Item Search

NameAudit NamePluginCategory
RHEL-10-200090 - RHEL 10 must not have a File Transfer Protocol (FTP) server package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

RHEL-10-200531 - RHEL 10 must have the "firewalld" service set to active.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

RHEL-10-200542 - RHEL 10 must disable the chrony daemon from acting as a server.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200543 - RHEL 10 must disable network management of the chrony daemon.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200561 - RHEL 10 must have the USBGuard package enabled.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-200570 - RHEL 10 must have the "policycoreutils" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-200590 - RHEL 10 must have the "sudo" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-200601 - RHEL 10 must enable the "fapolicy" module.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200602 - RHEL 10 must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200612 - RHEL 10 must have the "pcsc-lite-ccid" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-200630 - RHEL 10 must have the Advanced Intrusion Detection Environment (AIDE) package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

RHEL-10-200642 - RHEL 10 must be configured to forward audit records via Transmission Control Protocol (TCP) to a different system or media from the system being audited via rsyslog.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-200643 - RHEL 10 must be configured so that the rsyslog daemon does not accept log messages from other servers unless the server is being used for log aggregation.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-200645 - RHEL 10 must encrypt the transfer of audit records off-loaded onto a different system or media from the system being audited via rsyslog.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-200646 - RHEL 10 must encrypt, via the gtls driver, the transfer of audit records off-loaded onto a different system or media from the system being audited via rsyslog.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-200662 - RHEL 10 must have the "audispd-plugins" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-200721 - RHEL 10 must, for all networked systems, have and implement Secure Shell (SSH) to protect the confidentiality and integrity of transmitted and received information.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-300000 - RHEL 10 must have the "crypto-policies" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-300010 - RHEL 10 must implement a FIPS 140-3-compliant systemwide cryptographic policy.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-400075 - RHEL 10 must be configured so that the "/etc/shadow-" file is group-owned by "root".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400080 - RHEL 10 must be configured so that the "/var/log" directory is owned by "root".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

RHEL-10-400100 - RHEL 10 must be configured so that system commands are owned by "root".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-400120 - RHEL 10 must be configured so that library directories are owned by "root".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-400125 - RHEL 10 must be configured so that library directories are group-owned by "root" or a system account.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-400140 - RHEL 10 must be configured so that world-writable directories are owned by root, sys, bin, or an application user.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-400170 - RHEL 10 must enforce "root" ownership of the audit log directory to prevent unauthorized read access.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

RHEL-10-400265 - RHEL 10 must enforce mode "0644" or less permissive for the "/etc/passwd" file to prevent unauthorized access.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400285 - RHEL 10 must be configured so that all local files and directories have a valid group owner.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400320 - RHEL 10 must define default permissions for the c shell.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400325 - RHEL 10 must define default permissions for all authenticated users in such a way that the user can read and modify only their own files.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400345 - RHEL 10 must enforce "root" group ownership of the "/boot/grub2/grub.cfg" file.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-500000 - RHEL 10 must enable the systemd-journald service.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-500010 - RHEL 10 must audit local events.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-500025 - RHEL 10 must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-500110 - RHEL 10 must take action when allocated audit record storage volume reaches 95 percent of the repository maximum audit record storage capacity.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-500115 - RHEL 10 must take appropriate action when the internal event queue is full.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-500120 - RHEL 10 must produce audit records containing information to establish the identity of any individual or process associated with the event.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-500205 - RHEL 10 must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume 75 percent utilization.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-500210 - RHEL 10 must notify the system administrator (SA) and/or information system security officer (ISSO) (at a minimum) of an audit processing failure.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-500320 - RHEL 10 must generate audit records for successful and unsuccessful uses of "umount" system calls.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500350 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "chcon" command.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500420 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "chage" command.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500500 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "postdrop" command.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500540 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "su" command.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500590 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "userhelper" command.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500670 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "umount2" system call.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500730 - RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/passwd".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500750 - RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/var/log/faillock".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-600020 - RHEL 10 must not assign an interactive login shell for system accounts.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

RHEL-10-600230 - RHEL 10 must enforce password complexity by requiring at least one special character to be used.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION