Item Search

NameAudit NamePluginCategory
OL08-00-010730 - All OL 8 local interactive user home directories must have mode "0750" or less permissive.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010780 - All OL 8 files and directories must have a valid owner.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010830 - OL 8 must not allow users to override SSH environment variables.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-020000 - OL 8 temporary user accounts must be provisioned with an expiration time of 72 hours or less.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020010 - OL 8 systems below version 8.2 must automatically lock an account when three unsuccessful logon attempts occur.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020016 - OL 8 systems below version 8.2 must ensure account lockouts persist.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020022 - OL 8 systems below version 8.2 must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020023 - OL 8 systems, versions 8.2 and above, must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020027 - OL 8 systems, versions 8.2 and above, must configure SELinux context type to allow the use of a non-default faillock tally directory.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020030 - OL 8 must enable a user session lock until that user reestablishes access using established identification and authentication procedures for graphical user sessions.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020081 - OL 8 must prevent a user from overriding the session idle-delay setting for the graphical user interface.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020082 - OL 8 must prevent a user from overriding the session lock-enabled setting for the graphical user interface.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020100 - OL 8 must ensure the password complexity module is enabled in the password-auth file.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-020102 - OL 8 systems below version 8.4 must ensure the password complexity module in the system-auth file is configured for three retries or less.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-020120 - OL 8 must enforce password complexity by requiring that at least one lowercase character be used.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020160 - OL 8 must require the change of at least four character classes when passwords are changed.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020200 - OL 8 user account passwords must have a 60-day maximum password lifetime restriction.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020210 - OL 8 user account passwords must be configured so that existing passwords are restricted to a 60-day maximum lifetime.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020240 - OL 8 duplicate User IDs (UIDs) must not exist for interactive users.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION

OL08-00-020260 - The OL 8 system-auth file must disable access to the system for account identifiers (individuals, groups, roles, and devices) with 35 days of inactivity.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020264 - The OL 8 lastlog command must be group-owned by root.DISA Oracle Linux 8 STIG v2r8Unix

SYSTEM AND INFORMATION INTEGRITY

OL08-00-020310 - OL 8 must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-020331 - OL 8 must not allow blank or null passwords in the system-auth file.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-020352 - OL 8 must set the umask value to 077 for all local interactive user accounts.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-030061 - The OL 8 audit system must audit local events.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-030063 - OL 8 must resolve audit information before writing to disk.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-030070 - OL 8 audit logs must have a mode of "0600" or less permissive to prevent unauthorized read access.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030121 - The OL 8 audit system must protect auditing rules from unauthorized change.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030160 - OL 8 must generate audit records for all account creation events that affect "/etc/gshadow".DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030172 - OL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/sudoers.d/".DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030180 - The OL 8 audit package must be installed.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, MAINTENANCE

OL08-00-030280 - OL 8 must generate audit records for any use of the "ssh-agent" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030310 - OL 8 must generate audit records for any use of the "unix_update" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030311 - OL 8 must generate audit records for any use of the "postdrop" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030314 - OL 8 must generate audit records for any use of the "setfiles" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030315 - OL 8 must generate audit records for any use of the "userhelper" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030361 - OL 8 must generate audit records for any use of the "rename", "unlink", "rmdir", "renameat", and "unlinkat" system calls.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030480 - OL 8 must generate audit records for any use of the "chown", "fchown", "fchownat", and "lchown" system calls.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030600 - OL 8 must generate audit records for any attempted modifications to the "lastlog" file.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030602 - OL 8 must allocate an "audit_backlog_limit" of sufficient size to capture processes that start prior to the audit daemon.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030620 - OL 8 audit tools must have a mode of "0755" or less permissive.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030660 - OL 8 must allocate audit record storage capacity to store at least one week of audit records when audit records are not immediately sent to a central audit record storage facility.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030741 - OL 8 must disable the chrony daemon from acting as a server.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-030742 - OL 8 must disable network management of the chrony daemon.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040021 - OL 8 must not have the asynchronous transfer mode (ATM) kernel module installed if not required for operational support.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040022 - OL 8 must not have the Controller Area Network (CAN) kernel module installed if not required for operational support.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040026 - OL 8 must disable IEEE 1394 (FireWire) Support.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040030 - OL 8 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040090 - An OL 8 firewall must employ a deny-all, allow-by-exception policy for allowing connections to other systems.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-040121 - OL 8 must mount "/dev/shm" with the "nosuid" option.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT