SRG-OS-000327-GPOS-00127 Controls

STIG IDVersionTitleProduct
ALMA-09-007280V1R2AlmaLinux OS 9 must audit uses of the "execve" system call.
ALMA-09-031920V1R2AlmaLinux OS 9 must require users to provide authentication for privilege escalation.
ALMA-09-032030V1R2AlmaLinux OS 9 must require users to provide a password for privilege escalation.
ALMA-09-032140V1R2AlmaLinux OS 9 must not be configured to bypass password requirements for privilege escalation.
ALMA-09-032250V1R2AlmaLinux OS 9 must require reauthentication when using the "sudo" command.
OL07-00-030360V3R2The Oracle Linux operating system must audit all executions of privileged functions.
OL09-00-002362V1R1OL 9 must require users to reauthenticate for privilege escalation.
OL09-00-002363V1R1OL 9 must require users to provide a password for privilege escalation.
OL09-00-002364V1R1OL 9 must not be configured to bypass password requirements for privilege escalation.
RHEL-07-030360V3R9The Red Hat Enterprise Linux operating system must audit all executions of privileged functions.
SLES-12-020240V3R2The SUSE operating system must generate audit records for all uses of the privileged functions.
SLES-15-030640V2R4The SUSE operating system must generate audit records for all uses of the privileged functions.
WN10-AU-000105V3R4The system must be configured to audit Policy Change - Authentication Policy Change successes.
WN10-AU-000110V3R4The system must be configured to audit Privilege Use - Sensitive Privilege Use failures.
WN10-AU-000115V3R4The system must be configured to audit Privilege Use - Sensitive Privilege Use successes.
WN10-AU-000140V3R4The system must be configured to audit System - Security State Change successes.
WN10-AU-000150V3R4The system must be configured to audit System - Security System Extension successes.
WN10-AU-000155V3R4The system must be configured to audit System - System Integrity failures.
WN10-AU-000160V3R4The system must be configured to audit System - System Integrity successes.
WN11-AU-000110V2R3The system must be configured to audit Privilege Use - Sensitive Privilege Use failures.
WN16-AU-000100V2R9Windows Server 2016 must be configured to audit Account Management - Other Account Management Events successes.
WN16-AU-000170V2R9Windows Server 2016 must be configured to audit Detailed Tracking - Process Creation successes.
WN16-AU-000310V2R9Windows Server 2016 must be configured to audit Policy Change - Audit Policy Change successes.
WN16-AU-000320V2R9Windows Server 2016 must be configured to audit Policy Change - Audit Policy Change failures.
WN16-AU-000330V2R9Windows Server 2016 must be configured to audit Policy Change - Authentication Policy Change successes.
WN16-AU-000340V2R9Windows Server 2016 must be configured to audit Policy Change - Authorization Policy Change successes.
WN16-AU-000350V2R9Windows Server 2016 must be configured to audit Privilege Use - Sensitive Privilege Use successes.
WN16-AU-000360V2R9Windows Server 2016 must be configured to audit Privilege Use - Sensitive Privilege Use failures.
WN16-AU-000370V2R9Windows Server 2016 must be configured to audit System - IPsec Driver successes.
WN16-AU-000380V2R9Windows Server 2016 must be configured to audit System - IPsec Driver failures.
WN16-AU-000390V2R9Windows Server 2016 must be configured to audit System - Other System Events successes.
WN16-AU-000400V2R9Windows Server 2016 must be configured to audit System - Other System Events failures.
WN16-AU-000410V2R9Windows Server 2016 must be configured to audit System - Security State Change successes.
WN16-AU-000420V2R9Windows Server 2016 must be configured to audit System - Security System Extension successes.
WN16-AU-000440V2R9Windows Server 2016 must be configured to audit System - System Integrity successes.
WN16-AU-000450V2R9Windows Server 2016 must be configured to audit System - System Integrity failures.
WN16-DC-000170V2R9Active Directory Group Policy objects must be configured with proper audit settings.
WN16-DC-000180V2R9The Active Directory Domain object must be configured with proper audit settings.
WN16-DC-000190V2R9The Active Directory Infrastructure object must be configured with proper audit settings.
WN16-DC-000200V2R9The Active Directory Domain Controllers Organizational Unit (OU) object must be configured with proper audit settings.
WN16-DC-000210V2R9The Active Directory AdminSDHolder object must be configured with proper audit settings.
WN16-DC-000220V2R9The Active Directory RID Manager$ object must be configured with proper audit settings.
WN16-DC-000240V2R9Windows Server 2016 must be configured to audit DS Access - Directory Service Access successes.
WN16-DC-000250V2R9Windows Server 2016 must be configured to audit DS Access - Directory Service Access failures.
WN16-DC-000260V2R9Windows Server 2016 must be configured to audit DS Access - Directory Service Changes successes.
WN19-AU-000090V3R4Windows Server 2019 must be configured to audit Account Management - Other Account Management Events successes.
WN19-AU-000140V3R4Windows Server 2019 must be configured to audit Detailed Tracking - Process Creation successes.
WN19-AU-000260V3R4Windows Server 2019 must be configured to audit Policy Change - Audit Policy Change successes.
WN19-AU-000270V3R4Windows Server 2019 must be configured to audit Policy Change - Audit Policy Change failures.
WN19-AU-000280V3R4Windows Server 2019 must be configured to audit Policy Change - Authentication Policy Change successes.
WN19-AU-000290V3R4Windows Server 2019 must be configured to audit Policy Change - Authorization Policy Change successes.
WN19-AU-000300V3R4Windows Server 2019 must be configured to audit Privilege Use - Sensitive Privilege Use successes.
WN19-AU-000310V3R4Windows Server 2019 must be configured to audit Privilege Use - Sensitive Privilege Use failures.
WN19-AU-000320V3R4Windows Server 2019 must be configured to audit System - IPsec Driver successes.
WN19-AU-000330V3R4Windows Server 2019 must be configured to audit System - IPsec Driver failures.
WN19-AU-000340V3R4Windows Server 2019 must be configured to audit System - Other System Events successes.
WN19-AU-000350V3R4Windows Server 2019 must be configured to audit System - Other System Events failures.
WN19-AU-000360V3R4Windows Server 2019 must be configured to audit System - Security State Change successes.
WN19-AU-000370V3R4Windows Server 2019 must be configured to audit System - Security System Extension successes.
WN19-AU-000380V3R4Windows Server 2019 must be configured to audit System - System Integrity successes.
WN19-AU-000390V3R4Windows Server 2019 must be configured to audit System - System Integrity failures.
WN19-DC-000170V3R4Windows Server 2019 Active Directory Group Policy objects must be configured with proper audit settings.
WN19-DC-000180V3R4Windows Server 2019 Active Directory Domain object must be configured with proper audit settings.
WN19-DC-000190V3R4Windows Server 2019 Active Directory Infrastructure object must be configured with proper audit settings.
WN19-DC-000200V3R4Windows Server 2019 Active Directory Domain Controllers Organizational Unit (OU) object must be configured with proper audit settings.
WN19-DC-000210V3R4Windows Server 2019 Active Directory AdminSDHolder object must be configured with proper audit settings.
WN19-DC-000220V3R4Windows Server 2019 Active Directory RID Manager$ object must be configured with proper audit settings.
WN19-DC-000240V3R4Windows Server 2019 must be configured to audit DS Access - Directory Service Access successes.
WN19-DC-000250V3R4Windows Server 2019 must be configured to audit DS Access - Directory Service Access failures.
WN19-DC-000260V3R4Windows Server 2019 must be configured to audit DS Access - Directory Service Changes successes.
WN22-AU-000090V2R4Windows Server 2022 must be configured to audit Account Management - Other Account Management Events successes.
WN22-AU-000140V2R4Windows Server 2022 must be configured to audit Detailed Tracking - Process Creation successes.
WN22-AU-000260V2R4Windows Server 2022 must be configured to audit Policy Change - Audit Policy Change successes.
WN22-AU-000270V2R4Windows Server 2022 must be configured to audit Policy Change - Audit Policy Change failures.
WN22-AU-000280V2R4Windows Server 2022 must be configured to audit Policy Change - Authentication Policy Change successes.
WN22-AU-000290V2R4Windows Server 2022 must be configured to audit Policy Change - Authorization Policy Change successes.
WN22-AU-000300V2R4Windows Server 2022 must be configured to audit Privilege Use - Sensitive Privilege Use successes.
WN22-AU-000310V2R4Windows Server 2022 must be configured to audit Privilege Use - Sensitive Privilege Use failures.
WN22-AU-000320V2R4Windows Server 2022 must be configured to audit System - IPsec Driver successes.
WN22-AU-000330V2R4Windows Server 2022 must be configured to audit System - IPsec Driver failures.
WN22-AU-000340V2R4Windows Server 2022 must be configured to audit System - Other System Events successes.
WN22-AU-000350V2R4Windows Server 2022 must be configured to audit System - Other System Events failures.
WN22-AU-000360V2R4Windows Server 2022 must be configured to audit System - Security State Change successes.
WN22-AU-000370V2R4Windows Server 2022 must be configured to audit System - Security System Extension successes.
WN22-AU-000380V2R4Windows Server 2022 must be configured to audit System - System Integrity successes.
WN22-AU-000390V2R4Windows Server 2022 must be configured to audit System - System Integrity failures.
WN22-DC-000170V2R4Windows Server 2022 Active Directory Group Policy objects must be configured with proper audit settings.
WN22-DC-000180V2R4Windows Server 2022 Active Directory Domain object must be configured with proper audit settings.
WN22-DC-000190V2R4Windows Server 2022 Active Directory Infrastructure object must be configured with proper audit settings.
WN22-DC-000200V2R4Windows Server 2022 Active Directory Domain Controllers Organizational Unit (OU) object must be configured with proper audit settings.
WN22-DC-000210V2R4Windows Server 2022 Active Directory AdminSDHolder object must be configured with proper audit settings.
WN22-DC-000220V2R4Windows Server 2022 Active Directory RID Manager$ object must be configured with proper audit settings.
WN22-DC-000240V2R4Windows Server 2022 must be configured to audit DS Access - Directory Service Access successes.
WN22-DC-000250V2R4Windows Server 2022 must be configured to audit DS Access - Directory Service Access failures.
WN22-DC-000260V2R4Windows Server 2022 must be configured to audit DS Access - Directory Service Changes successes.