Item Search

NameAudit NamePluginCategory
OL08-00-010731 - All OL 8 local interactive user home directory files must have mode "0750" or less permissive.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010750 - All OL 8 local interactive user home directories defined in the "/etc/passwd" file must exist.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010790 - All OL 8 files and directories must have a valid group owner.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-020013 - OL 8 systems, versions 8.2 and above, must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020017 - OL 8 systems, versions 8.2 and above, must ensure account lockouts persist.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020025 - OL 8 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020031 - OL 8 must initiate a session lock for graphical user interfaces when the screensaver is activated.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020032 - OL 8 must disable the user list at logon for graphical user interfaces.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-020035 - OL 8 must terminate idle user sessions.DISA Oracle Linux 8 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-020050 - OL 8 must be able to initiate directly a session lock for all connection types using smartcard when the smartcard is removed.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020110 - OL 8 must enforce password complexity by requiring that at least one uppercase character be used.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020130 - OL 8 must enforce password complexity by requiring that at least one numeric character be used.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020230 - OL 8 passwords must have a minimum of 15 characters.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020262 - The OL 8 lastlog command must have a mode of "0750" or less permissive.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020280 - All OL 8 passwords must contain at least one special character.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020350 - OL 8 must display the date and time of the last successful account logon upon an SSH logon.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-030080 - OL 8 audit logs must be owned by root to prevent unauthorized read access.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030090 - OL 8 audit logs must be group-owned by root to prevent unauthorized read access.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030100 - The OL 8 audit log directory must be owned by root to prevent unauthorized read access.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030130 - OL 8 must generate audit records for all account creation events that affect "/etc/shadow".DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030181 - OL 8 audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, MAINTENANCE

OL08-00-030190 - OL 8 must generate audit records for any use of the "su" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030260 - OL 8 must generate audit records for any uses of the "chcon" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030312 - OL 8 must generate audit records for any use of the "postqueue" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030317 - OL 8 must generate audit records for any use of the "unix_chkpwd" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030320 - OL 8 must generate audit records for any use of the "ssh-keysign" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030330 - OL 8 must generate audit records for any use of the "setfacl" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030410 - OL 8 must generate audit records for any use of the "chsh" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030420 - OL 8 must generate audit records for any use of the "truncate", "ftruncate", "creat", "open", "openat", and "open_by_handle_at" system calls.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030570 - OL 8 must generate audit records for any use of the "chacl" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030580 - OL 8 must generate audit records for any use of the "kmod" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030640 - OL 8 audit tools must be group-owned by root.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030680 - OL 8 must have the packages required for encrypting offloaded audit logs installed.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-030690 - The OL 8 audit records must be offloaded onto a different system or storage media from the system being audited.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030700 - OL 8 must take appropriate action when the internal event queue is full.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030710 - OL 8 must encrypt the transfer of audit records offloaded onto a different system or media from the system being audited.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030731 - OL 8 must notify the System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) when allocated audit record storage volume 75 percent utilization.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-040000 - OL 8 must not have the telnet-server package installed.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040024 - OL 8 must disable the transparent inter-process communication (TIPC) protocol.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040111 - OL 8 Bluetooth must be disabled.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-040123 - OL 8 must mount "/tmp" with the "nodev" option.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040133 - OL 8 must mount "/var/tmp" with the "nosuid" option.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040139 - OL 8 must have the USBGuard installed.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-040140 - OL 8 must block unauthorized peripherals before establishing a connection.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-040150 - A firewall must be able to protect against or limit the effects of denial-of-service (DoS) attacks by ensuring OL 8 can implement rate-limiting measures on impacted network interfaces.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-040160 - All OL 8 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.DISA Oracle Linux 8 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-040171 - The x86 Ctrl-Alt-Delete key sequence in OL 8 must be disabled if a graphical user interface is installed.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040220 - OL 8 must not send Internet Control Message Protocol (ICMP) redirects.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040262 - OL 8 must not accept router advertisements on all IPv6 interfaces by default.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040270 - OL 8 must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT