2R3Successful/unsuccessful modifications to the faillock log file in RHEL 8 must generate an audit record.
RHEL-08-030600V2R3Successful/unsuccessful modifications to the lastlog file in RHEL 8 must generate an audit record.
RHEL-08-030601V2R3RHEL 8 must enable auditing of processes that start prior to the audit daemon.
RHEL-08-030603V2R3RHEL 8 must enable Linux audit logging for the USBGuard daemon.
RHEL-08-030181V2R3RHEL 8 audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.
RHEL-09-291025V2R4RHEL 9 must enable Linux audit logging for the USBGuard daemon.
RHEL-09-653010V2R4RHEL 9 audit package must be installed.
RHEL-09-653015V2R4RHEL 9 audit service must be enabled.
RHEL-09-653075V2R4RHEL 9 audit system must audit local events.
WN10-SO-000030V3R4Audit policy using subcategories must be enabled.
WN11-SO-000030V2R3Audit policy using subcategories must be enabled.
WN16-SO-000050V2R9Audit policy using subcategories must be enabled.
WN19-SO-000050V3R4Windows Server 2019 must force audit policy subcategory settings to override audit policy category settings.
WN22-SO-000050V2R4Windows Server 2022 must force audit policy subcategory settings to override audit policy category settings.