CCI|CCI-002165

Title

Enforce organization-defined discretionary access control policies over defined subjects and objects.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.6.1.3 Ensure SELinux policy is configuredUnixCIS Amazon Linux 2 STIG v2.0.0 L1 Workstation
1.6.1.3 Ensure SELinux policy is configuredUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.6.1.3 Ensure SELinux policy is configuredUnixCIS Amazon Linux 2 STIG v2.0.0 L1 Server
1.6.1.3 Ensure SELinux policy is configuredUnixCIS Amazon Linux 2 STIG v2.0.0 STIG
1.6.1.5 Ensure the SELinux mode is enforcingUnixCIS Amazon Linux 2 STIG v2.0.0 STIG
1.6.1.5 Ensure the SELinux mode is enforcingUnixCIS Amazon Linux 2 STIG v2.0.0 L2 Workstation
1.6.1.5 Ensure the SELinux mode is enforcingUnixCIS Amazon Linux 2 STIG v2.0.0 L2 Server
1.6.1.5 Ensure the SELinux mode is enforcingUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.6.1.9 Ensure non-privileged users are prevented from executing privileged functionsUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.6.1.9 Ensure non-privileged users are prevented from executing privileged functionsUnixCIS Amazon Linux 2 STIG v2.0.0 STIG
1.16 UBTU-24-100500UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.25 RHEL-09-213030UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.26 RHEL-09-213035UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.61 OL08-00-010373UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.64 OL08-00-010374UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.86 UBTU-22-431010UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.309 RHEL-09-432035UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
2.006 - ACLs for system files and directories do not conform to minimum requirements. - 'C:'WindowsDISA Windows Vista STIG v6r41
2.006 - ACLS FOR SYSTEM FILES AND DIRECTORIES DO NOT CONFORM TO MINIMUM REQUIREMENTS. - 'C:\Program Files'WindowsDISA Windows Vista STIG v6r41
2.006 - ACLS FOR SYSTEM FILES AND DIRECTORIES DO NOT CONFORM TO MINIMUM REQUIREMENTS. - 'C:\Windows'WindowsDISA Windows Vista STIG v6r41
6.1.11 Ensure no unowned files or directories existUnixCIS Amazon Linux 2 STIG v2.0.0 L1 Workstation
6.1.11 Ensure no unowned files or directories existUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
6.1.11 Ensure no unowned files or directories existUnixCIS Amazon Linux 2 STIG v2.0.0 STIG
6.1.11 Ensure no unowned files or directories existUnixCIS Amazon Linux 2 STIG v2.0.0 L1 Server
6.1.12 Ensure no ungrouped files or directories existUnixCIS Amazon Linux 2 STIG v2.0.0 L1 Workstation
6.1.12 Ensure no ungrouped files or directories existUnixCIS Amazon Linux 2 STIG v2.0.0 STIG
6.1.12 Ensure no ungrouped files or directories existUnixCIS Amazon Linux 2 STIG v2.0.0 L1 Server
6.1.12 Ensure no ungrouped files or directories existUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
6.1.15 Ensure the file permissions ownership and group membership of system files and commands match the vendor valuesUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
AIX7-00-003020 - AIX must use Trusted Execution (TE) Check policy.UnixDISA STIG AIX 7.x v3r1
AIX7-00-003098 - AIX must allow admins to send a message to all the users who logged in currently.UnixDISA STIG AIX 7.x v3r1
AIX7-00-003099 - AIX must allow admins to send a message to a user who logged in currently.UnixDISA STIG AIX 7.x v3r1
ALMA-09-032470 - AlmaLinux OS 9 must restrict the use of the "su" command.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r3
AZLX-23-001005 - Amazon Linux 2023 must not be configured to bypass password requirements for privilege escalation.UnixDISA Amazon Linux 2023 STIG v1r1
AZLX-23-002440 - Amazon Linux 2023 must restrict the use of the "su" command.UnixDISA Amazon Linux 2023 STIG v1r1
AZLX-23-002535 - Amazon Linux 2023 must enable discretionary access control on hardlinks.UnixDISA Amazon Linux 2023 STIG v1r1
AZLX-23-002540 - Amazon Linux 2023 must enable kernel parameters to enforce discretionary access control on symlinks.UnixDISA Amazon Linux 2023 STIG v1r1
Big Sur - Allow Administrators to Modify Security Settings and System AttributesUnixNIST macOS Big Sur v1.4.0 - All Profiles
Big Sur - Allow Administrators to Promote Other Users to Administrator StatusUnixNIST macOS Big Sur v1.4.0 - All Profiles
Big Sur - Allow Information Transfer with Other Operating SystemsUnixNIST macOS Big Sur v1.4.0 - All Profiles
Catalina - Allow Administrators to Modify Security Settings and System AttributesUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Allow Administrators to Promote Other Users to Administrator StatusUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Allow Information Transfer with Other Operating SystemsUnixNIST macOS Catalina v1.5.0 - All Profiles
CD12-00-002200 - PostgreSQL must enforce discretionary access control policies, as defined by the data owner, over defined subjects and objects.UnixDISA STIG Crunchy Data PostgreSQL OS v3r1
DKER-EE-001170 - A policy set using the built-in role-based access control (RBAC) capabilities in the Universal Control Plane (UCP) component of Docker Enterprise must be configured.UnixDISA STIG Docker Enterprise 2.x Linux/Unix UCP v2r2
DKER-EE-001180 - A policy set using the built-in role-based access control (RBAC) capabilities in the Docker Trusted Registry (DTR) component of Docker Enterprise must be set - repositoryAccessUnixDISA STIG Docker Enterprise 2.x Linux/Unix DTR v2r2
DKER-EE-001180 - A policy set using the built-in role-based access control (RBAC) capabilities in the Docker Trusted Registry (DTR) component of Docker Enterprise must be set - team member accessUnixDISA STIG Docker Enterprise 2.x Linux/Unix UCP v2r2
DTOO199 - Changing permissions on rights managed content for users must be enforced.WindowsDISA STIG Microsoft Office System 2013 v2r2
DTOO199 - Office System - Changing permissions on rights managed content for users must be enforced.WindowsDISA STIG Office System 2010 v1r13
DTOO200 - Office System - Office must be configured to not allow read with browsers.WindowsDISA STIG Office System 2010 v1r13