SRG-OS-000341-GPOS-00132 Controls

STIG IDVersionTitleProduct
ALMA-09-051830V1R2AlmaLinux OS 9 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.
ALMA-09-051940V1R2AlmaLinux OS 9 must use a separate file system for the system audit data path.
ALMA-09-052050V1R2AlmaLinux OS 9 must allocate audit record storage capacity to store at least one week's worth of audit records.
APPL-14-001029V2R3The macOS system must configure audit retention to seven days.
APPL-14-004050V2R3The macOS system must configure install.log retention to 365.
APPL-15-001029V1R3The macOS system must configure audit retention to seven days.
APPL-15-004050V1R3The macOS system must configure install.log retention to 365.
OL07-00-021330V3R2The Oracle Linux operating system must use a separate file system for the system audit data path large enough to hold at least one week of audit data.
OL08-00-030660V2R4OL 8 must allocate audit record storage capacity to store at least one week of audit records when audit records are not immediately sent to a central audit record storage facility.
OL09-00-000002V1R1OL 9 must use a separate file system for the system audit data path.
OL09-00-000850V1R1OL 9 must allocate audit record storage capacity to store at least one week's worth of audit records.
RHEL-08-030602V2R3RHEL 8 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.
RHEL-08-030660V2R3RHEL 8 must allocate audit record storage capacity to store at least one week of audit records, when audit records are not immediately sent to a central audit record storage facility.
RHEL-09-231030V2R4RHEL 9 must use a separate file system for the system audit data path.
RHEL-09-653030V2R4RHEL 9 must allocate audit record storage capacity to store at least one week's worth of audit records.
SLES-12-020020V3R2The SUSE operating system must allocate audit record storage capacity to store at least one weeks worth of audit records when audit records are not immediately sent to a central audit record storage facility.
SLES-15-030660V2R4The SUSE operating system must allocate audit record storage capacity to store at least one week of audit records when audit records are not immediately sent to a central audit record storage facility.
UBTU-18-010314V2R15The Ubuntu operating system must allocate audit record storage capacity to store at least one weeks worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
UBTU-20-010215V2R1The Ubuntu operating system must allocate audit record storage capacity to store at least one weeks' worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
UBTU-22-653035V2R4Ubuntu 22.04 LTS must allocate audit record storage capacity to store at least one weeks' worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
UBTU-24-900920V1R1Ubuntu 24.04 LTS must allocate audit record storage capacity to store at least one week's worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
WN10-AU-000500V3R4The Application event log size must be configured to 32768 KB or greater.
WN10-AU-000505V3R4The Security event log size must be configured to 1024000 KB or greater.
WN10-AU-000510V3R4The System event log size must be configured to 32768 KB or greater.
WN11-AU-000500V2R3The Application event log size must be configured to 32768 KB or greater.
WN11-AU-000505V2R3The Security event log size must be configured to 1024000 KB or greater.
WN11-AU-000510V2R3The System event log size must be configured to 32768 KB or greater.
WN16-CC-000300V2R9The Application event log size must be configured to 32768 KB or greater.
WN16-CC-000310V2R9The Security event log size must be configured to 196608 KB or greater.
WN16-CC-000320V2R9The System event log size must be configured to 32768 KB or greater.
WN19-CC-000270V3R4Windows Server 2019 Application event log size must be configured to 32768 KB or greater.
WN19-CC-000280V3R4Windows Server 2019 Security event log size must be configured to 196608 KB or greater.
WN19-CC-000290V3R4Windows Server 2019 System event log size must be configured to 32768 KB or greater.
WN22-CC-000270V2R4Windows Server 2022 Application event log size must be configured to 32768 KB or greater.
WN22-CC-000280V2R4Windows Server 2022 Security event log size must be configured to 196608 KB or greater.
WN22-CC-000290V2R4Windows Server 2022 System event log size must be configured to 32768 KB or greater.