SRG-OS-000373-GPOS-00156 Controls

STIG IDVersionTitleProduct
APPL-14-004022V2R3The macOS system must require users to reauthenticate for privilege escalation when using the "sudo" command.
APPL-14-004060V2R3The macOS system must configure sudoers timestamp type.
OL07-00-010340V3R2The Oracle Linux operating system must be configured so that users must provide a password for privilege escalation.
OL07-00-010350V3R2The Oracle Linux operating system must be configured so users must re-authenticate for privilege escalation.
OL07-00-010343V3R2The Oracle Linux operating system must require re-authentication when using the "sudo" command.
OL07-00-010344V3R2The Oracle Linux operating system must not be configured to bypass password requirements for privilege escalation.
OL08-00-010380V2R4OL 8 must require users to provide a password for privilege escalation.
OL08-00-010381V2R4OL 8 must require users to reauthenticate for privilege escalation and changing roles.
OL08-00-010384V2R4OL 8 must require reauthentication when using the "sudo" command.
OL08-00-010385V2R4The OL 8 operating system must not be configured to bypass password requirements for privilege escalation.
RHEL-07-010340V3R9The Red Hat Enterprise Linux operating system must be configured so that users must provide a password for privilege escalation.
RHEL-07-010350V3R9The Red Hat Enterprise Linux operating system must be configured so that users must re-authenticate for privilege escalation.
RHEL-07-010343V3R9The Red Hat Enterprise Linux operating system must require re-authentication when using the "sudo" command.
RHEL-07-010344V3R9The Red Hat Enterprise Linux operating system must not be configured to bypass password requirements for privilege escalation.
RHEL-08-010380V2R3RHEL 8 must require users to provide a password for privilege escalation.
RHEL-08-010381V2R3RHEL 8 must require users to reauthenticate for privilege escalation.
RHEL-08-010384V2R3RHEL 8 must require re-authentication when using the "sudo" command.
RHEL-08-010385V2R3The RHEL 8 operating system must not be configured to bypass password requirements for privilege escalation.
RHEL-09-432015V2R4RHEL 9 must require reauthentication when using the "sudo" command.
RHEL-09-432025V2R4RHEL 9 must require users to reauthenticate for privilege escalation.
RHEL-09-432035V2R4RHEL 9 must restrict the use of the "su" command.
RHEL-09-611085V2R4RHEL 9 must require users to provide a password for privilege escalation.
RHEL-09-611145V2R4RHEL 9 must not be configured to bypass password requirements for privilege escalation.
SLES-12-010110V3R2The SUSE operating system must reauthenticate users when changing authenticators, roles, or escalating privileges.
SLES-12-010113V3R2The SUSE operating system must require re-authentication when using the "sudo" command.
SLES-12-010114V3R2The SUSE operating system must not be configured to bypass password requirements for privilege escalation.
SLES-15-010450V2R4The SUSE operating system must reauthenticate users when changing authenticators, roles, or escalating privileges.
SLES-15-020102V2R4The SUSE operating system must require reauthentication when using the "sudo" command.
SLES-15-020104V2R4The SUSE operating system must not be configured to bypass password requirements for privilege escalation.
UBTU-18-010114V2R15The Ubuntu operating system must require users to re-authenticate for privilege escalation and changing roles.
UBTU-20-010014V2R1The Ubuntu operating system must require users to reauthenticate for privilege escalation or when changing roles.
UBTU-22-432010V2R4Ubuntu 22.04 LTS must require users to reauthenticate for privilege escalation or when changing roles.
WN10-CC-000145V3R4Users must be prompted for a password on resume from sleep (on battery).
WN10-CC-000150V3R4The user must be prompted for a password on resume from sleep (plugged in).
WN10-CC-000270V3R4Passwords must not be saved in the Remote Desktop Client.
WN10-CC-000280V3R4Remote Desktop Services must always prompt a client for passwords upon connection.
WN10-CC-000355V3R4The Windows Remote Management (WinRM) service must not store RunAs credentials.
WN11-CC-000145V2R3Users must be prompted for a password on resume from sleep (on battery).
WN11-CC-000150V2R3The user must be prompted for a password on resume from sleep (plugged in).
WN11-CC-000270V2R3Passwords must not be saved in the Remote Desktop Client.
WN11-CC-000280V2R3Remote Desktop Services must always prompt a client for passwords upon connection.
WN11-CC-000355V2R3The Windows Remote Management (WinRM) service must not store RunAs credentials.
WN22-CC-000340V2R4Windows Server 2022 must not save passwords in the Remote Desktop Client.
WN22-CC-000360V2R4Windows Server 2022 Remote Desktop Services must always prompt a client for passwords upon connection.
WN22-CC-000520V2R4Windows Server 2022 Windows Remote Management (WinRM) service must not store RunAs credentials.
WN22-SO-000380V2R4Windows Server 2022 User Account Control (UAC) approval mode for the built-in Administrator must be enabled.
WN22-SO-000410V2R4Windows Server 2022 User Account Control (UAC) must automatically deny standard user requests for elevation.
WN22-SO-000440V2R4Windows Server 2022 User Account Control (UAC) must run all administrators in Admin Approval Mode, enabling UAC.