Item Search

NameAudit NamePluginCategory
APPNET0060 - Remoting Services HTTP channels must utilize authentication and encryption.DISA Microsoft DotNet Framework 4.0 STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-22-211000 - Ubuntu 22.04 LTS must be a vendor-supported release.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-211015 - Ubuntu 22.04 LTS must disable the x86 Ctrl-Alt-Delete key sequence.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-212015 - Ubuntu 22.04 LTS must initiate session audits at system startup.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-213010 - Ubuntu 22.04 LTS must restrict access to the kernel message buffer.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-22-213020 - Ubuntu 22.04 LTS must implement address space layout randomization to protect its memory from unauthorized code execution.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

UBTU-22-215030 - Ubuntu 22.04 LTS must not have the "rsh-server" package installed.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-215040 - Ubuntu 22.04 LTS must not have the nfs-kernel-server package installed.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-232020 - Ubuntu 22.04 LTS library files must have mode "755" or less permissive.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-232027 - Ubuntu 22.04 LTS must generate system journal entries without revealing information that could be exploited by adversaries.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

UBTU-22-232040 - Ubuntu 22.04 LTS must have directories that contain system commands owned by "root".DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-232045 - Ubuntu 22.04 LTS must have directories that contain system commands group-owned by "root".DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-232065 - Ubuntu 22.04 LTS library directories must be group-owned by "root".DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-232075 - Ubuntu 22.04 LTS library files must be group-owned by "root".DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-232135 - Ubuntu 22.04 LTS must configure the "/var/log/syslog" file to be group-owned by "adm".DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

UBTU-22-232140 - Ubuntu 22.04 LTS must be configured so that the "journalctl" command is not accessible by unauthorized users.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

UBTU-22-232145 - Ubuntu 22.04 LTS must set a sticky bit on all public directories to prevent unauthorized and unintended information transferred via shared system resources.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-22-251010 - Ubuntu 22.04 LTS must have an application firewall installed in order to control remote access methods.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL

UBTU-22-251015 - Ubuntu 22.04 LTS must enable and run the Uncomplicated Firewall (ufw).DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL

UBTU-22-253010 - Ubuntu 22.04 LTS must be configured to use TCP syncookies.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-22-255020 - Ubuntu 22.04 LTS must display the Standard Mandatory DOD Notice and Consent Banner before granting any local or remote connection to the system.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL

UBTU-22-271015 - Ubuntu 22.04 LTS must display the Standard Mandatory DOD Notice and Consent Banner before granting local access to the system via a graphical user logon.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL

UBTU-22-271020 - Ubuntu 22.04 LTS must retain a user's session lock until that user reestablishes access using established identification and authentication procedures.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL

UBTU-22-271025 - Ubuntu 22.04 LTS must initiate a graphical session lock after 10 minutes of inactivity.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL

UBTU-22-411015 - Ubuntu 22.04 LTS must uniquely identify interactive users.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-411025 - Ubuntu 22.04 LTS must enforce 24 hours/one day as the minimum password lifetime. Passwords for new users must have a 24 hours/one day minimum password lifetime restriction.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-411030 - Ubuntu 22.04 LTS must enforce a 60-day maximum password lifetime restriction. Passwords for new users must have a 60-day maximum password lifetime restriction.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-411035 - Ubuntu 22.04 LTS must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-411040 - Ubuntu 22.04 LTS must automatically expire temporary accounts within 72 hours.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL

UBTU-22-411045 - Ubuntu 22.04 LTS must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts have been made.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL

UBTU-22-412025 - Ubuntu 22.04 LTS must allow users to directly initiate a session lock for all connection types.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL

UBTU-22-431010 - Ubuntu 22.04 LTS must have the "apparmor" package installed.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

UBTU-22-432010 - Ubuntu 22.04 LTS must require users to reauthenticate for privilege escalation or when changing roles.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-432011 - Ubuntu 22.04 LTS must require users to provide a password for privilege escalation.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-611010 - Ubuntu 22.04 LTS must enforce password complexity by requiring at least one uppercase character be used.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-611015 - Ubuntu 22.04 LTS must enforce password complexity by requiring at least one lowercase character be used.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-611070 - Ubuntu 22.04 LTS must encrypt all stored passwords with a FIPS 140-3-approved cryptographic hashing algorithm.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-651030 - Ubuntu 22.04 LTS must use cryptographic mechanisms to protect the integrity of audit tools.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-652010 - Ubuntu 22.04 LTS must be configured to preserve log records from failure events.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-22-652015 - Ubuntu 22.04 LTS must monitor remote access methods.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL

UBTU-22-653020 - Ubuntu 22.04 LTS audit event multiplexor must be configured to offload audit logs onto a different system from the system being audited.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-653030 - Ubuntu 22.04 LTS must shut down by default upon audit failure.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-653050 - Ubuntu 22.04 LTS must be configured to permit only authorized users ownership of the audit log files.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-653075 - Ubuntu 22.04 LTS must permit only authorized groups to own the audit configuration files.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654055 - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful attempts to use the kmod command.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654060 - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful attempts to use modprobe command.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654065 - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the mount command.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654145 - Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

UBTU-22-654190 - Ubuntu 22.04 LTS must generate audit records for all events that affect the systemd journal files.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-654225 - Ubuntu 22.04 LTS must generate audit records when successful/unsuccessful attempts to modify the /etc/sudoers.d directory occur.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY