800-53|AU-14

Title

SESSION AUDIT

Description

The information system provides the capability for authorized users to select a user session to capture/record or view/hear.

Supplemental

Session audits include, for example, monitoring keystrokes, tracking websites visited, and recording information and/or file transfers. Session auditing activities are developed, integrated, and used in consultation with legal counsel in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, or standards.

Reference Item Details

Related: AC-3,AU-11,AU-4,AU-5,AU-9

Category: AUDIT AND ACCOUNTABILITY

Family: AUDIT AND ACCOUNTABILITY

Priority: P0

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1.30 (L1) Ensure 'Disable Forget Button' is set to 'Enabled'WindowsCIS Mozilla Firefox ESR GPO v1.0.0 L1
1.3 CISC-L2-000060CiscoCIS Cisco NX OS Switch L2S STIG v1.0.0 CAT II
1.3 UBTU-22-212015UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.3 VCEM-80-000013UnixCIS VMware vSphere 8.0 vCenter Appliance ESX Agent Manager EAM STIG v1.0.0 CAT II
1.3 VCLU-80-000013UnixCIS VMware vSphere 8.0 vCenter Appliance Lookup Service STIG v1.0.0 CAT II
1.3 VCPF-80-000013UnixCIS VMware vSphere 8.0 vCenter Appliance Perfcharts STIG v1.0.0 CAT II
1.3 VCST-80-000013UnixCIS VMware vSphere 8.0 vCenter Appliance Secure Token Service STS STIG v1.0.0 CAT II
1.3 VCUI-80-000013UnixCIS VMware vSphere 8.0 vCenter Appliance User Interface UI STIG v1.0.0 CAT II
1.4 CISC-L2-000070CiscoCIS Cisco NX OS Switch L2S STIG v1.0.0 CAT II
1.9 MADB-10-000900MySQLDBCIS MariaDB Enterprise 10.x STIG v1.1.0 CAT II MySQLDB
1.12 SQLI-22-004700MS_SQLDBCIS Microsoft SQL Server 2022 Instance STIG v1.0.0 CAT II MS_SQLDB
1.20 RHEL-09-212055UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT III
1.24 AZLX-23-001025UnixCIS Amazon Linux 2023 STIG v1.0.0 CAT II
1.25 AZLX-23-001030UnixCIS Amazon Linux 2023 STIG v1.0.0 CAT II
1.29 IBMW-LS-001190UnixCIS IBM WebSphere Liberty Server STIG v1.0.0 CAT II
1.33 UBTU-24-102010UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.34 APPL-14-001003UnixCIS Apple macOS 14 Sonoma STIG v1.0.0 CAT II
1.35 APPL-15-001003UnixCIS Apple macOS 15 Sequoia STIG v1.0.0 CAT II
1.35 APPL-26-001003UnixCIS Apple macOS 26 Tahoe STIG v1.0.0 CAT II
1.36 PHTN-40-000080UnixCIS VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v1.0.0 CAT II
1.65 RHEL-10-200660UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II
1.66 RHEL-10-200661UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II
1.84 OL09-00-000440UnixCIS Oracle Linux 9 STIG v1.0.0 CAT II
1.85 OL09-00-000441UnixCIS Oracle Linux 9 STIG v1.0.0 CAT II
1.108 SLES-15-030050UnixCIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT II
1.142 OL09-00-000750UnixCIS Oracle Linux 9 STIG v1.0.0 CAT III
1.157 OL09-00-000830UnixCIS Oracle Linux 9 STIG v1.0.0 CAT III
1.172 RHEL-10-500030UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II
1.174 AZLX-23-002515UnixCIS Amazon Linux 2023 STIG v1.0.0 CAT II
1.175 AZLX-23-002520UnixCIS Amazon Linux 2023 STIG v1.0.0 CAT II
1.229 OL08-00-030180UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.230 OL08-00-030181UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.366 ALMA-09-047980UnixCIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT II
1.367 RHEL-09-653010UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.368 RHEL-09-653015UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.389 RHEL-09-653120UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT III
AIX7-00-002023 - AIX must start audit at boot.UnixDISA IBM AIX 7.x STIG v3r2
ALMA-09-047980 - AlmaLinux OS 9 must enable auditing of processes that start prior to the audit daemon.UnixDISA Cloud Linux AlmaLinux OS 9 STIG v1r6
AOSX-15-001003 - The macOS system must initiate session audits at system startupUnixDISA STIG Apple Mac OSX 10.15 v1r10
APPL-13-001003 - The macOS system must produce audit records containing information to establish when, where, what type, the source, and the outcome for all DOD-defined auditable events and actions.UnixDISA STIG Apple macOS 13 v1r5
APPL-14-001003 - The macOS system must enable security auditing.UnixDISA Apple macOS 14 Sonoma STIG v2r4
APPL-15-001003 - The macOS system must enable security auditing.UnixDISA Apple macOS 15 Sequoia STIG v1r7
APPL-26-001003 - The macOS system must enable security auditing.UnixDISA Apple macOS 26 Tahoe STIG v1r2
AS24-U1-000070 - The Apache web server must generate, at a minimum, log records for system startup and shutdown, system access, and system authentication eventsUnixDISA STIG Apache Server 2.4 Unix Server v3r2 Middleware
AS24-U1-000070 - The Apache web server must generate, at a minimum, log records for system startup and shutdown, system access, and system authentication events.UnixDISA STIG Apache Server 2.4 Unix Server v3r2
AS24-W1-000070 - The Apache web server must generate, at a minimum, log records for system startup and shutdown, system access, and system authentication events.WindowsDISA STIG Apache Server 2.4 Windows Server v3r4
AS24-W1-000070 - The Apache web server must generate, at a minimum, log records for system startup and shutdown, system access, and system authentication events.WindowsDISA STIG Apache Server 2.4 Windows Server v2r3
AZLX-23-001025 - Amazon Linux 2023 must have the audit package installed.UnixDISA Amazon Linux 2023 STIG v1r3
AZLX-23-001030 - Amazon Linux 2023 must produce audit records containing information to establish what type of events occurred.UnixDISA Amazon Linux 2023 STIG v1r3
AZLX-23-002515 - Amazon Linux 2023 must enable auditing of processes that start prior to the audit daemon.UnixDISA Amazon Linux 2023 STIG v1r3