Item Search

NameAudit NamePluginCategory
DO0120-ORACLE11 - The Oracle software installation account should not be granted excessive host system privileges - 'Oracle service account group membership is correct'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

ACCESS CONTROL

DO0120-ORACLE11 - The Oracle software installation account should not be granted excessive host system privileges - 'Oracle service account is denied logon on locally right'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

ACCESS CONTROL

DO0120-ORACLE11 - The Oracle software installation account should not be granted excessive host system privileges - 'Oracle services use appropriate service accounts'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

ACCESS CONTROL

OH12-1X-000220 - OHS must have all applicable patches (i.e., CPUs) applied/documented (OEM).DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

CONFIGURATION MANAGEMENT

OL08-00-010040 - OL 8 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via an SSH logon.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-010049 - OL 8 must display a banner before granting local or remote access to the system via a graphical user logon.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-010110 - OL 8 must encrypt all stored passwords with a FIPS 140-2 approved cryptographic hashing algorithm.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010152 - OL 8 operating systems must require authentication upon booting into emergency mode.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-010171 - OL 8 must have the "policycoreutils" package installed.DISA Oracle Linux 8 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010180 - OL 8 must have the crypto-policies package installed.DISA Oracle Linux 8 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010183 - OL 8 cryptographic policy must not be overridden.DISA Oracle Linux 8 STIG v2r8Unix

MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-020028 - OL 8 systems below version 8.2 must configure SELinux context type to allow the use of a non-default faillock tally directory.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020103 - OL 8 systems below version 8.4 must ensure the password complexity module in the password-auth file is configured for three retries or less.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-020150 - OL 8 must require the maximum number of repeating characters be limited to three when passwords are changed.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020190 - OL 8 passwords for new users or password changes must have a 24 hours/one day minimum password lifetime restriction in "/etc/login.defs".DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020250 - OL 8 must implement multifactor authentication for access to interactive accounts.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020261 - The OL 8 password-auth file must disable access to the system for account identifiers (individuals, groups, roles, and devices) with 35 days of inactivity.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020270 - OL 8 must automatically expire temporary accounts within 72 hours.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020353 - OL 8 must define default permissions for logon and non-logon shells.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-030000 - The OL 8 audit system must be configured to audit the execution of privileged functions and prevent all software from executing at higher privilege levels than users executing the software.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-030030 - The OL 8 Information System Security Officer (ISSO) and System Administrator (SA) (at a minimum) must have mail aliases to be notified of an audit processing failure.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030120 - The OL 8 audit log directory must have a mode of 0700 or less permissive to prevent unauthorized read access.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030150 - OL 8 must generate audit records for all account creation events that affect "/etc/passwd".DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030250 - OL 8 must generate audit records for any use of the "chage" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030290 - OL 8 must generate audit records for any use of the "passwd" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030301 - OL 8 must generate audit records for any use of the "umount" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030302 - OL 8 must generate audit records for any use of the "mount" syscall.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030316 - OL 8 must generate audit records for any use of the "setsebool" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030360 - OL 8 must generate audit records for any use of the "init_module" and "finit_module" system calls.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030370 - OL 8 must generate audit records for any use of the "gpasswd" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030400 - OL 8 must generate audit records for any use of the "crontab" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030650 - OL 8 must use cryptographic mechanisms to protect the integrity of audit tools.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030670 - OL 8 must have the packages required for offloading audit logs installed.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-030720 - OL 8 must authenticate the remote logging server for offloading audit logs.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-040020 - OL 8 must cover or disable the built-in or attached camera when not in use.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040080 - OL 8 must be configured to disable the ability to use USB mass storage devices.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-040125 - OL 8 must mount "/tmp" with the "noexec" option.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040126 - OL 8 must mount "/var/log" with the "nodev" option.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040127 - OL 8 must mount "/var/log" with the "nosuid" option.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040128 - OL 8 must mount "/var/log" with the "noexec" option.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040129 - OL 8 must mount "/var/log/audit" with the "nodev" option.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040130 - OL 8 must mount "/var/log/audit" with the "nosuid" option.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040134 - OL 8 must mount "/var/tmp" with the "noexec" option.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040136 - The OL 8 "fapolicy" module must be enabled.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040137 - The OL 8 fapolicy module must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040249 - OL 8 must not forward IPv4 source-routed packets by default.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040279 - OL 8 must ignore IPv4 Internet Control Message Protocol (ICMP) redirect messages.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040285 - OL 8 must use reverse path filtering on all IPv4 interfaces.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040290 - OL 8 must be configured to prevent unrestricted mail relaying.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040400 - OL 8 must prevent nonprivileged users from executing privileged functions, including disabling, circumventing, or altering implemented security safeguards/countermeasures.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL