Item Search

NameAudit NamePluginCategory
ALMA-09-011240 - AlmaLinux OS 9 must disable core dumps for all users.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-012560 - All AlmaLinux OS 9 local files and directories must have a valid owner.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-012780 - AlmaLinux OS 9 /etc/group- file must be owned by root.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-013880 - AlmaLinux OS 9 /etc/gshadow- file must have mode 0000 or less permissive to prevent unauthorized access.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-014650 - All AlmaLinux OS 9 local interactive user home directories defined in the /etc/passwd file must exist.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-014760 - All AlmaLinux OS 9 local interactive user home directories must be group-owned by the home directory owner's primary group.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-015090 - All AlmaLinux OS 9 local interactive users must have a home directory assigned in the /etc/passwd file.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-015420 - AlmaLinux OS 9 must not allow unattended or automatic logon via the graphical user interface.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-016300 - AlmaLinux OS 9 /etc/passwd file must be group-owned by root.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-017400 - AlmaLinux OS 9 must use the invoking user's password for privilege escalation when using "sudo".DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-017840 - AlmaLinux OS 9 must define default permissions for logon and nonlogon shells.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-019380 - AlmaLinux OS 9 must log packets with impossible addresses.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-020700 - AlmaLinux OS 9 SSH server configuration files must have mode 0600 or less permissive.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-020810 - AlmaLinux OS 9 must not allow a noncertificate trusted host SSH logon to the system.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-020920 - AlmaLinux OS 9 SSH private host key files must have mode 0600 or less permissive.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-021030 - AlmaLinux OS 9 SSH public host key files must have mode 0644 or less permissive.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-021250 - AlmaLinux OS 9 SSH daemon must display the date and time of the last successful account logon upon an SSH logon.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-021690 - If the Trivial File Transfer Protocol (TFTP) server is required, the TFTP daemon must be configured to operate in secure mode.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-021800 - AlmaLinux OS 9 must enable hardening for the Berkeley Packet Filter (BPF) just-in-time (JIT) compiler.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-023120 - AlmaLinux OS 9 must prevent special devices on file systems that are imported via Network File System (NFS).DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-026310 - AlmaLinux OS 9 must mount /boot with the nodev option.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-026420 - AlmaLinux OS 9 must prevent files with the setuid and setgid bit set from being executed on the /boot directory.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-026860 - AlmaLinux OS 9 must mount /tmp with the nodev option.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-026970 - AlmaLinux OS 9 must mount /tmp with the noexec option.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-027520 - AlmaLinux OS 9 must mount /var/log with the nodev option.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-027630 - AlmaLinux OS 9 must mount /var/log with the noexec option.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-028730 - AlmaLinux OS 9 must not have the iprutils package installed.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-028950 - AlmaLinux OS 9 must not have the sendmail package installed.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-029610 - AlmaLinux OS 9 must disable the Asynchronous Transfer Mode (ATM) kernel module.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-029940 - AlmaLinux OS 9 must disable mounting of cramfs.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-034890 - AlmaLinux OS 9 must disable the graphical user interface automount function unless required.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-035210 - AlmaLinux OS 9 must have the USBGuard package installed.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-035220 - AlmaLinux OS 9 must have the USBGuard package enabled.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-035990 - AlmaLinux OS 9 must ensure the password complexity module in the system-auth file is configured for three retries or less.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-037420 - AlmaLinux OS 9 must be configured so that the system's shadow file is configured to store only encrypted representations of passwords.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-037530 - AlmaLinux OS 9 must be configured so that the Pluggable Authentication Module is configured to store only encrypted representations of passwords.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-037640 - AlmaLinux OS 9 must be configured so that interactive user account passwords are using strong password hashes.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-038190 - Passwords for existing users must have a 24-hour minimum password lifetime restriction in /etc/shadow.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-040060 - AlmaLinux OS 9 must implement a FIPS 140-3-compliant systemwide cryptographic policy.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-040500 - AlmaLinux OS 9 must terminate idle user sessions.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-040720 - AlmaLinux OS 9 must disable access to network bpf system call from nonprivileged processes.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-040830 - AlmaLinux OS 9 must restrict exposed kernel pointer addresses access.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-041930 - AlmaLinux OS 9 must use a Linux Security Module configured to enforce limits on system services.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-042150 - Any AlmaLinux OS 9 world-writable directories must be owned by root, sys, bin, or an application user.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-042260 - A sticky bit must be set on all AlmaLinux OS 9 public directories.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-042700 - All AlmaLinux OS 9 networked systems must have the OpenSSH client package installed.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-044460 - AlmaLinux OS 9 /var/log directory must have mode 0755 or less permissive.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

SYSTEM AND INFORMATION INTEGRITY

ALMA-09-044790 - AlmaLinux OS 9 must clear memory when it is freed to prevent use-after-free attacks.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

SYSTEM AND INFORMATION INTEGRITY

ALMA-09-045670 - AlmaLinux OS 9 audit system must audit local events.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-046550 - AlmaLinux OS 9 must enable Linux audit logging for the USBGuard daemon.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY