CCI|CCI-003980

Title

Allow user installation of software only with explicit privileged status.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.8 SQLD-22-001400MS_SQLDBCIS Microsoft SQL Server 2022 Database STIG v1.0.0 CAT II
1.53 EX19-MB-000194WindowsCIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0 CAT II
1.56 EX19-ED-000195WindowsCIS Microsoft Exchange 2019 Edge Server STIG v1.0.0 CAT II
1.64 MADB-10-007800MySQLDBCIS MariaDB Enterprise 10.x STIG v1.1.0 CAT II MySQLDB
1.135 WN19-CC-000420WindowsCIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT II
1.135 WN19-CC-000420WindowsCIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT II
1.135 WN22-CC-000420WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT II
1.135 WN22-CC-000420WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT II
1.136 WN19-CC-000430WindowsCIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT I
1.136 WN19-CC-000430WindowsCIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT I
1.136 WN22-CC-000430WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT I
1.136 WN22-CC-000430WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT I
1.149 APPL-26-005080UnixCIS Apple macOS 26 Tahoe STIG v1.0.0 CAT II
1.150 APPL-14-005080UnixCIS Apple macOS 14 Sonoma STIG v1.0.0 CAT II
1.152 APPL-15-005080UnixCIS Apple macOS 15 Sequoia STIG v1.0.0 CAT II
1.164 WN10-CC-000310WindowsCIS Microsoft Windows 10 STIG v1.0.0 CAT II
1.165 WN10-CC-000315WindowsCIS Microsoft Windows 10 STIG v1.0.0 CAT I
1.167 WN11-CC-000310WindowsCIS Microsoft Windows 11 STIG v1.2.0 CAT II
1.168 WN11-CC-000315WindowsCIS Microsoft Windows 11 STIG v1.2.0 CAT I
1.245 RHEL-10-600170UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II
APPL-14-005080 - The macOS system must prohibit user installation of software into /users/.UnixDISA Apple macOS 14 Sonoma STIG v2r4
APPL-15-005080 - The macOS system must prohibit user installation of software into /users/.UnixDISA Apple macOS 15 Sequoia STIG v1r7
APPL-26-005080 - The macOS system must prohibit user installation of software into /users/.UnixDISA Apple macOS 26 Tahoe STIG v1r3
CD12-00-008400 - PostgreSQL must prohibit user installation of logic modules (functions, trigger procedures, views, etc.) without explicit privileged status.UnixDISA STIG Crunchy Data PostgreSQL OS v3r1
CNTR-R2-001270 - Rancher RKE2 must prohibit the installation of patches, updates, and instantiation of container images without explicit privileged status.UnixDISA Rancher Government Solutions RKE2 STIG v2r7
EDGE-00-000039 - URLs must be allowlisted for plugin use if used.WindowsDISA Microsoft Edge STIG v2r5
EDGE-00-000039 - URLs must be allowlisted for plugin use if used.WindowsDISA STIG Edge v2r3
EPAS-00-008400 - The EDB Postgres Advanced Server must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.PostgreSQLDBEnterpriseDB PostgreSQL Advanced Server DB v2r1
EX19-ED-000195 - The Exchange application directory must be protected from unauthorized access.WindowsDISA Microsoft Exchange 2019 Edge Server STIG v2r2
EX19-MB-000194 - The Exchange application directory must be protected from unauthorized access.WindowsDISA Microsoft Exchange 2019 Mailbox Server STIG v2r3
JUEX-NM-000450 - The Juniper EX switch must be configured to prohibit installation of software without explicit privileged status.JuniperDISA Juniper EX Series Switches Network Device Management STIG v2r5
JUNI-ND-001060 - The Juniper router must be configured to prohibit installation of software without explicit privileged status.JuniperDISA STIG Juniper Router NDM v3r2
JUSX-DM-000077 - The Juniper SRX Services Gateway must implement logon roles to ensure only authorized roles are allowed to install software and updates.JuniperDISA Juniper SRX Services Gateway NDM v3r3
MADB-10-007800 - MariaDB must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.MySQLDBDISA MariaDB Enterprise 10.x STIG v2r5 MySQLDB
MD8X-00-007300 - MongoDB must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.MongoDBDISA MongoDB Enterprise Advanced 8.x STIG v1r1 MongoDB
MYS8-00-009100 - The MySQL Database Server 8.0 must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.MySQLDBDISA Oracle MySQL 8.0 v2r2 DB
RHEL-10-600170 - RHEL 10 must be configured so that all local interactive user initialization file executable search path statements do not contain statements that will reference a working directory other than user home directories.UnixDISA Red Hat Enterprise Linux 10 STIG v1r2
WN10-CC-000310 - Users must be prevented from changing installation options.WindowsDISA Microsoft Windows 10 STIG v3r6
WN10-CC-000315 - The Windows Installer Always install with elevated privileges must be disabled.WindowsDISA Microsoft Windows 10 STIG v3r6
WN11-CC-000310 - Users must be prevented from changing installation options.WindowsDISA Microsoft Windows 11 STIG v2r9
WN11-CC-000315 - The Windows Installer feature 'Always install with elevated privileges' must be disabled.WindowsDISA Microsoft Windows 11 STIG v2r9
WN19-CC-000420 - Windows Server 2019 must prevent users from changing installation options.WindowsDISA Microsoft Windows Server 2019 STIG v3r8
WN19-CC-000430 - Windows Server 2019 must disable the Windows Installer Always install with elevated privileges option.WindowsDISA Microsoft Windows Server 2019 STIG v3r8
WN22-CC-000420 - Windows Server 2022 must prevent users from changing installation options.WindowsDISA Microsoft Windows Server 2022 STIG v2r8
WN22-CC-000420 - Windows Server 2022 must prevent users from changing installation options.WindowsDISA Microsoft Windows Server 2022 STIG v2r10
WN22-CC-000430 - Windows Server 2022 must disable the Windows Installer Always install with elevated privileges option.WindowsDISA Microsoft Windows Server 2022 STIG v2r8
WN22-CC-000430 - Windows Server 2022 must disable the Windows Installer Always install with elevated privileges option.WindowsDISA Microsoft Windows Server 2022 STIG v2r10
WN25-CC-000420 - Windows Server 2025 must prevent users from changing installation options.WindowsDISA Microsoft Windows Server 2025 STIG v1r1
WN25-CC-000420 - Windows Server 2025 must prevent users from changing installation options.WindowsDISA Microsoft Windows Server 2025 STIG v1r3
WN25-CC-000430 - Windows Server 2025 must disable the Windows Installer Always install with elevated privileges option.WindowsDISA Microsoft Windows Server 2025 STIG v1r1