CCI|CCI-001764

Title

Prevent program execution in accordance with organization-defined policies, rules of behavior, and/or access agreements regarding software program usage and restrictions; rules authorizing the terms and conditions of software program usage.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1.7 Ensure noexec option set on /dev/shm partition - fstabUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.1.7 Ensure noexec option set on /dev/shm partition - mountUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.1.8 Ensure nodev option set on /dev/shm partition - fstabUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.1.8 Ensure nodev option set on /dev/shm partition - mountUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.1.9 Ensure nosuid option set on /dev/shm partition - fstabUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.1.9 Ensure nosuid option set on /dev/shm partition - mountUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.16 UBTU-24-100500UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.17 UBTU-24-100510UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.77 RHEL-09-231045UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.78 RHEL-09-231050UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.86 RHEL-09-231095UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.86 UBTU-22-431010UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.87 UBTU-22-431015UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.88 RHEL-09-231105UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.89 RHEL-09-231110UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.90 RHEL-09-231115UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.91 RHEL-09-231120UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.92 RHEL-09-231125UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.93 RHEL-09-231130UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.94 RHEL-09-231135UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.95 RHEL-09-231140UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.96 RHEL-09-231145UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.97 RHEL-09-231150UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.98 RHEL-09-231155UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.99 RHEL-09-231160UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.100 RHEL-09-231165UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.101 RHEL-09-231170UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.102 RHEL-09-231175UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.103 RHEL-09-231180UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.104 RHEL-09-231185UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.241 RHEL-09-271030UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.310 RHEL-09-433010UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.311 RHEL-09-433015UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.312 RHEL-09-433016UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
2.022 - Disallow AutoPlay/Autorun from Autorun.infWindowsDISA Windows Vista STIG v6r41
3.059 - The system is configured to autoplay removable media.WindowsDISA Windows Vista STIG v6r41
AIOS-12-003600 - Apple iOS must be configured to display the DoD advisory warning message at start-up or each time the user unlocks the device.MDMAirWatch - DISA Apple iOS 12 v2r1
AIOS-12-003600 - Apple iOS must be configured to display the DoD advisory warning message at start-up or each time the user unlocks the device.MDMMobileIron - DISA Apple iOS 12 v2r1
AIOS-13-003600 - Apple iOS/iPadOS must be configured to display the DoD advisory warning message at start-up or each time the user unlocks the device.MDMAirWatch - DISA Apple iOS/iPadOS 13 v2r1
AIOS-13-003600 - Apple iOS/iPadOS must be configured to display the DoD advisory warning message at start-up or each time the user unlocks the device.MDMMobileIron - DISA Apple iOS/iPadOS 13 v2r1
AIX7-00-003025 - AIX must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.UnixDISA STIG AIX 7.x v3r1
ALMA-09-025980 - AlmaLinux OS 9 must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-026090 - AlmaLinux OS 9 must prevent device files from being interpreted on file systems that contain user home directories.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-026200 - AlmaLinux OS 9 must prevent files with the setuid and setgid bit set from being executed on the /boot/efi directory.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-026310 - AlmaLinux OS 9 must mount /boot with the nodev option.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-026420 - AlmaLinux OS 9 must prevent files with the setuid and setgid bit set from being executed on the /boot directory.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-026530 - AlmaLinux OS 9 must mount /dev/shm with the nodev option.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-026640 - AlmaLinux OS 9 must mount /dev/shm with the noexec option.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-026750 - AlmaLinux OS 9 must mount /dev/shm with the nosuid option.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-026860 - AlmaLinux OS 9 must mount /tmp with the nodev option.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2