CCI|CCI-000015

Title

Support the management of system accounts using (organization-defined automated mechanisms).

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.68 RHEL-09-215101UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.222 OL08-00-030130UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.223 OL08-00-030140UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.224 OL08-00-030150UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.225 OL08-00-030160UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.226 OL08-00-030170UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.227 OL08-00-030171UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.228 OL08-00-030172UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.433 RHEL-09-654215UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.434 RHEL-09-654220UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.435 RHEL-09-654225UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.436 RHEL-09-654230UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.437 RHEL-09-654235UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.438 RHEL-09-654240UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.439 RHEL-09-654245UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
AIX7-00-001000 - AIX /etc/security/mkuser.sys.custom file must not exist unless it is needed for customizing a new user account.UnixDISA STIG AIX 7.x v3r1
AIX7-00-001015 - The shipped /etc/security/mkuser.sys file on AIX must not be customized directly.UnixDISA STIG AIX 7.x v3r1
AIX7-00-001016 - The regular users default primary group must be staff (or equivalent) on AIX.UnixDISA STIG AIX 7.x v3r1
AIX7-00-002016 - AIX must provide audit record generation functionality for DoD-defined auditable events.UnixDISA STIG AIX 7.x v3r1
ALMA-09-004970 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-005080 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-005190 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-005300 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-005410 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-005960 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-006070 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect the files within /etc/sudoers.d/UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-006845 - AlmaLinux OS 9 must have the postfix package installed.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
Big Sur - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Big Sur - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
Big Sur - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Big Sur v1.4.0 - 800-53r4 High
Big Sur - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Big Sur v1.4.0 - All Profiles
Catalina - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
Catalina - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Catalina v1.5.0 - 800-53r5 Moderate
Catalina - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Catalina v1.5.0 - 800-53r4 Moderate
CD12-00-000500 - PostgreSQL must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.UnixDISA STIG Crunchy Data PostgreSQL OS v3r1
CNTR-K8-000220 - The Kubernetes Controller Manager must create unique service accounts for each work payload.UnixDISA STIG Kubernetes v2r4
CNTR-R2-000030 - RKE2 must use a centralized user management solution to support account management functions.UnixDISA Rancher Government Solutions RKE2 STIG v2r3
DB2X-00-000300 - DB2 must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principalsUnixDISA STIG IBM DB2 v10.5 LUW v2r1 OS Linux
DB2X-00-000300 - DB2 must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principalsWindowsDISA STIG IBM DB2 v10.5 LUW v2r1 OS Windows
DB2X-00-000300 - DB2 must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals - ldap enabledIBM_DB2DBDISA STIG IBM DB2 v10.5 LUW v2r1 Database
DKER-EE-001100 - LDAP integration in Docker Enterprise must be configured.UnixDISA STIG Docker Enterprise 2.x Linux/Unix UCP v2r2
EP11-00-000700 - The EDB Postgres Advanced Server must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.WindowsEDB PostgreSQL Advanced Server v11 Windows OS Audit v2r4
EPAS-00-000700 - The EDB Postgres Advanced Server must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.UnixEnterpriseDB PostgreSQL Advanced Server OS Linux v2r1
ESXI-80-000114 - The ESXi host must offload logs via syslog.VMwareDISA VMware vSphere 8.0 ESXi STIG v2r3
ESXI-80-000114 - The ESXi host must offload logs via syslog.VMwareDISA VMware vSphere 8.0 ESXi STIG v2r3 VMware