CCI|CCI-002132

Title

The information system notifies organization-defined personnel or roles for account enabling actions.

Reference Item Details

Category: 2013

Audit Items

View all Reference Audit Items

NamePluginAudit Name
AIX7-00-002016 - AIX must provide audit record generation functionality for DoD-defined auditable events.UnixDISA STIG AIX 7.x v2r9
Big Sur - Configure the System to Notify upon Account Enabled ActionsUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Configure the System to Notify upon Account Enabled ActionsUnixNIST macOS Big Sur v1.4.0 - 800-53r4 High
Big Sur - Configure the System to Notify upon Account Enabled ActionsUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Configure the System to Notify upon Account Enabled ActionsUnixNIST macOS Big Sur v1.4.0 - All Profiles
Catalina - Configure the System to Notify upon Account Enabled ActionsUnixNIST macOS Catalina v1.5.0 - 800-53r4 Moderate
Catalina - Configure the System to Notify upon Account Enabled ActionsUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
Catalina - Configure the System to Notify upon Account Enabled ActionsUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Configure the System to Notify upon Account Enabled ActionsUnixNIST macOS Catalina v1.5.0 - All Profiles
F5BI-DM-000173 - The BIG-IP appliance must be configured to generate an immediate alert for account-enabling actions.F5DISA F5 BIG-IP Device Management STIG v2r3
JUSX-DM-000097 - The Juniper SRX Services Gateway must be configured to use a centralized authentication server to authenticate privileged users for remote and nonlocal access for device management.JuniperDISA Juniper SRX Services Gateway NDM v2r1
Monterey - Configure the System to Notify upon Account Enabled ActionsUnixNIST macOS Monterey v1.0.0 - 800-53r4 High
Monterey - Configure the System to Notify upon Account Enabled ActionsUnixNIST macOS Monterey v1.0.0 - 800-53r4 Moderate
Monterey - Configure the System to Notify upon Account Enabled ActionsUnixNIST macOS Monterey v1.0.0 - All Profiles
Monterey - Configure the System to Notify upon Account Enabled ActionsUnixNIST macOS Monterey v1.0.0 - CNSSI 1253
OL08-00-030130 - OL 8 must generate audit records for all account creation events that affect '/etc/shadow' - /etc/shadow.UnixDISA Oracle Linux 8 STIG v1r8
OL08-00-030140 - OL 8 must generate audit records for all account creation events that affect '/etc/security/opasswd' - /etc/security/opasswd.UnixDISA Oracle Linux 8 STIG v1r8
OL08-00-030150 - OL 8 must generate audit records for all account creation events that affect '/etc/passwd' - /etc/passwd.UnixDISA Oracle Linux 8 STIG v1r8
OL08-00-030160 - OL 8 must generate audit records for all account creation events that affect '/etc/gshadow' - /etc/gshadow.UnixDISA Oracle Linux 8 STIG v1r8
OL08-00-030170 - OL 8 must generate audit records for all account creation events that affect '/etc/group' - /etc/group.UnixDISA Oracle Linux 8 STIG v1r8
OL08-00-030171 - OL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect '/etc/sudoers' - /etc/sudoers.UnixDISA Oracle Linux 8 STIG v1r8
OL08-00-030172 - OL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect '/etc/sudoers.d/' - /etc/sudoers.d/.UnixDISA Oracle Linux 8 STIG v1r8
PHTN-67-000045 - The Photon operating system must audit all account modifications - groupUnixDISA STIG VMware vSphere 6.7 Photon OS v1r6
PHTN-67-000045 - The Photon operating system must audit all account modifications - gshadowUnixDISA STIG VMware vSphere 6.7 Photon OS v1r6
PHTN-67-000045 - The Photon operating system must audit all account modifications - passwdUnixDISA STIG VMware vSphere 6.7 Photon OS v1r6
PHTN-67-000045 - The Photon operating system must audit all account modifications - shadowUnixDISA STIG VMware vSphere 6.7 Photon OS v1r6
RHEL-09-654215 - RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.UnixDISA Red Hat Enterprise Linux 9 STIG v1r2
RHEL-09-654220 - RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory.UnixDISA Red Hat Enterprise Linux 9 STIG v1r2
RHEL-09-654225 - RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.UnixDISA Red Hat Enterprise Linux 9 STIG v1r2
RHEL-09-654230 - RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.UnixDISA Red Hat Enterprise Linux 9 STIG v1r2
RHEL-09-654235 - RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.UnixDISA Red Hat Enterprise Linux 9 STIG v1r2
RHEL-09-654240 - RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.UnixDISA Red Hat Enterprise Linux 9 STIG v1r2
RHEL-09-654245 - RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.UnixDISA Red Hat Enterprise Linux 9 STIG v1r2
SLES-12-020200 - The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.UnixDISA SLES 12 STIG v2r13
SLES-12-020210 - The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.UnixDISA SLES 12 STIG v2r13
SLES-12-020220 - The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.UnixDISA SLES 12 STIG v2r13
SLES-12-020230 - The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.UnixDISA SLES 12 STIG v2r13
SLES-15-030000 - The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.UnixDISA SLES 15 STIG v1r12
SLES-15-030010 - The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.UnixDISA SLES 15 STIG v1r12
SLES-15-030020 - The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.UnixDISA SLES 15 STIG v1r12
SLES-15-030030 - The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.UnixDISA SLES 15 STIG v1r12
UBTU-16-020300 - The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.UnixDISA STIG Ubuntu 16.04 LTS v2r3
UBTU-16-020310 - The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.UnixDISA STIG Ubuntu 16.04 LTS v2r3
UBTU-16-020320 - The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.UnixDISA STIG Ubuntu 16.04 LTS v2r3
UBTU-16-020330 - The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.UnixDISA STIG Ubuntu 16.04 LTS v2r3
UBTU-16-020340 - The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.UnixDISA STIG Ubuntu 16.04 LTS v2r3
VCSA-70-000123 - The vCenter Server must provide an immediate real-time alert to the system administrator (SA) and information system security officer (ISSO), at a minimum, on every Single Sign-On (SSO) account action.VMwareDISA STIG VMware vSphere 7.0 vCenter v1r2