Item Search

NameAudit NamePluginCategory
RHEL-10-000540 - RHEL 10 must use a separate file system for "/tmp".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-001030 - RHEL 10 must check the GNU Privacy Guard (GPG) signature of software packages originating from external software repositories before installation.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-001040 - RHEL 10 must check the GNU Privacy Guard (GPG) signature of locally installed software packages before installation.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200090 - RHEL 10 must not have a File Transfer Protocol (FTP) server package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

RHEL-10-200500 - RHEL 10 must have the "subscription-manager" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200531 - RHEL 10 must have the "firewalld" service set to active.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

RHEL-10-200542 - RHEL 10 must disable the chrony daemon from acting as a server.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200543 - RHEL 10 must disable network management of the chrony daemon.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200561 - RHEL 10 must have the USBGuard package enabled.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-200570 - RHEL 10 must have the "policycoreutils" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-200590 - RHEL 10 must have the "sudo" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-200601 - RHEL 10 must enable the "fapolicy" module.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200602 - RHEL 10 must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200612 - RHEL 10 must have the "pcsc-lite-ccid" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-200630 - RHEL 10 must have the Advanced Intrusion Detection Environment (AIDE) package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

RHEL-10-200642 - RHEL 10 must be configured to forward audit records via Transmission Control Protocol (TCP) to a different system or media from the system being audited via rsyslog.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-200643 - RHEL 10 must be configured so that the rsyslog daemon does not accept log messages from other servers unless the server is being used for log aggregation.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-600550 - RHEL 10 must use the invoking user's password for privilege escalation when using "sudo".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-600610 - RHEL 10 must configure the use of the pam_faillock.so module in the "/etc/pam.d/password-auth" file.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-600720 - RHEL 10 must be configured so that password-auth uses a sufficient number of hashing rounds.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-700020 - RHEL 10 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a graphical user login.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-700110 - RHEL 10 must prevent files with the "setuid" and "setgid" bit set from being executed on file systems that are imported via Network File System (NFS).DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-700150 - RHEL 10 must mount "/tmp" with the "nodev" option.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-700180 - RHEL 10 must mount "/var/log" with the "nosuid" option.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-700190 - RHEL 10 must mount "/var/tmp" with the "noexec" option.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-700570 - RHEL 10 must be configured so that the Secure Shell (SSH) daemon displays the date and time of the last successful account login upon an SSH login.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

RHEL-10-700610 - RHEL 10 must be configured so that SSHD does not allow blank passwords.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-700620 - RHEL 10 must not permit direct logins to the root account using remote access via Secure Shell (SSH).DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-700630 - RHEL 10 must not allow a noncertificate trusted host Secure Shell (SSH) login to the system.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-700650 - RHEL 10 must force a frequent session key renegotiation for Secure Shell (SSH) connections to the server.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-700690 - RHEL 10 must not have any ".shosts" files on the system.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-700710 - RHEL 10 must prevent a user from overriding the disabling of the graphical user interface autorun function.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-700760 - RHEL 10 must prevent a user from overriding the session idle-delay setting for the graphical user interface.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-700900 - RHEL 10 must implement nonexecutable data to protect its memory from unauthorized code execution.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

RHEL-10-701000 - RHEL 10 must clear the page allocator to prevent use-after-free attacks.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-701030 - RHEL 10 must restrict access to the kernel message buffer.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-701040 - RHEL 10 must prevent kernel profiling by nonprivileged users.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-701050 - RHEL 10 must prevent the loading of a new kernel for later execution.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-701140 - RHEL 10 must restrict usage of ptrace to descendant processes.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-701200 - RHEL 10 must disable the kdump service.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-701210 - RHEL 10 must disable file system automount function unless required.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-701250 - RHEL 10 must require authentication to access emergency mode.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-701260 - RHEL 10 must require authentication to access single-user mode.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-800010 - RHEL 10 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-800190 - RHEL 10 must not send Internet Control Message Protocol (ICMP) redirects.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-800200 - RHEL 10 must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-800210 - RHEL 10 must not enable Internet Protocol version 4 (IPv4) packet forwarding unless the system is a router.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-800220 - RHEL 10 must not accept router advertisements on all Internet Protocol version 6 (IPv6) interfaces.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-800290 - RHEL 10 must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring that rate-limiting measures on impacted network interfaces are implemented.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-900100 - RHEL 10 must prevent unauthorized changes to the audit system.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY