CCI|CCI-000015

Title

Support the management of system accounts using (organization-defined automated mechanisms).

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.68 RHEL-09-215101UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.222 OL08-00-030130UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.223 OL08-00-030140UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.224 OL08-00-030150UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.225 OL08-00-030160UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.226 OL08-00-030170UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.227 OL08-00-030171UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.228 OL08-00-030172UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.433 RHEL-09-654215UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.434 RHEL-09-654220UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.435 RHEL-09-654225UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.436 RHEL-09-654230UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.437 RHEL-09-654235UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.438 RHEL-09-654240UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.439 RHEL-09-654245UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
AIX7-00-001000 - AIX /etc/security/mkuser.sys.custom file must not exist unless it is needed for customizing a new user account.UnixDISA STIG AIX 7.x v3r1
AIX7-00-001015 - The shipped /etc/security/mkuser.sys file on AIX must not be customized directly.UnixDISA STIG AIX 7.x v3r1
AIX7-00-001016 - The regular users default primary group must be staff (or equivalent) on AIX.UnixDISA STIG AIX 7.x v3r1
AIX7-00-002016 - AIX must provide audit record generation functionality for DoD-defined auditable events.UnixDISA STIG AIX 7.x v3r1
ALMA-09-004970 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r3
ALMA-09-005080 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r3
ALMA-09-005190 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r3
ALMA-09-005300 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r3
ALMA-09-005410 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r3
ALMA-09-005960 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r3
ALMA-09-006070 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect the files within /etc/sudoers.d/UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r3
ALMA-09-006845 - AlmaLinux OS 9 must have the postfix package installed.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r3
AZLX-23-001075 - Amazon Linux 2023 must have the firewalld package installed.UnixDISA Amazon Linux 2023 STIG v1r1
AZLX-23-001080 - Amazon Linux 2023 must have the firewalld servicew active.UnixDISA Amazon Linux 2023 STIG v1r1
AZLX-23-002085 - Amazon Linux 2023 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.UnixDISA Amazon Linux 2023 STIG v1r1
AZLX-23-002090 - Amazon Linux 2023 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory.UnixDISA Amazon Linux 2023 STIG v1r1
AZLX-23-002095 - Amazon Linux 2023 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.UnixDISA Amazon Linux 2023 STIG v1r1
AZLX-23-002100 - Amazon Linux 2023 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.UnixDISA Amazon Linux 2023 STIG v1r1
AZLX-23-002105 - Amazon Linux 2023 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.UnixDISA Amazon Linux 2023 STIG v1r1
AZLX-23-002205 - Amazon Linux 2023 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.UnixDISA Amazon Linux 2023 STIG v1r1
AZLX-23-002250 - Amazon Linux 2023 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.UnixDISA Amazon Linux 2023 STIG v1r1
AZLX-23-002255 - Amazon Linux 2023 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.UnixDISA Amazon Linux 2023 STIG v1r1
Big Sur - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Big Sur - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
Big Sur - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Big Sur v1.4.0 - 800-53r4 High
Big Sur - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Big Sur v1.4.0 - All Profiles
Catalina - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
Catalina - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
CD12-00-000500 - PostgreSQL must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.UnixDISA STIG Crunchy Data PostgreSQL OS v3r1
CNTR-K8-000220 - The Kubernetes Controller Manager must create unique service accounts for each work payload.UnixDISA STIG Kubernetes v2r4
CNTR-R2-000030 - RKE2 must use a centralized user management solution to support account management functions.UnixDISA Rancher Government Solutions RKE2 STIG v2r3