Item Search

NameAudit NamePluginCategory
DG0040-ORACLE11 - The DBMS software installation account should be restricted to authorized users - 'Oracle base directory file permissions are correct'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

CONFIGURATION MANAGEMENT

DG0040-ORACLE11 - The DBMS software installation account should be restricted to authorized users - 'Oracle home directory file permissions are correct'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

CONFIGURATION MANAGEMENT

DG0040-ORACLE11 - The DBMS software installation account should be restricted to authorized users - 'Oracle install account is disabled'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

ACCESS CONTROL

DG0187-ORACLE11 - DBMS software libraries should be periodically backed up - '$ORACLE_HOME files are being backed up'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

CONTINGENCY PLANNING

OL08-00-010060 - OL 8 must display the Standard Mandatory DoD Notice and Consent Banner before granting local or remote access to the system via a command line user logon.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-010160 - The OL 8 "pam_unix.so" module must be configured in the password-auth file to use a FIPS 140-2 approved cryptographic hashing algorithm for system authentication.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010170 - OL 8 must use a Linux Security Module configured to enforce limits on system services.DISA Oracle Linux 8 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010184 - The OL 8 SSH client must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-010187 - OL 8 must implement DOD-approved encryption in the bind package.DISA Oracle Linux 8 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010190 - A sticky bit must be set on all OL 8 public directories to prevent unauthorized and unintended information transferred via shared system resources.DISA Oracle Linux 8 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010240 - The OL 8 "/var/log" directory must have mode 0755 or less permissive.DISA Oracle Linux 8 STIG v2r8Unix

SYSTEM AND INFORMATION INTEGRITY

OL08-00-010373 - OL 8 must enable kernel parameters to enforce Discretionary Access Control (DAC) on symlinks.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-010380 - OL 8 must require users to provide a password for privilege escalation.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010383 - OL 8 must use the invoking user's password for privilege escalation when using "sudo".DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010384 - OL 8 must require reauthentication when using the "sudo" command.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010385 - The OL 8 operating system must not be configured to bypass password requirements for privilege escalation.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010420 - OL 8 must implement non-executable data to protect its memory from unauthorized code execution.DISA Oracle Linux 8 STIG v2r8Unix

SYSTEM AND INFORMATION INTEGRITY

OL08-00-010450 - OL 8 must enable the SELinux targeted policy.DISA Oracle Linux 8 STIG v2r8Unix

SYSTEM AND INFORMATION INTEGRITY

OL08-00-010473 - OL 8 must enable the hardware random number generator entropy gatherer service.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010540 - OL 8 must use a separate file system for "/var".DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010541 - OL 8 must use a separate file system for "/var/log".DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010543 - OL 8 must use a separate file system for "/tmp".DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010571 - OL 8 must prevent files with the setuid and setgid bit set from being executed on the /boot directory.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010610 - OL 8 file systems must not execute binary files on removable media.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010620 - OL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that are used with removable media.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010630 - OL 8 file systems must not execute binary files that are imported via Network File System (NFS).DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010671 - OL 8 must disable the "kernel.core_pattern".DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010680 - For OL 8 systems using Domain Name Servers (DNS) resolution, at least two name servers must be configured.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010690 - Executable search paths within the initialization files of all local interactive OL 8 users must only contain paths that resolve to the system default or the user's home directory.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010700 - All OL 8 world-writable directories must be owned by root, sys, bin, or an application user.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-030590 - OL 8 must generate audit records for any attempted modifications to the "faillock" log file.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030601 - OL 8 must enable auditing of processes that start prior to the audit daemon.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030610 - OL 8 must allow only the Information System Security Manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030645 - OL 8 must audit any script or executable called by cron as root or by any privileged user.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030740 - OL 8 must compare internal information system clocks at least every 24 hours with a server synchronized to an authoritative time source, such as the United States Naval Observatory (USNO) time servers, or a time server designated for the appropriate DOD network (NIPRNet/SIPRNet), and/or the Global Positioning System (GPS).DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-040001 - OL 8 must not have any automated bug reporting tools installed.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040004 - OL 8 must enable mitigations against processor-based vulnerabilities.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040025 - OL 8 must disable mounting of cramfs.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040070 - The OL 8 file system automounter must be disabled.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-040131 - OL 8 must mount "/var/log/audit" with the "noexec" option.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040132 - OL 8 must mount "/var/tmp" with the "nodev" option.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040141 - OL 8 must enable the USBGuard.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-040172 - OL 8 must disable the systemd Ctrl-Alt-Delete burst key sequence.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040190 - The Trivial File Transfer Protocol (TFTP) server package must not be installed if not required for OL 8 operational support.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040200 - The root account must be the only account having unrestricted access to the OL 8 system.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040210 - OL 8 must prevent IPv6 Internet Control Message Protocol (ICMP) redirect messages from being accepted.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040280 - OL 8 must ignore IPv6 Internet Control Message Protocol (ICMP) redirect messages.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040281 - OL 8 must disable access to the network "bpf" syscall from nonprivileged processes.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040284 - OL 8 must disable the use of user namespaces.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040390 - OL 8 must not have the "tuned" package installed if not required for operational support.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT