Item Search

NameAudit NamePluginCategory
OL08-00-010049 - OL 8 must display a banner before granting local or remote access to the system via a graphical user logon.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-010060 - OL 8 must display the Standard Mandatory DoD Notice and Consent Banner before granting local or remote access to the system via a command line user logon.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-010110 - OL 8 must encrypt all stored passwords with a FIPS 140-2 approved cryptographic hashing algorithm.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010186 - OL 8 IP tunnels must use FIPS 140-3-approved cryptographic algorithms.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-010210 - The OL 8 "/var/log/messages" file must have mode 0640 or less permissive.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

OL08-00-010230 - The OL 8 "/var/log/messages" file must be group-owned by root.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

OL08-00-010330 - OL 8 library files must have mode 755 or less permissive.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010350 - OL 8 library files must be group-owned by root.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010359 - The OL 8 operating system must use a file integrity tool to verify correct operation of all security functions.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

OL08-00-010370 - YUM must be configured to prevent the installation of patches, service packs, device drivers, or OL 8 system components that have not been digitally signed using a certificate that is recognized and approved by the organization.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010371 - OL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components of local packages without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010374 - OL 8 must enable kernel parameters to enforce Discretionary Access Control (DAC) on hardlinks.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-010379 - OL 8 must specify the default "include" directory for the /etc/sudoers file.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010381 - OL 8 must require users to reauthenticate for privilege escalation and changing roles.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010383 - OL 8 must use the invoking user's password for privilege escalation when using "sudo".DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010424 - OL 8 must not let Meltdown and Spectre exploit critical vulnerabilities in modern processors.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010450 - OL 8 must enable the SELinux targeted policy.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

OL08-00-010500 - The OL 8 SSH daemon must perform strict mode checking of home directory configuration files.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010522 - The OL 8 SSH daemon must not allow GSSAPI authentication, except to fulfill documented and validated mission requirements.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010540 - OL 8 must use a separate file system for "/var".DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010561 - OL 8 must have the rsyslog service enabled and active.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010570 - OL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010571 - OL 8 must prevent files with the setuid and setgid bit set from being executed on the /boot directory.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010580 - OL 8 must prevent special devices on nonroot local partitions.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010600 - OL 8 file systems must not interpret character or block special devices from untrusted file systems.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010620 - OL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that are used with removable media.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010820 - Unattended or automatic logon via the OL 8 graphical user interface must not be allowed.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-020019 - OL 8 systems, versions 8.2 and above, must prevent system messages from being presented when three unsuccessful logon attempts occur.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-020020 - OL 8 systems below version 8.2 must log user name information when unsuccessful logon attempts occur.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-020021 - OL 8 systems, versions 8.2 and above, must log user name information when unsuccessful logon attempts occur.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-020022 - OL 8 systems below version 8.2 must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-020032 - OL 8 must disable the user list at logon for graphical user interfaces.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-020035 - OL 8 must terminate idle user sessions.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-020040 - OL 8 must automatically exit interactive command shell user sessions after 10 minutes of inactivity.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-020082 - OL 8 must prevent a user from overriding the session lock-enabled setting for the graphical user interface.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-020102 - OL 8 systems below version 8.4 must ensure the password complexity module in the system-auth file is configured for three retries or less.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-020104 - OL 8 systems, version 8.4 and above, must ensure the password complexity module is configured for three retries or less.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-020110 - OL 8 must enforce password complexity by requiring that at least one uppercase character be used.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020120 - OL 8 must enforce password complexity by requiring that at least one lowercase character be used.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020140 - OL 8 must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020263 - The OL 8 lastlog command must be owned by root.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

OL08-00-020310 - OL 8 must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-020330 - OL 8 must not allow accounts configured with blank or null passwords.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-030040 - The OL 8 System must take appropriate action when an audit processing failure occurs.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030080 - OL 8 audit logs must be owned by root to prevent unauthorized read access.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

WN11-UR-000010 - The 'Access this computer from the network' user right must only be assigned to the Administrators and Remote Desktop Users groups.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-UR-000055 - The 'Create permanent shared objects' user right must not be assigned to any groups or accounts.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-UR-000080 - The 'Deny log on as a service' user right on Windows 11 domain-joined workstations must be configured to prevent access from highly privileged domain accounts.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-UR-000090 - The 'Deny log on through Remote Desktop Services' user right on Windows 11 workstations must be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-UR-000095 - The 'Enable computer and user accounts to be trusted for delegation' user right must not be assigned to any groups or accounts.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL