Item Search

NameAudit NamePluginCategory
GEN002720-5 - The audit system must be configured to audit failed attempts to access files and programs - '-S ftruncate -F success=0'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

AUDIT AND ACCOUNTABILITY

GEN002750 - The audit system must be configured to audit account creation - 'group'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN002750 - The audit system must be configured to audit account creation - 'passwd'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN002751 - The audit system must be configured to audit account modification - 'groupmod'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN002751 - The audit system must be configured to audit account modification - 'usermod'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN002760-3 - The audit system must be configured to audit all administrative, privileged, and security actions - 'adjtimex'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

CONFIGURATION MANAGEMENT

GEN002760-5 - The audit system must be configured to audit all administrative, privileged, and security actions - 'stime'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

CONFIGURATION MANAGEMENT

GEN002760-9 - The audit system must be configured to audit all administrative, privileged, and security actions - 'sched_setparam'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

CONFIGURATION MANAGEMENT

GEN002820-5 - The audit system must be configured to audit all discretionary access control permission modifications - 'fchown'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

AUDIT AND ACCOUNTABILITY

GEN002820-10 - The audit system must be configured to audit all discretionary access control permission modifications - 'fsetxattr'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

AUDIT AND ACCOUNTABILITY

GEN002820-11 - The audit system must be configured to audit all discretionary access control permission modifications - 'removexattr'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

AUDIT AND ACCOUNTABILITY

GEN002825-3 - The audit system must be configured to audit the loading and unloading of dynamic kernel modules - '/sbin/insmod'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

AUDIT AND ACCOUNTABILITY

GEN003000 - Cron must not execute group-writable or world-writable programs.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003020 - Cron must not execute programs in, or subordinate to, world-writable directories.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003040 - Crontabs must be owned by root or the crontab creator - '/etc/cron.d/*'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003040 - Crontabs must be owned by root or the crontab creator - '/etc/cron.hourly/*'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003040 - Crontabs must be owned by root or the crontab creator - '/var/spool/cron/*'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003060 - System accounts must not be listed in cron.allow or must be included in cron.deny - 'adm' - cron.allowDISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003060 - System accounts must not be listed in cron.allow or must be included in cron.deny - 'halt' - cron.allowDISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003060 - System accounts must not be listed in cron.allow or must be included in cron.deny - 'news' - cron.allowDISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003060 - System accounts must not be listed in cron.allow or must be included in cron.deny - 'nobody' - cron.allowDISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003060 - System accounts must not be listed in cron.allow or must be included in cron.deny - 'shutdown' - cron.denyDISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003080-2 - Files in cron script directories must have mode 0700 or less permissive - '/etc/cron.daily/*'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003090 - Crontab files must not have extended ACLs - '/etc/cron.d'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003100 - Cron and crontab directories must have mode 0755 or less permissive - '/etc/cron.hourly'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003100 - Cron and crontab directories must have mode 0755 or less permissive - '/etc/cron.monthly'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003110 - Cron and crontab directories must not have extended ACLs - '/etc/cron.d'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003110 - Cron and crontab directories must not have extended ACLs - '/etc/cron.weekly'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003110 - Cron and crontab directories must not have extended ACLs - '/var/spool/cron'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003120 - Cron and crontab directories must be owned by root or bin - '/etc/cron.d'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003120 - Cron and crontab directories must be owned by root or bin - '/etc/cron.monthly'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003140 - Cron and crontab directories must be group-owned by root, sys, bin or cron - '/etc/cron.d'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003180 - The cronlog file must have mode 0600 or less permissive.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003250 - The cron.allow file must be group-owned by root, bin, sys, or cron.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003255 - The at.deny file must not have an extended ACL.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'daemon' - at.allowDISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'games' - at.denyDISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'lp' - at.denyDISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'news' - at.denyDISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003340 - The at.allow file must have mode 0600 or less permissive.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003470 - The at.allow file must be group-owned by root, bin, sys, or cron.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003480 - The at.deny file must be owned by root, bin, or sys.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003490 - The at.deny file must be group-owned by root, bin, sys, or cron.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003523 - The kernel core dump data directory must not have an extended ACL.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003540 - The system must implement non-executable program stacks - 'kernel.exec-shield'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

CONFIGURATION MANAGEMENT

GEN003619 - The system must not be configured for network bridging.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003623 - The system must use a separate file system for the system audit data path.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

SYSTEM AND COMMUNICATIONS PROTECTION

GEN003640 - The root file system must employ journaling or another mechanism that ensures file system consistency - 'fs type'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

CONTINGENCY PLANNING

GEN003640 - The root file system must employ journaling or another mechanism that ensures file system consistency - 'nolog option'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

CONTINGENCY PLANNING

GEN003660 - The system must log authentication informational data - rsyslog authpriv.*DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

AUDIT AND ACCOUNTABILITY