Item Search

NameAudit NamePluginCategory
5.4.1 Ensure password creation requirements are configured - minlenCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1 Ensure password creation requirements are configured - password-auth retry=3CIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-411050 - RHEL 9 must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-411080 - RHEL 9 must automatically lock the root account until the root account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-412055 - RHEL 9 must define default permissions for the bash shell.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-412070 - RHEL 9 must define default permissions for the system default profile.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-432025 - RHEL 9 must require users to reauthenticate for privilege escalation.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-432030 - RHEL 9 must restrict privilege elevation to authorized personnel.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-433010 - RHEL 9 fapolicy module must be installed.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-611050 - RHEL 9 password-auth must be configured to use a sufficient number of hashing rounds.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-611070 - RHEL 9 must enforce password complexity by requiring that at least one numeric character be used.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-611100 - RHEL 9 must enforce password complexity by requiring that at least one special character be used.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-611105 - RHEL 9 must prevent the use of dictionary words for passwords.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-611145 - RHEL 9 must not be configured to bypass password requirements for privilege escalation.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-631010 - RHEL 9, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-631015 - RHEL 9 must map the authenticated identity to the user or group account for PKI-based authentication.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-651030 - RHEL 9 must be configured so that the file integrity tool verifies Access Control Lists (ACLs).DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-652015 - RHEL 9 must have the packages required for encrypting offloaded audit logs installed.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-652025 - RHEL 9 must be configured so that the rsyslog daemon does not accept log messages from other servers unless the server is being used for log aggregation.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-652040 - RHEL 9 must authenticate the remote logging server for offloading audit logs via rsyslog.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-652050 - RHEL 9 must encrypt via the gtls driver the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-652055 - RHEL 9 must be configured to forward audit records via TCP to a different system or media from the system being audited via rsyslog.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-652060 - RHEL 9 must use cron logging.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-653060 - RHEL 9 must label all offloaded audit logs before sending them to the central log server.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-653065 - RHEL 9 must take appropriate action when the internal event queue is full.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-653090 - RHEL 9 audit logs file must have mode 0600 or less permissive to prevent unauthorized access to the audit log.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

RHEL-09-653105 - RHEL 9 must write audit records to disk.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-653110 - RHEL 9 must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-653120 - RHEL 9 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-653125 - RHEL 9 must have mail aliases to notify the information system security officer (ISSO) and system administrator (SA) (at a minimum) in the event of an audit processing failure.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-653130 - RHEL 9 audispd-plugins package must be installed.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-654025 - RHEL 9 must audit all uses of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-09-654030 - RHEL 9 must audit all uses of umount system calls.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-09-654050 - RHEL 9 must audit all uses of the semanage command.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-09-654055 - RHEL 9 must audit all uses of the setfiles command.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-09-654060 - RHEL 9 must audit all uses of the setsebool command.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-09-654097 - RHEL 9 must audit any script or executable called by cron as root or by any privileged user.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-654125 - RHEL 9 must audit all uses of the postdrop command.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-09-654130 - RHEL 9 must audit all uses of the postqueue command.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-09-654150 - RHEL 9 must audit all uses of the sudo command.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-09-654170 - RHEL 9 must audit all uses of the userhelper command.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-09-654200 - Successful/unsuccessful uses of the shutdown command in RHEL 9 must generate an audit record.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-654220 - RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/directory.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-09-654230 - RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-09-654240 - RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-09-654250 - RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/faillock.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-09-654255 - RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/lastlog.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-09-654270 - RHEL 9 audit system must protect logon UIDs from unauthorized change.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-671015 - RHEL 9 must employ FIPS 140-3-approved cryptographic hashing algorithms for all stored passwords.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-671025 - RHEL 9 pam_unix.so module must be configured in the password-auth file to use a FIPS 140-3 approved cryptographic hashing algorithm for system authentication.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION