Item Search

NameAudit NamePluginCategory
RHEL-09-255045 - RHEL 9 must not permit direct logons to the root account using remote access via SSH.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-255070 - The RHEL 9 SSH client must be configured to use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-255075 - The RHEL 9 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-271010 - RHEL 9 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a graphical user logon.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-271020 - RHEL 9 must disable the graphical user interface automount function unless required.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-271040 - RHEL 9 must not allow unattended or automatic logon via the graphical user interface.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-271045 - RHEL 9 must be able to initiate directly a session lock for all connection types using smart card when the smart card is removed.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-291010 - RHEL 9 must be configured to disable USB mass storage.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-291040 - RHEL 9 wireless network adapters must be disabled.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-09-411015 - RHEL 9 user account passwords must have a 60-day maximum password lifetime restriction.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-411025 - RHEL 9 must set the umask value to 077 for all local interactive user accounts.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-411070 - All RHEL 9 local interactive user home directories must be group-owned by the home directory owner's primary group.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-411075 - RHEL 9 must automatically lock an account when three unsuccessful logon attempts occur.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-411090 - RHEL 9 must maintain an account lock until the locked account is released by an administrator.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-411110 - RHEL 9 groups must have unique Group ID (GID).DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-412060 - RHEL 9 must define default permissions for the c shell.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-412065 - RHEL 9 must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-431010 - RHEL 9 must use a Linux Security Module configured to enforce limits on system services.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

RHEL-09-431016 - RHEL 9 must elevate the SELinux context when an administrator calls the sudo command.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-431030 - RHEL 9 policycoreutils-python-utils package must be installed.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-433015 - RHEL 9 fapolicy module must be enabled.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-611025 - RHEL 9 must not allow blank or null passwords.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-611035 - RHEL 9 must configure the use of the pam_faillock.so module in the /etc/pam.d/password-auth file.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-611040 - RHEL 9 must ensure the password complexity module is enabled in the password-auth file.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-611045 - RHEL 9 must ensure the password complexity module is enabled in the system-auth file.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-611055 - RHEL 9 system-auth must be configured to use a sufficient number of hashing rounds.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-611115 - RHEL 9 must require the change of at least eight characters when passwords are changed.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-611130 - RHEL 9 must require the change of at least four character classes when passwords are changed.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-611190 - RHEL 9, for PKI-based authentication, must enforce authorized access to the corresponding private key.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-611200 - RHEL 9 must require authentication to access single-user mode.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-651015 - RHEL 9 must routinely check the baseline configuration for unauthorized changes and notify the system administrator when anomalies in the operation of any security functions are discovered.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

RHEL-09-651025 - RHEL 9 must use cryptographic mechanisms to protect the integrity of audit tools.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-651035 - RHEL 9 must be configured so that the file integrity tool verifies extended attributes.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-652010 - RHEL 9 must have the rsyslog package installed.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-652045 - RHEL 9 must encrypt the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-653025 - RHEL 9 audit system must take appropriate action when the audit storage volume is full.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-653040 - RHEL 9 must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume reaches 75 percent utilization.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-653055 - RHEL 9 audit system must take appropriate action when the audit files have reached maximum size.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-653080 - RHEL 9 audit logs must be group-owned by root or by a restricted logging group to prevent unauthorized read access.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

RHEL-09-653095 - RHEL 9 must periodically flush audit records to disk to prevent the loss of audit records.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-654010 - RHEL 9 must audit uses of the "execve" system call.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-654020 - RHEL 9 must audit all uses of the chown, fchown, fchownat, and lchown system calls.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-09-654040 - RHEL 9 must audit all uses of the setfacl command.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-09-654105 - RHEL 9 must audit all uses of the kmod command.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-09-654115 - RHEL 9 must audit all uses of the pam_timestamp_check command.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-09-654120 - RHEL 9 must audit all uses of the passwd command.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-09-654145 - RHEL 9 must audit all uses of the su command.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-09-654165 - RHEL 9 must audit all uses of the unix_update command.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-09-654185 - Successful/unsuccessful uses of the init command in RHEL 9 must generate an audit record.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-654210 - Successful/unsuccessful uses of the umount2 system call in RHEL 9 must generate an audit record.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE