CCI|CCI-004188

Title

Monitor the use of maintenance tools that execute with increased privilege.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.32 APPL-14-001001UnixCIS Apple macOS 14 (Sonoma) STIG v1.0.0 CAT II
1.34 APPL-14-001003UnixCIS Apple macOS 14 (Sonoma) STIG v1.0.0 CAT II
1.97 UBTU-24-500010UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.178 UBTU-22-654235UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.230 OL08-00-030181UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.368 RHEL-09-653015UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
ALMA-09-004970 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r3
APPL-14-001001 - The macOS system must be configured to audit all administrative action events.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-001003 - The macOS system must enable security auditing.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-15-001003 - The macOS system must enable security auditing.UnixDISA Apple macOS 15 (Sequoia) STIG v1r4
OL08-00-030181 - OL 8 audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.UnixDISA Oracle Linux 8 STIG v2r5
OL09-00-000715 - OL 9 must audit uses of the execve system call.UnixDISA Oracle Linux 9 STIG v1r2
RHEL-09-653015 - RHEL 9 audit service must be enabled.UnixDISA Red Hat Enterprise Linux 9 STIG v2r4
SOL-11.1-010040 - The audit system must produce records containing sufficient information to establish the identity of any user/subject associated with the event.UnixDISA Solaris 11 SPARC STIG v3r3
SOL-11.1-010040 - The audit system must produce records containing sufficient information to establish the identity of any user/subject associated with the event.UnixDISA Solaris 11 X86 STIG v3r3
UBTU-22-654235 - Ubuntu 22.04 LTS must generate audit records for privileged activities, nonlocal maintenance, diagnostic sessions and other system-level access.UnixDISA Canonical Ubuntu 22.04 LTS STIG v2r5
UBTU-24-200580 - Ubuntu 24.04 LTS must prevent all software from executing at higher privilege levels than users executing the software and the audit system must be configured to audit the execution of privileged functions.UnixDISA Canonical Ubuntu 24.04 LTS STIG v1r2