SV-215662r1050869_rule - The Cisco router must be configured to limit the number of concurrent management sessions to an organization-defined number.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215662r1050869_rule
SV-215663r960777_rule - The Cisco router must be configured to automatically audit account creation.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215663r960777_rule
SV-215664r960780_rule - The Cisco router must be configured to automatically audit account modification.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215664r960780_rule
SV-215665r960783_rule - The Cisco router must be configured to automatically audit account disabling actions.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215665r960783_rule
SV-215666r960786_rule - The Cisco router must be configured to automatically audit account removal actions.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215666r960786_rule
SV-215667r991819_rule - The Cisco router must be configured to enforce approved authorizations for controlling the flow of management information within the device based on control policies.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215667r991819_rule
SV-215668r960840_rule - The Cisco router must be configured to enforce the limit of three consecutive invalid logon attempts, after which time it must lock out the user account from accessing the device for 15 minutes.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215668r960840_rule
SV-215669r960843_rule - The Cisco router must be configured to display the Standard Mandatory DoD Notice and Consent Banner before granting access to the device.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215669r960843_rule
SV-215670r984088_rule - The Cisco device must be configured to audit all administrator activity.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215670r984088_rule
SV-215672r960894_rule - The Cisco router must produce audit records containing information to establish when (date and time) the events occurred.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215672r960894_rule
SV-215673r960897_rule - The Cisco router must produce audit records containing information to establish where the events occurred.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215673r960897_rule
SV-215674r960909_rule - The Cisco router must be configured to generate audit records containing the full-text recording of privileged commands.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215674r960909_rule
SV-215675r960933_rule - The Cisco router must be configured to protect audit information from unauthorized modification.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215675r960933_rule
SV-215676r960936_rule - The Cisco router must be configured to protect audit information from unauthorized deletion.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215676r960936_rule
SV-215677r960960_rule - The Cisco router must be configured to limit privileges to change the software resident within software libraries.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215677r960960_rule
SV-215678r1043177_rule - The Cisco router must be configured to prohibit the use of all unnecessary and nonsecure functions and services.
cisco_ios_router_ndm · high (CAT I)
stig://rule/SV-215678r1043177_rule
SV-215679r1051115_rule - The Cisco router must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215679r1051115_rule
SV-215681r991820_rule - The Cisco router must be configured to enforce a minimum 15-character password length.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215681r991820_rule
SV-215682r991823_rule - The Cisco router must be configured to enforce password complexity by requiring that at least one uppercase character be used.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215682r991823_rule
SV-215683r991826_rule - The Cisco router must be configured to enforce password complexity by requiring that at least one lowercase character be used.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215683r991826_rule
SV-215684r991827_rule - The Cisco router must be configured to enforce password complexity by requiring that at least one numeric character be used.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215684r991827_rule
SV-215685r991828_rule - The Cisco router must be configured to enforce password complexity by requiring that at least one special character be used.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215685r991828_rule
SV-215686r1043189_rule - The Cisco router must be configured to require that when a password is changed, the characters are changed in at least eight of the positions within the password.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215686r1043189_rule
SV-215687r991830_rule - The Cisco router must only store cryptographic representations of passwords.
cisco_ios_router_ndm · high (CAT I)
stig://rule/SV-215687r991830_rule
SV-215688r961068_rule - The Cisco router must be configured to terminate all network connections associated with device management after five minutes of inactivity.
cisco_ios_router_ndm · high (CAT I)
stig://rule/SV-215688r961068_rule
SV-215689r961290_rule - The Cisco router must be configured to automatically audit account enabling actions.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215689r961290_rule
SV-215691r961392_rule - The Cisco router must be configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215691r961392_rule
SV-215692r991831_rule - The Cisco router must be configured to generate an alert for all audit failure events.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215692r991831_rule
SV-215693r991832_rule - The Cisco router must be configured to synchronize its clock with the primary and secondary time sources using redundant authoritative time sources.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215693r991832_rule
SV-215696r961506_rule - The Cisco router must be configured to authenticate SNMP messages using a FIPS-validated Keyed-Hash Message Authentication Code (HMAC).
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215696r961506_rule
SV-215697r961506_rule - The Cisco router must be configured to encrypt SNMP messages using a FIPS 140-2 approved algorithm.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215697r961506_rule
SV-215698r1107152_rule - The Cisco router must be configured to authenticate Network Time Protocol (NTP) sources using authentication that is cryptographically based.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215698r1107152_rule
SV-215699r961554_rule - The Cisco router must be configured to use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of remote maintenance sessions.
cisco_ios_router_ndm · high (CAT I)
stig://rule/SV-215699r961554_rule
SV-215700r961557_rule - The Cisco router must be configured to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions.
cisco_ios_router_ndm · high (CAT I)
stig://rule/SV-215700r961557_rule
SV-215701r961620_rule - The Cisco router must be configured to protect against known types of denial-of-service (DoS) attacks by employing organization-defined security safeguards.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215701r961620_rule
SV-215703r961812_rule - The Cisco router must be configured to generate log records when administrator privileges are deleted.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215703r961812_rule
SV-215704r961824_rule - The Cisco router must be configured to generate audit records when successful/unsuccessful logon attempts occur.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215704r961824_rule
SV-215705r961827_rule - The Cisco router must be configured to generate log records for privileged activities.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215705r961827_rule
SV-215709r961863_rule - The Cisco router must be configured to use at least two authentication servers for the purpose of authenticating users prior to granting administrative access.
cisco_ios_router_ndm · high (CAT I)
stig://rule/SV-215709r961863_rule
SV-215710r1069534_rule - The Cisco router must be configured to back up the configuration when changes occur.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215710r1069534_rule
SV-215711r991834_rule - The Cisco router must be configured to obtain its public key certificates from an appropriate certificate policy through an approved service provider.
cisco_ios_router_ndm · medium (CAT II)
stig://rule/SV-215711r991834_rule
SV-220136r961863_rule - The Cisco router must be configured to send log data to at least two syslog servers for the purpose of forwarding alerts to the administrators and the ISSO.
cisco_ios_router_ndm · high (CAT I)
stig://rule/SV-220136r961863_rule
SV-220137r961863_rule - The Cisco router must be running an IOS release that is currently supported by Cisco Systems.
cisco_ios_router_ndm · high (CAT I)
stig://rule/SV-220137r961863_rule
SV-216551r1117236_rule - The Cisco router must be configured to enforce approved authorizations for controlling the flow of information within the network based on organization-defined information flow control policies.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216551r1117236_rule
SV-216555r1007824_rule - The Cisco router must be configured to enable routing protocol authentication using FIPS 198-1 algorithms with keys not exceeding 180 days of lifetime.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216555r1007824_rule
SV-216556r1117237_rule - The Cisco router must be configured to have all inactive interfaces disabled.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216556r1117237_rule
SV-216559r856180_rule - The Cisco router must not be configured to have any zero-touch deployment feature enabled when connected to an operational network.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216559r856180_rule
SV-216560r991835_rule - The Cisco router must be configured to protect against or limit the effects of denial-of-service (DoS) attacks by employing control plane protection.
cisco_ios_router_rtr · high (CAT I)
stig://rule/SV-216560r991835_rule
SV-216563r856182_rule - The Cisco router must be configured to have Gratuitous ARP disabled on all external interfaces.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216563r856182_rule
SV-216564r856183_rule - The Cisco router must be configured to have IP directed broadcast disabled on all interfaces.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216564r856183_rule
SV-216565r856184_rule - The Cisco router must be configured to have Internet Control Message Protocol (ICMP) unreachable messages disabled on all external interfaces.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216565r856184_rule
SV-216566r856185_rule - The Cisco router must be configured to have Internet Control Message Protocol (ICMP) mask reply messages disabled on all external interfaces.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216566r856185_rule
SV-216567r856186_rule - The Cisco router must be configured to have Internet Control Message Protocol (ICMP) redirect messages disabled on all external interfaces.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216567r856186_rule
SV-216568r531085_rule - The Cisco router must be configured to log all packets that have been dropped at interfaces via an ACL.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216568r531085_rule
SV-216569r531085_rule - The Cisco router must be configured to produce audit records containing information to establish where the events occurred.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216569r531085_rule
SV-216570r531085_rule - The Cisco router must be configured to produce audit records containing information to establish the source of the events.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216570r531085_rule
SV-216571r1117237_rule - The Cisco router must be configured to disable the auxiliary port unless it is connected to a secured modem providing encryption and authentication.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216571r1117237_rule
SV-216572r1117241_rule - The Cisco perimeter router must be configured to deny network traffic by default and allow network traffic by exception.
cisco_ios_router_rtr · high (CAT I)
stig://rule/SV-216572r1117241_rule
SV-216573r1117237_rule - The Cisco perimeter router must be configured to enforce approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216573r1117237_rule
SV-216574r856187_rule - The Cisco perimeter router must be configured to only allow incoming communications from authorized sources to be routed to authorized destinations.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216574r856187_rule
SV-216575r863237_rule - The Cisco perimeter router must be configured to block inbound packets with source Bogon IP address prefixes.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216575r863237_rule
SV-216576r1117237_rule - The Cisco perimeter router must be configured to protect an enclave connected to an approved gateway by using an inbound filter that only permits packets with destination addresses within the sites address space.
cisco_ios_router_rtr · high (CAT I)
stig://rule/SV-216576r1117237_rule
SV-216577r1117237_rule - The Cisco perimeter router must be configured to not be a Border Gateway Protocol (BGP) peer to an approved gateway service provider.
cisco_ios_router_rtr · high (CAT I)
stig://rule/SV-216577r1117237_rule
SV-216578r1117237_rule - The Cisco perimeter router must be configured to not redistribute static routes to an approved gateway service provider into BGP, an IGP peering with the NIPRNet, or other autonomous systems.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216578r1117237_rule
SV-216580r1007822_rule - The Cisco perimeter router must be configured to filter traffic destined to the enclave in accordance with the guidelines contained in DoD Instruction 8551.1.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216580r1007822_rule
SV-216581r531085_rule - The Cisco perimeter router must be configured to filter ingress traffic at the external interface on an inbound direction.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216581r531085_rule
SV-216582r531085_rule - The Cisco perimeter router must be configured to filter egress traffic at the internal interface on an inbound direction.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216582r531085_rule
SV-216584r856189_rule - The Cisco perimeter router must be configured to have Link Layer Discovery Protocol (LLDP) disabled on all external interfaces.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216584r856189_rule
SV-216585r856190_rule - The Cisco perimeter router must be configured to have Cisco Discovery Protocol (CDP) disabled on all external interfaces.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216585r856190_rule
SV-216586r856191_rule - The Cisco perimeter router must be configured to have Proxy ARP disabled on all external interfaces.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216586r856191_rule
SV-216587r945857_rule - The Cisco perimeter router must be configured to block all outbound management traffic.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216587r945857_rule
SV-216588r991838_rule - The Cisco out-of-band management (OOBM) gateway router must be configured to transport management traffic to the Network Operations Center (NOC) via dedicated circuit, MPLS/VPN service, or IPsec tunnel.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216588r991838_rule
SV-216589r531085_rule - The Cisco out-of-band management (OOBM) gateway router must be configured to forward only authorized management traffic to the Network Operations Center (NOC).
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216589r531085_rule
SV-216590r1117237_rule - The Cisco out-of-band management (OOBM) gateway router must be configured to have separate IGP instances for the managed network and management network.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216590r1117237_rule
SV-216591r1117237_rule - The Cisco out-of-band management (OOBM) gateway router must be configured to not redistribute routes between the management network routing domain and the managed network routing domain.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216591r1117237_rule
SV-216592r531085_rule - The Cisco out-of-band management (OOBM) gateway router must be configured to block any traffic destined to itself that is not sourced from the OOBM network or the Network Operations Center (NOC).
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216592r531085_rule
SV-216593r531085_rule - The Cisco router must be configured to only permit management traffic that ingresses and egresses the out-of-band management (OOBM) interface.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216593r531085_rule
SV-216594r531085_rule - The Cisco router providing connectivity to the Network Operations Center (NOC) must be configured to forward all in-band management traffic via an IPsec tunnel.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216594r531085_rule
SV-216597r1117236_rule - The Cisco BGP router must be configured to reject inbound route advertisements for any Bogon prefixes.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216597r1117236_rule
SV-216598r1117236_rule - The Cisco BGP router must be configured to reject inbound route advertisements for any prefixes belonging to the local autonomous system (AS).
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216598r1117236_rule
SV-216599r1117236_rule - The Cisco BGP router must be configured to reject inbound route advertisements from a customer edge (CE) router for prefixes that are not allocated to that customer.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216599r1117236_rule
SV-216600r1117236_rule - The Cisco BGP router must be configured to reject outbound route advertisements for any prefixes that do not belong to any customers or the local autonomous system (AS).
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216600r1117236_rule
SV-216601r531085_rule - The Cisco BGP router must be configured to reject outbound route advertisements for any prefixes belonging to the IP core.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216601r531085_rule
SV-216602r1117236_rule - The Cisco BGP router must be configured to reject route advertisements from BGP peers that do not list their autonomous system (AS) number as the first AS in the AS_PATH attribute.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216602r1117236_rule
SV-216603r1117236_rule - The Cisco BGP router must be configured to reject route advertisements from CE routers with an originating AS in the AS_PATH attribute that does not belong to that customer.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216603r1117236_rule
SV-216604r856192_rule - The Cisco BGP router must be configured to use the maximum prefixes feature to protect against route table flooding and prefix de-aggregation attacks.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216604r856192_rule
SV-216605r856193_rule - The Cisco BGP router must be configured to limit the prefix size on any inbound route advertisement to /24 or the least significant prefixes issued to the customer.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216605r856193_rule
SV-216606r991839_rule - The Cisco BGP router must be configured to use its loopback address as the source address for iBGP peering sessions.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216606r991839_rule
SV-216607r991840_rule - The Cisco MPLS router must be configured to use its loopback address as the source address for LDP peering sessions.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216607r991840_rule
SV-216608r531085_rule - The Cisco MPLS router must be configured to synchronize IGP and LDP to minimize packet loss when an IGP adjacency is established prior to LDP peers completing label exchange.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216608r531085_rule
SV-216609r531085_rule - The MPLS router with RSVP-TE enabled must be configured with message pacing to adjust maximum burst and maximum number of RSVP messages to an output queue based on the link speed and input queue size of adjacent core routers.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216609r531085_rule
SV-216610r531085_rule - The Cisco MPLS router must be configured to have TTL Propagation disabled.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216610r531085_rule
SV-216611r991841_rule - The Cisco PE router must be configured to have each Virtual Routing and Forwarding (VRF) instance bound to the appropriate physical or logical interfaces to maintain traffic separation between all MPLS L3VPNs.
cisco_ios_router_rtr · high (CAT I)
stig://rule/SV-216611r991841_rule
SV-216612r991842_rule - The Cisco PE router must be configured to have each Virtual Routing and Forwarding (VRF) instance with the appropriate Route Target (RT).
cisco_ios_router_rtr · high (CAT I)
stig://rule/SV-216612r991842_rule
SV-216613r991844_rule - The Cisco PE router must be configured to have each VRF with the appropriate Route Distinguisher (RD).
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216613r991844_rule
SV-216614r864155_rule - The Cisco PE router providing MPLS Layer 2 Virtual Private Network (L2VPN) services must be configured to authenticate targeted Label Distribution Protocol (LDP) sessions used to exchange virtual circuit (VC) information using a FIPS-approved message authentication code algorithm.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216614r864155_rule
SV-216615r991845_rule - The Cisco PE router providing MPLS Virtual Private Wire Service (VPWS) must be configured to have the appropriate virtual circuit identification (VC ID) for each attachment circuit.
cisco_ios_router_rtr · high (CAT I)
stig://rule/SV-216615r991845_rule
SV-216616r531085_rule - The Cisco PE router must be configured to block any traffic that is destined to IP core infrastructure.
cisco_ios_router_rtr · high (CAT I)
stig://rule/SV-216616r531085_rule
SV-216617r531085_rule - The Cisco PE router must be configured with Unicast Reverse Path Forwarding (uRPF) loose mode enabled on all CE-facing interfaces.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216617r531085_rule
SV-216619r917417_rule - The Cisco PE router must be configured to enforce a Quality-of-Service (QoS) policy to provide preferred treatment for mission-critical applications.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216619r917417_rule
SV-216620r917420_rule - The Cisco P router must be configured to enforce a Quality-of-Service (QoS) policy to provide preferred treatment for mission-critical applications.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216620r917420_rule
SV-216621r531085_rule - The Cisco PE router must be configured to enforce a Quality-of-Service (QoS) policy to limit the effects of packet flooding denial-of-service (DoS) attacks.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216621r531085_rule
SV-216622r1117237_rule - The Cisco multicast router must be configured to disable Protocol Independent Multicast (PIM) on all interfaces that are not required to support multicast routing.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216622r1117237_rule
SV-216623r1117237_rule - The Cisco multicast router must be configured to bind a Protocol Independent Multicast (PIM) neighbor filter to interfaces that have PIM enabled.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216623r1117237_rule
SV-216624r1117237_rule - The Cisco multicast edge router must be configured to establish boundaries for administratively scoped multicast traffic.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216624r1117237_rule
SV-216625r864156_rule - The Cisco multicast Rendezvous Point (RP) router must be configured to limit the multicast forwarding cache so that its resources are not saturated by managing an overwhelming number of Protocol Independent Multicast (PIM) and Multicast Source Discovery Protocol (MSDP) source-active entries.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216625r864156_rule
SV-216626r1117237_rule - The Cisco multicast Rendezvous Point (RP) router must be configured to filter Protocol Independent Multicast (PIM) Register messages received from the Designated Router (DR) for any undesirable multicast groups and sources.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216626r1117237_rule
SV-216627r1117237_rule - The Cisco multicast Rendezvous Point (RP) router must be configured to filter Protocol Independent Multicast (PIM) Join messages received from the Designated Router (DR) for any undesirable multicast groups.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216627r1117237_rule
SV-216628r856196_rule - The Cisco multicast Rendezvous Point (RP) must be configured to rate limit the number of Protocol Independent Multicast (PIM) Register messages.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216628r856196_rule
SV-216629r864157_rule - The Cisco multicast Designated Router (DR) must be configured to filter the Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) Report messages to allow hosts to join only multicast groups that have been approved by the organization.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216629r864157_rule
SV-216630r864158_rule - The Cisco multicast Designated Router (DR) must be configured to filter the Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) Report messages to allow hosts to join a multicast group only from sources that have been approved by the organization.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216630r864158_rule
SV-216631r856199_rule - The Cisco multicast Designated Router (DR) must be configured to limit the number of mroute states resulting from Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) Host Membership Reports.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216631r856199_rule
SV-216632r945856_rule - The Cisco multicast Designated Router (DR) must be configured to set the shortest-path tree (SPT) threshold to infinity to minimalize source-group (S, G) state within the multicast topology where Any Source Multicast (ASM) is deployed.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216632r945856_rule
SV-216633r856201_rule - The Cisco Multicast Source Discovery Protocol (MSDP) router must be configured to only accept MSDP packets from known MSDP peers.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216633r856201_rule
SV-216634r856202_rule - The Cisco Multicast Source Discovery Protocol (MSDP) router must be configured to authenticate all received MSDP packets.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216634r856202_rule
SV-216635r1117236_rule - The Cisco Multicast Source Discovery Protocol (MSDP) router must be configured to filter received source-active multicast advertisements for any undesirable multicast groups and sources.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216635r1117236_rule
SV-216636r1117236_rule - The Cisco Multicast Source Discovery Protocol (MSDP) router must be configured to filter source-active multicast advertisements to external MSDP peers to avoid global visibility of local-only multicast sources and groups.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216636r1117236_rule
SV-216637r1117236_rule - The Cisco Multicast Source Discovery Protocol (MSDP) router must be configured to limit the amount of source-active messages it accepts on a per-peer basis.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216637r1117236_rule
SV-216638r991846_rule - The Cisco Multicast Source Discovery Protocol (MSDP) router must be configured to use a loopback address as the source address when originating MSDP traffic.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216638r991846_rule
SV-216989r945858_rule - The Cisco perimeter router must be configured to restrict it from accepting outbound IP packets that contain an illegitimate address in the source address field via egress filter or by enabling Unicast Reverse Path Forwarding (uRPF).
cisco_ios_router_rtr · high (CAT I)
stig://rule/SV-216989r945858_rule
SV-216990r945859_rule - The Cisco perimeter router must be configured to block all packets with any IP options.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216990r945859_rule
SV-216991r856208_rule - The Cisco BGP router must be configured to enable the Generalized TTL Security Mechanism (GTSM).
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-216991r856208_rule
SV-216992r945862_rule - The Cisco BGP router must be configured to use a unique key for each autonomous system (AS) that it peers with.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216992r945862_rule
SV-216993r945860_rule - The Cisco PE router must be configured to drop all packets with any IP options.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-216993r945860_rule
SV-229030r878127_rule - The Cisco router must be configured to have Cisco Express Forwarding enabled.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-229030r878127_rule
SV-230038r531386_rule - The Cisco router must be configured to advertise a hop limit of at least 32 in Router Advertisement messages for IPv6 stateless auto-configuration deployments.
cisco_ios_router_rtr · low (CAT III)
stig://rule/SV-230038r531386_rule
SV-230041r532998_rule - The Cisco router must not be configured to use IPv6 Site Local Unicast addresses.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-230041r532998_rule
SV-230044r533005_rule - The Cisco perimeter router must be configured to suppress Router Advertisements on all external IPv6-enabled interfaces.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-230044r533005_rule
SV-230047r950991_rule - The Cisco perimeter router must be configured to drop IPv6 undetermined transport packets.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-230047r950991_rule
SV-230050r856665_rule - The Cisco perimeter router must be configured drop IPv6 packets with a Routing Header type 0, 1, or 3–255.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-230050r856665_rule
SV-230145r1132551_rule - The Cisco perimeter router must be configured to drop IPv6 packets containing a Hop-by-Hop header with invalid option type values.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-230145r1132551_rule
SV-230149r1132504_rule - The Cisco perimeter router must be configured to drop IPv6 packets containing a Destination Option header with invalid option type values.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-230149r1132504_rule
SV-230152r1132507_rule - The Cisco perimeter router must be configured to drop IPv6 packets containing an extension header with the Endpoint Identification option.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-230152r1132507_rule
SV-230155r1132510_rule - The Cisco perimeter router must be configured to drop IPv6 packets containing the NSAP address option within Destination Option header.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-230155r1132510_rule
SV-230158r1132513_rule - The Cisco perimeter router must be configured to drop IPv6 packets containing a Hop-by-Hop or Destination Option extension header with an undefined option type.
cisco_ios_router_rtr · medium (CAT II)
stig://rule/SV-230158r1132513_rule
SV-220623r863275_rule - The Cisco switch must uniquely identify and authenticate all network-connected endpoint devices before establishing any connection.
cisco_ios_switch_l2s · high (CAT I)
stig://rule/SV-220623r863275_rule
SV-220624r539671_rule - The Cisco switch must authenticate all VLAN Trunk Protocol (VTP) messages with a hash function using the most secured cryptographic algorithm available.
cisco_ios_switch_l2s · medium (CAT II)
stig://rule/SV-220624r539671_rule
SV-220625r991847_rule - The Cisco switch must manage excess bandwidth to limit the effects of packet-flooding types of denial-of-service (DoS) attacks.
cisco_ios_switch_l2s · medium (CAT II)
stig://rule/SV-220625r991847_rule
SV-220629r856223_rule - The Cisco switch must have Root Guard enabled on all switch ports connecting to access layer switches.
cisco_ios_switch_l2s · low (CAT III)
stig://rule/SV-220629r856223_rule
SV-220630r856224_rule - The Cisco switch must have Bridge Protocol Data Unit (BPDU) Guard enabled on all user-facing or untrusted access switch ports.
cisco_ios_switch_l2s · medium (CAT II)
stig://rule/SV-220630r856224_rule
SV-220631r856225_rule - The Cisco switch must have Spanning Tree Protocol (STP) Loop Guard enabled.
cisco_ios_switch_l2s · medium (CAT II)
stig://rule/SV-220631r856225_rule
SV-220632r856226_rule - The Cisco switch must have Unknown Unicast Flood Blocking (UUFB) enabled.
cisco_ios_switch_l2s · medium (CAT II)
stig://rule/SV-220632r856226_rule
SV-220633r929007_rule - The Cisco switch must have DHCP snooping for all user VLANs to validate DHCP messages from untrusted sources.
cisco_ios_switch_l2s · medium (CAT II)
stig://rule/SV-220633r929007_rule
SV-220634r929009_rule - The Cisco switch must have IP Source Guard enabled on all user-facing or untrusted access switch ports.
cisco_ios_switch_l2s · medium (CAT II)
stig://rule/SV-220634r929009_rule
SV-220635r929011_rule - The Cisco switch must have Dynamic Address Resolution Protocol (ARP) Inspection (DAI) enabled on all user VLANs.
cisco_ios_switch_l2s · medium (CAT II)
stig://rule/SV-220635r929011_rule
SV-220636r648763_rule - The Cisco switch must have Storm Control configured on all host-facing switchports.
cisco_ios_switch_l2s · low (CAT III)
stig://rule/SV-220636r648763_rule
SV-220637r539671_rule - The Cisco switch must have IGMP or MLD Snooping configured on all VLANs.
cisco_ios_switch_l2s · low (CAT III)
stig://rule/SV-220637r539671_rule
SV-220638r539671_rule - The Cisco switch must implement Rapid Spanning Tree Protocol (STP) where VLANs span multiple switches with redundant links.
cisco_ios_switch_l2s · medium (CAT II)
stig://rule/SV-220638r539671_rule
SV-220639r539671_rule - The Cisco switch must enable Unidirectional Link Detection (UDLD) to protect against one-way connections.
cisco_ios_switch_l2s · medium (CAT II)
stig://rule/SV-220639r539671_rule
SV-220640r539671_rule - The Cisco switch must have all trunk links enabled statically.
cisco_ios_switch_l2s · medium (CAT II)
stig://rule/SV-220640r539671_rule
SV-220641r991848_rule - The Cisco switch must have all disabled switch ports assigned to an unused VLAN.
cisco_ios_switch_l2s · medium (CAT II)
stig://rule/SV-220641r991848_rule
SV-220642r991849_rule - The Cisco switch must not have the default VLAN assigned to any host-facing switch ports.
cisco_ios_switch_l2s · medium (CAT II)
stig://rule/SV-220642r991849_rule
SV-220643r991850_rule - The Cisco switch must have the default VLAN pruned from all trunk ports that do not require it.
cisco_ios_switch_l2s · medium (CAT II)
stig://rule/SV-220643r991850_rule
SV-220644r991852_rule - The Cisco switch must not use the default VLAN for management traffic.
cisco_ios_switch_l2s · medium (CAT II)
stig://rule/SV-220644r991852_rule
SV-220645r991853_rule - The Cisco switch must have all user-facing or untrusted ports configured as access switch ports.
cisco_ios_switch_l2s · medium (CAT II)
stig://rule/SV-220645r991853_rule
SV-220646r991854_rule - The Cisco switch must have the native VLAN assigned to an ID other than the default VLAN for all 802.1q trunk links.
cisco_ios_switch_l2s · medium (CAT II)
stig://rule/SV-220646r991854_rule
SV-220647r991855_rule - The Cisco switch must not have any switchports assigned to the native VLAN.
cisco_ios_switch_l2s · low (CAT III)
stig://rule/SV-220647r991855_rule
SV-220570r960735_rule - The Cisco switch must be configured to limit the number of concurrent management sessions to an organization-defined number.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220570r960735_rule
SV-220571r960777_rule - The Cisco switch must be configured to automatically audit account creation.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220571r960777_rule
SV-220572r960780_rule - The Cisco switch must be configured to automatically audit account modification.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220572r960780_rule
SV-220573r960783_rule - The Cisco switch must be configured to automatically audit account disabling actions.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220573r960783_rule
SV-220574r960786_rule - The Cisco switch must be configured to automatically audit account removal actions.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220574r960786_rule
SV-220575r1107154_rule - The Cisco switch must be configured to enforce approved authorizations for controlling the flow of management information within the device based on control policies.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220575r1107154_rule
SV-220576r960840_rule - The Cisco switch must be configured to enforce the limit of three consecutive invalid logon attempts, after which time it must lock out the user account from accessing the device for 15 minutes.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220576r960840_rule
SV-220577r960843_rule - The Cisco switch must be configured to display the Standard Mandatory DoD Notice and Consent Banner before granting access to the device.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220577r960843_rule
SV-220578r960864_rule - The Cisco device must be configured to audit all administrator activity.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220578r960864_rule
SV-220580r960894_rule - The Cisco switch must produce audit records containing information to establish when (date and time) the events occurred.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220580r960894_rule
SV-220581r960897_rule - The Cisco switch must produce audit records containing information to establish where the events occurred.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220581r960897_rule
SV-220582r960909_rule - The Cisco switch must be configured to generate audit records containing the full-text recording of privileged commands.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220582r960909_rule
SV-220583r960933_rule - The Cisco switch must be configured to protect audit information from unauthorized modification.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220583r960933_rule
SV-220584r960936_rule - The Cisco switch must be configured to protect audit information from unauthorized deletion.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220584r960936_rule
SV-220585r960960_rule - The Cisco switch must be configured to limit privileges to change the software resident within software libraries.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220585r960960_rule
SV-220586r1043177_rule - The Cisco switch must be configured to prohibit the use of all unnecessary and non-secure functions and services.
cisco_ios_switch_ndm · high (CAT I)
stig://rule/SV-220586r1043177_rule
SV-220587r1051115_rule - The Cisco switch must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220587r1051115_rule
SV-220589r1015280_rule - The Cisco switch must be configured to enforce a minimum 15-character password length.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220589r1015280_rule
SV-220590r1015281_rule - The Cisco switch must be configured to enforce password complexity by requiring that at least one uppercase character be used.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220590r1015281_rule
SV-220591r1015282_rule - The Cisco switch must be configured to enforce password complexity by requiring that at least one lowercase character be used.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220591r1015282_rule
SV-220592r1015283_rule - The Cisco switch must be configured to enforce password complexity by requiring that at least one numeric character be used.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220592r1015283_rule
SV-220593r1015284_rule - The Cisco switch must be configured to enforce password complexity by requiring that at least one special character be used.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220593r1015284_rule
SV-220594r1043189_rule - The Cisco switch must be configured to require that when a password is changed, the characters are changed in at least eight of the positions within the password.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220594r1043189_rule
SV-220595r1015286_rule - The Cisco switch must only store cryptographic representations of passwords.
cisco_ios_switch_ndm · high (CAT I)
stig://rule/SV-220595r1015286_rule
SV-220596r961068_rule - The Cisco switch must be configured to terminate all network connections associated with device management after five minutes of inactivity.
cisco_ios_switch_ndm · high (CAT I)
stig://rule/SV-220596r961068_rule
SV-220597r961290_rule - The Cisco switch must be configured to automatically audit account enabling actions.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220597r961290_rule
SV-220599r961392_rule - The Cisco switch must be configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220599r961392_rule
SV-220600r991868_rule - The Cisco switch must be configured to generate an alert for all audit failure events.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220600r991868_rule
SV-220601r1015287_rule - The Cisco switch must be configured to synchronize its clock with the primary and secondary time sources using redundant authoritative time sources.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220601r1015287_rule
SV-220604r961506_rule - The Cisco switch must be configured to authenticate SNMP messages using a FIPS-validated Keyed-Hash Message Authentication Code (HMAC).
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220604r961506_rule
SV-220605r961506_rule - The Cisco switch must be configured to encrypt SNMP messages using a FIPS 140-2 approved algorithm.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220605r961506_rule
SV-220606r1107157_rule - The Cisco switch must be configured to authenticate Network Time Protocol (NTP) sources using authentication that is cryptographically based.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220606r1107157_rule
SV-220607r1056197_rule - The Cisco switch must be configured to use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of remote maintenance sessions.
cisco_ios_switch_ndm · high (CAT I)
stig://rule/SV-220607r1056197_rule
SV-220608r961557_rule - The Cisco switch must be configured to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions.
cisco_ios_switch_ndm · high (CAT I)
stig://rule/SV-220608r961557_rule
SV-220609r1056195_rule - The Cisco switch must be configured to protect against known types of denial-of-service (DoS) attacks by employing organization-defined security safeguards.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220609r1056195_rule
SV-220611r961812_rule - The Cisco switch must be configured to generate log records when administrator privileges are deleted.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220611r961812_rule
SV-220612r961824_rule - The Cisco switch must be configured to generate audit records when successful/unsuccessful logon attempts occur.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220612r961824_rule
SV-220613r961827_rule - The Cisco switch must be configured to generate log records for privileged activities.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220613r961827_rule
SV-220617r961863_rule - The Cisco switch must be configured to use at least two authentication servers to authenticate users prior to granting administrative access.
cisco_ios_switch_ndm · high (CAT I)
stig://rule/SV-220617r961863_rule
SV-220618r1069531_rule - The Cisco switch must be configured to support organizational requirements to conduct backups of the configuration when changes occur.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220618r1069531_rule
SV-220619r991871_rule - The Cisco switch must be configured to obtain its public key certificates from an appropriate certificate policy through an approved service provider.
cisco_ios_switch_ndm · medium (CAT II)
stig://rule/SV-220619r991871_rule
SV-220620r961863_rule - The Cisco switch must be configured to send log data to at least two central log servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO).
cisco_ios_switch_ndm · high (CAT I)
stig://rule/SV-220620r961863_rule
SV-220621r961863_rule - The Cisco switch must be running an IOS release that is currently supported by Cisco Systems.
cisco_ios_switch_ndm · high (CAT I)
stig://rule/SV-220621r961863_rule
SV-220419r1117236_rule - The Cisco switch must be configured to enforce approved authorizations for controlling the flow of information within the network based on organization-defined information flow control policies.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220419r1117236_rule
SV-220423r929046_rule - The Cisco switch must be configured to enable routing protocol authentication using FIPS 198-1 algorithms with keys not exceeding 180 days of lifetime.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220423r929046_rule
SV-220424r1117237_rule - The Cisco switch must be configured to have all inactive Layer 3 interfaces disabled.
cisco_ios_switch_rtr · low (CAT III)
stig://rule/SV-220424r1117237_rule
SV-220427r856231_rule - The Cisco switch must not be configured to have any zero-touch deployment feature enabled when connected to an operational network.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220427r856231_rule
SV-220428r991872_rule - The Cisco switch must be configured to protect against or limit the effects of denial-of-service (DoS) attacks by employing control plane protection.
cisco_ios_switch_rtr · high (CAT I)
stig://rule/SV-220428r991872_rule
SV-220431r856233_rule - The Cisco switch must be configured to have gratuitous ARP disabled on all external interfaces.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220431r856233_rule
SV-220432r856234_rule - The Cisco switch must be configured to have IP directed broadcast disabled on all interfaces.
cisco_ios_switch_rtr · low (CAT III)
stig://rule/SV-220432r856234_rule
SV-220433r856235_rule - The Cisco switch must be configured to have Internet Control Message Protocol (ICMP) unreachable messages disabled on all external interfaces.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220433r856235_rule
SV-220434r856236_rule - The Cisco switch must be configured to have Internet Control Message Protocol (ICMP) mask reply messages disabled on all external interfaces.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220434r856236_rule
SV-220435r856237_rule - The Cisco switch must be configured to have Internet Control Message Protocol (ICMP) redirect messages disabled on all external interfaces.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220435r856237_rule
SV-220436r622190_rule - The Cisco switch must be configured to log all packets that have been dropped at interfaces via an access control list (ACL).
cisco_ios_switch_rtr · low (CAT III)
stig://rule/SV-220436r622190_rule
SV-220437r622190_rule - The Cisco switch must be configured to produce audit records containing information to establish where the events occurred.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220437r622190_rule
SV-220438r622190_rule - The Cisco switch must be configured to produce audit records containing information to establish the source of the events.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220438r622190_rule
SV-220439r1117237_rule - The Cisco switch must be configured to disable the auxiliary port unless it is connected to a secured modem providing encryption and authentication.
cisco_ios_switch_rtr · low (CAT III)
stig://rule/SV-220439r1117237_rule
SV-220440r1117241_rule - The Cisco perimeter switch must be configured to deny network traffic by default and allow network traffic by exception.
cisco_ios_switch_rtr · high (CAT I)
stig://rule/SV-220440r1117241_rule
SV-220441r1117237_rule - The Cisco perimeter switch must be configured to enforce approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220441r1117237_rule
SV-220442r856238_rule - The Cisco perimeter switch must be configured to only allow incoming communications from authorized sources to be routed to authorized destinations.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220442r856238_rule
SV-220443r863240_rule - The Cisco perimeter switch must be configured to block inbound packets with source Bogon IP address prefixes.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220443r863240_rule
SV-220445r622190_rule - The Cisco perimeter switch must be configured to filter traffic destined to the enclave in accordance with the guidelines contained in DoD Instruction 8551.1.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220445r622190_rule
SV-220446r622190_rule - The Cisco perimeter switch must be configured to filter ingress traffic at the external interface on an inbound direction.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220446r622190_rule
SV-220447r622190_rule - The Cisco perimeter switch must be configured to filter egress traffic at the internal interface on an inbound direction.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220447r622190_rule
SV-220449r856240_rule - The Cisco perimeter switch must be configured to have Link Layer Discovery Protocol (LLDP) disabled on all external interfaces.
cisco_ios_switch_rtr · low (CAT III)
stig://rule/SV-220449r856240_rule
SV-220450r856241_rule - The Cisco perimeter switch must be configured to have Cisco Discovery Protocol (CDP) disabled on all external interfaces.
cisco_ios_switch_rtr · low (CAT III)
stig://rule/SV-220450r856241_rule
SV-220451r856242_rule - The Cisco perimeter switch must be configured to have Proxy ARP disabled on all external interfaces.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220451r856242_rule
SV-220452r945857_rule - The Cisco perimeter switch must be configured to block all outbound management traffic.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220452r945857_rule
SV-220453r991873_rule - The Cisco switch must be configured to only permit management traffic that ingresses and egresses the out-of-band management (OOBM) interface.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220453r991873_rule
SV-220454r864159_rule - The Cisco PE switch providing MPLS Layer 2 Virtual Private Network (L2VPN) services must be configured to authenticate targeted Label Distribution Protocol (LDP) sessions used to exchange virtual circuit (VC) information using a FIPS-approved message authentication code algorithm.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220454r864159_rule
SV-220455r622190_rule - The Cisco PE switch must be configured to block any traffic that is destined to the IP core infrastructure.
cisco_ios_switch_rtr · high (CAT I)
stig://rule/SV-220455r622190_rule
SV-220456r622190_rule - The Cisco PE switch must be configured with Unicast Reverse Path Forwarding (uRPF) loose mode enabled on all CE-facing interfaces.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220456r622190_rule
SV-220458r917423_rule - The Cisco PE switch must be configured to enforce a Quality-of-Service (QoS) policy to provide preferred treatment for mission-critical applications.
cisco_ios_switch_rtr · low (CAT III)
stig://rule/SV-220458r917423_rule
SV-220459r917426_rule - The Cisco P switch must be configured to enforce a Quality-of-Service (QoS) policy to provide preferred treatment for mission-critical applications.
cisco_ios_switch_rtr · low (CAT III)
stig://rule/SV-220459r917426_rule
SV-220460r622190_rule - The Cisco switch must be configured to enforce a Quality-of-Service (QoS) policy to limit the effects of packet flooding denial-of-service (DoS) attacks.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220460r622190_rule
SV-220461r1117237_rule - The Cisco multicast switch must be configured to disable Protocol Independent Multicast (PIM) on all interfaces that are not required to support multicast routing.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220461r1117237_rule
SV-220462r1117237_rule - The Cisco multicast switch must be configured to bind a Protocol Independent Multicast (PIM) neighbor filter to interfaces that have PIM enabled.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220462r1117237_rule
SV-220463r1117237_rule - The Cisco multicast edge switch must be configured to establish boundaries for administratively scoped multicast traffic.
cisco_ios_switch_rtr · low (CAT III)
stig://rule/SV-220463r1117237_rule
SV-220464r864160_rule - The Cisco multicast Designated switch (DR) must be configured to filter the Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) Report messages to allow hosts to join only multicast groups that have been approved by the organization.
cisco_ios_switch_rtr · low (CAT III)
stig://rule/SV-220464r864160_rule
SV-220465r864161_rule - The Cisco multicast Designated switch (DR) must be configured to filter the Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) Report messages to allow hosts to join a multicast group only from sources that have been approved by the organization.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220465r864161_rule
SV-220466r856246_rule - The Cisco multicast Designated switch (DR) must be configured to limit the number of mroute states resulting from Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) Host Membership Reports.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220466r856246_rule
SV-220467r945856_rule - The Cisco multicast Designated switch (DR) must be configured to set the shortest-path tree (SPT) threshold to infinity to minimalize source-group (S, G) state within the multicast topology where Any Source Multicast (ASM) is deployed.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220467r945856_rule
SV-220471r945858_rule - The Cisco perimeter switch must be configured to restrict it from accepting outbound IP packets that contain an illegitimate address in the source address field via egress filter or by enabling Unicast Reverse Path Forwarding (uRPF).
cisco_ios_switch_rtr · high (CAT I)
stig://rule/SV-220471r945858_rule
SV-220472r945859_rule - The Cisco perimeter switch must be configured to block all packets with any IP options.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220472r945859_rule
SV-220473r945860_rule - The Cisco PE switch must be configured to ignore or drop all packets with any IP options.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-220473r945860_rule
SV-237749r648775_rule - The Cisco switch must be configured to have Cisco Express Forwarding enabled.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-237749r648775_rule
SV-237751r648779_rule - The Cisco switch must be configured to advertise a hop limit of at least 32 in Switch Advertisement messages for IPv6 stateless auto-configuration deployments.
cisco_ios_switch_rtr · low (CAT III)
stig://rule/SV-237751r648779_rule
SV-237755r999760_rule - The Cisco switch must not be configured to use IPv6 Site Local Unicast addresses.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-237755r999760_rule
SV-237758r648791_rule - The Cisco perimeter switch must be configured to suppress Router Advertisements on all external IPv6-enabled interfaces.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-237758r648791_rule
SV-237761r950991_rule - The Cisco perimeter switch must be configured to drop IPv6 undetermined transport packets.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-237761r950991_rule
SV-237763r856665_rule - The Cisco perimeter switch must be configured drop IPv6 packets with a Routing Header type 0, 1, or 3-255.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-237763r856665_rule
SV-237765r1132544_rule - The Cisco perimeter switch must be configured to drop IPv6 packets containing a Hop-by-Hop header with invalid option type values.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-237765r1132544_rule
SV-237771r1135076_rule - The Cisco perimeter switch must be configured to drop IPv6 packets containing a Destination Option header with invalid option type values.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-237771r1135076_rule
SV-237773r1135078_rule - The Cisco perimeter switch must be configured to drop IPv6 packets containing an extension header with the Endpoint Identification option.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-237773r1135078_rule
SV-237775r1132548_rule - The Cisco perimeter switch must be configured to drop IPv6 packets containing the NSAP address option within Destination Option header.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-237775r1132548_rule
SV-237777r1132528_rule - The Cisco perimeter switch must be configured to drop IPv6 packets containing a Hop-by-Hop or Destination Option extension header with an undefined option type.
cisco_ios_switch_rtr · medium (CAT II)
stig://rule/SV-237777r1132528_rule
SV-242575r812732_rule - The Cisco ISE must use TLS 1.2, at a minimum, to protect the confidentiality of information passed between the endpoint agent and the Cisco ISE. This is This is required for compliance with C2C Step 1.
cisco_ise_nac · high (CAT I)
stig://rule/SV-242575r812732_rule
SV-242576r812734_rule - The Cisco ISE must enforce approved access by employing authorization policies with specific attributes; such as resource groups, device type, certificate attributes, or any other attributes that are specific to a group of endpoints, and/or mission conditions as defined in the site's Cisco ISE System Security Plan (SSP). This is required for compliance with C2C Step 4.
cisco_ise_nac · high (CAT I)
stig://rule/SV-242576r812734_rule
SV-242577r812736_rule - The Cisco ISE must be configured to profile endpoints connecting to the network. This is required for compliance with C2C Step 4.
cisco_ise_nac · high (CAT I)
stig://rule/SV-242577r812736_rule
SV-242578r812738_rule - The Cisco ISE must verify host-based firewall software is running on posture required clients defined in the NAC System Security Plan (SSP) prior to granting trusted network access. This is required for compliance with C2C Step 4.
cisco_ise_nac · high (CAT I)
stig://rule/SV-242578r812738_rule
SV-242579r1025166_rule - The Cisco ISE must verify anti-malware software is installed and up to date on posture required clients defined in the NAC System Security Plan (SSP) prior to granting trusted network access. This is required for compliance with C2C Step 4.
cisco_ise_nac · high (CAT I)
stig://rule/SV-242579r1025166_rule
SV-242580r1025168_rule - The Cisco ISE must verify host-based IDS/IPS software is authorized and running on posture required clients defined in the NAC System Security Plan (SSP) prior to granting trusted network access. This is required for compliance with C2C Step 4.
cisco_ise_nac · high (CAT I)
stig://rule/SV-242580r1025168_rule
SV-242581r812744_rule - For endpoints that require automated remediation, the Cisco ISE must be configured to redirect endpoints to a logically separate VLAN for remediation services. This is required for compliance with C2C Step 4.
cisco_ise_nac · medium (CAT II)
stig://rule/SV-242581r812744_rule
SV-242582r812746_rule - The Cisco ISE must be configured to notify the user before proceeding with remediation of the user's endpoint device when automated remediation is used. This is required for compliance with C2C Step 3.
cisco_ise_nac · low (CAT III)
stig://rule/SV-242582r812746_rule
SV-242583r812748_rule - The Cisco ISE must be configured so that all endpoints that are allowed to bypass policy assessment are approved by the Information System Security Manager (ISSM) and documented in the System Security Plan (SSP). This is This is required for compliance with C2C Step 1.
cisco_ise_nac · medium (CAT II)
stig://rule/SV-242583r812748_rule
SV-242584r812750_rule - The Cisco ISE must send an alert to the Information System Security Manager (ISSM) and System Administrator (SA), at a minimum, when security issues are found that put the network at risk. This is required for compliance with C2C Step 2.
cisco_ise_nac · medium (CAT II)
stig://rule/SV-242584r812750_rule
SV-242585r812752_rule - When endpoints fail the policy assessment, the Cisco ISE must create a record with sufficient detail suitable for forwarding to a remediation server for automated remediation or sending to the user for manual remediation. This is required for compliance with C2C Step 3.
cisco_ise_nac · medium (CAT II)
stig://rule/SV-242585r812752_rule
SV-242586r1018688_rule - The Cisco ISE must place client machines on the blacklist and terminate the agent connection when critical security issues are found that put the network at risk. This is required for compliance with C2C Step 4.
cisco_ise_nac · medium (CAT II)
stig://rule/SV-242586r1018688_rule
SV-242587r812756_rule - The Cisco ISE must be configured so client machines do not communicate with other network devices in the DMZ or subnet except as needed to perform an access client assessment or to identify themselves. This is required for compliance with C2C Step 2.
cisco_ise_nac · medium (CAT II)
stig://rule/SV-242587r812756_rule
SV-242588r1001248_rule - The Cisco ISE must deny or restrict access for endpoints that fail required posture checks. This is required for compliance with C2C Step 4.
cisco_ise_nac · medium (CAT II)
stig://rule/SV-242588r1001248_rule
SV-242589r812760_rule - The Cisco ISE must generate a log record when an endpoint fails authentication. This is This is required for compliance with C2C Step 1.
cisco_ise_nac · medium (CAT II)
stig://rule/SV-242589r812760_rule
SV-242590r812762_rule - The Cisco ISE must generate a log record when the client machine fails posture assessment because required security software is missing or has been deleted. This is This is required for compliance with C2C Step 1.
cisco_ise_nac · medium (CAT II)
stig://rule/SV-242590r812762_rule
SV-242591r812764_rule - The Cisco ISE must send an alert to the system administrator, at a minimum, when endpoints fail the policy assessment checks for organization-defined infractions. This is required for compliance with C2C Step 3.
cisco_ise_nac · medium (CAT II)
stig://rule/SV-242591r812764_rule
SV-242594r855855_rule - The Cisco ISE must generate a critical alert to be sent to the ISSO and SA (at a minimum) in the event of an audit processing failure. This is required for compliance with C2C Step 1.
cisco_ise_nac · medium (CAT II)
stig://rule/SV-242594r855855_rule
SV-242595r855856_rule - The Cisco ISE must provide an alert to, at a minimum, the SA and ISSO of all audit failure events where the detection and/or prevention function is unable to write events to either local storage or the centralized server. This is required for compliance with C2C Step 1.
cisco_ise_nac · medium (CAT II)
stig://rule/SV-242595r855856_rule
SV-242596r1001250_rule - The Cisco ISE must be configured with a secondary log server in case the primary log is unreachable. This is required for compliance with C2C Step 1.
cisco_ise_nac · medium (CAT II)
stig://rule/SV-242596r1001250_rule
SV-242597r812776_rule - The Cisco ISE must generate a critical alert to be sent to the ISSO and SA (at a minimum) if it is unable to communicate with the central event log. This is required for compliance with C2C Step 1.
cisco_ise_nac · medium (CAT II)
stig://rule/SV-242597r812776_rule
SV-242598r812778_rule - The Cisco ISE must continue to queue traffic log records locally when communication with the central log server is lost and there is an audit archival failure. This is required for compliance with C2C Step 1.
cisco_ise_nac · medium (CAT II)
stig://rule/SV-242598r812778_rule
SV-242599r812780_rule - The Cisco ISE must perform continuous detection and tracking of endpoint devices attached to the network. This is required for compliance with C2C Step 1.
cisco_ise_nac · medium (CAT II)
stig://rule/SV-242599r812780_rule
SV-242600r812782_rule - The Cisco ISE must deny network connection for endpoints that cannot be authenticated using an approved method. This is required for compliance with C2C Step 4.
cisco_ise_nac · medium (CAT II)
stig://rule/SV-242600r812782_rule
SV-242601r855858_rule - The Cisco ISE must authenticate all endpoint devices before establishing a connection and proceeding with posture assessment. This is required for compliance with C2C Step 4.
cisco_ise_nac · medium (CAT II)
stig://rule/SV-242601r855858_rule
SV-242602r855859_rule - The Cisco ISE must be configured to dynamically apply restricted access of endpoints that are granted access using MAC Authentication Bypass (MAB). This is required for compliance with C2C Step 4.
cisco_ise_nac · medium (CAT II)
stig://rule/SV-242602r855859_rule
SV-242603r878130_rule - Before establishing a connection with a Network Time Protocol (NTP) server, the Cisco ISE must authenticate using a bidirectional, cryptographically based authentication method that uses a FIPS-validated Advanced Encryption Standard (AES) cipher block algorithm to authenticate with the NTP server. This is required for compliance with C2C Step 1.
cisco_ise_nac · medium (CAT II)
stig://rule/SV-242603r878130_rule
SV-242604r971529_rule - Before establishing a local, remote, and/or network connection with any endpoint device, the Cisco ISE must use a bidirectional authentication mechanism configured with a FIPS-validated Advanced Encryption Standard (AES) cipher block algorithm to authenticate with the endpoint device. This is required for compliance with C2C Step 1.
cisco_ise_nac · medium (CAT II)
stig://rule/SV-242604r971529_rule
SV-242605r944370_rule - The Cisco ISE must enforce posture status assessment for posture required clients defined in the NAC System Security Plan (SSP). This is required for compliance with C2C Step 3.
cisco_ise_nac · high (CAT I)
stig://rule/SV-242605r944370_rule
SV-242606r944368_rule - The Cisco ISE must have a posture policy for posture required clients defined in the NAC System Security Plan (SSP). This is required for compliance with C2C Step 2.
cisco_ise_nac · high (CAT I)
stig://rule/SV-242606r944368_rule
SV-242607r1025177_rule - The Cisco ISE must limit the number of CLI and GUI sessions to an organization-defined number.
cisco_ise_ndm · low (CAT III)
stig://rule/SV-242607r1025177_rule
SV-242608r1018744_rule - The Cisco ISE must change the password for the local CLI and web-based account when members who have access to the password leave the role and are no longer authorized access.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242608r1018744_rule
SV-242609r960777_rule - For the local web-based account of last resort, the Cisco ISE must automatically audit account creation.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242609r960777_rule
SV-242610r960780_rule - For the local web-based account of last resort and the default local CLI account, the Cisco ISE must automatically audit account modification.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242610r960780_rule
SV-242611r960783_rule - For the local web-based account of last resort, the Cisco ISE must automatically audit account disabling actions.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242611r960783_rule
SV-242612r960786_rule - For the local account of last resort, the Cisco ISE must automatically audit account removal actions.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242612r960786_rule
SV-242613r961290_rule - The Cisco ISE must automatically audit account enabling actions.
cisco_ise_ndm · low (CAT III)
stig://rule/SV-242613r961290_rule
SV-242614r960969_rule - The Cisco ISE must be configured with only one local web-based account to be used as the account of last resort in the event the authentication server is unavailable.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242614r960969_rule
SV-242615r961353_rule - The Cisco ISE must prevent non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.
cisco_ise_ndm · high (CAT I)
stig://rule/SV-242615r961353_rule
SV-242616r961362_rule - The Cisco ISE must audit the execution of privileged functions.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242616r961362_rule
SV-242617r960840_rule - The Cisco ISE must be configured to enforce the limit of three consecutive invalid logon attempts, after which time it must lock out the user account from accessing the device for 15 minutes.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242617r960840_rule
SV-242618r960843_rule - For the local account of last resort, the Cisco ISE must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the device.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242618r960843_rule
SV-242619r960864_rule - The Cisco ISE must protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242619r960864_rule
SV-242620r960885_rule - The Cisco ISE must generate audit records when successful attempts to access privileges occur.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242620r960885_rule
SV-242621r961800_rule - The Cisco ISE must generate audit records when successful attempts to modify administrator privileges occur.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242621r961800_rule
SV-242622r961812_rule - The Cisco ISE must generate audit records when successful attempts to delete administrator privileges occur.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242622r961812_rule
SV-242623r961824_rule - The Cisco ISE must generate audit records when successful logon attempts occur.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242623r961824_rule
SV-242624r961827_rule - The Cisco ISE must generate audit records for privileged activities or other system-level access.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242624r961827_rule
SV-242625r961833_rule - The Cisco ISE must generate audit records when concurrent logons from different workstations occur.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242625r961833_rule
SV-242626r961392_rule - The Cisco ISE must limit audit record storage capacity for all locally stored logs.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242626r961392_rule
SV-242627r961860_rule - The Cisco ISE must configure a remote syslog where audit records are stored on a centralized logging target that is different from the system being audited.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242627r961860_rule
SV-242628r961401_rule - The Cisco ISE must send an alarm to one or more individuals when the monitoring collector process has an error or failure.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242628r961401_rule
SV-242629r1018745_rule - The Cisco ISE must be configured to synchronize internal information system clocks using redundant authoritative time sources.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242629r1018745_rule
SV-242630r961443_rule - The Cisco ISE must record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC).
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242630r961443_rule
SV-242632r961863_rule - The Cisco ISE must enforce access restrictions associated with changes to the firmware, OS, and hardware components.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242632r961863_rule
SV-242633r997485_rule - The Cisco ISE must be configured to use an external authentication server to authenticate administrators prior to granting administrative access.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242633r997485_rule
SV-242634r961863_rule - The Cisco ISE must be running an operating system release that is currently supported by the vendor.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242634r961863_rule
SV-242636r961863_rule - The Cisco ISE must generate log records for a locally developed list of auditable events.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242636r961863_rule
SV-242638r1025180_rule - The Cisco ISE must conduct configuration and operational backups when changes are made or must schedule backups weekly, at a minimum.
cisco_ise_ndm · low (CAT III)
stig://rule/SV-242638r1025180_rule
SV-242639r961863_rule - The Cisco ISE must use DoD-approved PKI rather than proprietary or self-signed device certificates.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242639r961863_rule
SV-242640r960966_rule - The Cisco ISE must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services.
cisco_ise_ndm · high (CAT I)
stig://rule/SV-242640r960966_rule
SV-242641r960966_rule - The Cisco ISE must be configured to disable Wireless Setup for production systems.
cisco_ise_ndm · high (CAT I)
stig://rule/SV-242641r960966_rule
SV-242642r960993_rule - For accounts using password authentication, the Cisco ISE must implement replay-resistant authentication mechanisms for network access to privileged accounts.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242642r960993_rule
SV-242643r961506_rule - The Cisco ISE must be configured to authenticate SNMP messages using a FIPS-validated Keyed-Hash Message Authentication Code (HMAC).
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242643r961506_rule
SV-242644r1025183_rule - The Cisco ISE must authenticate Network Time Protocol (NTP) sources using authentication that is cryptographically based.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242644r1025183_rule
SV-242645r1018746_rule - For accounts using password authentication, the Cisco ISE must enforce a minimum 15-character password length.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242645r1018746_rule
SV-242646r1018747_rule - For accounts using password authentication, the Cisco ISE must enforce password complexity by requiring that at least one uppercase character be used.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242646r1018747_rule
SV-242647r1018748_rule - For accounts using password authentication, the Cisco ISE must enforce password complexity by requiring that at least one lowercase character be used.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242647r1018748_rule
SV-242648r1018749_rule - For accounts using password authentication, the Cisco ISE must enforce password complexity by requiring that at least one digit be used.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242648r1018749_rule
SV-242649r1018750_rule - For accounts using password authentication, the Cisco ISE must enforce password complexity by requiring that at least one special character be used.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242649r1018750_rule
SV-242651r961029_rule - For accounts using password authentication, the Cisco ISE must use FIPS-validated SHA-2 or later protocol to protect the integrity of the password authentication process.
cisco_ise_ndm · high (CAT I)
stig://rule/SV-242651r961029_rule
SV-242652r961521_rule - The Cisco ISE must prohibit the use of cached authenticators after an organization-defined time period.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242652r961521_rule
SV-242653r961050_rule - The Cisco ISE must use FIPS-validated SHA-2 (or greater) to protect the integrity of hash message authentication code (HMAC), Key Derivation Functions (KDFs), Random Bit Generation, and hash-only applications.
cisco_ise_ndm · high (CAT I)
stig://rule/SV-242653r961050_rule
SV-242654r961554_rule - The Cisco ISE must use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of nonlocal maintenance and diagnostic communications.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242654r961554_rule
SV-242655r961554_rule - The Cisco ISE must verify the checksum value of any software download, including install files (ISO or OVA), patch files, and upgrade bundles.
cisco_ise_ndm · high (CAT I)
stig://rule/SV-242655r961554_rule
SV-242656r961557_rule - The Cisco ISE must be configured to implement cryptographic mechanisms using a FIPS 140-2 validated algorithm to protect the confidentiality of remote maintenance sessions.
cisco_ise_ndm · high (CAT I)
stig://rule/SV-242656r961557_rule
SV-242657r961068_rule - The Cisco ISE must terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after five minutes of inactivity except to fulfill documented and validated mission requirements.
cisco_ise_ndm · high (CAT I)
stig://rule/SV-242657r961068_rule
SV-242658r961119_rule - The Cisco ISE must generate unique session identifiers using a FIPS 140-2 approved Random Number Generator (RNG) using DRGB.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242658r961119_rule
SV-242659r961128_rule - The Cisco ISE must only allow authorized administrators to view or change the device configuration, system files, and other files stored.
cisco_ise_ndm · high (CAT I)
stig://rule/SV-242659r961128_rule
SV-242660r1025184_rule - The Cisco ISE must configure the control plane to protect against or limit the effects of common types of Denial of Service (DoS) attacks on the device itself by configuring applicable system options and internet-options.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242660r1025184_rule
SV-242661r961863_rule - The Cisco ISE must be configured to send log data to at least two central log servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO).
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242661r961863_rule
SV-242662r960888_rule - The Cisco ISE must initiate session auditing upon startup.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242662r960888_rule
SV-242663r960909_rule - The Cisco ISE must generate audit records containing the full-text recording of privileged commands.
cisco_ise_ndm · medium (CAT II)
stig://rule/SV-242663r960909_rule
SV-220675r539671_rule - The Cisco switch must uniquely identify all network-connected endpoint devices before establishing any connection.
cisco_nxos_switch_l2s · high (CAT I)
stig://rule/SV-220675r539671_rule
SV-220676r539671_rule - The Cisco switch must authenticate all VLAN Trunk Protocol (VTP) messages with a hash function using the most secured cryptographic algorithm available.
cisco_nxos_switch_l2s · medium (CAT II)
stig://rule/SV-220676r539671_rule
SV-220677r1015266_rule - The Cisco switch must be configured for authorized users to select a user session to capture.
cisco_nxos_switch_l2s · medium (CAT II)
stig://rule/SV-220677r1015266_rule
SV-220678r856487_rule - The Cisco switch must be configured for authorized users to remotely view, in real time, all content related to an established user session from a component separate from The Cisco switch.
cisco_nxos_switch_l2s · medium (CAT II)
stig://rule/SV-220678r856487_rule
SV-220679r856488_rule - The Cisco switch must authenticate all endpoint devices before establishing any connection.
cisco_nxos_switch_l2s · medium (CAT II)
stig://rule/SV-220679r856488_rule
SV-220680r940009_rule - The Cisco switch must have Root Guard enabled on all switch ports connecting to access layer switches and hosts.
cisco_nxos_switch_l2s · low (CAT III)
stig://rule/SV-220680r940009_rule
SV-220681r856490_rule - The Cisco switch must have BPDU Guard enabled on all user-facing or untrusted access switch ports.
cisco_nxos_switch_l2s · medium (CAT II)
stig://rule/SV-220681r856490_rule
SV-220682r856491_rule - The Cisco switch must have STP Loop Guard enabled.
cisco_nxos_switch_l2s · medium (CAT II)
stig://rule/SV-220682r856491_rule
SV-220683r856492_rule - The Cisco switch must have Unknown Unicast Flood Blocking (UUFB) enabled.
cisco_nxos_switch_l2s · medium (CAT II)
stig://rule/SV-220683r856492_rule
SV-220684r856493_rule - The Cisco switch must have DHCP snooping for all user VLANs to validate DHCP messages from untrusted sources.
cisco_nxos_switch_l2s · medium (CAT II)
stig://rule/SV-220684r856493_rule
SV-220685r856494_rule - The Cisco switch must have IP Source Guard enabled on all user-facing or untrusted access switch ports.
cisco_nxos_switch_l2s · medium (CAT II)
stig://rule/SV-220685r856494_rule
SV-220686r856495_rule - The Cisco switch must have Dynamic Address Resolution Protocol (ARP) Inspection (DAI) enabled on all user VLANs.
cisco_nxos_switch_l2s · medium (CAT II)
stig://rule/SV-220686r856495_rule
SV-220687r539671_rule - The Cisco switch must have Storm Control configured on all host-facing switchports.
cisco_nxos_switch_l2s · low (CAT III)
stig://rule/SV-220687r539671_rule
SV-220688r539671_rule - The Cisco switch must have IGMP or MLD Snooping configured on all VLANs.
cisco_nxos_switch_l2s · low (CAT III)
stig://rule/SV-220688r539671_rule
SV-220689r917685_rule - The Cisco switch must enable Unidirectional Link Detection (UDLD) to protect against one-way connections.
cisco_nxos_switch_l2s · medium (CAT II)
stig://rule/SV-220689r917685_rule
SV-220690r991946_rule - The Cisco switch must have all disabled switch ports assigned to an unused VLAN.
cisco_nxos_switch_l2s · medium (CAT II)
stig://rule/SV-220690r991946_rule
SV-220691r991947_rule - The Cisco switch must not have the default VLAN assigned to any host-facing switch ports.
cisco_nxos_switch_l2s · medium (CAT II)
stig://rule/SV-220691r991947_rule
SV-220692r991948_rule - The Cisco switch must have the default VLAN pruned from all trunk ports that do not require it.
cisco_nxos_switch_l2s · medium (CAT II)
stig://rule/SV-220692r991948_rule
SV-220693r991949_rule - The Cisco switch must not use the default VLAN for management traffic.
cisco_nxos_switch_l2s · medium (CAT II)
stig://rule/SV-220693r991949_rule
SV-220694r991951_rule - The Cisco switch must have all user-facing or untrusted ports configured as access switch ports.
cisco_nxos_switch_l2s · medium (CAT II)
stig://rule/SV-220694r991951_rule
SV-220695r991952_rule - The Cisco switch must have the native VLAN assigned to an ID other than the default VLAN for all 802.1q trunk links.
cisco_nxos_switch_l2s · medium (CAT II)
stig://rule/SV-220695r991952_rule
SV-220696r991953_rule - The Cisco switch must not have any switchports assigned to the native VLAN.
cisco_nxos_switch_l2s · low (CAT III)
stig://rule/SV-220696r991953_rule
SV-220474r960735_rule - The Cisco switch must be configured to limit the number of concurrent management sessions to an organization-defined number.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220474r960735_rule
SV-220475r960777_rule - The Cisco switch must be configured to automatically audit account creation.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220475r960777_rule
SV-220476r960780_rule - The Cisco switch must be configured to automatically audit account modification.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220476r960780_rule
SV-220477r960783_rule - The Cisco switch must be configured to automatically audit account disabling actions.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220477r960783_rule
SV-220478r960786_rule - The Cisco switch must be configured to automatically audit account removal actions.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220478r960786_rule
SV-220479r1117168_rule - The Cisco switch must be configured to enforce approved authorizations for controlling the flow of management information within the device based on control policies.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220479r1117168_rule
SV-220480r960840_rule - The Cisco switch must be configured to enforce the limit of three consecutive invalid logon attempts, after which time it must disconnect the session.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220480r960840_rule
SV-220481r960843_rule - The Cisco switch must be configured to display the Standard Mandatory DoD Notice and Consent Banner before granting access to the device.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220481r960843_rule
SV-220482r960864_rule - The Cisco switch must be configured to protect against an individual falsely denying having performed organization-defined actions to be covered by non-repudiation.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220482r960864_rule
SV-220484r1026067_rule - The Cisco switch must produce audit records containing information to establish where the events occurred.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220484r1026067_rule
SV-220485r960909_rule - The Cisco switch must be configured to generate audit records containing the full-text recording of privileged commands.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220485r960909_rule
SV-220486r1043177_rule - The Cisco switch must be configured to prohibit the use of all unnecessary and nonsecure functions and services.
cisco_nxos_switch_ndm · high (CAT I)
stig://rule/SV-220486r1043177_rule
SV-220487r1051115_rule - The Cisco switch must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220487r1051115_rule
SV-220488r1026069_rule - The Cisco switch must be configured to implement replay-resistant authentication mechanisms for network access to privileged accounts.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220488r1026069_rule
SV-220489r1026157_rule - The Cisco switch must be configured to enforce password complexity by requiring that at least one uppercase character be used.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220489r1026157_rule
SV-220490r1026158_rule - The Cisco switch must be configured to enforce password complexity by requiring that at least one lower-case character be used.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220490r1026158_rule
SV-220491r1026159_rule - The Cisco switch must be configured to enforce password complexity by requiring that at least one numeric character be used.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220491r1026159_rule
SV-220492r1026160_rule - The Cisco switch must be configured to enforce password complexity by requiring that at least one special character be used.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220492r1026160_rule
SV-220493r961068_rule - The Cisco switch must be configured to terminate all network connections associated with device management after five minutes of inactivity.
cisco_nxos_switch_ndm · high (CAT I)
stig://rule/SV-220493r961068_rule
SV-220494r961290_rule - The Cisco switch must be configured to automatically audit account enabling actions.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220494r961290_rule
SV-220495r961362_rule - The Cisco switch must be configured to audit the execution of privileged functions.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220495r961362_rule
SV-220496r961392_rule - The Cisco switch must be configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220496r961392_rule
SV-220497r991965_rule - The Cisco switch must be configured to generate an alert for all audit failure events.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220497r991965_rule
SV-220498r1026071_rule - The Cisco switch must be configured to synchronize its clock with the primary and secondary time sources using redundant authoritative time sources.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220498r1026071_rule
SV-220499r961443_rule - The Cisco switch must be configured to record time stamps for log records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220499r961443_rule
SV-220500r961506_rule - The Cisco switch must be configured to authenticate SNMP messages using a FIPS-validated Keyed-Hash Message Authentication Code (HMAC).
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220500r961506_rule
SV-220501r961506_rule - The Cisco switch must be configured to encrypt SNMP messages using a FIPS 140-2 approved algorithm.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220501r961506_rule
SV-220502r1107166_rule - The Cisco switch must be configured to authenticate Network Time Protocol (NTP) sources using authentication that is cryptographically based.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220502r1107166_rule
SV-220503r1026073_rule - The Cisco switch must be configured to use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of remote maintenance sessions.
cisco_nxos_switch_ndm · high (CAT I)
stig://rule/SV-220503r1026073_rule
SV-220504r1026075_rule - The Cisco switch must be configured to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions.
cisco_nxos_switch_ndm · high (CAT I)
stig://rule/SV-220504r1026075_rule
SV-220506r961800_rule - The Cisco switch must be configured to generate log records when administrator privileges are modified.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220506r961800_rule
SV-220507r961812_rule - The Cisco switch must be configured to generate log records when administrator privileges are deleted.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220507r961812_rule
SV-220508r961824_rule - The Cisco switch must be configured to generate audit records when successful/unsuccessful logon attempts occur.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220508r961824_rule
SV-220509r961827_rule - The Cisco switch must be configured to generate log records for privileged activities.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220509r961827_rule
SV-220510r961830_rule - The Cisco switch must generate audit records showing starting and ending time for administrator access to the system.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220510r961830_rule
SV-220512r961860_rule - The Cisco switch must be configured to off-load log records onto a different system than the system being audited.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220512r961860_rule
SV-220513r961863_rule - The Cisco switch must be configured to use at least two authentication servers for the purpose of authenticating users prior to granting administrative access.
cisco_nxos_switch_ndm · high (CAT I)
stig://rule/SV-220513r961863_rule
SV-220514r1135491_rule - The Cisco switch must be configured to support organizational requirements to conduct backups of the configuration when changes occur.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220514r1135491_rule
SV-220515r991969_rule - The Cisco switch must be configured to obtain its public key certificates from an appropriate certificate policy through an approved service provider.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-220515r991969_rule
SV-220516r961863_rule - The Cisco switch must be configured to send log data to at least two central log servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO).
cisco_nxos_switch_ndm · high (CAT I)
stig://rule/SV-220516r961863_rule
SV-220517r961863_rule - The Cisco switch must be running an IOS release that is currently supported by Cisco Systems.
cisco_nxos_switch_ndm · high (CAT I)
stig://rule/SV-220517r961863_rule
SV-260464r1082186_rule - The Cisco switch must be configured to protect against known types of denial-of-service (DoS) attacks by employing organization-defined security safeguards.
cisco_nxos_switch_ndm · medium (CAT II)
stig://rule/SV-260464r1082186_rule
SV-221071r999679_rule - The Cisco switch must be configured to enforce approved authorizations for controlling the flow of information within the network based on organization-defined information flow control policies.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221071r999679_rule
SV-221072r999681_rule - The Cisco switch must be configured to implement message authentication for all control plane protocols.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221072r999681_rule
SV-221073r999682_rule - The Cisco switch must be configured to use keys with a duration not exceeding 180 days for authenticating routing protocol messages.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221073r999682_rule
SV-221074r999683_rule - The Cisco switch must be configured to use encryption for routing protocol authentication.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221074r999683_rule
SV-221075r999684_rule - The Cisco switch must be configured to authenticate all routing protocol messages using NIST-validated FIPS 198-1 message authentication code algorithm.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221075r999684_rule
SV-221076r999685_rule - The Cisco switch must be configured to have all inactive layer 3 interfaces disabled.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221076r999685_rule
SV-221078r999687_rule - The Cisco switch must not be configured to have any feature enabled that calls home to the vendor.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221078r999687_rule
SV-221079r1055901_rule - The Cisco switch must be configured to protect against or limit the effects of denial-of-service (DoS) attacks by employing control plane protection.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221079r1055901_rule
SV-221081r999690_rule - The Cisco switch must be configured to drop all fragmented Internet Control Message Protocol (ICMP) packets destined to itself.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221081r999690_rule
SV-221082r999691_rule - The Cisco switch must be configured to have Gratuitous ARP disabled on all external interfaces.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221082r999691_rule
SV-221083r999692_rule - The Cisco switch must be configured to have IP directed broadcast disabled on all interfaces.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221083r999692_rule
SV-221084r999693_rule - The Cisco switch must be configured to have Internet Control Message Protocol (ICMP) unreachable messages disabled on all external interfaces.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221084r999693_rule
SV-221085r999694_rule - The Cisco switch must be configured to have Internet Control Message Protocol (ICMP) redirect messages disabled on all external interfaces.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221085r999694_rule
SV-221086r999695_rule - The Cisco switch must be configured to log all packets that have been dropped at interfaces via an ACL.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221086r999695_rule
SV-221087r999696_rule - The Cisco perimeter switch must be configured to deny network traffic by default and allow network traffic by exception.
cisco_nxos_switch_rtr · high (CAT I)
stig://rule/SV-221087r999696_rule
SV-221088r999697_rule - The Cisco perimeter switch must be configured to enforce approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221088r999697_rule
SV-221089r999698_rule - The Cisco perimeter switch must be configured to only allow incoming communications from authorized sources to be routed to authorized destinations.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221089r999698_rule
SV-221090r999699_rule - The Cisco perimeter switch must be configured to block inbound packets with source Bogon IP address prefixes.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221090r999699_rule
SV-221091r999700_rule - The Cisco perimeter switch must be configured to restrict it from accepting outbound IP packets that contain an illegitimate address in the source address field via egress filter or by enabling Unicast Reverse Path Forwarding (uRPF).
cisco_nxos_switch_rtr · high (CAT I)
stig://rule/SV-221091r999700_rule
SV-221092r999701_rule - The Cisco perimeter switch must be configured to filter traffic destined to the enclave in accordance with the guidelines contained in DoD Instruction 8551.1.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221092r999701_rule
SV-221093r999702_rule - The Cisco perimeter switch must be configured to filter ingress traffic at the external interface on an inbound direction.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221093r999702_rule
SV-221094r999703_rule - The Cisco perimeter switch must be configured to filter egress traffic at the internal interface on an inbound direction.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221094r999703_rule
SV-221095r999704_rule - The Cisco perimeter switch must be configured to block all packets with any IP options.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221095r999704_rule
SV-221096r999705_rule - The Cisco perimeter switch must be configured to have Link Layer Discovery Protocol (LLDP) disabled on all external interfaces.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221096r999705_rule
SV-221097r999706_rule - The Cisco perimeter switch must be configured to have Cisco Discovery Protocol (CDP) disabled on all external interfaces.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221097r999706_rule
SV-221098r999707_rule - The Cisco perimeter switch must be configured to have Proxy ARP disabled on all external interfaces.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221098r999707_rule
SV-221099r999708_rule - The Cisco perimeter switch must be configured to block all outbound management traffic.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221099r999708_rule
SV-221100r999709_rule - The Cisco switch must be configured to only permit management traffic that ingresses and egresses the out-of-band management (OOBM) interface.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221100r999709_rule
SV-221101r999710_rule - The Cisco BGP switch must be configured to check whether a single-hop eBGP peer is directly connected.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221101r999710_rule
SV-221102r999711_rule - The Cisco BGP switch must be configured to use a unique key for each autonomous system (AS) that it peers with.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221102r999711_rule
SV-221103r999712_rule - The Cisco BGP switch must be configured to reject inbound route advertisements for any Bogon prefixes.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221103r999712_rule
SV-221104r999713_rule - The Cisco BGP switch must be configured to reject inbound route advertisements for any prefixes belonging to the local autonomous system (AS).
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221104r999713_rule
SV-221105r999714_rule - The Cisco BGP switch must be configured to reject inbound route advertisements from a customer edge (CE) switch for prefixes that are not allocated to that customer.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221105r999714_rule
SV-221106r999715_rule - The Cisco BGP switch must be configured to reject outbound route advertisements for any prefixes that do not belong to any customers or the local autonomous system (AS).
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221106r999715_rule
SV-221107r999716_rule - The Cisco BGP switch must be configured to reject outbound route advertisements for any prefixes belonging to the IP core.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221107r999716_rule
SV-221108r999717_rule - The Cisco BGP switch must be configured to reject route advertisements from BGP peers that do not list their autonomous system (AS) number as the first AS in the AS_PATH attribute.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221108r999717_rule
SV-221109r999718_rule - The Cisco BGP switch must be configured to reject route advertisements from CE switches with an originating AS in the AS_PATH attribute that does not belong to that customer.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221109r999718_rule
SV-221110r999719_rule - The Cisco BGP switch must be configured to use the maximum prefixes feature to protect against route table flooding and prefix de-aggregation attacks.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221110r999719_rule
SV-221111r999720_rule - The Cisco BGP switch must be configured to limit the prefix size on any inbound route advertisement to /24, or the least significant prefixes issued to the customer.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221111r999720_rule
SV-221112r999769_rule - The Cisco BGP switch must be configured to use its loopback address as the source address for iBGP peering sessions.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221112r999769_rule
SV-221113r999770_rule - The Cisco MPLS switch must be configured to use its loopback address as the source address for LDP peering sessions.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221113r999770_rule
SV-221114r999723_rule - The Cisco MPLS switch must be configured to synchronize Interior Gateway Protocol (IGP) and LDP to minimize packet loss when an IGP adjacency is established prior to LDP peers completing label exchange.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221114r999723_rule
SV-221115r999724_rule - The MPLS switch with RSVP-TE enabled must be configured with message pacing to adjust maximum burst and maximum number of RSVP messages to an output queue based on the link speed and input queue size of adjacent core switches.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221115r999724_rule
SV-221116r999725_rule - The Cisco MPLS switch must be configured to have TTL Propagation disabled.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221116r999725_rule
SV-221117r999771_rule - The Cisco PE switch must be configured to have each Virtual Routing and Forwarding (VRF) instance bound to the appropriate physical or logical interfaces to maintain traffic separation between all MPLS L3VPNs.
cisco_nxos_switch_rtr · high (CAT I)
stig://rule/SV-221117r999771_rule
SV-221118r999772_rule - The Cisco PE switch must be configured to have each Virtual Routing and Forwarding (VRF) instance with the appropriate Route Target (RT).
cisco_nxos_switch_rtr · high (CAT I)
stig://rule/SV-221118r999772_rule
SV-221119r999773_rule - The Cisco PE switch must be configured to have each VRF with the appropriate Route Distinguisher (RD).
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221119r999773_rule
SV-221120r999729_rule - The Cisco PE switch providing MPLS Layer 2 Virtual Private Network (L2VPN) services must be configured to authenticate targeted Label Distribution Protocol (LDP) sessions used to exchange virtual circuit (VC) information using a FIPS-approved message authentication code algorithm.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221120r999729_rule
SV-221121r999774_rule - The Cisco PE switch providing MPLS Virtual Private Wire Service (VPWS) must be configured to have the appropriate virtual circuit identification (VC ID) for each attachment circuit.
cisco_nxos_switch_rtr · high (CAT I)
stig://rule/SV-221121r999774_rule
SV-221122r999775_rule - The Cisco PE switch providing Virtual Private LAN Services (VPLS) must be configured to have all attachment circuits defined to the virtual forwarding instance (VFI) with the globally unique VPN ID assigned for each customer VLAN.
cisco_nxos_switch_rtr · high (CAT I)
stig://rule/SV-221122r999775_rule
SV-221123r999732_rule - The Cisco PE switch providing Virtual Private LAN Services (VPLS) must be configured to have traffic storm control thresholds on CE-facing interfaces.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221123r999732_rule
SV-221124r999733_rule - The Cisco PE switch must be configured to implement Internet Group Management Protocol (IGMP) or Multicast Listener Discovery (MLD) snooping for each Virtual Private LAN Services (VPLS) bridge domain.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221124r999733_rule
SV-221125r999734_rule - The Cisco PE switch must be configured to limit the number of MAC addresses it can learn for each Virtual Private LAN Services (VPLS) bridge domain.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221125r999734_rule
SV-221126r999735_rule - The Cisco PE switch must be configured to block any traffic that is destined to the IP core infrastructure.
cisco_nxos_switch_rtr · high (CAT I)
stig://rule/SV-221126r999735_rule
SV-221127r999736_rule - The Cisco PE switch must be configured with Unicast Reverse Path Forwarding (uRPF) loose mode enabled on all CE-facing interfaces.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221127r999736_rule
SV-221128r999737_rule - The Cisco PE switch must be configured to ignore or drop all packets with any IP options.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221128r999737_rule
SV-221129r999738_rule - The Cisco PE switch must be configured to enforce a Quality-of-Service (QoS) policy to provide preferred treatment for mission-critical applications.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221129r999738_rule
SV-221130r999739_rule - The Cisco P switch must be configured to enforce a Quality-of-Service (QoS) policy to provide preferred treatment for mission-critical applications.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221130r999739_rule
SV-221131r999740_rule - The Cisco switch must be configured to enforce a Quality-of-Service (QoS) policy to limit the effects of packet flooding denial-of-service (DoS) attacks.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221131r999740_rule
SV-221132r999741_rule - The Cisco multicast switch must be configured to disable Protocol Independent Multicast (PIM) on all interfaces that are not required to support multicast routing.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221132r999741_rule
SV-221133r999742_rule - The Cisco multicast switch must be configured to bind a Protocol Independent Multicast (PIM) neighbor filter to interfaces that have PIM enabled.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221133r999742_rule
SV-221134r999743_rule - The Cisco multicast edge switch must be configured to establish boundaries for administratively scoped multicast traffic.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221134r999743_rule
SV-221135r999744_rule - The Cisco multicast Rendezvous Point (RP) switch must be configured to limit the multicast forwarding cache so that its resources are not saturated by managing an overwhelming number of Protocol Independent Multicast (PIM) and Multicast Source Discovery Protocol (MSDP) source-active entries.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221135r999744_rule
SV-221136r999745_rule - The Cisco multicast Rendezvous Point (RP) switch must be configured to filter Protocol Independent Multicast (PIM) Register messages received from the Designated switch (DR) for any undesirable multicast groups and sources.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221136r999745_rule
SV-221137r999746_rule - The Cisco multicast Rendezvous Point (RP) switch must be configured to filter Protocol Independent Multicast (PIM) Join messages received from the Designated Cisco switch (DR) for any undesirable multicast groups.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221137r999746_rule
SV-221138r999747_rule - The Cisco multicast Designated switch (DR) must be configured to filter the Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) Report messages to allow hosts to join only multicast groups that have been approved by the organization.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221138r999747_rule
SV-221139r999748_rule - The Cisco multicast Designated switch (DR) must be configured to filter the Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) Report messages to allow hosts to join a multicast group only from sources that have been approved by the organization.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221139r999748_rule
SV-221140r999749_rule - The Cisco multicast Designated switch (DR) must be configured to limit the number of mroute states resulting from Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) Host Membership Reports.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221140r999749_rule
SV-221141r999750_rule - The Cisco multicast Designated switch (DR) must be configured to set the shortest-path tree (SPT) threshold to infinity to minimalize source-group (S, G) state within the multicast topology where Any Source Multicast (ASM) is deployed.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221141r999750_rule
SV-221142r999751_rule - The Cisco Multicast Source Discovery Protocol (MSDP) switch must be configured to only accept MSDP packets from known MSDP peers.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221142r999751_rule
SV-221143r999752_rule - The Cisco Multicast Source Discovery Protocol (MSDP) switch must be configured to authenticate all received MSDP packets.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-221143r999752_rule
SV-221144r999753_rule - The Cisco Multicast Source Discovery Protocol (MSDP) switch must be configured to filter received source-active multicast advertisements for any undesirable multicast groups and sources.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221144r999753_rule
SV-221145r999754_rule - The Cisco Multicast Source Discovery Protocol (MSDP) switch must be configured to filter source-active multicast advertisements to external MSDP peers to avoid global visibility of local-only multicast sources and groups.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221145r999754_rule
SV-221146r999755_rule - The Cisco Multicast Source Discovery Protocol (MSDP) switch must be configured to limit the amount of source-active messages it accepts on a per-peer basis.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221146r999755_rule
SV-221147r999776_rule - The Cisco Multicast Source Discovery Protocol (MSDP) switch must be configured to use a loopback address as the source address when originating MSDP traffic.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-221147r999776_rule
SV-237754r999759_rule - The Cisco switch must be configured to advertise a hop limit of at least 32 in Switch Advertisement messages for IPv6 stateless auto-configuration deployments.
cisco_nxos_switch_rtr · low (CAT III)
stig://rule/SV-237754r999759_rule
SV-237757r999761_rule - The Cisco switch must not be configured to use IPv6 Site Local Unicast addresses.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-237757r999761_rule
SV-237760r999764_rule - The Cisco perimeter switch must be configured to suppress Router Advertisements on all external IPv6-enabled interfaces.
cisco_nxos_switch_rtr · medium (CAT II)
stig://rule/SV-237760r999764_rule
SV-260469r991589_rule - Ubuntu 22.04 LTS must disable the x86 Ctrl-Alt-Delete key sequence.
ubuntu2204 · high (CAT I)
stig://rule/SV-260469r991589_rule
SV-260470r1117265_rule - Ubuntu 22.04 LTS, when booted, must require authentication upon booting into single-user and maintenance modes.
ubuntu2204 · high (CAT I)
stig://rule/SV-260470r1117265_rule
SV-260471r1134800_rule - Ubuntu 22.04 LTS must initiate session audits at system startup.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260471r1134800_rule
SV-260472r1117267_rule - Ubuntu 22.04 LTS must restrict access to the kernel message buffer.
ubuntu2204 · low (CAT III)
stig://rule/SV-260472r1117267_rule
SV-260473r1044782_rule - Ubuntu 22.04 LTS must disable kernel core dumps so that it can fail to a secure state if system initialization fails, shutdown fails or aborts fail.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260473r1044782_rule
SV-260474r958928_rule - Ubuntu 22.04 LTS must implement address space layout randomization to protect its memory from unauthorized code execution.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260474r958928_rule
SV-260475r958928_rule - Ubuntu 22.04 LTS must implement nonexecutable data to protect its memory from unauthorized code execution.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260475r958928_rule
SV-260476r1015003_rule - Ubuntu 22.04 LTS must be configured so that the Advance Package Tool (APT) prevents the installation of patches, service packs, device drivers, or operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.
ubuntu2204 · low (CAT III)
stig://rule/SV-260476r1015003_rule
SV-260477r1044773_rule - Ubuntu 22.04 LTS must be configured so that the Advance Package Tool (APT) removes all software components after updated versions have been installed.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260477r1044773_rule
SV-260478r991587_rule - Ubuntu 22.04 LTS must have the "libpam-pwquality" package installed.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260478r991587_rule
SV-260479r991589_rule - Ubuntu 22.04 LTS must have the "chrony" package installed.
ubuntu2204 · low (CAT III)
stig://rule/SV-260479r991589_rule
SV-260480r991589_rule - Ubuntu 22.04 LTS must not have the "systemd-timesyncd" package installed.
ubuntu2204 · low (CAT III)
stig://rule/SV-260480r991589_rule
SV-260481r991589_rule - Ubuntu 22.04 LTS must not have the "ntp" package installed.
ubuntu2204 · low (CAT III)
stig://rule/SV-260481r991589_rule
SV-260482r958478_rule - Ubuntu 22.04 LTS must not have the "rsh-server" package installed.
ubuntu2204 · high (CAT I)
stig://rule/SV-260482r958478_rule
SV-260483r987796_rule - Ubuntu 22.04 LTS must not have the "telnet" package installed.
ubuntu2204 · high (CAT I)
stig://rule/SV-260483r987796_rule
SV-260484r958552_rule - Ubuntu 22.04 LTS must implement cryptographic mechanisms to prevent unauthorized disclosure and modification of all information that requires protection at rest.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260484r958552_rule
SV-260485r991559_rule - Ubuntu 22.04 LTS must have directories that contain system commands set to a mode of "755" or less permissive.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260485r991559_rule
SV-260486r991560_rule - Ubuntu 22.04 LTS must have system commands set to a mode of "755" or less permissive.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260486r991560_rule
SV-260487r1107262_rule - Ubuntu 22.04 LTS library files must have mode "755" or less permissive.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260487r1107262_rule
SV-260488r958566_rule - Ubuntu 22.04 LTS must configure the "/var/log" directory to have mode "755" or less permissive.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260488r958566_rule
SV-260489r1134796_rule - Ubuntu 22.04 LTS must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260489r1134796_rule
SV-260490r1069105_rule - Ubuntu 22.04 LTS must generate system journal entries without revealing information that could be exploited by adversaries.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260490r1069105_rule
SV-260491r958566_rule - Ubuntu 22.04 LTS must configure "/var/log/syslog" file with mode "640" or less permissive.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260491r958566_rule
SV-260492r991557_rule - Ubuntu 22.04 LTS must configure audit tools with a mode of "755" or less permissive.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260492r991557_rule
SV-260493r991559_rule - Ubuntu 22.04 LTS must have directories that contain system commands owned by "root".
ubuntu2204 · medium (CAT II)
stig://rule/SV-260493r991559_rule
SV-260494r991559_rule - Ubuntu 22.04 LTS must have directories that contain system commands group-owned by "root".
ubuntu2204 · medium (CAT II)
stig://rule/SV-260494r991559_rule
SV-260495r991560_rule - Ubuntu 22.04 LTS must have system commands owned by "root" or a system account.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260495r991560_rule
SV-260496r991560_rule - Ubuntu 22.04 LTS must have system commands group-owned by "root" or a system account.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260496r991560_rule
SV-260497r991560_rule - Ubuntu 22.04 LTS library directories must be owned by "root".
ubuntu2204 · medium (CAT II)
stig://rule/SV-260497r991560_rule
SV-260498r991560_rule - Ubuntu 22.04 LTS library directories must be group-owned by "root".
ubuntu2204 · medium (CAT II)
stig://rule/SV-260498r991560_rule
SV-260499r1107264_rule - Ubuntu 22.04 LTS library files must be owned by "root".
ubuntu2204 · medium (CAT II)
stig://rule/SV-260499r1107264_rule
SV-260500r1107266_rule - Ubuntu 22.04 LTS library files must be group-owned by "root".
ubuntu2204 · medium (CAT II)
stig://rule/SV-260500r1107266_rule
SV-260501r958566_rule - Ubuntu 22.04 LTS must configure the directories used by the system journal to be owned by "root".
ubuntu2204 · medium (CAT II)
stig://rule/SV-260501r958566_rule
SV-260502r958566_rule - Ubuntu 22.04 LTS must configure the directories used by the system journal to be group-owned by "systemd-journal".
ubuntu2204 · medium (CAT II)
stig://rule/SV-260502r958566_rule
SV-260503r958566_rule - Ubuntu 22.04 LTS must configure the files used by the system journal to be owned by "root".
ubuntu2204 · medium (CAT II)
stig://rule/SV-260503r958566_rule
SV-260504r958566_rule - Ubuntu 22.04 LTS must configure the files used by the system journal to be group-owned by "systemd-journal".
ubuntu2204 · medium (CAT II)
stig://rule/SV-260504r958566_rule
SV-260505r958566_rule - Ubuntu 22.04 LTS must be configured so that the "journalctl" command is owned by "root".
ubuntu2204 · medium (CAT II)
stig://rule/SV-260505r958566_rule
SV-260506r958566_rule - Ubuntu 22.04 LTS must be configured so that the "journalctl" command is group-owned by "root".
ubuntu2204 · medium (CAT II)
stig://rule/SV-260506r958566_rule
SV-260507r1101725_rule - Ubuntu 22.04 LTS must configure audit tools to be owned by "root".
ubuntu2204 · medium (CAT II)
stig://rule/SV-260507r1101725_rule
SV-260508r958566_rule - Ubuntu 22.04 LTS must configure the "/var/log" directory to be owned by "root".
ubuntu2204 · medium (CAT II)
stig://rule/SV-260508r958566_rule
SV-260509r958566_rule - Ubuntu 22.04 LTS must configure the "/var/log" directory to be group-owned by "syslog".
ubuntu2204 · medium (CAT II)
stig://rule/SV-260509r958566_rule
SV-260510r958566_rule - Ubuntu 22.04 LTS must configure "/var/log/syslog" file to be owned by "syslog".
ubuntu2204 · medium (CAT II)
stig://rule/SV-260510r958566_rule
SV-260511r958566_rule - Ubuntu 22.04 LTS must configure the "/var/log/syslog" file to be group-owned by "adm".
ubuntu2204 · medium (CAT II)
stig://rule/SV-260511r958566_rule
SV-260512r958564_rule - Ubuntu 22.04 LTS must be configured so that the "journalctl" command is not accessible by unauthorized users.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260512r958564_rule
SV-260513r1117267_rule - Ubuntu 22.04 LTS must set a sticky bit on all public directories to prevent unauthorized and unintended information transferred via shared system resources.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260513r1117267_rule
SV-260514r958672_rule - Ubuntu 22.04 LTS must have an application firewall installed in order to control remote access methods.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260514r958672_rule
SV-260515r958672_rule - Ubuntu 22.04 LTS must enable and run the Uncomplicated Firewall (ufw).
ubuntu2204 · medium (CAT II)
stig://rule/SV-260515r958672_rule
SV-260516r991593_rule - Ubuntu 22.04 LTS must have an application firewall enabled.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260516r991593_rule
SV-260517r958902_rule - Ubuntu 22.04 LTS must configure the Uncomplicated Firewall (ufw) to rate-limit impacted network interfaces.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260517r958902_rule
SV-260518r958480_rule - Ubuntu 22.04 LTS must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260518r958480_rule
SV-260519r1038944_rule - Ubuntu 22.04 LTS must, for networked systems, compare internal information system clocks at least every 24 hours with a server synchronized to one of the redundant United States Naval Observatory (USNO) time servers, or a time server designated for the appropriate DOD network (NIPRNet/SIPRNet), and/or the Global Positioning System (GPS).
ubuntu2204 · low (CAT III)
stig://rule/SV-260519r1038944_rule
SV-260520r1044776_rule - Ubuntu 22.04 LTS must synchronize internal information system clocks to the authoritative time source when the time difference is greater than one second.
ubuntu2204 · low (CAT III)
stig://rule/SV-260520r1044776_rule
SV-260521r958788_rule - Ubuntu 22.04 LTS must record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC).
ubuntu2204 · low (CAT III)
stig://rule/SV-260521r958788_rule
SV-260522r1069097_rule - Ubuntu 22.04 LTS must be configured to use TCP syncookies.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260522r1069097_rule
SV-260523r958908_rule - Ubuntu 22.04 LTS must have SSH installed.
ubuntu2204 · high (CAT I)
stig://rule/SV-260523r958908_rule
SV-260524r958908_rule - Ubuntu 22.04 LTS must use SSH to protect the confidentiality and integrity of transmitted information.
ubuntu2204 · high (CAT I)
stig://rule/SV-260524r958908_rule
SV-260525r958390_rule - Ubuntu 22.04 LTS must display the Standard Mandatory DOD Notice and Consent Banner before granting any local or remote connection to the system.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260525r958390_rule
SV-260526r991591_rule - Ubuntu 22.04 LTS must not allow unattended or automatic login via SSH.
ubuntu2204 · high (CAT I)
stig://rule/SV-260526r991591_rule
SV-260527r986275_rule - Ubuntu 22.04 LTS must be configured so that all network connections associated with SSH traffic terminate after becoming unresponsive.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260527r986275_rule
SV-260528r970703_rule - Ubuntu 22.04 LTS must be configured so that all network connections associated with SSH traffic are terminated after 10 minutes of becoming unresponsive.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260528r970703_rule
SV-260529r991589_rule - Ubuntu 22.04 LTS must be configured so that remote X connections are disabled, unless to fulfill documented and validated mission requirements.
ubuntu2204 · high (CAT I)
stig://rule/SV-260529r991589_rule
SV-260530r991589_rule - Ubuntu 22.04 LTS SSH daemon must prevent remote hosts from connecting to the proxy display.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260530r991589_rule
SV-260531r958408_rule - Ubuntu 22.04 LTS must configure the SSH daemon to use FIPS 140-3-approved ciphers to prevent the unauthorized disclosure of information and/or detect changes to information during transmission.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260531r958408_rule
SV-260532r991554_rule - Ubuntu 22.04 LTS must configure the SSH daemon to use Message Authentication Codes (MACs) employing FIPS 140-3-approved cryptographic hashes to prevent the unauthorized disclosure of information and/or detect changes to information during transmission.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260532r991554_rule
SV-260533r958408_rule - Ubuntu 22.04 LTS SSH server must be configured to use only FIPS-validated key exchange algorithms.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260533r958408_rule
SV-260534r958510_rule - Ubuntu 22.04 LTS must use strong authenticators in establishing nonlocal maintenance and diagnostic sessions.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260534r958510_rule
SV-260535r958390_rule - Ubuntu 22.04 LTS must enable the graphical user logon banner to display the Standard Mandatory DOD Notice and Consent Banner before granting local access to the system via a graphical user logon.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260535r958390_rule
SV-260536r958390_rule - Ubuntu 22.04 LTS must display the Standard Mandatory DOD Notice and Consent Banner before granting local access to the system via a graphical user logon.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260536r958390_rule
SV-260537r1069101_rule - Ubuntu 22.04 LTS must retain a user's session lock until that user reestablishes access using established identification and authentication procedures.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260537r1069101_rule
SV-260538r1069119_rule - Ubuntu 22.04 LTS must initiate a graphical session lock after 15 minutes of inactivity.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260538r1069119_rule
SV-260539r1069103_rule - Ubuntu 22.04 LTS must disable the x86 Ctrl-Alt-Delete key sequence if a graphical user interface is installed.
ubuntu2204 · high (CAT I)
stig://rule/SV-260539r1069103_rule
SV-260540r986276_rule - Ubuntu 22.04 LTS must disable automatic mounting of Universal Serial Bus (USB) mass storage driver.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260540r986276_rule
SV-260541r958358_rule - Ubuntu 22.04 LTS must disable all wireless network adapters.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260541r958358_rule
SV-260542r1015006_rule - Ubuntu 22.04 LTS must prevent direct login into the root account.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260542r1015006_rule
SV-260543r958482_rule - Ubuntu 22.04 LTS must uniquely identify interactive users.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260543r958482_rule
SV-260545r1015007_rule - Ubuntu 22.04 LTS must enforce 24 hours/one day as the minimum password lifetime. Passwords for new users must have a 24 hours/one day minimum password lifetime restriction.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260545r1015007_rule
SV-260546r1038967_rule - Ubuntu 22.04 LTS must enforce a 60-day maximum password lifetime restriction. Passwords for new users must have a 60-day maximum password lifetime restriction.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260546r1038967_rule
SV-260547r1015009_rule - Ubuntu 22.04 LTS must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260547r1015009_rule
SV-260548r958364_rule - Ubuntu 22.04 LTS must automatically expire temporary accounts within 72 hours.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260548r958364_rule
SV-260549r958388_rule - Ubuntu 22.04 LTS must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts have been made.
ubuntu2204 · low (CAT III)
stig://rule/SV-260549r958388_rule
SV-260550r991588_rule - Ubuntu 22.04 LTS must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
ubuntu2204 · low (CAT III)
stig://rule/SV-260550r991588_rule
SV-260552r958398_rule - Ubuntu 22.04 LTS must limit the number of concurrent sessions to ten for all accounts and/or account types.
ubuntu2204 · low (CAT III)
stig://rule/SV-260552r958398_rule
SV-260553r1015010_rule - Ubuntu 22.04 LTS must allow users to directly initiate a session lock for all connection types.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260553r1015010_rule
SV-260554r958636_rule - Ubuntu 22.04 LTS must automatically exit interactive command shell user sessions after 15 minutes of inactivity.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260554r958636_rule
SV-260555r991590_rule - Ubuntu 22.04 LTS default filesystem permissions must be defined in such a way that all authenticated users can read and modify only their own files.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260555r991590_rule
SV-260556r958702_rule - Ubuntu 22.04 LTS must have the "apparmor" package installed.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260556r958702_rule
SV-260557r958804_rule - Ubuntu 22.04 LTS must be configured to use AppArmor.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260557r958804_rule
SV-260558r1101733_rule - Ubuntu 22.04 LTS must require users to reauthenticate for privilege escalation or when changing roles.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260558r1101733_rule
SV-260559r958518_rule - Ubuntu 22.04 LTS must ensure only users who need access to security functions are part of sudo group.
ubuntu2204 · high (CAT I)
stig://rule/SV-260559r958518_rule
SV-260560r1015012_rule - Ubuntu 22.04 LTS must enforce password complexity by requiring at least one uppercase character be used.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260560r1015012_rule
SV-260561r1015013_rule - Ubuntu 22.04 LTS must enforce password complexity by requiring at least one lowercase character be used.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260561r1015013_rule
SV-260562r1015014_rule - Ubuntu 22.04 LTS must enforce password complexity by requiring that at least one numeric character be used.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260562r1015014_rule
SV-260563r1015015_rule - Ubuntu 22.04 LTS must enforce password complexity by requiring that at least one special character be used.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260563r1015015_rule
SV-260564r991587_rule - Ubuntu 22.04 LTS must prevent the use of dictionary words for passwords.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260564r991587_rule
SV-260565r1015016_rule - Ubuntu 22.04 LTS must enforce a minimum 15-character password length.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260565r1015016_rule
SV-260566r1015017_rule - Ubuntu 22.04 LTS must require the change of at least eight characters when passwords are changed.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260566r1015017_rule
SV-260567r991587_rule - Ubuntu 22.04 LTS must be configured so that when passwords are changed or new passwords are established, pwquality must be used.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260567r991587_rule
SV-260569r1101736_rule - Ubuntu 22.04 LTS must store only encrypted representations of passwords.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260569r1101736_rule
SV-260570r1082233_rule - Ubuntu 22.04 LTS must not allow accounts configured with blank or null passwords.
ubuntu2204 · high (CAT I)
stig://rule/SV-260570r1082233_rule
SV-260571r991589_rule - Ubuntu 22.04 LTS must not have accounts configured with blank or null passwords.
ubuntu2204 · high (CAT I)
stig://rule/SV-260571r991589_rule
SV-260572r971535_rule - Ubuntu 22.04 LTS must encrypt all stored passwords with a FIPS 140-3-approved cryptographic hashing algorithm.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260572r971535_rule
SV-260573r1015019_rule - Ubuntu 22.04 LTS must implement multifactor authentication for remote access to privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260573r1015019_rule
SV-260574r958816_rule - Ubuntu 22.04 LTS must accept personal identity verification (PIV) credentials.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260574r958816_rule
SV-260575r1044770_rule - Ubuntu 22.04 LTS must implement smart card logins for multifactor authentication for local and network access to privileged and nonprivileged accounts.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260575r1044770_rule
SV-260576r1069114_rule - Ubuntu 22.04 LTS must electronically verify personal identity verification (PIV) credentials.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260576r1069114_rule
SV-260577r1069112_rule - Ubuntu 22.04 LTS, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260577r1069112_rule
SV-260578r1015021_rule - Ubuntu 22.04 LTS for PKI-based authentication, must implement a local cache of revocation data in case of the inability to access revocation information via the network.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260578r1015021_rule
SV-260579r958452_rule - Ubuntu 22.04 LTS must map the authenticated identity to the user or group account for PKI-based authentication.
ubuntu2204 · high (CAT I)
stig://rule/SV-260579r958452_rule
SV-260580r958868_rule - Ubuntu 22.04 LTS must use DOD PKI-established certificate authorities for verification of the establishment of protected sessions.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260580r958868_rule
SV-260581r958828_rule - Ubuntu 22.04 LTS must be configured such that Pluggable Authentication Module (PAM) prohibits the use of cached authentications after one day.
ubuntu2204 · low (CAT III)
stig://rule/SV-260581r958828_rule
SV-260582r958944_rule - Ubuntu 22.04 LTS must use a file integrity tool to verify correct operation of all security functions.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260582r958944_rule
SV-260583r1134798_rule - Ubuntu 22.04 LTS must configure AIDE to perform file integrity checking on the file system.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260583r1134798_rule
SV-260584r958794_rule - Ubuntu 22.04 LTS must notify designated personnel if baseline configurations are changed in an unauthorized manner. The file integrity tool must notify the system administrator when changes to the baseline configuration or anomalies in the operation of any security functions are discovered.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260584r958794_rule
SV-260585r958946_rule - Ubuntu 22.04 LTS must be configured so that the script that runs each 30 days or less to check file integrity is the default.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260585r958946_rule
SV-260586r1069107_rule - Ubuntu 22.04 LTS must use cryptographic mechanisms to protect the integrity of audit tools.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260586r1069107_rule
SV-260587r959008_rule - Ubuntu 22.04 LTS must have a crontab script running weekly to offload audit events of standalone systems.
ubuntu2204 · low (CAT III)
stig://rule/SV-260587r959008_rule
SV-260588r991562_rule - Ubuntu 22.04 LTS must be configured to preserve log records from failure events.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260588r991562_rule
SV-260589r958406_rule - Ubuntu 22.04 LTS must monitor remote access methods.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260589r958406_rule
SV-260590r1015022_rule - Ubuntu 22.04 LTS must have the "auditd" package installed.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260590r1015022_rule
SV-260591r1015023_rule - Ubuntu 22.04 LTS must produce audit records and reports containing information to establish when, where, what type, the source, and the outcome for all DOD-defined auditable events and actions in near real time.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260591r1015023_rule
SV-260592r1101709_rule - Ubuntu 22.04 LTS audit event multiplexor must be configured to offload audit logs onto a different system from the system being audited.
ubuntu2204 · low (CAT III)
stig://rule/SV-260592r1101709_rule
SV-260593r958424_rule - Ubuntu 22.04 LTS must alert the information system security officer (ISSO) and system administrator (SA) in the event of an audit processing failure.
ubuntu2204 · low (CAT III)
stig://rule/SV-260593r958424_rule
SV-260594r1038966_rule - Ubuntu 22.04 LTS must shut down by default upon audit failure.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260594r1038966_rule
SV-260595r958752_rule - Ubuntu 22.04 LTS must allocate audit record storage capacity to store at least one weeks' worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
ubuntu2204 · low (CAT III)
stig://rule/SV-260595r958752_rule
SV-260596r971542_rule - Ubuntu 22.04 LTS must immediately notify the system administrator (SA) and information system security officer (ISSO) when the audit record storage volume reaches 25 percent remaining of the allocated capacity.
ubuntu2204 · low (CAT III)
stig://rule/SV-260596r971542_rule
SV-260597r958434_rule - Ubuntu 22.04 LTS must be configured so that audit log files are not read- or write-accessible by unauthorized users.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260597r958434_rule
SV-260598r958434_rule - Ubuntu 22.04 LTS must be configured to permit only authorized users ownership of the audit log files.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260598r958434_rule
SV-260599r958434_rule - Ubuntu 22.04 LTS must permit only authorized groups ownership of the audit log files.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260599r958434_rule
SV-260600r958438_rule - Ubuntu 22.04 LTS must be configured so that the audit log directory is not write-accessible by unauthorized users.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260600r958438_rule
SV-260601r958444_rule - Ubuntu 22.04 LTS must be configured so that audit configuration files are not write-accessible by unauthorized users.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260601r958444_rule
SV-260602r958444_rule - Ubuntu 22.04 LTS must permit only authorized accounts to own the audit configuration files.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260602r958444_rule
SV-260603r958444_rule - Ubuntu 22.04 LTS must permit only authorized groups to own the audit configuration files.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260603r958444_rule
SV-260604r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the apparmor_parser command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260604r958446_rule
SV-260605r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the chacl command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260605r958446_rule
SV-260606r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the chage command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260606r958446_rule
SV-260607r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the chcon command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260607r958446_rule
SV-260608r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the chfn command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260608r958446_rule
SV-260609r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the chsh command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260609r958446_rule
SV-260610r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the crontab command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260610r958446_rule
SV-260611r991586_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful attempts to use the fdisk command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260611r991586_rule
SV-260612r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the gpasswd command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260612r958446_rule
SV-260613r991586_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful attempts to use the kmod command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260613r991586_rule
SV-260614r991586_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful attempts to use modprobe command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260614r991586_rule
SV-260615r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the mount command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260615r958446_rule
SV-260616r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the newgrp command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260616r958446_rule
SV-260617r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the pam_timestamp_check command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260617r958446_rule
SV-260618r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the passwd command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260618r958446_rule
SV-260619r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the setfacl command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260619r958446_rule
SV-260620r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the ssh-agent command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260620r958446_rule
SV-260621r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the ssh-keysign command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260621r958446_rule
SV-260622r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the su command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260622r958446_rule
SV-260623r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the sudo command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260623r958446_rule
SV-260624r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the sudoedit command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260624r958446_rule
SV-260625r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the umount command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260625r958446_rule
SV-260626r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the unix_update command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260626r958446_rule
SV-260627r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the usermod command.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260627r958446_rule
SV-260628r958368_rule - Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260628r958368_rule
SV-260629r958368_rule - Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260629r958368_rule
SV-260630r958368_rule - Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260630r958368_rule
SV-260631r958368_rule - Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260631r958368_rule
SV-260632r958368_rule - Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260632r958368_rule
SV-260633r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the chmod, fchmod, and fchmodat system calls.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260633r958446_rule
SV-260634r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the chown, fchown, fchownat, and lchown system calls.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260634r958446_rule
SV-260635r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the creat, open, openat, open_by_handle_at, truncate, and ftruncate system calls.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260635r958446_rule
SV-260636r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the delete_module system call.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260636r958446_rule
SV-260637r958446_rule - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the init_module and finit_module system calls.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260637r958446_rule
SV-260638r958446_rule - Ubuntu 22.04 LTS must generate audit records for any use of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260638r958446_rule
SV-260639r991577_rule - Ubuntu 22.04 LTS must generate audit records for any successful/unsuccessful use of unlink, unlinkat, rename, renameat, and rmdir system calls.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260639r991577_rule
SV-260640r991589_rule - Ubuntu 22.04 LTS must generate audit records for all events that affect the systemd journal files.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260640r991589_rule
SV-260641r991581_rule - Ubuntu 22.04 LTS must generate audit records for the /var/log/btmp file.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260641r991581_rule
SV-260642r991581_rule - Ubuntu 22.04 LTS must generate audit records for the /var/log/wtmp file.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260642r991581_rule
SV-260643r991581_rule - Ubuntu 22.04 LTS must generate audit records for the /var/run/utmp file.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260643r991581_rule
SV-260644r958446_rule - Ubuntu 22.04 LTS must generate audit records for the use and modification of faillog file.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260644r958446_rule
SV-260645r958446_rule - Ubuntu 22.04 LTS must generate audit records for the use and modification of the lastlog file.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260645r958446_rule
SV-260646r991575_rule - Ubuntu 22.04 LTS must generate audit records when successful/unsuccessful attempts to modify the /etc/sudoers file occur.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260646r991575_rule
SV-260647r991575_rule - Ubuntu 22.04 LTS must generate audit records when successful/unsuccessful attempts to modify the /etc/sudoers.d directory occur.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260647r991575_rule
SV-260648r958730_rule - Ubuntu 22.04 LTS must prevent all software from executing at higher privilege levels than users executing the software and the audit system must be configured to audit the execution of privileged functions.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260648r958730_rule
SV-260649r986298_rule - Ubuntu 22.04 LTS must generate audit records for privileged activities, nonlocal maintenance, diagnostic sessions and other system-level access.
ubuntu2204 · medium (CAT II)
stig://rule/SV-260649r986298_rule
SV-260650r987791_rule - Ubuntu 22.04 LTS must implement NIST FIPS-validated cryptography to protect classified information and for the following: To provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
ubuntu2204 · high (CAT I)
stig://rule/SV-260650r987791_rule
SV-274860r1107272_rule - The operating system must require users to provide a password for privilege escalation.
ubuntu2204 · medium (CAT II)
stig://rule/SV-274860r1107272_rule
SV-274861r1101704_rule - The operating system must restrict privilege elevation to authorized personnel.
ubuntu2204 · medium (CAT II)
stig://rule/SV-274861r1101704_rule
SV-274862r1107273_rule - Ubuntu 22.04 LTS must audit any script or executable called by cron as root or by any privileged user.
ubuntu2204 · medium (CAT II)
stig://rule/SV-274862r1107273_rule
SV-274863r1107271_rule - Ubuntu 22.04 LTS must be configured such that Pluggable Authentication Module (PAM) prohibits the use of cached authentications after one day.
ubuntu2204 · low (CAT III)
stig://rule/SV-274863r1107271_rule
SV-274864r1107268_rule - Ubuntu 22.04 LTS must have the "SSSD" package installed.
ubuntu2204 · medium (CAT II)
stig://rule/SV-274864r1107268_rule
SV-274865r1101731_rule - Ubuntu 22.04 LTS must map the authenticated identity to the user or group account for PKI-based authentication.
ubuntu2204 · medium (CAT II)
stig://rule/SV-274865r1101731_rule
SV-274866r1101739_rule - Ubuntu 22.04 LTS must use the "SSSD" package for multifactor authentication services.
ubuntu2204 · medium (CAT II)
stig://rule/SV-274866r1101739_rule
SV-274867r1107270_rule - Ubuntu 22.04 LTS must ensure SSSD performs certificate path validation, including revocation checking, against a trusted anchor for PKI-based authentication.
ubuntu2204 · medium (CAT II)
stig://rule/SV-274867r1107270_rule
SV-278951r1135403_rule - Ubuntu 22.04 LTS must be a vendor-supported release.
ubuntu2204 · high (CAT I)
stig://rule/SV-278951r1135403_rule
SV-230221r1017040_rule - RHEL 8 must be a vendor-supported release.
rhel8 · high (CAT I)
stig://rule/SV-230221r1017040_rule
SV-230222r1017041_rule - RHEL 8 vendor packaged system security patches and updates must be installed and up to date.
rhel8 · medium (CAT II)
stig://rule/SV-230222r1017041_rule
SV-230223r1069327_rule - RHEL 8 must implement NIST FIPS-validated cryptography for the following: To provision digital signatures, to generate cryptographic hashes, and to protect data requiring data-at-rest protections in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
rhel8 · high (CAT I)
stig://rule/SV-230223r1069327_rule
SV-230224r1044787_rule - All RHEL 8 local disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at rest protection.
rhel8 · high (CAT I)
stig://rule/SV-230224r1044787_rule
SV-230225r1069297_rule - RHEL 8 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a ssh logon.
rhel8 · medium (CAT II)
stig://rule/SV-230225r1069297_rule
SV-230226r1069298_rule - RHEL 8 must display the Standard Mandatory DoD Notice and Consent Banner before granting local or remote access to the system via a graphical user logon.
rhel8 · medium (CAT II)
stig://rule/SV-230226r1069298_rule
SV-230227r1017046_rule - RHEL 8 must display the Standard Mandatory DoD Notice and Consent Banner before granting local or remote access to the system via a command line user logon.
rhel8 · medium (CAT II)
stig://rule/SV-230227r1017046_rule
SV-230228r1069299_rule - All RHEL 8 remote access methods must be monitored.
rhel8 · medium (CAT II)
stig://rule/SV-230228r1069299_rule
SV-230229r1017048_rule - RHEL 8, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
rhel8 · medium (CAT II)
stig://rule/SV-230229r1017048_rule
SV-230230r1069287_rule - RHEL 8, for certificate-based authentication, must enforce authorized access to the corresponding private key.
rhel8 · medium (CAT II)
stig://rule/SV-230230r1069287_rule
SV-230231r1017050_rule - RHEL 8 must encrypt all stored passwords with a FIPS 140-2 approved cryptographic hashing algorithm.
rhel8 · medium (CAT II)
stig://rule/SV-230231r1017050_rule
SV-230232r1017051_rule - RHEL 8 must employ FIPS 140-2 approved cryptographic hashing algorithms for all stored passwords.
rhel8 · medium (CAT II)
stig://rule/SV-230232r1017051_rule
SV-230233r1044790_rule - The RHEL 8 shadow password suite must be configured to use a sufficient number of hashing rounds.
rhel8 · medium (CAT II)
stig://rule/SV-230233r1044790_rule
SV-230234r1117265_rule - RHEL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must require authentication upon booting into single-user mode and maintenance.
rhel8 · high (CAT I)
stig://rule/SV-230234r1117265_rule
SV-230235r1117265_rule - RHEL 8 operating systems booted with a BIOS must require authentication upon booting into single-user and maintenance modes.
rhel8 · high (CAT I)
stig://rule/SV-230235r1117265_rule
SV-230236r1117265_rule - RHEL 8 operating systems must require authentication upon booting into rescue mode.
rhel8 · medium (CAT II)
stig://rule/SV-230236r1117265_rule
SV-230237r1017056_rule - The RHEL 8 pam_unix.so module must be configured in the password-auth file to use a FIPS 140-2 approved cryptographic hashing algorithm for system authentication.
rhel8 · medium (CAT II)
stig://rule/SV-230237r1017056_rule
SV-230238r1017057_rule - RHEL 8 must prevent system daemons from using Kerberos for authentication.
rhel8 · medium (CAT II)
stig://rule/SV-230238r1017057_rule
SV-230239r1017058_rule - The krb5-workstation package must not be installed on RHEL 8.
rhel8 · medium (CAT II)
stig://rule/SV-230239r1017058_rule
SV-230240r1017059_rule - RHEL 8 must use a Linux Security Module configured to enforce limits on system services.
rhel8 · medium (CAT II)
stig://rule/SV-230240r1017059_rule
SV-230241r1017060_rule - RHEL 8 must have policycoreutils package installed.
rhel8 · low (CAT III)
stig://rule/SV-230241r1017060_rule
SV-230243r1117267_rule - A sticky bit must be set on all RHEL 8 public directories to prevent unauthorized and unintended information transferred via shared system resources.
rhel8 · medium (CAT II)
stig://rule/SV-230243r1117267_rule
SV-230244r1069300_rule - RHEL 8 must be configured so that all network connections associated with SSH traffic terminate after becoming unresponsive.
rhel8 · medium (CAT II)
stig://rule/SV-230244r1069300_rule
SV-230245r1017063_rule - The RHEL 8 /var/log/messages file must have mode 0640 or less permissive.
rhel8 · medium (CAT II)
stig://rule/SV-230245r1017063_rule
SV-230246r1017064_rule - The RHEL 8 /var/log/messages file must be owned by root.
rhel8 · medium (CAT II)
stig://rule/SV-230246r1017064_rule
SV-230247r1017065_rule - The RHEL 8 /var/log/messages file must be group-owned by root.
rhel8 · medium (CAT II)
stig://rule/SV-230247r1017065_rule
SV-230248r1069291_rule - The RHEL 8 /var/log directory must have mode 0755 or less permissive.
rhel8 · medium (CAT II)
stig://rule/SV-230248r1069291_rule
SV-230249r1017067_rule - The RHEL 8 /var/log directory must be owned by root.
rhel8 · medium (CAT II)
stig://rule/SV-230249r1017067_rule
SV-230250r1017068_rule - The RHEL 8 /var/log directory must be group-owned by root.
rhel8 · medium (CAT II)
stig://rule/SV-230250r1017068_rule
SV-230251r1044814_rule - The RHEL 8 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms.
rhel8 · medium (CAT II)
stig://rule/SV-230251r1044814_rule
SV-230252r1067104_rule - The RHEL 8 operating system must implement DOD-approved encryption to protect the confidentiality of SSH server connections.
rhel8 · medium (CAT II)
stig://rule/SV-230252r1067104_rule
SV-230253r1044799_rule - RHEL 8 must ensure the SSH server uses strong entropy.
rhel8 · low (CAT III)
stig://rule/SV-230253r1044799_rule
SV-230254r1017072_rule - The RHEL 8 operating system must implement DoD-approved encryption in the OpenSSL package.
rhel8 · medium (CAT II)
stig://rule/SV-230254r1017072_rule
SV-230255r1017075_rule - The RHEL 8 operating system must implement DoD-approved TLS encryption in the OpenSSL package.
rhel8 · medium (CAT II)
stig://rule/SV-230255r1017075_rule
SV-230256r1017076_rule - The RHEL 8 operating system must implement DoD-approved TLS encryption in the GnuTLS package.
rhel8 · medium (CAT II)
stig://rule/SV-230256r1017076_rule
SV-230257r1017077_rule - RHEL 8 system commands must have mode 755 or less permissive.
rhel8 · medium (CAT II)
stig://rule/SV-230257r1017077_rule
SV-230258r1017078_rule - RHEL 8 system commands must be owned by root.
rhel8 · medium (CAT II)
stig://rule/SV-230258r1017078_rule
SV-230259r1017079_rule - RHEL 8 system commands must be group-owned by root or a system account.
rhel8 · medium (CAT II)
stig://rule/SV-230259r1017079_rule
SV-230260r1101888_rule - RHEL 8 library files must have mode 755 or less permissive.
rhel8 · medium (CAT II)
stig://rule/SV-230260r1101888_rule
SV-230261r1101891_rule - RHEL 8 library files must be owned by root.
rhel8 · medium (CAT II)
stig://rule/SV-230261r1101891_rule
SV-230262r1101894_rule - RHEL 8 library files must be group-owned by root or a system account.
rhel8 · medium (CAT II)
stig://rule/SV-230262r1101894_rule
SV-230263r1017083_rule - The RHEL 8 file integrity tool must notify the system administrator when changes to the baseline configuration or anomalies in the operation of any security functions are discovered within an organizationally defined frequency.
rhel8 · medium (CAT II)
stig://rule/SV-230263r1017083_rule
SV-230264r1017377_rule - RHEL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components from a repository without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.
rhel8 · high (CAT I)
stig://rule/SV-230264r1017377_rule
SV-230265r1017378_rule - RHEL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components of local packages without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.
rhel8 · high (CAT I)
stig://rule/SV-230265r1017378_rule
SV-230266r1017084_rule - RHEL 8 must prevent the loading of a new kernel for later execution.
rhel8 · medium (CAT II)
stig://rule/SV-230266r1017084_rule
SV-230267r1017085_rule - RHEL 8 must enable kernel parameters to enforce discretionary access control on symlinks.
rhel8 · medium (CAT II)
stig://rule/SV-230267r1017085_rule
SV-230268r1017086_rule - RHEL 8 must enable kernel parameters to enforce discretionary access control on hardlinks.
rhel8 · medium (CAT II)
stig://rule/SV-230268r1017086_rule
SV-230269r1117267_rule - RHEL 8 must restrict access to the kernel message buffer.
rhel8 · low (CAT III)
stig://rule/SV-230269r1117267_rule
SV-230270r1117267_rule - RHEL 8 must prevent kernel profiling by unprivileged users.
rhel8 · low (CAT III)
stig://rule/SV-230270r1117267_rule
SV-230271r1101896_rule - RHEL 8 must require users to provide a password for privilege escalation.
rhel8 · medium (CAT II)
stig://rule/SV-230271r1101896_rule
SV-230272r1101898_rule - RHEL 8 must require users to reauthenticate for privilege escalation.
rhel8 · medium (CAT II)
stig://rule/SV-230272r1101898_rule
SV-230273r1017381_rule - RHEL 8 must have the packages required for multifactor authentication installed.
rhel8 · medium (CAT II)
stig://rule/SV-230273r1017381_rule
SV-230274r1017089_rule - RHEL 8 must implement certificate status checking for multifactor authentication.
rhel8 · medium (CAT II)
stig://rule/SV-230274r1017089_rule
SV-230275r958816_rule - RHEL 8 must accept Personal Identity Verification (PIV) credentials.
rhel8 · medium (CAT II)
stig://rule/SV-230275r958816_rule
SV-230276r958928_rule - RHEL 8 must implement non-executable data to protect its memory from unauthorized code execution.
rhel8 · medium (CAT II)
stig://rule/SV-230276r958928_rule
SV-230277r1017090_rule - RHEL 8 must clear the page allocator to prevent use-after-free attacks.
rhel8 · medium (CAT II)
stig://rule/SV-230277r1017090_rule
SV-230278r1017091_rule - RHEL 8 must disable virtual syscalls.
rhel8 · medium (CAT II)
stig://rule/SV-230278r1017091_rule
SV-230279r1069286_rule - RHEL 8 must clear memory when it is freed to prevent use-after-free attacks.
rhel8 · medium (CAT II)
stig://rule/SV-230279r1069286_rule
SV-230280r1017093_rule - RHEL 8 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution.
rhel8 · medium (CAT II)
stig://rule/SV-230280r1017093_rule
SV-230281r958936_rule - YUM must remove all software components after updated versions have been installed on RHEL 8.
rhel8 · low (CAT III)
stig://rule/SV-230281r958936_rule
SV-230282r958944_rule - RHEL 8 must enable the SELinux targeted policy.
rhel8 · medium (CAT II)
stig://rule/SV-230282r958944_rule
SV-230283r1017094_rule - There must be no shosts.equiv files on the RHEL 8 operating system.
rhel8 · high (CAT I)
stig://rule/SV-230283r1017094_rule
SV-230284r1017095_rule - There must be no .shosts files on the RHEL 8 operating system.
rhel8 · high (CAT I)
stig://rule/SV-230284r1017095_rule
SV-230285r1017096_rule - RHEL 8 must enable the hardware random number generator entropy gatherer service.
rhel8 · low (CAT III)
stig://rule/SV-230285r1017096_rule
SV-230286r1017097_rule - The RHEL 8 SSH public host key files must have mode 0644 or less permissive.
rhel8 · medium (CAT II)
stig://rule/SV-230286r1017097_rule
SV-230287r1017098_rule - The RHEL 8 SSH private host key files must have mode 0640 or less permissive.
rhel8 · medium (CAT II)
stig://rule/SV-230287r1017098_rule
SV-230288r1069301_rule - The RHEL 8 SSH daemon must perform strict mode checking of home directory configuration files.
rhel8 · medium (CAT II)
stig://rule/SV-230288r1069301_rule
SV-230290r1069302_rule - The RHEL 8 SSH daemon must not allow authentication using known host’s authentication.
rhel8 · medium (CAT II)
stig://rule/SV-230290r1069302_rule
SV-230291r1069303_rule - The RHEL 8 SSH daemon must not allow Kerberos authentication, except to fulfill documented and validated mission requirements.
rhel8 · medium (CAT II)
stig://rule/SV-230291r1069303_rule
SV-230292r1017103_rule - RHEL 8 must use a separate file system for /var.
rhel8 · low (CAT III)
stig://rule/SV-230292r1017103_rule
SV-230293r1017104_rule - RHEL 8 must use a separate file system for /var/log.
rhel8 · low (CAT III)
stig://rule/SV-230293r1017104_rule
SV-230294r1017105_rule - RHEL 8 must use a separate file system for the system audit data path.
rhel8 · low (CAT III)
stig://rule/SV-230294r1017105_rule
SV-230295r1017106_rule - A separate RHEL 8 filesystem must be used for the /tmp directory.
rhel8 · medium (CAT II)
stig://rule/SV-230295r1017106_rule
SV-230296r1069322_rule - RHEL 8 must not permit direct logons to the root account using remote access via SSH.
rhel8 · medium (CAT II)
stig://rule/SV-230296r1069322_rule
SV-230298r1017108_rule - The rsyslog service must be running in RHEL 8.
rhel8 · medium (CAT II)
stig://rule/SV-230298r1017108_rule
SV-230299r1017109_rule - RHEL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories.
rhel8 · medium (CAT II)
stig://rule/SV-230299r1017109_rule
SV-230300r1017110_rule - RHEL 8 must prevent files with the setuid and setgid bit set from being executed on the /boot directory.
rhel8 · medium (CAT II)
stig://rule/SV-230300r1017110_rule
SV-230301r1017111_rule - RHEL 8 must prevent special devices on non-root local partitions.
rhel8 · medium (CAT II)
stig://rule/SV-230301r1017111_rule
SV-230302r1017112_rule - RHEL 8 must prevent code from being executed on file systems that contain user home directories.
rhel8 · medium (CAT II)
stig://rule/SV-230302r1017112_rule
SV-230303r1017113_rule - RHEL 8 must prevent special devices on file systems that are used with removable media.
rhel8 · medium (CAT II)
stig://rule/SV-230303r1017113_rule
SV-230304r1017114_rule - RHEL 8 must prevent code from being executed on file systems that are used with removable media.
rhel8 · medium (CAT II)
stig://rule/SV-230304r1017114_rule
SV-230305r1017115_rule - RHEL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that are used with removable media.
rhel8 · medium (CAT II)
stig://rule/SV-230305r1017115_rule
SV-230306r1017116_rule - RHEL 8 must prevent code from being executed on file systems that are imported via Network File System (NFS).
rhel8 · medium (CAT II)
stig://rule/SV-230306r1017116_rule
SV-230307r1017117_rule - RHEL 8 must prevent special devices on file systems that are imported via Network File System (NFS).
rhel8 · medium (CAT II)
stig://rule/SV-230307r1017117_rule
SV-230308r1017118_rule - RHEL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that are imported via Network File System (NFS).
rhel8 · medium (CAT II)
stig://rule/SV-230308r1017118_rule
SV-230309r1017119_rule - Local RHEL 8 initialization files must not execute world-writable programs.
rhel8 · medium (CAT II)
stig://rule/SV-230309r1017119_rule
SV-230310r1017120_rule - RHEL 8 must disable kernel dumps unless needed.
rhel8 · medium (CAT II)
stig://rule/SV-230310r1017120_rule
SV-230311r1017121_rule - RHEL 8 must disable the kernel.core_pattern.
rhel8 · medium (CAT II)
stig://rule/SV-230311r1017121_rule
SV-230312r1134877_rule - RHEL 8 must disable acquiring, saving, and processing core dumps.
rhel8 · medium (CAT II)
stig://rule/SV-230312r1134877_rule
SV-230313r1134879_rule - RHEL 8 must disable core dumps for all users.
rhel8 · medium (CAT II)
stig://rule/SV-230313r1134879_rule
SV-230314r1134881_rule - RHEL 8 must disable storing core dumps.
rhel8 · medium (CAT II)
stig://rule/SV-230314r1134881_rule
SV-230315r1134883_rule - RHEL 8 must disable core dump backtraces.
rhel8 · medium (CAT II)
stig://rule/SV-230315r1134883_rule
SV-230316r1044801_rule - For RHEL 8 systems using Domain Name Servers (DNS) resolution, at least two name servers must be configured.
rhel8 · medium (CAT II)
stig://rule/SV-230316r1044801_rule
SV-230317r1069320_rule - Executable search paths within the initialization files of all local interactive RHEL 8 users must only contain paths that resolve to the system default or the users home directory.
rhel8 · medium (CAT II)
stig://rule/SV-230317r1069320_rule
SV-230318r1017129_rule - All RHEL 8 world-writable directories must be owned by root, sys, bin, or an application user.
rhel8 · medium (CAT II)
stig://rule/SV-230318r1017129_rule
SV-230319r1017130_rule - All RHEL 8 world-writable directories must be group-owned by root, sys, bin, or an application group.
rhel8 · medium (CAT II)
stig://rule/SV-230319r1017130_rule
SV-230320r1017131_rule - All RHEL 8 local interactive users must have a home directory assigned in the /etc/passwd file.
rhel8 · medium (CAT II)
stig://rule/SV-230320r1017131_rule
SV-230321r1017132_rule - All RHEL 8 local interactive user home directories must have mode 0750 or less permissive.
rhel8 · medium (CAT II)
stig://rule/SV-230321r1017132_rule
SV-230322r1017133_rule - All RHEL 8 local interactive user home directories must be group-owned by the home directory owner’s primary group.
rhel8 · medium (CAT II)
stig://rule/SV-230322r1017133_rule
SV-230323r1017134_rule - All RHEL 8 local interactive user home directories defined in the /etc/passwd file must exist.
rhel8 · medium (CAT II)
stig://rule/SV-230323r1017134_rule
SV-230324r1017135_rule - All RHEL 8 local interactive user accounts must be assigned a home directory upon creation.
rhel8 · medium (CAT II)
stig://rule/SV-230324r1017135_rule
SV-230325r1017136_rule - All RHEL 8 local initialization files must have mode 0740 or less permissive.
rhel8 · medium (CAT II)
stig://rule/SV-230325r1017136_rule
SV-230326r1069284_rule - All RHEL 8 local files and directories must have a valid owner.
rhel8 · medium (CAT II)
stig://rule/SV-230326r1069284_rule
SV-230327r1069285_rule - All RHEL 8 local files and directories must have a valid group owner.
rhel8 · medium (CAT II)
stig://rule/SV-230327r1069285_rule
SV-230328r1017139_rule - A separate RHEL 8 filesystem must be used for user home directories (such as /home or an equivalent).
rhel8 · medium (CAT II)
stig://rule/SV-230328r1017139_rule
SV-230329r1017140_rule - Unattended or automatic logon via the RHEL 8 graphical user interface must not be allowed.
rhel8 · high (CAT I)
stig://rule/SV-230329r1017140_rule
SV-230330r1069305_rule - RHEL 8 must not allow users to override SSH environment variables.
rhel8 · medium (CAT II)
stig://rule/SV-230330r1069305_rule
SV-230332r1017144_rule - RHEL 8 must automatically lock an account when three unsuccessful logon attempts occur.
rhel8 · medium (CAT II)
stig://rule/SV-230332r1017144_rule
SV-230333r1017145_rule - RHEL 8 must automatically lock an account when three unsuccessful logon attempts occur.
rhel8 · medium (CAT II)
stig://rule/SV-230333r1017145_rule
SV-230334r1017146_rule - RHEL 8 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period.
rhel8 · medium (CAT II)
stig://rule/SV-230334r1017146_rule
SV-230335r1017147_rule - RHEL 8 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period.
rhel8 · medium (CAT II)
stig://rule/SV-230335r1017147_rule
SV-230336r1017148_rule - RHEL 8 must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.
rhel8 · medium (CAT II)
stig://rule/SV-230336r1017148_rule
SV-230337r1134885_rule - RHEL 8 must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.
rhel8 · medium (CAT II)
stig://rule/SV-230337r1134885_rule
SV-230338r1017150_rule - RHEL 8 must ensure account lockouts persist.
rhel8 · medium (CAT II)
stig://rule/SV-230338r1017150_rule
SV-230339r1017151_rule - RHEL 8 must ensure account lockouts persist.
rhel8 · medium (CAT II)
stig://rule/SV-230339r1017151_rule
SV-230340r1017152_rule - RHEL 8 must prevent system messages from being presented when three unsuccessful logon attempts occur.
rhel8 · medium (CAT II)
stig://rule/SV-230340r1017152_rule
SV-230341r1017153_rule - RHEL 8 must prevent system messages from being presented when three unsuccessful logon attempts occur.
rhel8 · medium (CAT II)
stig://rule/SV-230341r1017153_rule
SV-230342r1017154_rule - RHEL 8 must log user name information when unsuccessful logon attempts occur.
rhel8 · medium (CAT II)
stig://rule/SV-230342r1017154_rule
SV-230343r1017155_rule - RHEL 8 must log user name information when unsuccessful logon attempts occur.
rhel8 · medium (CAT II)
stig://rule/SV-230343r1017155_rule
SV-230344r1017156_rule - RHEL 8 must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.
rhel8 · medium (CAT II)
stig://rule/SV-230344r1017156_rule
SV-230345r1017157_rule - RHEL 8 must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.
rhel8 · medium (CAT II)
stig://rule/SV-230345r1017157_rule
SV-230346r1069306_rule - RHEL 8 must limit the number of concurrent sessions to ten for all accounts and/or account types.
rhel8 · low (CAT III)
stig://rule/SV-230346r1069306_rule
SV-230347r1017160_rule - RHEL 8 must enable a user session lock until that user re-establishes access using established identification and authentication procedures for graphical user sessions.
rhel8 · medium (CAT II)
stig://rule/SV-230347r1017160_rule
SV-230351r1017164_rule - RHEL 8 must be able to initiate directly a session lock for all connection types using smartcard when the smartcard is removed.
rhel8 · medium (CAT II)
stig://rule/SV-230351r1017164_rule
SV-230352r1017165_rule - RHEL 8 must automatically lock graphical user sessions after 15 minutes of inactivity.
rhel8 · medium (CAT II)
stig://rule/SV-230352r1017165_rule
SV-230354r1069323_rule - RHEL 8 must prevent a user from overriding the session lock-delay setting for the graphical user interface.
rhel8 · medium (CAT II)
stig://rule/SV-230354r1069323_rule
SV-230355r1017168_rule - RHEL 8 must map the authenticated identity to the user or group account for PKI-based authentication.
rhel8 · medium (CAT II)
stig://rule/SV-230355r1017168_rule
SV-230356r982195_rule - RHEL 8 must ensure the password complexity module is enabled in the password-auth file.
rhel8 · medium (CAT II)
stig://rule/SV-230356r982195_rule
SV-230357r1017169_rule - RHEL 8 must enforce password complexity by requiring that at least one uppercase character be used.
rhel8 · medium (CAT II)
stig://rule/SV-230357r1017169_rule
SV-230358r1017170_rule - RHEL 8 must enforce password complexity by requiring that at least one lower-case character be used.
rhel8 · medium (CAT II)
stig://rule/SV-230358r1017170_rule
SV-230359r1017171_rule - RHEL 8 must enforce password complexity by requiring that at least one numeric character be used.
rhel8 · medium (CAT II)
stig://rule/SV-230359r1017171_rule
SV-230360r1017172_rule - RHEL 8 must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed.
rhel8 · medium (CAT II)
stig://rule/SV-230360r1017172_rule
SV-230361r1017173_rule - RHEL 8 must require the maximum number of repeating characters be limited to three when passwords are changed.
rhel8 · medium (CAT II)
stig://rule/SV-230361r1017173_rule
SV-230362r1017174_rule - RHEL 8 must require the change of at least four character classes when passwords are changed.
rhel8 · medium (CAT II)
stig://rule/SV-230362r1017174_rule
SV-230363r1017175_rule - RHEL 8 must require the change of at least 8 characters when passwords are changed.
rhel8 · medium (CAT II)
stig://rule/SV-230363r1017175_rule
SV-230364r1017176_rule - RHEL 8 passwords must have a 24 hours/1 day minimum password lifetime restriction in /etc/shadow.
rhel8 · medium (CAT II)
stig://rule/SV-230364r1017176_rule
SV-230365r1017177_rule - RHEL 8 passwords for new users or password changes must have a 24 hours/1 day minimum password lifetime restriction in /etc/login.defs.
rhel8 · medium (CAT II)
stig://rule/SV-230365r1017177_rule
SV-230366r1038967_rule - RHEL 8 user account passwords must have a 60-day maximum password lifetime restriction.
rhel8 · medium (CAT II)
stig://rule/SV-230366r1038967_rule
SV-230367r1038967_rule - RHEL 8 user account passwords must be configured so that existing passwords are restricted to a 60-day maximum lifetime.
rhel8 · medium (CAT II)
stig://rule/SV-230367r1038967_rule
SV-230369r1017181_rule - RHEL 8 passwords must have a minimum of 15 characters.
rhel8 · medium (CAT II)
stig://rule/SV-230369r1017181_rule
SV-230370r1017182_rule - RHEL 8 passwords for new users must have a minimum of 15 characters.
rhel8 · medium (CAT II)
stig://rule/SV-230370r1017182_rule
SV-230371r1017183_rule - RHEL 8 duplicate User IDs (UIDs) must not exist for interactive users.
rhel8 · medium (CAT II)
stig://rule/SV-230371r1017183_rule
SV-230372r1017184_rule - RHEL 8 must implement smart card logon for multifactor authentication for access to interactive accounts.
rhel8 · medium (CAT II)
stig://rule/SV-230372r1017184_rule
SV-230373r1017185_rule - RHEL 8 account identifiers (individuals, groups, roles, and devices) must be disabled after 35 days of inactivity.
rhel8 · medium (CAT II)
stig://rule/SV-230373r1017185_rule
SV-230374r1069293_rule - RHEL 8 must automatically expire temporary accounts within 72 hours.
rhel8 · medium (CAT II)
stig://rule/SV-230374r1069293_rule
SV-230375r1017187_rule - All RHEL 8 passwords must contain at least one special character.
rhel8 · medium (CAT II)
stig://rule/SV-230375r1017187_rule
SV-230376r1069307_rule - RHEL 8 must prohibit the use of cached authentications after one day.
rhel8 · medium (CAT II)
stig://rule/SV-230376r1069307_rule
SV-230377r1017188_rule - RHEL 8 must prevent the use of dictionary words for passwords.
rhel8 · medium (CAT II)
stig://rule/SV-230377r1017188_rule
SV-230378r1017189_rule - RHEL 8 must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
rhel8 · medium (CAT II)
stig://rule/SV-230378r1017189_rule
SV-230379r1017190_rule - RHEL 8 must not have unnecessary accounts.
rhel8 · medium (CAT II)
stig://rule/SV-230379r1017190_rule
SV-230380r1069308_rule - RHEL 8 must not allow accounts configured with blank or null passwords.
rhel8 · high (CAT I)
stig://rule/SV-230380r1069308_rule
SV-230381r1069295_rule - RHEL 8 must display the date and time of the last successful account logon upon logon.
rhel8 · low (CAT III)
stig://rule/SV-230381r1069295_rule
SV-230382r1069309_rule - RHEL 8 must display the date and time of the last successful account logon upon an SSH logon.
rhel8 · medium (CAT II)
stig://rule/SV-230382r1069309_rule
SV-230383r1017192_rule - RHEL 8 must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.
rhel8 · medium (CAT II)
stig://rule/SV-230383r1017192_rule
SV-230384r1017193_rule - RHEL 8 must set the umask value to 077 for all local interactive user accounts.
rhel8 · medium (CAT II)
stig://rule/SV-230384r1017193_rule
SV-230385r1017194_rule - RHEL 8 must define default permissions for logon and non-logon shells.
rhel8 · medium (CAT II)
stig://rule/SV-230385r1017194_rule
SV-230386r958730_rule - The RHEL 8 audit system must be configured to audit the execution of privileged functions and prevent all software from executing at higher privilege levels than users executing the software.
rhel8 · medium (CAT II)
stig://rule/SV-230386r958730_rule
SV-230387r1017195_rule - Cron logging must be implemented in RHEL 8.
rhel8 · medium (CAT II)
stig://rule/SV-230387r1017195_rule
SV-230388r1017196_rule - The RHEL 8 System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) must be alerted of an audit processing failure event.
rhel8 · medium (CAT II)
stig://rule/SV-230388r1017196_rule
SV-230389r1017197_rule - The RHEL 8 Information System Security Officer (ISSO) and System Administrator (SA) (at a minimum) must have mail aliases to be notified of an audit processing failure.
rhel8 · medium (CAT II)
stig://rule/SV-230389r1017197_rule
SV-230390r1038966_rule - The RHEL 8 System must take appropriate action when an audit processing failure occurs.
rhel8 · medium (CAT II)
stig://rule/SV-230390r1038966_rule
SV-230392r1038966_rule - The RHEL 8 audit system must take appropriate action when the audit storage volume is full.
rhel8 · medium (CAT II)
stig://rule/SV-230392r1038966_rule
SV-230393r1017200_rule - The RHEL 8 audit system must audit local events.
rhel8 · medium (CAT II)
stig://rule/SV-230393r1017200_rule
SV-230394r958754_rule - RHEL 8 must label all off-loaded audit logs before sending them to the central log server.
rhel8 · medium (CAT II)
stig://rule/SV-230394r958754_rule
SV-230395r1017201_rule - RHEL 8 must resolve audit information before writing to disk.
rhel8 · low (CAT III)
stig://rule/SV-230395r1017201_rule
SV-230396r1017202_rule - RHEL 8 audit logs must have a mode of 0600 or less permissive to prevent unauthorized read access.
rhel8 · medium (CAT II)
stig://rule/SV-230396r1017202_rule
SV-230397r1017203_rule - RHEL 8 audit logs must be owned by root to prevent unauthorized read access.
rhel8 · medium (CAT II)
stig://rule/SV-230397r1017203_rule
SV-230398r1017204_rule - RHEL 8 audit logs must be group-owned by root to prevent unauthorized read access.
rhel8 · medium (CAT II)
stig://rule/SV-230398r1017204_rule
SV-230399r1017205_rule - RHEL 8 audit log directory must be owned by root to prevent unauthorized read access.
rhel8 · medium (CAT II)
stig://rule/SV-230399r1017205_rule
SV-230400r1017206_rule - RHEL 8 audit log directory must be group-owned by root to prevent unauthorized read access.
rhel8 · medium (CAT II)
stig://rule/SV-230400r1017206_rule
SV-230401r1017207_rule - RHEL 8 audit log directory must have a mode of 0700 or less permissive to prevent unauthorized read access.
rhel8 · medium (CAT II)
stig://rule/SV-230401r1017207_rule
SV-230402r1017208_rule - RHEL 8 audit system must protect auditing rules from unauthorized change.
rhel8 · medium (CAT II)
stig://rule/SV-230402r1017208_rule
SV-230403r1017209_rule - RHEL 8 audit system must protect logon UIDs from unauthorized change.
rhel8 · medium (CAT II)
stig://rule/SV-230403r1017209_rule
SV-230404r1017210_rule - RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
rhel8 · medium (CAT II)
stig://rule/SV-230404r1017210_rule
SV-230405r1017211_rule - RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.
rhel8 · medium (CAT II)
stig://rule/SV-230405r1017211_rule
SV-230406r1017212_rule - RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
rhel8 · medium (CAT II)
stig://rule/SV-230406r1017212_rule
SV-230407r1017213_rule - RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
rhel8 · medium (CAT II)
stig://rule/SV-230407r1017213_rule
SV-230408r1017214_rule - RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
rhel8 · medium (CAT II)
stig://rule/SV-230408r1017214_rule
SV-230409r1017215_rule - RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.
rhel8 · medium (CAT II)
stig://rule/SV-230409r1017215_rule
SV-230410r1017216_rule - RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/.
rhel8 · medium (CAT II)
stig://rule/SV-230410r1017216_rule
SV-230411r1017217_rule - The RHEL 8 audit package must be installed.
rhel8 · medium (CAT II)
stig://rule/SV-230411r1017217_rule
SV-230412r1017218_rule - Successful/unsuccessful uses of the su command in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230412r1017218_rule
SV-230413r1017219_rule - The RHEL 8 audit system must be configured to audit any usage of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls.
rhel8 · medium (CAT II)
stig://rule/SV-230413r1017219_rule
SV-230418r1017220_rule - Successful/unsuccessful uses of the chage command in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230418r1017220_rule
SV-230419r1017221_rule - Successful/unsuccessful uses of the chcon command in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230419r1017221_rule
SV-230421r1017222_rule - Successful/unsuccessful uses of the ssh-agent in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230421r1017222_rule
SV-230422r1017223_rule - Successful/unsuccessful uses of the passwd command in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230422r1017223_rule
SV-230423r1017224_rule - Successful/unsuccessful uses of the mount command in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230423r1017224_rule
SV-230424r1017225_rule - Successful/unsuccessful uses of the umount command in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230424r1017225_rule
SV-230425r1017226_rule - Successful/unsuccessful uses of the mount syscall in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230425r1017226_rule
SV-230426r1017227_rule - Successful/unsuccessful uses of the unix_update in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230426r1017227_rule
SV-230427r1017228_rule - Successful/unsuccessful uses of postdrop in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230427r1017228_rule
SV-230428r1017229_rule - Successful/unsuccessful uses of postqueue in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230428r1017229_rule
SV-230429r1017230_rule - Successful/unsuccessful uses of semanage in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230429r1017230_rule
SV-230430r1017231_rule - Successful/unsuccessful uses of setfiles in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230430r1017231_rule
SV-230431r1017232_rule - Successful/unsuccessful uses of userhelper in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230431r1017232_rule
SV-230432r1017233_rule - Successful/unsuccessful uses of setsebool in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230432r1017233_rule
SV-230433r1017234_rule - Successful/unsuccessful uses of unix_chkpwd in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230433r1017234_rule
SV-230434r1017235_rule - Successful/unsuccessful uses of the ssh-keysign in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230434r1017235_rule
SV-230435r1017236_rule - Successful/unsuccessful uses of the setfacl command in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230435r1017236_rule
SV-230436r1017237_rule - Successful/unsuccessful uses of the pam_timestamp_check command in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230436r1017237_rule
SV-230437r1017238_rule - Successful/unsuccessful uses of the newgrp command in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230437r1017238_rule
SV-230438r1017241_rule - Successful/unsuccessful uses of the init_module and finit_module system calls in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230438r1017241_rule
SV-230439r1017243_rule - Successful/unsuccessful uses of the rename, unlink, rmdir, renameat, and unlinkat system calls in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230439r1017243_rule
SV-230444r1017244_rule - Successful/unsuccessful uses of the gpasswd command in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230444r1017244_rule
SV-230446r1017245_rule - Successful/unsuccessful uses of the delete_module command in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230446r1017245_rule
SV-230447r1017246_rule - Successful/unsuccessful uses of the crontab command in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230447r1017246_rule
SV-230448r1017247_rule - Successful/unsuccessful uses of the chsh command in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230448r1017247_rule
SV-230449r1017249_rule - Successful/unsuccessful uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230449r1017249_rule
SV-230455r1017251_rule - Successful/unsuccessful uses of the chown, fchown, fchownat, and lchown system calls in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230455r1017251_rule
SV-230456r1017253_rule - Successful/unsuccessful uses of the chmod, fchmod, and fchmodat system calls in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230456r1017253_rule
SV-230462r1017254_rule - Successful/unsuccessful uses of the sudo command in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230462r1017254_rule
SV-230463r1017255_rule - Successful/unsuccessful uses of the usermod command in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230463r1017255_rule
SV-230464r1017256_rule - Successful/unsuccessful uses of the chacl command in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230464r1017256_rule
SV-230465r1017257_rule - Successful/unsuccessful uses of the kmod command in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230465r1017257_rule
SV-230466r1017258_rule - Successful/unsuccessful modifications to the faillock log file in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230466r1017258_rule
SV-230467r1017259_rule - Successful/unsuccessful modifications to the lastlog file in RHEL 8 must generate an audit record.
rhel8 · medium (CAT II)
stig://rule/SV-230467r1017259_rule
SV-230468r1017260_rule - RHEL 8 must enable auditing of processes that start prior to the audit daemon.
rhel8 · low (CAT III)
stig://rule/SV-230468r1017260_rule
SV-230469r958752_rule - RHEL 8 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.
rhel8 · low (CAT III)
stig://rule/SV-230469r958752_rule
SV-230470r1017261_rule - RHEL 8 must enable Linux audit logging for the USBGuard daemon.
rhel8 · low (CAT III)
stig://rule/SV-230470r1017261_rule
SV-230471r1069296_rule - RHEL 8 must allow only the Information System Security Manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.
rhel8 · medium (CAT II)
stig://rule/SV-230471r1069296_rule
SV-230472r1017263_rule - RHEL 8 audit tools must have a mode of 0755 or less permissive.
rhel8 · medium (CAT II)
stig://rule/SV-230472r1017263_rule
SV-230473r1017264_rule - RHEL 8 audit tools must be owned by root.
rhel8 · medium (CAT II)
stig://rule/SV-230473r1017264_rule
SV-230474r1017265_rule - RHEL 8 audit tools must be group-owned by root.
rhel8 · medium (CAT II)
stig://rule/SV-230474r1017265_rule
SV-230475r1017266_rule - RHEL 8 must use cryptographic mechanisms to protect the integrity of audit tools.
rhel8 · medium (CAT II)
stig://rule/SV-230475r1017266_rule
SV-230476r958752_rule - RHEL 8 must allocate audit record storage capacity to store at least one week of audit records, when audit records are not immediately sent to a central audit record storage facility.
rhel8 · medium (CAT II)
stig://rule/SV-230476r958752_rule
SV-230477r1017267_rule - RHEL 8 must have the packages required for offloading audit logs installed.
rhel8 · medium (CAT II)
stig://rule/SV-230477r1017267_rule
SV-230478r1017268_rule - RHEL 8 must have the packages required for encrypting offloaded audit logs installed.
rhel8 · medium (CAT II)
stig://rule/SV-230478r1017268_rule
SV-230479r958754_rule - The RHEL 8 audit records must be off-loaded onto a different system or storage media from the system being audited.
rhel8 · medium (CAT II)
stig://rule/SV-230479r958754_rule
SV-230480r958754_rule - RHEL 8 must take appropriate action when the internal event queue is full.
rhel8 · medium (CAT II)
stig://rule/SV-230480r958754_rule
SV-230481r958754_rule - RHEL 8 must encrypt the transfer of audit records off-loaded onto a different system or media from the system being audited.
rhel8 · medium (CAT II)
stig://rule/SV-230481r958754_rule
SV-230482r1069330_rule - RHEL 8 must authenticate the remote logging server for off-loading audit logs.
rhel8 · medium (CAT II)
stig://rule/SV-230482r1069330_rule
SV-230483r971542_rule - RHEL 8 must take action when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity.
rhel8 · medium (CAT II)
stig://rule/SV-230483r971542_rule
SV-230484r1038944_rule - RHEL 8 must securely compare internal information system clocks at least every 24 hours with a server synchronized to an authoritative time source, such as the United States Naval Observatory (USNO) time servers, or a time server designated for the appropriate DoD network (NIPRNet/SIPRNet), and/or the Global Positioning System (GPS).
rhel8 · medium (CAT II)
stig://rule/SV-230484r1038944_rule
SV-230485r1017269_rule - RHEL 8 must disable the chrony daemon from acting as a server.
rhel8 · low (CAT III)
stig://rule/SV-230485r1017269_rule
SV-230486r1017270_rule - RHEL 8 must disable network management of the chrony daemon.
rhel8 · low (CAT III)
stig://rule/SV-230486r1017270_rule
SV-230487r1017271_rule - RHEL 8 must not have the telnet-server package installed.
rhel8 · high (CAT I)
stig://rule/SV-230487r1017271_rule
SV-230488r1017272_rule - RHEL 8 must not have any automated bug reporting tools installed.
rhel8 · medium (CAT II)
stig://rule/SV-230488r1017272_rule
SV-230489r1017273_rule - RHEL 8 must not have the sendmail package installed.
rhel8 · medium (CAT II)
stig://rule/SV-230489r1017273_rule
SV-230491r1017274_rule - RHEL 8 must enable mitigations against processor-based vulnerabilities.
rhel8 · low (CAT III)
stig://rule/SV-230491r1017274_rule
SV-230492r1134888_rule - RHEL 8 must not install packages from the Extra Packages for Enterprise Linux (EPEL) repository.
rhel8 · high (CAT I)
stig://rule/SV-230492r1134888_rule
SV-230493r1017276_rule - RHEL 8 must cover or disable the built-in or attached camera when not in use.
rhel8 · medium (CAT II)
stig://rule/SV-230493r1017276_rule
SV-230494r1069310_rule - RHEL 8 must disable the asynchronous transfer mode (ATM) protocol.
rhel8 · low (CAT III)
stig://rule/SV-230494r1069310_rule
SV-230495r1069311_rule - RHEL 8 must disable the controller area network (CAN) protocol.
rhel8 · low (CAT III)
stig://rule/SV-230495r1069311_rule
SV-230496r1069312_rule - RHEL 8 must disable the stream control transmission protocol (SCTP).
rhel8 · low (CAT III)
stig://rule/SV-230496r1069312_rule
SV-230497r1069313_rule - RHEL 8 must disable the transparent inter-process communication (TIPC) protocol.
rhel8 · low (CAT III)
stig://rule/SV-230497r1069313_rule
SV-230498r1069314_rule - RHEL 8 must disable mounting of cramfs.
rhel8 · low (CAT III)
stig://rule/SV-230498r1069314_rule
SV-230499r1069315_rule - RHEL 8 must disable IEEE 1394 (FireWire) Support.
rhel8 · low (CAT III)
stig://rule/SV-230499r1069315_rule
SV-230500r1101900_rule - RHEL 8 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.
rhel8 · medium (CAT II)
stig://rule/SV-230500r1101900_rule
SV-230502r1017284_rule - The RHEL 8 file system automounter must be disabled unless required.
rhel8 · medium (CAT II)
stig://rule/SV-230502r1017284_rule
SV-230503r1069316_rule - RHEL 8 must be configured to disable USB mass storage.
rhel8 · medium (CAT II)
stig://rule/SV-230503r1069316_rule
SV-230504r958672_rule - A RHEL 8 firewall must employ a deny-all, allow-by-exception policy for allowing connections to other systems.
rhel8 · medium (CAT II)
stig://rule/SV-230504r958672_rule
SV-230505r958672_rule - A firewall must be installed on RHEL 8.
rhel8 · medium (CAT II)
stig://rule/SV-230505r958672_rule
SV-230506r1017286_rule - RHEL 8 wireless network adapters must be disabled.
rhel8 · medium (CAT II)
stig://rule/SV-230506r1017286_rule
SV-230507r1017287_rule - RHEL 8 Bluetooth must be disabled.
rhel8 · medium (CAT II)
stig://rule/SV-230507r1017287_rule
SV-230508r958804_rule - RHEL 8 must mount /dev/shm with the nodev option.
rhel8 · medium (CAT II)
stig://rule/SV-230508r958804_rule
SV-230509r958804_rule - RHEL 8 must mount /dev/shm with the nosuid option.
rhel8 · medium (CAT II)
stig://rule/SV-230509r958804_rule
SV-230510r958804_rule - RHEL 8 must mount /dev/shm with the noexec option.
rhel8 · medium (CAT II)
stig://rule/SV-230510r958804_rule
SV-230511r958804_rule - RHEL 8 must mount /tmp with the nodev option.
rhel8 · medium (CAT II)
stig://rule/SV-230511r958804_rule
SV-230512r958804_rule - RHEL 8 must mount /tmp with the nosuid option.
rhel8 · medium (CAT II)
stig://rule/SV-230512r958804_rule
SV-230513r958804_rule - RHEL 8 must mount /tmp with the noexec option.
rhel8 · medium (CAT II)
stig://rule/SV-230513r958804_rule
SV-230514r958804_rule - RHEL 8 must mount /var/log with the nodev option.
rhel8 · medium (CAT II)
stig://rule/SV-230514r958804_rule
SV-230515r958804_rule - RHEL 8 must mount /var/log with the nosuid option.
rhel8 · medium (CAT II)
stig://rule/SV-230515r958804_rule
SV-230516r958804_rule - RHEL 8 must mount /var/log with the noexec option.
rhel8 · medium (CAT II)
stig://rule/SV-230516r958804_rule
SV-230517r958804_rule - RHEL 8 must mount /var/log/audit with the nodev option.
rhel8 · medium (CAT II)
stig://rule/SV-230517r958804_rule
SV-230518r958804_rule - RHEL 8 must mount /var/log/audit with the nosuid option.
rhel8 · medium (CAT II)
stig://rule/SV-230518r958804_rule
SV-230519r958804_rule - RHEL 8 must mount /var/log/audit with the noexec option.
rhel8 · medium (CAT II)
stig://rule/SV-230519r958804_rule
SV-230520r958804_rule - RHEL 8 must mount /var/tmp with the nodev option.
rhel8 · medium (CAT II)
stig://rule/SV-230520r958804_rule
SV-230521r958804_rule - RHEL 8 must mount /var/tmp with the nosuid option.
rhel8 · medium (CAT II)
stig://rule/SV-230521r958804_rule
SV-230522r958804_rule - RHEL 8 must mount /var/tmp with the noexec option.
rhel8 · medium (CAT II)
stig://rule/SV-230522r958804_rule
SV-230523r958804_rule - The RHEL 8 fapolicy module must be installed.
rhel8 · medium (CAT II)
stig://rule/SV-230523r958804_rule
SV-230524r1014813_rule - RHEL 8 must block unauthorized peripherals before establishing a connection.
rhel8 · medium (CAT II)
stig://rule/SV-230524r1014813_rule
SV-230525r958902_rule - A firewall must be able to protect against or limit the effects of Denial of Service (DoS) attacks by ensuring RHEL 8 can implement rate-limiting measures on impacted network interfaces.
rhel8 · medium (CAT II)
stig://rule/SV-230525r958902_rule
SV-230526r958908_rule - All RHEL 8 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
rhel8 · medium (CAT II)
stig://rule/SV-230526r958908_rule
SV-230527r1017288_rule - RHEL 8 must force a frequent session key renegotiation for SSH connections to the server.
rhel8 · medium (CAT II)
stig://rule/SV-230527r1017288_rule
SV-230529r1017289_rule - The x86 Ctrl-Alt-Delete key sequence must be disabled on RHEL 8.
rhel8 · high (CAT I)
stig://rule/SV-230529r1017289_rule
SV-230530r1069317_rule - The x86 Ctrl-Alt-Delete key sequence in RHEL 8 must be disabled if a graphical user interface is installed.
rhel8 · high (CAT I)
stig://rule/SV-230530r1069317_rule
SV-230531r1134890_rule - The systemd Ctrl-Alt-Delete burst key sequence in RHEL 8 must be disabled.
rhel8 · high (CAT I)
stig://rule/SV-230531r1134890_rule
SV-230532r1017294_rule - The debug-shell systemd service must be disabled on RHEL 8.
rhel8 · medium (CAT II)
stig://rule/SV-230532r1017294_rule
SV-230533r1017295_rule - The Trivial File Transfer Protocol (TFTP) server package must not be installed if not required for RHEL 8 operational support.
rhel8 · high (CAT I)
stig://rule/SV-230533r1017295_rule
SV-230534r1017296_rule - The root account must be the only account having unrestricted access to the RHEL 8 system.
rhel8 · high (CAT I)
stig://rule/SV-230534r1017296_rule
SV-230535r1017297_rule - RHEL 8 must prevent IPv6 Internet Control Message Protocol (ICMP) redirect messages from being accepted.
rhel8 · medium (CAT II)
stig://rule/SV-230535r1017297_rule
SV-230536r1017298_rule - RHEL 8 must not send Internet Control Message Protocol (ICMP) redirects.
rhel8 · medium (CAT II)
stig://rule/SV-230536r1017298_rule
SV-230537r1017299_rule - RHEL 8 must not respond to Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.
rhel8 · medium (CAT II)
stig://rule/SV-230537r1017299_rule
SV-230538r1017300_rule - RHEL 8 must not forward IPv6 source-routed packets.
rhel8 · medium (CAT II)
stig://rule/SV-230538r1017300_rule
SV-230539r1017301_rule - RHEL 8 must not forward IPv6 source-routed packets by default.
rhel8 · medium (CAT II)
stig://rule/SV-230539r1017301_rule
SV-230540r1017302_rule - RHEL 8 must not enable IPv6 packet forwarding unless the system is a router.
rhel8 · medium (CAT II)
stig://rule/SV-230540r1017302_rule
SV-230541r1017303_rule - RHEL 8 must not accept router advertisements on all IPv6 interfaces.
rhel8 · medium (CAT II)
stig://rule/SV-230541r1017303_rule
SV-230542r1017304_rule - RHEL 8 must not accept router advertisements on all IPv6 interfaces by default.
rhel8 · medium (CAT II)
stig://rule/SV-230542r1017304_rule
SV-230543r1017305_rule - RHEL 8 must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default.
rhel8 · medium (CAT II)
stig://rule/SV-230543r1017305_rule
SV-230544r1017306_rule - RHEL 8 must ignore IPv6 Internet Control Message Protocol (ICMP) redirect messages.
rhel8 · medium (CAT II)
stig://rule/SV-230544r1017306_rule
SV-230545r1017307_rule - RHEL 8 must disable access to network bpf syscall from unprivileged processes.
rhel8 · medium (CAT II)
stig://rule/SV-230545r1017307_rule
SV-230546r1017308_rule - RHEL 8 must restrict usage of ptrace to descendant processes.
rhel8 · medium (CAT II)
stig://rule/SV-230546r1017308_rule
SV-230547r1017309_rule - RHEL 8 must restrict exposed kernel pointer addresses access.
rhel8 · medium (CAT II)
stig://rule/SV-230547r1017309_rule
SV-230548r1017310_rule - RHEL 8 must disable the use of user namespaces.
rhel8 · medium (CAT II)
stig://rule/SV-230548r1017310_rule
SV-230549r1017311_rule - RHEL 8 must use reverse path filtering on all IPv4 interfaces.
rhel8 · medium (CAT II)
stig://rule/SV-230549r1017311_rule
SV-230550r1017312_rule - RHEL 8 must be configured to prevent unrestricted mail relaying.
rhel8 · medium (CAT II)
stig://rule/SV-230550r1017312_rule
SV-230551r1017313_rule - The RHEL 8 file integrity tool must be configured to verify extended attributes.
rhel8 · low (CAT III)
stig://rule/SV-230551r1017313_rule
SV-230552r1101902_rule - The RHEL 8 file integrity tool must be configured to verify Access Control Lists (ACLs).
rhel8 · low (CAT III)
stig://rule/SV-230552r1101902_rule
SV-230553r1017315_rule - The graphical display manager must not be installed on RHEL 8 unless approved.
rhel8 · medium (CAT II)
stig://rule/SV-230553r1017315_rule
SV-230554r1017316_rule - RHEL 8 network interfaces must not be in promiscuous mode.
rhel8 · medium (CAT II)
stig://rule/SV-230554r1017316_rule
SV-230555r1017317_rule - RHEL 8 remote X connections for interactive users must be disabled unless to fulfill documented and validated mission requirements.
rhel8 · medium (CAT II)
stig://rule/SV-230555r1017317_rule
SV-230556r1017318_rule - The RHEL 8 SSH daemon must prevent remote hosts from connecting to the proxy display.
rhel8 · medium (CAT II)
stig://rule/SV-230556r1017318_rule
SV-230557r1088855_rule - If the Trivial File Transfer Protocol (TFTP) server is required, the RHEL 8 TFTP daemon must be configured to operate in secure mode.
rhel8 · medium (CAT II)
stig://rule/SV-230557r1088855_rule
SV-230558r1017320_rule - A File Transfer Protocol (FTP) server package must not be installed unless mission essential on RHEL 8.
rhel8 · high (CAT I)
stig://rule/SV-230558r1017320_rule
SV-230559r1014820_rule - The gssproxy package must not be installed unless mission essential on RHEL 8.
rhel8 · medium (CAT II)
stig://rule/SV-230559r1014820_rule
SV-230560r1017321_rule - The iprutils package must not be installed unless mission essential on RHEL 8.
rhel8 · medium (CAT II)
stig://rule/SV-230560r1017321_rule
SV-230561r1017322_rule - The tuned package must not be installed unless mission essential on RHEL 8.
rhel8 · medium (CAT II)
stig://rule/SV-230561r1017322_rule
SV-237640r1017323_rule - The krb5-server package must not be installed on RHEL 8.
rhel8 · medium (CAT II)
stig://rule/SV-237640r1017323_rule
SV-237641r1101904_rule - RHEL 8 must restrict privilege elevation to authorized personnel.
rhel8 · medium (CAT II)
stig://rule/SV-237641r1101904_rule
SV-237642r991589_rule - RHEL 8 must use the invoking user's password for privilege escalation when using "sudo".
rhel8 · medium (CAT II)
stig://rule/SV-237642r991589_rule
SV-237643r1050789_rule - RHEL 8 must require re-authentication when using the "sudo" command.
rhel8 · medium (CAT II)
stig://rule/SV-237643r1050789_rule
SV-244519r1017326_rule - RHEL 8 must display a banner before granting local or remote access to the system via a graphical user logon.
rhel8 · medium (CAT II)
stig://rule/SV-244519r1017326_rule
SV-244521r1117265_rule - RHEL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must require a unique superusers name upon booting into single-user mode and maintenance.
rhel8 · medium (CAT II)
stig://rule/SV-244521r1117265_rule
SV-244522r1117265_rule - RHEL 8 operating systems booted with a BIOS must require a unique superusers name upon booting into single-user and maintenance modes.
rhel8 · medium (CAT II)
stig://rule/SV-244522r1117265_rule
SV-244523r1117265_rule - RHEL 8 operating systems must require authentication upon booting into emergency mode.
rhel8 · medium (CAT II)
stig://rule/SV-244523r1117265_rule
SV-244524r1017330_rule - The RHEL 8 pam_unix.so module must be configured in the system-auth file to use a FIPS 140-2 approved cryptographic hashing algorithm for system authentication.
rhel8 · medium (CAT II)
stig://rule/SV-244524r1017330_rule
SV-244525r1017331_rule - RHEL 8 must be configured so that all network connections associated with SSH traffic are terminated after 10 minutes of becoming unresponsive.
rhel8 · medium (CAT II)
stig://rule/SV-244525r1017331_rule
SV-244526r1017332_rule - The RHEL 8 SSH daemon must be configured to use system-wide crypto policies.
rhel8 · medium (CAT II)
stig://rule/SV-244526r1017332_rule
SV-244527r1017333_rule - RHEL 8 must have the packages required to use the hardware random number generator entropy gatherer service.
rhel8 · low (CAT III)
stig://rule/SV-244527r1017333_rule
SV-244528r1017335_rule - The RHEL 8 SSH daemon must not allow GSSAPI authentication, except to fulfill documented and validated mission requirements.
rhel8 · medium (CAT II)
stig://rule/SV-244528r1017335_rule
SV-244529r1017336_rule - RHEL 8 must use a separate file system for /var/tmp.
rhel8 · medium (CAT II)
stig://rule/SV-244529r1017336_rule
SV-244530r1017337_rule - RHEL 8 must prevent files with the setuid and setgid bit set from being executed on the /boot/efi directory.
rhel8 · medium (CAT II)
stig://rule/SV-244530r1017337_rule
SV-244531r1017338_rule - All RHEL 8 local interactive user home directory files must have mode 0750 or less permissive.
rhel8 · medium (CAT II)
stig://rule/SV-244531r1017338_rule
SV-244532r1101906_rule - RHEL 8 must be configured so that all files and directories contained in local interactive user home directories are group-owned by a group of which the home directory owner is a member.
rhel8 · medium (CAT II)
stig://rule/SV-244532r1101906_rule
SV-244533r1069318_rule - RHEL 8 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file.
rhel8 · medium (CAT II)
stig://rule/SV-244533r1069318_rule
SV-244534r1069319_rule - RHEL 8 must configure the use of the pam_faillock.so module in the /etc/pam.d/password-auth file.
rhel8 · medium (CAT II)
stig://rule/SV-244534r1069319_rule
SV-244535r1017342_rule - RHEL 8 must initiate a session lock for graphical user interfaces when the screensaver is activated.
rhel8 · medium (CAT II)
stig://rule/SV-244535r1017342_rule
SV-244536r1017343_rule - RHEL 8 must disable the user list at logon for graphical user interfaces.
rhel8 · medium (CAT II)
stig://rule/SV-244536r1017343_rule
SV-244538r1069324_rule - RHEL 8 must prevent a user from overriding the session idle-delay setting for the graphical user interface.
rhel8 · medium (CAT II)
stig://rule/SV-244538r1069324_rule
SV-244539r1069325_rule - RHEL 8 must prevent a user from overriding the screensaver lock-enabled setting for the graphical user interface.
rhel8 · medium (CAT II)
stig://rule/SV-244539r1069325_rule
SV-244541r1017347_rule - RHEL 8 must not allow blank or null passwords in the password-auth file.
rhel8 · high (CAT I)
stig://rule/SV-244541r1017347_rule
SV-244542r1017348_rule - RHEL 8 audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.
rhel8 · medium (CAT II)
stig://rule/SV-244542r1017348_rule
SV-244543r971542_rule - RHEL 8 must notify the System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) when allocated audit record storage volume 75 percent utilization.
rhel8 · medium (CAT II)
stig://rule/SV-244543r971542_rule
SV-244544r958672_rule - A firewall must be active on RHEL 8.
rhel8 · medium (CAT II)
stig://rule/SV-244544r958672_rule
SV-244545r958804_rule - The RHEL 8 fapolicy module must be enabled.
rhel8 · medium (CAT II)
stig://rule/SV-244545r958804_rule
SV-244546r1017349_rule - The RHEL 8 fapolicy module must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
rhel8 · medium (CAT II)
stig://rule/SV-244546r1017349_rule
SV-244547r1014811_rule - RHEL 8 must have the USBGuard installed.
rhel8 · medium (CAT II)
stig://rule/SV-244547r1014811_rule
SV-244548r1014815_rule - RHEL 8 must enable the USBGuard.
rhel8 · medium (CAT II)
stig://rule/SV-244548r1014815_rule
SV-244549r958908_rule - All RHEL 8 networked systems must have SSH installed.
rhel8 · medium (CAT II)
stig://rule/SV-244549r958908_rule
SV-244550r1017350_rule - RHEL 8 must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted.
rhel8 · medium (CAT II)
stig://rule/SV-244550r1017350_rule
SV-244551r1017351_rule - RHEL 8 must not forward IPv4 source-routed packets.
rhel8 · medium (CAT II)
stig://rule/SV-244551r1017351_rule
SV-244552r1017352_rule - RHEL 8 must not forward IPv4 source-routed packets by default.
rhel8 · medium (CAT II)
stig://rule/SV-244552r1017352_rule
SV-244553r1017353_rule - RHEL 8 must ignore IPv4 Internet Control Message Protocol (ICMP) redirect messages.
rhel8 · medium (CAT II)
stig://rule/SV-244553r1017353_rule
SV-244554r1017354_rule - RHEL 8 must enable hardening for the Berkeley Packet Filter Just-in-time compiler.
rhel8 · medium (CAT II)
stig://rule/SV-244554r1017354_rule
SV-250315r1017356_rule - RHEL 8 systems, versions 8.2 and above, must configure SELinux context type to allow the use of a non-default faillock tally directory.
rhel8 · medium (CAT II)
stig://rule/SV-250315r1017356_rule
SV-250316r1017357_rule - RHEL 8 systems below version 8.2 must configure SELinux context type to allow the use of a non-default faillock tally directory.
rhel8 · medium (CAT II)
stig://rule/SV-250316r1017357_rule
SV-250317r1017358_rule - RHEL 8 must not enable IPv4 packet forwarding unless the system is a router.
rhel8 · medium (CAT II)
stig://rule/SV-250317r1017358_rule
SV-251706r1017359_rule - The RHEL 8 operating system must not have accounts configured with blank or null passwords.
rhel8 · high (CAT I)
stig://rule/SV-251706r1017359_rule
SV-251707r1017360_rule - RHEL 8 library directories must have mode 755 or less permissive.
rhel8 · medium (CAT II)
stig://rule/SV-251707r1017360_rule
SV-251708r1017362_rule - RHEL 8 library directories must be owned by root.
rhel8 · medium (CAT II)
stig://rule/SV-251708r1017362_rule
SV-251709r1017364_rule - RHEL 8 library directories must be group-owned by root or a system account.
rhel8 · medium (CAT II)
stig://rule/SV-251709r1017364_rule
SV-251710r958944_rule - The RHEL 8 operating system must use a file integrity tool to verify correct operation of all security functions.
rhel8 · medium (CAT II)
stig://rule/SV-251710r958944_rule
SV-251711r1017365_rule - RHEL 8 must specify the default "include" directory for the /etc/sudoers file.
rhel8 · medium (CAT II)
stig://rule/SV-251711r1017365_rule
SV-251712r1050789_rule - The RHEL 8 operating system must not be configured to bypass password requirements for privilege escalation.
rhel8 · medium (CAT II)
stig://rule/SV-251712r1050789_rule
SV-251713r1017366_rule - RHEL 8 must ensure the password complexity module is enabled in the system-auth file.
rhel8 · medium (CAT II)
stig://rule/SV-251713r1017366_rule
SV-251716r1069329_rule - RHEL 8 systems, version 8.4 and above, must ensure the password complexity module is configured for three retries or less.
rhel8 · medium (CAT II)
stig://rule/SV-251716r1069329_rule
SV-251718r1017371_rule - The graphical display manager must not be the default target on RHEL 8 unless approved.
rhel8 · medium (CAT II)
stig://rule/SV-251718r1017371_rule
SV-254520r1069331_rule - RHEL 8 must prevent nonprivileged users from executing privileged functions, including disabling, circumventing, or altering implemented security safeguards/countermeasures.
rhel8 · medium (CAT II)
stig://rule/SV-254520r1069331_rule
SV-255924r1017372_rule - RHEL 8 SSH server must be configured to use only FIPS-validated key exchange algorithms.
rhel8 · medium (CAT II)
stig://rule/SV-255924r1017372_rule
SV-256973r1017373_rule - RHEL 8 must ensure cryptographic verification of vendor software packages.
rhel8 · medium (CAT II)
stig://rule/SV-256973r1017373_rule
SV-256974r1069321_rule - RHEL 8 must be configured to allow sending email notifications of unauthorized configuration changes to designated personnel.
rhel8 · medium (CAT II)
stig://rule/SV-256974r1069321_rule
SV-257258r1069328_rule - RHEL 8.7 and higher must terminate idle user sessions.
rhel8 · medium (CAT II)
stig://rule/SV-257258r1069328_rule
SV-268322r1017568_rule - RHEL 8 must not allow blank or null passwords in the system-auth file.
rhel8 · high (CAT I)
stig://rule/SV-268322r1017568_rule
SV-272482r1069414_rule - RHEL 8 SSH client must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms.
rhel8 · medium (CAT II)
stig://rule/SV-272482r1069414_rule
SV-272483r1069415_rule - RHEL 8 SSH client must be configured to use only ciphers employing FIPS 140-3 validated cryptographic hash algorithms.
rhel8 · medium (CAT II)
stig://rule/SV-272483r1069415_rule
SV-272484r1134875_rule - RHEL 8 must elevate the SELinux context when an administrator calls the sudo command.
rhel8 · medium (CAT II)
stig://rule/SV-272484r1134875_rule
SV-274877r1106148_rule - RHEL 8 must audit any script or executable called by cron as root or by any privileged user.
rhel8 · medium (CAT II)
stig://rule/SV-274877r1106148_rule
SV-257777r991589_rule - RHEL 9 must be a vendor-supported release.
rhel9 · high (CAT I)
stig://rule/SV-257777r991589_rule
SV-257778r1134892_rule - RHEL 9 vendor packaged system security patches and updates must be installed and up to date.
rhel9 · medium (CAT II)
stig://rule/SV-257778r1134892_rule
SV-257779r958390_rule - RHEL 9 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a command line user logon.
rhel9 · medium (CAT II)
stig://rule/SV-257779r958390_rule
SV-257781r991589_rule - The graphical display manager must not be the default target on RHEL 9 unless approved.
rhel9 · medium (CAT II)
stig://rule/SV-257781r991589_rule
SV-257782r991589_rule - RHEL 9 must enable the hardware random number generator entropy gatherer service.
rhel9 · low (CAT III)
stig://rule/SV-257782r991589_rule
SV-257783r991562_rule - RHEL 9 systemd-journald service must be enabled.
rhel9 · medium (CAT II)
stig://rule/SV-257783r991562_rule
SV-257784r1044832_rule - The systemd Ctrl-Alt-Delete burst key sequence in RHEL 9 must be disabled.
rhel9 · high (CAT I)
stig://rule/SV-257784r1044832_rule
SV-257785r1044833_rule - The x86 Ctrl-Alt-Delete key sequence must be disabled on RHEL 9.
rhel9 · high (CAT I)
stig://rule/SV-257785r1044833_rule
SV-257786r1044834_rule - RHEL 9 debug-shell systemd service must be disabled.
rhel9 · medium (CAT II)
stig://rule/SV-257786r1044834_rule
SV-257787r1117265_rule - RHEL 9 must require a boot loader superuser password.
rhel9 · medium (CAT II)
stig://rule/SV-257787r1117265_rule
SV-257788r1044838_rule - RHEL 9 must disable the ability of systemd to spawn an interactive boot process.
rhel9 · medium (CAT II)
stig://rule/SV-257788r1044838_rule
SV-257789r1134895_rule - RHEL 9 must require a unique superusers name upon booting into single-user and maintenance modes.
rhel9 · high (CAT I)
stig://rule/SV-257789r1134895_rule
SV-257790r991589_rule - RHEL 9 /boot/grub2/grub.cfg file must be group-owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257790r991589_rule
SV-257791r991589_rule - RHEL 9 /boot/grub2/grub.cfg file must be owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257791r991589_rule
SV-257792r1044842_rule - RHEL 9 must disable virtual system calls.
rhel9 · medium (CAT II)
stig://rule/SV-257792r1044842_rule
SV-257793r1044843_rule - RHEL 9 must clear the page allocator to prevent use-after-free attacks.
rhel9 · medium (CAT II)
stig://rule/SV-257793r1044843_rule
SV-257794r1069362_rule - RHEL 9 must clear memory when it is freed to prevent use-after-free attacks.
rhel9 · medium (CAT II)
stig://rule/SV-257794r1069362_rule
SV-257795r1044845_rule - RHEL 9 must enable mitigations against processor-based vulnerabilities.
rhel9 · low (CAT III)
stig://rule/SV-257795r1044845_rule
SV-257796r1044847_rule - RHEL 9 must enable auditing of processes that start prior to the audit daemon.
rhel9 · low (CAT III)
stig://rule/SV-257796r1044847_rule
SV-257797r1117266_rule - RHEL 9 must restrict access to the kernel message buffer.
rhel9 · medium (CAT II)
stig://rule/SV-257797r1117266_rule
SV-257798r1117266_rule - RHEL 9 must prevent kernel profiling by nonprivileged users.
rhel9 · medium (CAT II)
stig://rule/SV-257798r1117266_rule
SV-257799r1106273_rule - RHEL 9 must prevent the loading of a new kernel for later execution.
rhel9 · medium (CAT II)
stig://rule/SV-257799r1106273_rule
SV-257800r1117266_rule - RHEL 9 must restrict exposed kernel pointer addresses access.
rhel9 · medium (CAT II)
stig://rule/SV-257800r1117266_rule
SV-257801r1106279_rule - RHEL 9 must enable kernel parameters to enforce discretionary access control on hardlinks.
rhel9 · medium (CAT II)
stig://rule/SV-257801r1106279_rule
SV-257802r1106282_rule - RHEL 9 must enable kernel parameters to enforce discretionary access control on symlinks.
rhel9 · medium (CAT II)
stig://rule/SV-257802r1106282_rule
SV-257803r1106429_rule - RHEL 9 must disable the kernel.core_pattern.
rhel9 · medium (CAT II)
stig://rule/SV-257803r1106429_rule
SV-257804r1044853_rule - RHEL 9 must be configured to disable the Asynchronous Transfer Mode kernel module.
rhel9 · medium (CAT II)
stig://rule/SV-257804r1044853_rule
SV-257805r1044856_rule - RHEL 9 must be configured to disable the Controller Area Network kernel module.
rhel9 · medium (CAT II)
stig://rule/SV-257805r1044856_rule
SV-257806r1044859_rule - RHEL 9 must be configured to disable the FireWire kernel module.
rhel9 · medium (CAT II)
stig://rule/SV-257806r1044859_rule
SV-257807r1044862_rule - RHEL 9 must disable the Stream Control Transmission Protocol (SCTP) kernel module.
rhel9 · medium (CAT II)
stig://rule/SV-257807r1044862_rule
SV-257808r1044865_rule - RHEL 9 must disable the Transparent Inter Process Communication (TIPC) kernel module.
rhel9 · medium (CAT II)
stig://rule/SV-257808r1044865_rule
SV-257809r1106288_rule - RHEL 9 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution.
rhel9 · medium (CAT II)
stig://rule/SV-257809r1106288_rule
SV-257810r1117266_rule - RHEL 9 must disable access to network bpf system call from nonprivileged processes.
rhel9 · medium (CAT II)
stig://rule/SV-257810r1117266_rule
SV-257811r1117266_rule - RHEL 9 must restrict usage of ptrace to descendant processes.
rhel9 · medium (CAT II)
stig://rule/SV-257811r1117266_rule
SV-257812r1134897_rule - RHEL 9 must disable core dump backtraces.
rhel9 · medium (CAT II)
stig://rule/SV-257812r1134897_rule
SV-257813r1134899_rule - RHEL 9 must disable storing core dumps.
rhel9 · medium (CAT II)
stig://rule/SV-257813r1134899_rule
SV-257814r1134901_rule - RHEL 9 must disable core dumps for all users.
rhel9 · medium (CAT II)
stig://rule/SV-257814r1134901_rule
SV-257815r1134903_rule - RHEL 9 must disable acquiring, saving, and processing core dumps.
rhel9 · medium (CAT II)
stig://rule/SV-257815r1134903_rule
SV-257816r1106435_rule - RHEL 9 must disable the use of user namespaces.
rhel9 · medium (CAT II)
stig://rule/SV-257816r1106435_rule
SV-257817r1069383_rule - RHEL 9 must implement nonexecutable data to protect its memory from unauthorized code execution.
rhel9 · medium (CAT II)
stig://rule/SV-257817r1069383_rule
SV-257818r1044876_rule - The kdump service on RHEL 9 must be disabled.
rhel9 · medium (CAT II)
stig://rule/SV-257818r1044876_rule
SV-257819r1015075_rule - RHEL 9 must ensure cryptographic verification of vendor software packages.
rhel9 · medium (CAT II)
stig://rule/SV-257819r1015075_rule
SV-257820r1044878_rule - RHEL 9 must check the GPG signature of software packages originating from external software repositories before installation.
rhel9 · high (CAT I)
stig://rule/SV-257820r1044878_rule
SV-257821r1015077_rule - RHEL 9 must check the GPG signature of locally installed software packages before installation.
rhel9 · high (CAT I)
stig://rule/SV-257821r1015077_rule
SV-257822r1044880_rule - RHEL 9 must have GPG signature verification enabled for all software repositories.
rhel9 · high (CAT I)
stig://rule/SV-257822r1044880_rule
SV-257823r1051231_rule - RHEL 9 must be configured so that the cryptographic hashes of system files match vendor values.
rhel9 · medium (CAT II)
stig://rule/SV-257823r1051231_rule
SV-257824r1044886_rule - RHEL 9 must remove all software components after updated versions have been installed.
rhel9 · low (CAT III)
stig://rule/SV-257824r1044886_rule
SV-257825r1044888_rule - RHEL 9 subscription-manager package must be installed.
rhel9 · medium (CAT II)
stig://rule/SV-257825r1044888_rule
SV-257826r1106299_rule - RHEL 9 must not have a File Transfer Protocol (FTP) server package installed.
rhel9 · high (CAT I)
stig://rule/SV-257826r1106299_rule
SV-257827r1044892_rule - RHEL 9 must not have the sendmail package installed.
rhel9 · medium (CAT II)
stig://rule/SV-257827r1044892_rule
SV-257828r1044894_rule - RHEL 9 must not have the nfs-utils package installed.
rhel9 · medium (CAT II)
stig://rule/SV-257828r1044894_rule
SV-257829r1044896_rule - RHEL 9 must not have the ypserv package installed.
rhel9 · medium (CAT II)
stig://rule/SV-257829r1044896_rule
SV-257830r1134906_rule - RHEL 9 must not install packages from the Extra Packages for Enterprise Linux (EPEL) repository.
rhel9 · medium (CAT II)
stig://rule/SV-257830r1134906_rule
SV-257831r1044898_rule - RHEL 9 must not have the telnet-server package installed.
rhel9 · medium (CAT II)
stig://rule/SV-257831r1044898_rule
SV-257832r1044900_rule - RHEL 9 must not have the gssproxy package installed.
rhel9 · medium (CAT II)
stig://rule/SV-257832r1044900_rule
SV-257833r1044902_rule - RHEL 9 must not have the iprutils package installed.
rhel9 · medium (CAT II)
stig://rule/SV-257833r1044902_rule
SV-257834r1044904_rule - RHEL 9 must not have the tuned package installed.
rhel9 · medium (CAT II)
stig://rule/SV-257834r1044904_rule
SV-257835r1102037_rule - RHEL 9 must not have a Trivial File Transfer Protocol (TFTP) server package installed.
rhel9 · high (CAT I)
stig://rule/SV-257835r1102037_rule
SV-257836r1044908_rule - RHEL 9 must not have the quagga package installed.
rhel9 · medium (CAT II)
stig://rule/SV-257836r1044908_rule
SV-257837r1044910_rule - A graphical display manager must not be installed on RHEL 9 unless approved.
rhel9 · medium (CAT II)
stig://rule/SV-257837r1044910_rule
SV-257838r1044912_rule - RHEL 9 must have the openssl-pkcs11 package installed.
rhel9 · medium (CAT II)
stig://rule/SV-257838r1044912_rule
SV-257839r991589_rule - RHEL 9 must have the gnutls-utils package installed.
rhel9 · medium (CAT II)
stig://rule/SV-257839r991589_rule
SV-257840r991589_rule - RHEL 9 must have the nss-tools package installed.
rhel9 · medium (CAT II)
stig://rule/SV-257840r991589_rule
SV-257841r1044914_rule - RHEL 9 must have the rng-tools package installed.
rhel9 · medium (CAT II)
stig://rule/SV-257841r1044914_rule
SV-257842r1044916_rule - RHEL 9 must have the s-nail package installed.
rhel9 · medium (CAT II)
stig://rule/SV-257842r1044916_rule
SV-257843r991589_rule - A separate RHEL 9 file system must be used for user home directories (such as /home or an equivalent).
rhel9 · medium (CAT II)
stig://rule/SV-257843r991589_rule
SV-257844r1044918_rule - RHEL 9 must use a separate file system for /tmp.
rhel9 · medium (CAT II)
stig://rule/SV-257844r1044918_rule
SV-257845r1044920_rule - RHEL 9 must use a separate file system for /var.
rhel9 · low (CAT III)
stig://rule/SV-257845r1044920_rule
SV-257846r1044922_rule - RHEL 9 must use a separate file system for /var/log.
rhel9 · low (CAT III)
stig://rule/SV-257846r1044922_rule
SV-257847r1044924_rule - RHEL 9 must use a separate file system for the system audit data path.
rhel9 · low (CAT III)
stig://rule/SV-257847r1044924_rule
SV-257848r1044926_rule - RHEL 9 must use a separate file system for /var/tmp.
rhel9 · medium (CAT II)
stig://rule/SV-257848r1044926_rule
SV-257849r1044928_rule - RHEL 9 file system automount function must be disabled unless required.
rhel9 · medium (CAT II)
stig://rule/SV-257849r1044928_rule
SV-257850r1044930_rule - RHEL 9 must prevent device files from being interpreted on file systems that contain user home directories.
rhel9 · medium (CAT II)
stig://rule/SV-257850r1044930_rule
SV-257851r1044932_rule - RHEL 9 must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories.
rhel9 · medium (CAT II)
stig://rule/SV-257851r1044932_rule
SV-257852r991589_rule - RHEL 9 must prevent code from being executed on file systems that contain user home directories.
rhel9 · medium (CAT II)
stig://rule/SV-257852r991589_rule
SV-257854r1044934_rule - RHEL 9 must prevent special devices on file systems that are imported via Network File System (NFS).
rhel9 · medium (CAT II)
stig://rule/SV-257854r1044934_rule
SV-257855r1044936_rule - RHEL 9 must prevent code from being executed on file systems that are imported via Network File System (NFS).
rhel9 · medium (CAT II)
stig://rule/SV-257855r1044936_rule
SV-257856r1044938_rule - RHEL 9 must prevent files with the setuid and setgid bit set from being executed on file systems that are imported via Network File System (NFS).
rhel9 · medium (CAT II)
stig://rule/SV-257856r1044938_rule
SV-257857r991589_rule - RHEL 9 must prevent code from being executed on file systems that are used with removable media.
rhel9 · medium (CAT II)
stig://rule/SV-257857r991589_rule
SV-257858r991589_rule - RHEL 9 must prevent special devices on file systems that are used with removable media.
rhel9 · medium (CAT II)
stig://rule/SV-257858r991589_rule
SV-257859r991589_rule - RHEL 9 must prevent files with the setuid and setgid bit set from being executed on file systems that are used with removable media.
rhel9 · medium (CAT II)
stig://rule/SV-257859r991589_rule
SV-257860r1044940_rule - RHEL 9 must mount /boot with the nodev option.
rhel9 · medium (CAT II)
stig://rule/SV-257860r1044940_rule
SV-257861r1044941_rule - RHEL 9 must prevent files with the setuid and setgid bit set from being executed on the /boot directory.
rhel9 · medium (CAT II)
stig://rule/SV-257861r1044941_rule
SV-257862r1134908_rule - RHEL 9 must prevent files with the setuid and setgid bit set from being executed on the /boot/efi directory.
rhel9 · medium (CAT II)
stig://rule/SV-257862r1134908_rule
SV-257863r958804_rule - RHEL 9 must mount /dev/shm with the nodev option.
rhel9 · medium (CAT II)
stig://rule/SV-257863r958804_rule
SV-257864r1106304_rule - RHEL 9 must mount /dev/shm with the noexec option.
rhel9 · medium (CAT II)
stig://rule/SV-257864r1106304_rule
SV-257865r1044946_rule - RHEL 9 must mount /dev/shm with the nosuid option.
rhel9 · medium (CAT II)
stig://rule/SV-257865r1044946_rule
SV-257866r958804_rule - RHEL 9 must mount /tmp with the nodev option.
rhel9 · medium (CAT II)
stig://rule/SV-257866r958804_rule
SV-257867r958804_rule - RHEL 9 must mount /tmp with the noexec option.
rhel9 · medium (CAT II)
stig://rule/SV-257867r958804_rule
SV-257868r958804_rule - RHEL 9 must mount /tmp with the nosuid option.
rhel9 · medium (CAT II)
stig://rule/SV-257868r958804_rule
SV-257869r1102009_rule - RHEL 9 must mount /var with the nodev option.
rhel9 · medium (CAT II)
stig://rule/SV-257869r1102009_rule
SV-257870r958804_rule - RHEL 9 must mount /var/log with the nodev option.
rhel9 · medium (CAT II)
stig://rule/SV-257870r958804_rule
SV-257871r958804_rule - RHEL 9 must mount /var/log with the noexec option.
rhel9 · medium (CAT II)
stig://rule/SV-257871r958804_rule
SV-257872r958804_rule - RHEL 9 must mount /var/log with the nosuid option.
rhel9 · medium (CAT II)
stig://rule/SV-257872r958804_rule
SV-257873r958804_rule - RHEL 9 must mount /var/log/audit with the nodev option.
rhel9 · medium (CAT II)
stig://rule/SV-257873r958804_rule
SV-257874r958804_rule - RHEL 9 must mount /var/log/audit with the noexec option.
rhel9 · medium (CAT II)
stig://rule/SV-257874r958804_rule
SV-257875r958804_rule - RHEL 9 must mount /var/log/audit with the nosuid option.
rhel9 · medium (CAT II)
stig://rule/SV-257875r958804_rule
SV-257876r958804_rule - RHEL 9 must mount /var/tmp with the nodev option.
rhel9 · medium (CAT II)
stig://rule/SV-257876r958804_rule
SV-257877r958804_rule - RHEL 9 must mount /var/tmp with the noexec option.
rhel9 · medium (CAT II)
stig://rule/SV-257877r958804_rule
SV-257878r958804_rule - RHEL 9 must mount /var/tmp with the nosuid option.
rhel9 · medium (CAT II)
stig://rule/SV-257878r958804_rule
SV-257879r1045454_rule - RHEL 9 local disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at rest protection.
rhel9 · high (CAT I)
stig://rule/SV-257879r1045454_rule
SV-257880r1044951_rule - RHEL 9 must disable mounting of cramfs.
rhel9 · low (CAT III)
stig://rule/SV-257880r1044951_rule
SV-257881r991589_rule - RHEL 9 must prevent special devices on non-root local partitions.
rhel9 · medium (CAT II)
stig://rule/SV-257881r991589_rule
SV-257882r991560_rule - RHEL 9 system commands must have mode 755 or less permissive.
rhel9 · medium (CAT II)
stig://rule/SV-257882r991560_rule
SV-257883r991560_rule - RHEL 9 library directories must have mode 755 or less permissive.
rhel9 · medium (CAT II)
stig://rule/SV-257883r991560_rule
SV-257884r1106306_rule - RHEL 9 library files must have mode 755 or less permissive.
rhel9 · medium (CAT II)
stig://rule/SV-257884r1106306_rule
SV-257885r1044953_rule - RHEL 9 /var/log directory must have mode 0755 or less permissive.
rhel9 · medium (CAT II)
stig://rule/SV-257885r1044953_rule
SV-257886r1044955_rule - RHEL 9 /var/log/messages file must have mode 0640 or less permissive.
rhel9 · medium (CAT II)
stig://rule/SV-257886r1044955_rule
SV-257887r991557_rule - RHEL 9 audit tools must have a mode of 0755 or less permissive.
rhel9 · medium (CAT II)
stig://rule/SV-257887r991557_rule
SV-257888r1134910_rule - RHEL 9 permissions of cron configuration files and directories must not be modified from the operating system defaults.
rhel9 · medium (CAT II)
stig://rule/SV-257888r1134910_rule
SV-257889r1044959_rule - All RHEL 9 local initialization files must have mode 0740 or less permissive.
rhel9 · medium (CAT II)
stig://rule/SV-257889r1044959_rule
SV-257890r1044961_rule - All RHEL 9 local interactive user home directories must have mode 0750 or less permissive.
rhel9 · medium (CAT II)
stig://rule/SV-257890r1044961_rule
SV-257891r991589_rule - RHEL 9 /etc/group file must have mode 0644 or less permissive to prevent unauthorized access.
rhel9 · medium (CAT II)
stig://rule/SV-257891r991589_rule
SV-257892r991589_rule - RHEL 9 /etc/group- file must have mode 0644 or less permissive to prevent unauthorized access.
rhel9 · medium (CAT II)
stig://rule/SV-257892r991589_rule
SV-257893r991589_rule - RHEL 9 /etc/gshadow file must have mode 0000 or less permissive to prevent unauthorized access.
rhel9 · medium (CAT II)
stig://rule/SV-257893r991589_rule
SV-257894r991589_rule - RHEL 9 /etc/gshadow- file must have mode 0000 or less permissive to prevent unauthorized access.
rhel9 · medium (CAT II)
stig://rule/SV-257894r991589_rule
SV-257895r991589_rule - RHEL 9 /etc/passwd file must have mode 0644 or less permissive to prevent unauthorized access.
rhel9 · medium (CAT II)
stig://rule/SV-257895r991589_rule
SV-257896r991589_rule - RHEL 9 /etc/passwd- file must have mode 0644 or less permissive to prevent unauthorized access.
rhel9 · medium (CAT II)
stig://rule/SV-257896r991589_rule
SV-257897r991589_rule - RHEL 9 /etc/shadow- file must have mode 0000 or less permissive to prevent unauthorized access.
rhel9 · medium (CAT II)
stig://rule/SV-257897r991589_rule
SV-257898r991589_rule - RHEL 9 /etc/group file must be owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257898r991589_rule
SV-257899r991589_rule - RHEL 9 /etc/group file must be group-owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257899r991589_rule
SV-257900r991589_rule - RHEL 9 /etc/group- file must be owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257900r991589_rule
SV-257901r991589_rule - RHEL 9 /etc/group- file must be group-owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257901r991589_rule
SV-257902r991589_rule - RHEL 9 /etc/gshadow file must be owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257902r991589_rule
SV-257903r991589_rule - RHEL 9 /etc/gshadow file must be group-owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257903r991589_rule
SV-257904r991589_rule - RHEL 9 /etc/gshadow- file must be owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257904r991589_rule
SV-257905r991589_rule - RHEL 9 /etc/gshadow- file must be group-owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257905r991589_rule
SV-257906r991589_rule - RHEL 9 /etc/passwd file must be owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257906r991589_rule
SV-257907r991589_rule - RHEL 9 /etc/passwd file must be group-owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257907r991589_rule
SV-257908r991589_rule - RHEL 9 /etc/passwd- file must be owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257908r991589_rule
SV-257909r991589_rule - RHEL 9 /etc/passwd- file must be group-owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257909r991589_rule
SV-257910r991589_rule - RHEL 9 /etc/shadow file must be owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257910r991589_rule
SV-257911r991589_rule - RHEL 9 /etc/shadow file must be group-owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257911r991589_rule
SV-257912r991589_rule - RHEL 9 /etc/shadow- file must be owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257912r991589_rule
SV-257913r991589_rule - RHEL 9 /etc/shadow- file must be group-owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257913r991589_rule
SV-257914r1044969_rule - RHEL 9 /var/log directory must be owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257914r1044969_rule
SV-257915r1044971_rule - RHEL 9 /var/log directory must be group-owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257915r1044971_rule
SV-257916r1101916_rule - RHEL 9 /var/log/messages file must be owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257916r1101916_rule
SV-257917r1101914_rule - RHEL 9 /var/log/messages file must be group-owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257917r1101914_rule
SV-257918r1044977_rule - RHEL 9 system commands must be owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257918r1044977_rule
SV-257919r1044979_rule - RHEL 9 system commands must be group-owned by root or a system account.
rhel9 · medium (CAT II)
stig://rule/SV-257919r1044979_rule
SV-257920r1101926_rule - RHEL 9 library files must be owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257920r1101926_rule
SV-257921r1106308_rule - RHEL 9 library files must be group-owned by root or a system account.
rhel9 · medium (CAT II)
stig://rule/SV-257921r1106308_rule
SV-257922r1044988_rule - RHEL 9 library directories must be owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257922r1044988_rule
SV-257923r1044991_rule - RHEL 9 library directories must be group-owned by root or a system account.
rhel9 · medium (CAT II)
stig://rule/SV-257923r1044991_rule
SV-257924r991557_rule - RHEL 9 audit tools must be owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257924r991557_rule
SV-257925r991557_rule - RHEL 9 audit tools must be group-owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257925r991557_rule
SV-257926r991589_rule - RHEL 9 cron configuration files directory must be owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257926r991589_rule
SV-257927r991589_rule - RHEL 9 cron configuration files directory must be group-owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257927r991589_rule
SV-257928r1044992_rule - All RHEL 9 world-writable directories must be owned by root, sys, bin, or an application user.
rhel9 · medium (CAT II)
stig://rule/SV-257928r1044992_rule
SV-257929r1117267_rule - A sticky bit must be set on all RHEL 9 public directories.
rhel9 · medium (CAT II)
stig://rule/SV-257929r1117267_rule
SV-257930r991589_rule - All RHEL 9 local files and directories must have a valid group owner.
rhel9 · medium (CAT II)
stig://rule/SV-257930r991589_rule
SV-257931r991589_rule - All RHEL 9 local files and directories must have a valid owner.
rhel9 · medium (CAT II)
stig://rule/SV-257931r991589_rule
SV-257932r1014838_rule - RHEL 9 must be configured so that all system device files are correctly labeled to prevent unauthorized modification.
rhel9 · medium (CAT II)
stig://rule/SV-257932r1014838_rule
SV-257934r991589_rule - RHEL 9 /etc/shadow file must have mode 0000 to prevent unauthorized access.
rhel9 · medium (CAT II)
stig://rule/SV-257934r991589_rule
SV-257935r1044994_rule - RHEL 9 must have the firewalld package installed.
rhel9 · medium (CAT II)
stig://rule/SV-257935r1044994_rule
SV-257936r1044995_rule - The firewalld service on RHEL 9 must be active.
rhel9 · medium (CAT II)
stig://rule/SV-257936r1044995_rule
SV-257937r1106310_rule - The RHEL 9 firewall must employ a deny-all, allow-by-exception policy for allowing connections to other systems.
rhel9 · medium (CAT II)
stig://rule/SV-257937r1106310_rule
SV-257939r1044997_rule - RHEL 9 must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring rate-limiting measures on impacted network interfaces are implemented.
rhel9 · medium (CAT II)
stig://rule/SV-257939r1044997_rule
SV-257940r1106312_rule - RHEL 9 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.
rhel9 · medium (CAT II)
stig://rule/SV-257940r1106312_rule
SV-257941r991589_rule - RHEL 9 network interfaces must not be in promiscuous mode.
rhel9 · medium (CAT II)
stig://rule/SV-257941r991589_rule
SV-257942r1106314_rule - RHEL 9 must enable hardening for the Berkeley Packet Filter just-in-time compiler.
rhel9 · medium (CAT II)
stig://rule/SV-257942r1106314_rule
SV-257943r1045001_rule - RHEL 9 must have the chrony package installed.
rhel9 · medium (CAT II)
stig://rule/SV-257943r1045001_rule
SV-257944r1038944_rule - RHEL 9 chronyd service must be enabled.
rhel9 · medium (CAT II)
stig://rule/SV-257944r1038944_rule
SV-257945r1038944_rule - RHEL 9 must securely compare internal information system clocks at least every 24 hours.
rhel9 · medium (CAT II)
stig://rule/SV-257945r1038944_rule
SV-257946r958480_rule - RHEL 9 must disable the chrony daemon from acting as a server.
rhel9 · low (CAT III)
stig://rule/SV-257946r958480_rule
SV-257947r958480_rule - RHEL 9 must disable network management of the chrony daemon.
rhel9 · low (CAT III)
stig://rule/SV-257947r958480_rule
SV-257948r1045004_rule - RHEL 9 systems using Domain Name Servers (DNS) resolution must have at least two name servers configured.
rhel9 · medium (CAT II)
stig://rule/SV-257948r1045004_rule
SV-257949r1134947_rule - RHEL 9 must configure a DNS processing mode in Network Manager.
rhel9 · medium (CAT II)
stig://rule/SV-257949r1134947_rule
SV-257950r1045006_rule - RHEL 9 must not have unauthorized IP tunnels configured.
rhel9 · medium (CAT II)
stig://rule/SV-257950r1045006_rule
SV-257951r1014843_rule - RHEL 9 must be configured to prevent unrestricted mail relaying.
rhel9 · medium (CAT II)
stig://rule/SV-257951r1014843_rule
SV-257953r958424_rule - RHEL 9 must forward mail from postmaster to the root account using a postfix alias.
rhel9 · medium (CAT II)
stig://rule/SV-257953r958424_rule
SV-257954r1106315_rule - RHEL 9 libreswan package must be installed.
rhel9 · medium (CAT II)
stig://rule/SV-257954r1106315_rule
SV-257955r991589_rule - There must be no shosts.equiv files on RHEL 9.
rhel9 · high (CAT I)
stig://rule/SV-257955r991589_rule
SV-257956r991589_rule - There must be no .shosts files on RHEL 9.
rhel9 · high (CAT I)
stig://rule/SV-257956r991589_rule
SV-257957r1106317_rule - RHEL 9 must be configured to use TCP syncookies.
rhel9 · medium (CAT II)
stig://rule/SV-257957r1106317_rule
SV-257958r1106319_rule - RHEL 9 must ignore Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages.
rhel9 · medium (CAT II)
stig://rule/SV-257958r1106319_rule
SV-257959r1102024_rule - RHEL 9 must not forward Internet Protocol version 4 (IPv4) source-routed packets.
rhel9 · medium (CAT II)
stig://rule/SV-257959r1102024_rule
SV-257960r1106321_rule - RHEL 9 must log IPv4 packets with impossible addresses.
rhel9 · medium (CAT II)
stig://rule/SV-257960r1106321_rule
SV-257961r1106323_rule - RHEL 9 must log IPv4 packets with impossible addresses by default.
rhel9 · medium (CAT II)
stig://rule/SV-257961r1106323_rule
SV-257962r1106437_rule - RHEL 9 must use reverse path filtering on all IPv4 interfaces.
rhel9 · medium (CAT II)
stig://rule/SV-257962r1106437_rule
SV-257963r1106328_rule - RHEL 9 must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted.
rhel9 · medium (CAT II)
stig://rule/SV-257963r1106328_rule
SV-257964r1106438_rule - RHEL 9 must not forward IPv4 source-routed packets by default.
rhel9 · medium (CAT II)
stig://rule/SV-257964r1106438_rule
SV-257965r1106333_rule - RHEL 9 must use a reverse-path filter for IPv4 network traffic when possible by default.
rhel9 · medium (CAT II)
stig://rule/SV-257965r1106333_rule
SV-257966r1106440_rule - RHEL 9 must not respond to Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.
rhel9 · medium (CAT II)
stig://rule/SV-257966r1106440_rule
SV-257967r1106337_rule - RHEL 9 must limit the number of bogus Internet Control Message Protocol (ICMP) response errors logs.
rhel9 · medium (CAT II)
stig://rule/SV-257967r1106337_rule
SV-257968r1106339_rule - RHEL 9 must not send Internet Control Message Protocol (ICMP) redirects.
rhel9 · medium (CAT II)
stig://rule/SV-257968r1106339_rule
SV-257969r991589_rule - RHEL 9 must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default.
rhel9 · medium (CAT II)
stig://rule/SV-257969r991589_rule
SV-257970r1106442_rule - RHEL 9 must not enable IPv4 packet forwarding unless the system is a router.
rhel9 · medium (CAT II)
stig://rule/SV-257970r1106442_rule
SV-257971r1106444_rule - RHEL 9 must not accept router advertisements on all IPv6 interfaces.
rhel9 · medium (CAT II)
stig://rule/SV-257971r1106444_rule
SV-257972r1106446_rule - RHEL 9 must ignore IPv6 Internet Control Message Protocol (ICMP) redirect messages.
rhel9 · medium (CAT II)
stig://rule/SV-257972r1106446_rule
SV-257973r1106448_rule - RHEL 9 must not forward IPv6 source-routed packets.
rhel9 · medium (CAT II)
stig://rule/SV-257973r1106448_rule
SV-257974r1106450_rule - RHEL 9 must not enable IPv6 packet forwarding unless the system is a router.
rhel9 · medium (CAT II)
stig://rule/SV-257974r1106450_rule
SV-257975r1106452_rule - RHEL 9 must not accept router advertisements on all IPv6 interfaces by default.
rhel9 · medium (CAT II)
stig://rule/SV-257975r1106452_rule
SV-257976r1106454_rule - RHEL 9 must prevent IPv6 Internet Control Message Protocol (ICMP) redirect messages from being accepted.
rhel9 · medium (CAT II)
stig://rule/SV-257976r1106454_rule
SV-257977r1106456_rule - RHEL 9 must not forward IPv6 source-routed packets by default.
rhel9 · medium (CAT II)
stig://rule/SV-257977r1106456_rule
SV-257978r1045013_rule - All RHEL 9 networked systems must have SSH installed.
rhel9 · medium (CAT II)
stig://rule/SV-257978r1045013_rule
SV-257979r958908_rule - All RHEL 9 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
rhel9 · medium (CAT II)
stig://rule/SV-257979r958908_rule
SV-257980r1045016_rule - RHEL 9 must have the openssh-clients package installed.
rhel9 · medium (CAT II)
stig://rule/SV-257980r1045016_rule
SV-257981r1101970_rule - RHEL 9 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a SSH logon.
rhel9 · medium (CAT II)
stig://rule/SV-257981r1101970_rule
SV-257982r1045021_rule - RHEL 9 must log SSH connection attempts and failures to the server.
rhel9 · medium (CAT II)
stig://rule/SV-257982r1045021_rule
SV-257983r1045024_rule - RHEL 9 SSHD must accept public key authentication.
rhel9 · medium (CAT II)
stig://rule/SV-257983r1045024_rule
SV-257984r1045026_rule - RHEL 9 SSHD must not allow blank passwords.
rhel9 · high (CAT I)
stig://rule/SV-257984r1045026_rule
SV-257985r1069364_rule - RHEL 9 must not permit direct logons to the root account using remote access via SSH.
rhel9 · medium (CAT II)
stig://rule/SV-257985r1069364_rule
SV-257986r1045030_rule - RHEL 9 must enable the Pluggable Authentication Module (PAM) interface for SSHD.
rhel9 · high (CAT I)
stig://rule/SV-257986r1045030_rule
SV-257989r1051240_rule - The RHEL 9 SSH server must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.
rhel9 · medium (CAT II)
stig://rule/SV-257989r1051240_rule
SV-257991r1051246_rule - The RHEL 9 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.
rhel9 · medium (CAT II)
stig://rule/SV-257991r1051246_rule
SV-257992r1045047_rule - RHEL 9 must not allow a noncertificate trusted host SSH logon to the system.
rhel9 · medium (CAT II)
stig://rule/SV-257992r1045047_rule
SV-257993r1045049_rule - RHEL 9 must not allow users to override SSH environment variables.
rhel9 · medium (CAT II)
stig://rule/SV-257993r1045049_rule
SV-257994r1045051_rule - RHEL 9 must force a frequent session key renegotiation for SSH connections to the server.
rhel9 · medium (CAT II)
stig://rule/SV-257994r1045051_rule
SV-257995r1045053_rule - RHEL 9 must be configured so that all network connections associated with SSH traffic terminate after becoming unresponsive.
rhel9 · medium (CAT II)
stig://rule/SV-257995r1045053_rule
SV-257996r1134915_rule - RHEL 9 must be configured so that all network connections associated with SSH traffic are terminated after 10 minutes of becoming unresponsive.
rhel9 · medium (CAT II)
stig://rule/SV-257996r1134915_rule
SV-257997r1069370_rule - RHEL 9 SSH server configuration file must be group-owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257997r1069370_rule
SV-257998r1082181_rule - The RHEL 9 SSH server configuration file must be owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-257998r1082181_rule
SV-257999r1134918_rule - RHEL 9 SSH server configuration files' permissions must not be modified.
rhel9 · medium (CAT II)
stig://rule/SV-257999r1134918_rule
SV-258000r1045063_rule - RHEL 9 SSH private host key files must have mode 0640 or less permissive.
rhel9 · medium (CAT II)
stig://rule/SV-258000r1045063_rule
SV-258001r991589_rule - RHEL 9 SSH public host key files must have mode 0644 or less permissive.
rhel9 · medium (CAT II)
stig://rule/SV-258001r991589_rule
SV-258002r991589_rule - RHEL 9 SSH daemon must not allow compression or must only allow compression after successful authentication.
rhel9 · medium (CAT II)
stig://rule/SV-258002r991589_rule
SV-258003r1045065_rule - RHEL 9 SSH daemon must not allow GSSAPI authentication.
rhel9 · medium (CAT II)
stig://rule/SV-258003r1045065_rule
SV-258004r1045067_rule - RHEL 9 SSH daemon must not allow Kerberos authentication.
rhel9 · medium (CAT II)
stig://rule/SV-258004r1045067_rule
SV-258005r1045069_rule - RHEL 9 SSH daemon must not allow rhosts authentication.
rhel9 · medium (CAT II)
stig://rule/SV-258005r1045069_rule
SV-258006r1045071_rule - RHEL 9 SSH daemon must not allow known hosts authentication.
rhel9 · medium (CAT II)
stig://rule/SV-258006r1045071_rule
SV-258007r1045073_rule - RHEL 9 SSH daemon must disable remote X connections for interactive users.
rhel9 · medium (CAT II)
stig://rule/SV-258007r1045073_rule
SV-258008r1045075_rule - RHEL 9 SSH daemon must perform strict mode checking of home directory configuration files.
rhel9 · medium (CAT II)
stig://rule/SV-258008r1045075_rule
SV-258009r1045077_rule - RHEL 9 SSH daemon must display the date and time of the last successful account logon upon an SSH logon.
rhel9 · medium (CAT II)
stig://rule/SV-258009r1045077_rule
SV-258011r1045079_rule - RHEL 9 SSH daemon must prevent remote hosts from connecting to the proxy display.
rhel9 · medium (CAT II)
stig://rule/SV-258011r1045079_rule
SV-258012r1014855_rule - RHEL 9 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a graphical user logon.
rhel9 · medium (CAT II)
stig://rule/SV-258012r1014855_rule
SV-258013r1045082_rule - RHEL 9 must prevent a user from overriding the banner-message-enable setting for the graphical user interface.
rhel9 · medium (CAT II)
stig://rule/SV-258013r1045082_rule
SV-258014r1045084_rule - RHEL 9 must disable the graphical user interface automount function unless required.
rhel9 · medium (CAT II)
stig://rule/SV-258014r1045084_rule
SV-258015r1045086_rule - RHEL 9 must prevent a user from overriding the disabling of the graphical user interface automount function.
rhel9 · medium (CAT II)
stig://rule/SV-258015r1045086_rule
SV-258016r958804_rule - RHEL 9 must disable the graphical user interface autorun function unless required.
rhel9 · medium (CAT II)
stig://rule/SV-258016r958804_rule
SV-258017r1045088_rule - RHEL 9 must prevent a user from overriding the disabling of the graphical user interface autorun function.
rhel9 · medium (CAT II)
stig://rule/SV-258017r1045088_rule
SV-258018r1045090_rule - RHEL 9 must not allow unattended or automatic logon via the graphical user interface.
rhel9 · high (CAT I)
stig://rule/SV-258018r1045090_rule
SV-258019r1045092_rule - RHEL 9 must be able to initiate directly a session lock for all connection types using smart card when the smart card is removed.
rhel9 · medium (CAT II)
stig://rule/SV-258019r1045092_rule
SV-258020r1045094_rule - RHEL 9 must prevent a user from overriding the disabling of the graphical user smart card removal action.
rhel9 · medium (CAT II)
stig://rule/SV-258020r1045094_rule
SV-258021r1015088_rule - RHEL 9 must enable a user session lock until that user re-establishes access using established identification and authentication procedures for graphical user sessions.
rhel9 · medium (CAT II)
stig://rule/SV-258021r1015088_rule
SV-258022r1045097_rule - RHEL 9 must prevent a user from overriding the screensaver lock-enabled setting for the graphical user interface.
rhel9 · medium (CAT II)
stig://rule/SV-258022r1045097_rule
SV-258023r958402_rule - RHEL 9 must automatically lock graphical user sessions after 15 minutes of inactivity.
rhel9 · medium (CAT II)
stig://rule/SV-258023r958402_rule
SV-258024r1045100_rule - RHEL 9 must prevent a user from overriding the session idle-delay setting for the graphical user interface.
rhel9 · medium (CAT II)
stig://rule/SV-258024r1045100_rule
SV-258025r958402_rule - RHEL 9 must initiate a session lock for graphical user interfaces when the screensaver is activated.
rhel9 · medium (CAT II)
stig://rule/SV-258025r958402_rule
SV-258026r1045103_rule - RHEL 9 must prevent a user from overriding the session lock-delay setting for the graphical user interface.
rhel9 · medium (CAT II)
stig://rule/SV-258026r1045103_rule
SV-258027r1045106_rule - RHEL 9 must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
rhel9 · medium (CAT II)
stig://rule/SV-258027r1045106_rule
SV-258028r991589_rule - RHEL 9 effective dconf policy must match the policy keyfiles.
rhel9 · medium (CAT II)
stig://rule/SV-258028r991589_rule
SV-258029r1045109_rule - RHEL 9 must disable the ability of a user to restart the system from the login screen.
rhel9 · medium (CAT II)
stig://rule/SV-258029r1045109_rule
SV-258030r1045112_rule - RHEL 9 must prevent a user from overriding the disable-restart-buttons setting for the graphical user interface.
rhel9 · medium (CAT II)
stig://rule/SV-258030r1045112_rule
SV-258031r1134920_rule - RHEL 9 must disable the ability of a user to accidentally press Ctrl-Alt-Del and cause a system to shut down or reboot.
rhel9 · medium (CAT II)
stig://rule/SV-258031r1134920_rule
SV-258032r1045117_rule - RHEL 9 must prevent a user from overriding the Ctrl-Alt-Del sequence settings for the graphical user interface.
rhel9 · medium (CAT II)
stig://rule/SV-258032r1045117_rule
SV-258033r1045120_rule - RHEL 9 must disable the user list at logon for graphical user interfaces.
rhel9 · medium (CAT II)
stig://rule/SV-258033r1045120_rule
SV-258034r1051267_rule - RHEL 9 must be configured to disable USB mass storage.
rhel9 · medium (CAT II)
stig://rule/SV-258034r1051267_rule
SV-258035r1045125_rule - RHEL 9 must have the USBGuard package installed.
rhel9 · medium (CAT II)
stig://rule/SV-258035r1045125_rule
SV-258036r1014861_rule - RHEL 9 must have the USBGuard package enabled.
rhel9 · medium (CAT II)
stig://rule/SV-258036r1014861_rule
SV-258037r1014863_rule - RHEL 9 must enable Linux audit logging for the USBGuard daemon.
rhel9 · low (CAT III)
stig://rule/SV-258037r1014863_rule
SV-258038r1045128_rule - RHEL 9 must block unauthorized peripherals before establishing a connection.
rhel9 · medium (CAT II)
stig://rule/SV-258038r1045128_rule
SV-258039r1045131_rule - RHEL 9 Bluetooth must be disabled.
rhel9 · medium (CAT II)
stig://rule/SV-258039r1045131_rule
SV-258040r991568_rule - RHEL 9 wireless network adapters must be disabled.
rhel9 · medium (CAT II)
stig://rule/SV-258040r991568_rule
SV-258041r1038967_rule - RHEL 9 user account passwords for new users or password changes must have a 60-day maximum password lifetime restriction in /etc/login.defs.
rhel9 · medium (CAT II)
stig://rule/SV-258041r1038967_rule
SV-258042r1045133_rule - RHEL 9 user account passwords must have a 60-day maximum password lifetime restriction.
rhel9 · medium (CAT II)
stig://rule/SV-258042r1045133_rule
SV-258043r991589_rule - All RHEL 9 local interactive user accounts must be assigned a home directory upon creation.
rhel9 · medium (CAT II)
stig://rule/SV-258043r991589_rule
SV-258044r1045135_rule - RHEL 9 must set the umask value to 077 for all local interactive user accounts.
rhel9 · medium (CAT II)
stig://rule/SV-258044r1045135_rule
SV-258045r958482_rule - RHEL 9 duplicate User IDs (UIDs) must not exist for interactive users.
rhel9 · medium (CAT II)
stig://rule/SV-258045r958482_rule
SV-258046r991589_rule - RHEL 9 system accounts must not have an interactive login shell.
rhel9 · medium (CAT II)
stig://rule/SV-258046r991589_rule
SV-258047r1101951_rule - RHEL 9 must automatically expire temporary accounts within 72 hours.
rhel9 · medium (CAT II)
stig://rule/SV-258047r1101951_rule
SV-258048r1069380_rule - All RHEL 9 interactive users must have a primary group that exists.
rhel9 · medium (CAT II)
stig://rule/SV-258048r1069380_rule
SV-258049r1015092_rule - RHEL 9 must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.
rhel9 · medium (CAT II)
stig://rule/SV-258049r1015092_rule
SV-258050r1045137_rule - Executable search paths within the initialization files of all local interactive RHEL 9 users must only contain paths that resolve to the system default or the users home directory.
rhel9 · medium (CAT II)
stig://rule/SV-258050r1045137_rule
SV-258051r991589_rule - All RHEL 9 local interactive users must have a home directory assigned in the /etc/passwd file.
rhel9 · medium (CAT II)
stig://rule/SV-258051r991589_rule
SV-258052r991589_rule - All RHEL 9 local interactive user home directories defined in the /etc/passwd file must exist.
rhel9 · medium (CAT II)
stig://rule/SV-258052r991589_rule
SV-258053r991589_rule - All RHEL 9 local interactive user home directories must be group-owned by the home directory owner's primary group.
rhel9 · medium (CAT II)
stig://rule/SV-258053r991589_rule
SV-258054r958736_rule - RHEL 9 must automatically lock an account when three unsuccessful logon attempts occur.
rhel9 · medium (CAT II)
stig://rule/SV-258054r958736_rule
SV-258055r1045140_rule - RHEL 9 must automatically lock the root account until the root account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.
rhel9 · medium (CAT II)
stig://rule/SV-258055r1045140_rule
SV-258056r1045143_rule - RHEL 9 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period.
rhel9 · medium (CAT II)
stig://rule/SV-258056r1045143_rule
SV-258057r1045146_rule - RHEL 9 must maintain an account lock until the locked account is released by an administrator.
rhel9 · medium (CAT II)
stig://rule/SV-258057r1045146_rule
SV-258058r1045148_rule - RHEL 9 must not have unauthorized accounts.
rhel9 · medium (CAT II)
stig://rule/SV-258058r1045148_rule
SV-258059r991589_rule - The root account must be the only account having unrestricted access to RHEL 9 system.
rhel9 · high (CAT I)
stig://rule/SV-258059r991589_rule
SV-258060r1045150_rule - RHEL 9 must ensure account lockouts persist.
rhel9 · medium (CAT II)
stig://rule/SV-258060r1045150_rule
SV-258061r958482_rule - RHEL 9 groups must have unique Group ID (GID).
rhel9 · medium (CAT II)
stig://rule/SV-258061r958482_rule
SV-258062r991589_rule - Local RHEL 9 initialization files must not execute world-writable programs.
rhel9 · medium (CAT II)
stig://rule/SV-258062r991589_rule
SV-258068r1101950_rule - RHEL 9 must automatically exit interactive command shell user sessions after 10 minutes of inactivity.
rhel9 · medium (CAT II)
stig://rule/SV-258068r1101950_rule
SV-258069r958398_rule - RHEL 9 must limit the number of concurrent sessions to ten for all accounts and/or account types.
rhel9 · low (CAT III)
stig://rule/SV-258069r958398_rule
SV-258070r1045153_rule - RHEL 9 must log username information when unsuccessful logon attempts occur.
rhel9 · medium (CAT II)
stig://rule/SV-258070r1045153_rule
SV-258071r991588_rule - RHEL 9 must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
rhel9 · medium (CAT II)
stig://rule/SV-258071r991588_rule
SV-258072r1045155_rule - RHEL 9 must define default permissions for the bash shell.
rhel9 · medium (CAT II)
stig://rule/SV-258072r1045155_rule
SV-258073r1045157_rule - RHEL 9 must define default permissions for the c shell.
rhel9 · medium (CAT II)
stig://rule/SV-258073r1045157_rule
SV-258074r991590_rule - RHEL 9 must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.
rhel9 · medium (CAT II)
stig://rule/SV-258074r991590_rule
SV-258075r991590_rule - RHEL 9 must define default permissions for the system default profile.
rhel9 · medium (CAT II)
stig://rule/SV-258075r991590_rule
SV-258076r991589_rule - RHEL 9 must display the date and time of the last successful account logon upon logon.
rhel9 · low (CAT III)
stig://rule/SV-258076r991589_rule
SV-258077r1014874_rule - RHEL 9 must terminate idle user sessions.
rhel9 · medium (CAT II)
stig://rule/SV-258077r1014874_rule
SV-258078r958944_rule - RHEL 9 must use a Linux Security Module configured to enforce limits on system services.
rhel9 · high (CAT I)
stig://rule/SV-258078r958944_rule
SV-258079r1045159_rule - RHEL 9 must enable the SELinux targeted policy.
rhel9 · medium (CAT II)
stig://rule/SV-258079r1045159_rule
SV-258080r1045162_rule - RHEL 9 must configure SELinux context type to allow the use of a nondefault faillock tally directory.
rhel9 · medium (CAT II)
stig://rule/SV-258080r1045162_rule
SV-258081r1045164_rule - RHEL 9 must have policycoreutils package installed.
rhel9 · medium (CAT II)
stig://rule/SV-258081r1045164_rule
SV-258082r1045166_rule - RHEL 9 policycoreutils-python-utils package must be installed.
rhel9 · medium (CAT II)
stig://rule/SV-258082r1045166_rule
SV-258083r1045168_rule - RHEL 9 must have the sudo package installed.
rhel9 · medium (CAT II)
stig://rule/SV-258083r1045168_rule
SV-258084r1050789_rule - RHEL 9 must require reauthentication when using the "sudo" command.
rhel9 · medium (CAT II)
stig://rule/SV-258084r1050789_rule
SV-258085r1045173_rule - RHEL 9 must use the invoking user's password for privilege escalation when using "sudo".
rhel9 · medium (CAT II)
stig://rule/SV-258085r1045173_rule
SV-258086r1102063_rule - RHEL 9 must require users to reauthenticate for privilege escalation.
rhel9 · medium (CAT II)
stig://rule/SV-258086r1102063_rule
SV-258087r1102071_rule - RHEL 9 must restrict privilege elevation to authorized personnel.
rhel9 · medium (CAT II)
stig://rule/SV-258087r1102071_rule
SV-258088r1050789_rule - RHEL 9 must restrict the use of the "su" command.
rhel9 · medium (CAT II)
stig://rule/SV-258088r1050789_rule
SV-258089r1045179_rule - RHEL 9 fapolicy module must be installed.
rhel9 · medium (CAT II)
stig://rule/SV-258089r1045179_rule
SV-258090r958808_rule - RHEL 9 fapolicy module must be enabled.
rhel9 · medium (CAT II)
stig://rule/SV-258090r958808_rule
SV-258091r1045185_rule - RHEL 9 must ensure the password complexity module in the system-auth file is configured for three retries or less.
rhel9 · medium (CAT II)
stig://rule/SV-258091r1045185_rule
SV-258094r1045187_rule - RHEL 9 must not allow blank or null passwords.
rhel9 · high (CAT I)
stig://rule/SV-258094r1045187_rule
SV-258095r1045189_rule - RHEL 9 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file.
rhel9 · medium (CAT II)
stig://rule/SV-258095r1045189_rule
SV-258096r1045191_rule - RHEL 9 must configure the use of the pam_faillock.so module in the /etc/pam.d/password-auth file.
rhel9 · medium (CAT II)
stig://rule/SV-258096r1045191_rule
SV-258097r1045193_rule - RHEL 9 must ensure the password complexity module is enabled in the password-auth file.
rhel9 · medium (CAT II)
stig://rule/SV-258097r1045193_rule
SV-258098r1045195_rule - RHEL 9 must ensure the password complexity module is enabled in the system-auth file.
rhel9 · medium (CAT II)
stig://rule/SV-258098r1045195_rule
SV-258099r1045198_rule - RHEL 9 password-auth must be configured to use a sufficient number of hashing rounds.
rhel9 · medium (CAT II)
stig://rule/SV-258099r1045198_rule
SV-258100r1045201_rule - RHEL 9 system-auth must be configured to use a sufficient number of hashing rounds.
rhel9 · medium (CAT II)
stig://rule/SV-258100r1045201_rule
SV-258101r1045204_rule - RHEL 9 must enforce password complexity rules for the root account.
rhel9 · medium (CAT II)
stig://rule/SV-258101r1045204_rule
SV-258102r1045207_rule - RHEL 9 must enforce password complexity by requiring that at least one lowercase character be used.
rhel9 · medium (CAT II)
stig://rule/SV-258102r1045207_rule
SV-258103r1045210_rule - RHEL 9 must enforce password complexity by requiring that at least one numeric character be used.
rhel9 · medium (CAT II)
stig://rule/SV-258103r1045210_rule
SV-258104r1015104_rule - RHEL 9 passwords for new users or password changes must have a 24 hours minimum password lifetime restriction in /etc/login.defs.
rhel9 · medium (CAT II)
stig://rule/SV-258104r1015104_rule
SV-258105r1045212_rule - RHEL 9 passwords must have a 24 hours minimum password lifetime restriction in /etc/shadow.
rhel9 · medium (CAT II)
stig://rule/SV-258105r1045212_rule
SV-258106r1102061_rule - RHEL 9 must require users to provide a password for privilege escalation.
rhel9 · medium (CAT II)
stig://rule/SV-258106r1102061_rule
SV-258107r1045218_rule - RHEL 9 passwords must be created with a minimum of 15 characters.
rhel9 · medium (CAT II)
stig://rule/SV-258107r1045218_rule
SV-258109r1045220_rule - RHEL 9 must enforce password complexity by requiring that at least one special character be used.
rhel9 · medium (CAT II)
stig://rule/SV-258109r1045220_rule
SV-258110r1045223_rule - RHEL 9 must prevent the use of dictionary words for passwords.
rhel9 · medium (CAT II)
stig://rule/SV-258110r1045223_rule
SV-258111r1045226_rule - RHEL 9 must enforce password complexity by requiring that at least one uppercase character be used.
rhel9 · medium (CAT II)
stig://rule/SV-258111r1045226_rule
SV-258112r1045229_rule - RHEL 9 must require the change of at least eight characters when passwords are changed.
rhel9 · medium (CAT II)
stig://rule/SV-258112r1045229_rule
SV-258113r1045232_rule - RHEL 9 must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed.
rhel9 · medium (CAT II)
stig://rule/SV-258113r1045232_rule
SV-258114r1045235_rule - RHEL 9 must require the maximum number of repeating characters be limited to three when passwords are changed.
rhel9 · medium (CAT II)
stig://rule/SV-258114r1045235_rule
SV-258115r1045238_rule - RHEL 9 must require the change of at least four character classes when passwords are changed.
rhel9 · medium (CAT II)
stig://rule/SV-258115r1045238_rule
SV-258116r1045240_rule - RHEL 9 must be configured so that user and group account administration utilities are configured to store only encrypted representations of passwords.
rhel9 · medium (CAT II)
stig://rule/SV-258116r1045240_rule
SV-258117r1015116_rule - RHEL 9 must be configured to use the shadow file to store only encrypted representations of passwords.
rhel9 · medium (CAT II)
stig://rule/SV-258117r1015116_rule
SV-258118r1050789_rule - RHEL 9 must not be configured to bypass password requirements for privilege escalation.
rhel9 · medium (CAT II)
stig://rule/SV-258118r1050789_rule
SV-258120r991589_rule - RHEL 9 must not have accounts configured with blank or null passwords.
rhel9 · medium (CAT II)
stig://rule/SV-258120r991589_rule
SV-258121r1102086_rule - RHEL 9 must use the common access card (CAC) smart card driver.
rhel9 · medium (CAT II)
stig://rule/SV-258121r1102086_rule
SV-258122r1045246_rule - RHEL 9 must enable certificate based smart card authentication.
rhel9 · medium (CAT II)
stig://rule/SV-258122r1045246_rule
SV-258123r1134923_rule - RHEL 9 must implement certificate status checking for multifactor authentication.
rhel9 · medium (CAT II)
stig://rule/SV-258123r1134923_rule
SV-258124r1045250_rule - RHEL 9 must have the pcsc-lite package installed.
rhel9 · medium (CAT II)
stig://rule/SV-258124r1045250_rule
SV-258125r1045253_rule - The pcscd service on RHEL 9 must be active.
rhel9 · medium (CAT II)
stig://rule/SV-258125r1045253_rule
SV-258126r1045255_rule - RHEL 9 must have the opensc package installed.
rhel9 · medium (CAT II)
stig://rule/SV-258126r1045255_rule
SV-258127r1134925_rule - RHEL 9, for PKI-based authentication, must enforce authorized access to the corresponding private key.
rhel9 · medium (CAT II)
stig://rule/SV-258127r1134925_rule
SV-258128r1117265_rule - RHEL 9 must require authentication to access emergency mode.
rhel9 · medium (CAT II)
stig://rule/SV-258128r1117265_rule
SV-258129r1117265_rule - RHEL 9 must require authentication to access single-user mode.
rhel9 · medium (CAT II)
stig://rule/SV-258129r1117265_rule
SV-258131r1134927_rule - RHEL 9, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
rhel9 · medium (CAT II)
stig://rule/SV-258131r1134927_rule
SV-258132r1134929_rule - RHEL 9 must map the authenticated identity to the user or group account for PKI-based authentication.
rhel9 · medium (CAT II)
stig://rule/SV-258132r1134929_rule
SV-258133r1045263_rule - RHEL 9 must prohibit the use of cached authenticators after one day.
rhel9 · medium (CAT II)
stig://rule/SV-258133r1045263_rule
SV-258134r1101983_rule - RHEL 9 must have the AIDE package installed.
rhel9 · medium (CAT II)
stig://rule/SV-258134r1101983_rule
SV-258135r1045267_rule - RHEL 9 must routinely check the baseline configuration for unauthorized changes and notify the system administrator when anomalies in the operation of any security functions are discovered.
rhel9 · medium (CAT II)
stig://rule/SV-258135r1045267_rule
SV-258136r1045270_rule - RHEL 9 must use a file integrity tool that is configured to use FIPS 140-3-approved cryptographic hashes for validating file contents and directories.
rhel9 · medium (CAT II)
stig://rule/SV-258136r1045270_rule
SV-258137r1102081_rule - RHEL 9 must use cryptographic mechanisms to protect the integrity of audit tools.
rhel9 · medium (CAT II)
stig://rule/SV-258137r1102081_rule
SV-258138r1045274_rule - RHEL 9 must be configured so that the file integrity tool verifies Access Control Lists (ACLs).
rhel9 · low (CAT III)
stig://rule/SV-258138r1045274_rule
SV-258139r1045276_rule - RHEL 9 must be configured so that the file integrity tool verifies extended attributes.
rhel9 · low (CAT III)
stig://rule/SV-258139r1045276_rule
SV-258140r1106460_rule - RHEL 9 must have the rsyslog package installed.
rhel9 · medium (CAT II)
stig://rule/SV-258140r1106460_rule
SV-258141r1045280_rule - RHEL 9 must have the packages required for encrypting offloaded audit logs installed.
rhel9 · medium (CAT II)
stig://rule/SV-258141r1045280_rule
SV-258142r991589_rule - The rsyslog service on RHEL 9 must be active.
rhel9 · medium (CAT II)
stig://rule/SV-258142r991589_rule
SV-258143r1134931_rule - RHEL 9 must be configured so that the rsyslog daemon does not accept log messages from other servers unless the server is being used for log aggregation.
rhel9 · medium (CAT II)
stig://rule/SV-258143r1134931_rule
SV-258144r1045286_rule - All RHEL 9 remote access methods must be monitored.
rhel9 · medium (CAT II)
stig://rule/SV-258144r1045286_rule
SV-258146r1045288_rule - RHEL 9 must authenticate the remote logging server for offloading audit logs via rsyslog.
rhel9 · medium (CAT II)
stig://rule/SV-258146r1045288_rule
SV-258147r1045290_rule - RHEL 9 must encrypt the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog.
rhel9 · medium (CAT II)
stig://rule/SV-258147r1045290_rule
SV-258148r1045292_rule - RHEL 9 must encrypt via the gtls driver the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog.
rhel9 · medium (CAT II)
stig://rule/SV-258148r1045292_rule
SV-258149r1106462_rule - RHEL 9 must be configured to forward audit records via TCP to a different system or media from the system being audited via rsyslog.
rhel9 · medium (CAT II)
stig://rule/SV-258149r1106462_rule
SV-258150r1045296_rule - RHEL 9 must use cron logging.
rhel9 · medium (CAT II)
stig://rule/SV-258150r1045296_rule
SV-258151r1045298_rule - RHEL 9 audit package must be installed.
rhel9 · medium (CAT II)
stig://rule/SV-258151r1045298_rule
SV-258152r1015127_rule - RHEL 9 audit service must be enabled.
rhel9 · medium (CAT II)
stig://rule/SV-258152r1015127_rule
SV-258153r1038966_rule - RHEL 9 audit system must take appropriate action when an error writing to the audit storage volume occurs.
rhel9 · medium (CAT II)
stig://rule/SV-258153r1038966_rule
SV-258154r1038966_rule - RHEL 9 audit system must take appropriate action when the audit storage volume is full.
rhel9 · medium (CAT II)
stig://rule/SV-258154r1038966_rule
SV-258155r1045300_rule - RHEL 9 must allocate audit record storage capacity to store at least one week's worth of audit records.
rhel9 · medium (CAT II)
stig://rule/SV-258155r1045300_rule
SV-258156r1106364_rule - RHEL 9 must take action when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity.
rhel9 · medium (CAT II)
stig://rule/SV-258156r1106364_rule
SV-258157r1134932_rule - RHEL 9 must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume reaches 75 percent utilization.
rhel9 · medium (CAT II)
stig://rule/SV-258157r1134932_rule
SV-258158r971542_rule - RHEL 9 must take action when allocated audit record storage volume reaches 95 percent of the audit record storage capacity.
rhel9 · medium (CAT II)
stig://rule/SV-258158r971542_rule
SV-258159r971542_rule - RHEL 9 must take action when allocated audit record storage volume reaches 95 percent of the repository maximum audit record storage capacity.
rhel9 · medium (CAT II)
stig://rule/SV-258159r971542_rule
SV-258160r1038966_rule - RHEL 9 audit system must take appropriate action when the audit files have reached maximum size.
rhel9 · medium (CAT II)
stig://rule/SV-258160r1038966_rule
SV-258161r958416_rule - RHEL 9 must label all offloaded audit logs before sending them to the central log server.
rhel9 · medium (CAT II)
stig://rule/SV-258161r958416_rule
SV-258162r958754_rule - RHEL 9 must take appropriate action when the internal event queue is full.
rhel9 · medium (CAT II)
stig://rule/SV-258162r958754_rule
SV-258163r958424_rule - RHEL 9 System Administrator (SA) and/or information system security officer (ISSO) (at a minimum) must be alerted of an audit processing failure event.
rhel9 · medium (CAT II)
stig://rule/SV-258163r958424_rule
SV-258164r1045301_rule - RHEL 9 audit system must audit local events.
rhel9 · medium (CAT II)
stig://rule/SV-258164r1045301_rule
SV-258165r958434_rule - RHEL 9 audit logs must be group-owned by root or by a restricted logging group to prevent unauthorized read access.
rhel9 · medium (CAT II)
stig://rule/SV-258165r958434_rule
SV-258166r1045303_rule - RHEL 9 audit log directory must be owned by root to prevent unauthorized read access.
rhel9 · medium (CAT II)
stig://rule/SV-258166r1045303_rule
SV-258167r1101918_rule - RHEL 9 audit logs file must have mode 0600 or less permissive to prevent unauthorized access to the audit log.
rhel9 · medium (CAT II)
stig://rule/SV-258167r1101918_rule
SV-258168r958428_rule - RHEL 9 must periodically flush audit records to disk to prevent the loss of audit records.
rhel9 · medium (CAT II)
stig://rule/SV-258168r958428_rule
SV-258169r991556_rule - RHEL 9 must produce audit records containing information to establish the identity of any individual or process associated with the event.
rhel9 · medium (CAT II)
stig://rule/SV-258169r991556_rule
SV-258170r991589_rule - RHEL 9 must write audit records to disk.
rhel9 · medium (CAT II)
stig://rule/SV-258170r991589_rule
SV-258171r1134934_rule - RHEL 9 must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.
rhel9 · medium (CAT II)
stig://rule/SV-258171r1134934_rule
SV-258173r1101933_rule - RHEL 9 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.
rhel9 · low (CAT III)
stig://rule/SV-258173r1101933_rule
SV-258174r958424_rule - RHEL 9 must have mail aliases to notify the information system security officer (ISSO) and system administrator (SA) (at a minimum) in the event of an audit processing failure.
rhel9 · medium (CAT II)
stig://rule/SV-258174r958424_rule
SV-258175r1045310_rule - RHEL 9 audispd-plugins package must be installed.
rhel9 · medium (CAT II)
stig://rule/SV-258175r1045310_rule
SV-258176r1106366_rule - RHEL 9 must audit uses of the "execve" system call.
rhel9 · medium (CAT II)
stig://rule/SV-258176r1106366_rule
SV-258177r1106368_rule - RHEL 9 must audit all uses of the chmod, fchmod, and fchmodat system calls.
rhel9 · medium (CAT II)
stig://rule/SV-258177r1106368_rule
SV-258178r1106370_rule - RHEL 9 must audit all uses of the chown, fchown, fchownat, and lchown system calls.
rhel9 · medium (CAT II)
stig://rule/SV-258178r1106370_rule
SV-258179r1106371_rule - RHEL 9 must audit all uses of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls.
rhel9 · medium (CAT II)
stig://rule/SV-258179r1106371_rule
SV-258180r1045325_rule - RHEL 9 must audit all uses of umount system calls.
rhel9 · medium (CAT II)
stig://rule/SV-258180r1045325_rule
SV-258181r1045328_rule - RHEL 9 must audit all uses of the chacl command.
rhel9 · medium (CAT II)
stig://rule/SV-258181r1045328_rule
SV-258182r1045331_rule - RHEL 9 must audit all uses of the setfacl command.
rhel9 · medium (CAT II)
stig://rule/SV-258182r1045331_rule
SV-258183r1045334_rule - RHEL 9 must audit all uses of the chcon command.
rhel9 · medium (CAT II)
stig://rule/SV-258183r1045334_rule
SV-258184r1045337_rule - RHEL 9 must audit all uses of the semanage command.
rhel9 · medium (CAT II)
stig://rule/SV-258184r1045337_rule
SV-258185r1045340_rule - RHEL 9 must audit all uses of the setfiles command.
rhel9 · medium (CAT II)
stig://rule/SV-258185r1045340_rule
SV-258186r1045343_rule - RHEL 9 must audit all uses of the setsebool command.
rhel9 · medium (CAT II)
stig://rule/SV-258186r1045343_rule
SV-258187r1106373_rule - RHEL 9 must audit all uses of the rename, unlink, rmdir, renameat, and unlinkat system calls.
rhel9 · medium (CAT II)
stig://rule/SV-258187r1106373_rule
SV-258188r1106375_rule - RHEL 9 must audit all uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls.
rhel9 · medium (CAT II)
stig://rule/SV-258188r1106375_rule
SV-258189r1106377_rule - RHEL 9 must audit all uses of the delete_module system call.
rhel9 · medium (CAT II)
stig://rule/SV-258189r1106377_rule
SV-258190r1106379_rule - RHEL 9 must audit all uses of the init_module and finit_module system calls.
rhel9 · medium (CAT II)
stig://rule/SV-258190r1106379_rule
SV-258191r1045358_rule - RHEL 9 must audit all uses of the chage command.
rhel9 · medium (CAT II)
stig://rule/SV-258191r1045358_rule
SV-258192r1045361_rule - RHEL 9 must audit all uses of the chsh command.
rhel9 · medium (CAT II)
stig://rule/SV-258192r1045361_rule
SV-258193r1045364_rule - RHEL 9 must audit all uses of the crontab command.
rhel9 · medium (CAT II)
stig://rule/SV-258193r1045364_rule
SV-258194r1045367_rule - RHEL 9 must audit all uses of the gpasswd command.
rhel9 · medium (CAT II)
stig://rule/SV-258194r1045367_rule
SV-258195r1045370_rule - RHEL 9 must audit all uses of the kmod command.
rhel9 · medium (CAT II)
stig://rule/SV-258195r1045370_rule
SV-258196r1045373_rule - RHEL 9 must audit all uses of the newgrp command.
rhel9 · medium (CAT II)
stig://rule/SV-258196r1045373_rule
SV-258197r1045376_rule - RHEL 9 must audit all uses of the pam_timestamp_check command.
rhel9 · medium (CAT II)
stig://rule/SV-258197r1045376_rule
SV-258198r1045379_rule - RHEL 9 must audit all uses of the passwd command.
rhel9 · medium (CAT II)
stig://rule/SV-258198r1045379_rule
SV-258199r1045382_rule - RHEL 9 must audit all uses of the postdrop command.
rhel9 · medium (CAT II)
stig://rule/SV-258199r1045382_rule
SV-258200r1045385_rule - RHEL 9 must audit all uses of the postqueue command.
rhel9 · medium (CAT II)
stig://rule/SV-258200r1045385_rule
SV-258201r1045388_rule - RHEL 9 must audit all uses of the ssh-agent command.
rhel9 · medium (CAT II)
stig://rule/SV-258201r1045388_rule
SV-258202r1045391_rule - RHEL 9 must audit all uses of the ssh-keysign command.
rhel9 · medium (CAT II)
stig://rule/SV-258202r1045391_rule
SV-258203r1045394_rule - RHEL 9 must audit all uses of the su command.
rhel9 · medium (CAT II)
stig://rule/SV-258203r1045394_rule
SV-258204r1045397_rule - RHEL 9 must audit all uses of the sudo command.
rhel9 · medium (CAT II)
stig://rule/SV-258204r1045397_rule
SV-258205r1045400_rule - RHEL 9 must audit all uses of the sudoedit command.
rhel9 · medium (CAT II)
stig://rule/SV-258205r1045400_rule
SV-258206r1045403_rule - RHEL 9 must audit all uses of the unix_chkpwd command.
rhel9 · medium (CAT II)
stig://rule/SV-258206r1045403_rule
SV-258207r1045406_rule - RHEL 9 must audit all uses of the unix_update command.
rhel9 · medium (CAT II)
stig://rule/SV-258207r1045406_rule
SV-258208r1045409_rule - RHEL 9 must audit all uses of the userhelper command.
rhel9 · medium (CAT II)
stig://rule/SV-258208r1045409_rule
SV-258209r1045412_rule - RHEL 9 must audit all uses of the usermod command.
rhel9 · medium (CAT II)
stig://rule/SV-258209r1045412_rule
SV-258210r1045415_rule - RHEL 9 must audit all uses of the mount command.
rhel9 · medium (CAT II)
stig://rule/SV-258210r1045415_rule
SV-258211r1045418_rule - Successful/unsuccessful uses of the init command in RHEL 9 must generate an audit record.
rhel9 · medium (CAT II)
stig://rule/SV-258211r1045418_rule
SV-258212r1045421_rule - Successful/unsuccessful uses of the poweroff command in RHEL 9 must generate an audit record.
rhel9 · medium (CAT II)
stig://rule/SV-258212r1045421_rule
SV-258213r1045424_rule - Successful/unsuccessful uses of the reboot command in RHEL 9 must generate an audit record.
rhel9 · medium (CAT II)
stig://rule/SV-258213r1045424_rule
SV-258214r1045427_rule - Successful/unsuccessful uses of the shutdown command in RHEL 9 must generate an audit record.
rhel9 · medium (CAT II)
stig://rule/SV-258214r1045427_rule
SV-258215r1106381_rule - Successful/unsuccessful uses of the umount system call in RHEL 9 must generate an audit record.
rhel9 · medium (CAT II)
stig://rule/SV-258215r1106381_rule
SV-258216r1102090_rule - Successful/unsuccessful uses of the umount2 system call in RHEL 9 must generate an audit record.
rhel9 · medium (CAT II)
stig://rule/SV-258216r1102090_rule
SV-258217r1045436_rule - RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.
rhel9 · medium (CAT II)
stig://rule/SV-258217r1045436_rule
SV-258218r1101981_rule - RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory.
rhel9 · medium (CAT II)
stig://rule/SV-258218r1101981_rule
SV-258219r1015130_rule - RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
rhel9 · medium (CAT II)
stig://rule/SV-258219r1015130_rule
SV-258220r1015131_rule - RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
rhel9 · medium (CAT II)
stig://rule/SV-258220r1015131_rule
SV-258221r1015132_rule - RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
rhel9 · medium (CAT II)
stig://rule/SV-258221r1015132_rule
SV-258222r1015133_rule - RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
rhel9 · medium (CAT II)
stig://rule/SV-258222r1015133_rule
SV-258223r1015134_rule - RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
rhel9 · medium (CAT II)
stig://rule/SV-258223r1015134_rule
SV-258224r1014988_rule - RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/faillock.
rhel9 · medium (CAT II)
stig://rule/SV-258224r1014988_rule
SV-258225r1014990_rule - RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/lastlog.
rhel9 · medium (CAT II)
stig://rule/SV-258225r1014990_rule
SV-258227r1014992_rule - RHEL 9 must take appropriate action when a critical audit processing failure occurs.
rhel9 · medium (CAT II)
stig://rule/SV-258227r1014992_rule
SV-258228r991572_rule - RHEL 9 audit system must protect logon UIDs from unauthorized change.
rhel9 · medium (CAT II)
stig://rule/SV-258228r991572_rule
SV-258229r958434_rule - RHEL 9 audit system must protect auditing rules from unauthorized change.
rhel9 · medium (CAT II)
stig://rule/SV-258229r958434_rule
SV-258230r1134936_rule - RHEL 9 must enable FIPS mode.
rhel9 · high (CAT I)
stig://rule/SV-258230r1134936_rule
SV-258231r1069375_rule - RHEL 9 must employ FIPS 140-3 approved cryptographic hashing algorithms for all stored passwords.
rhel9 · medium (CAT II)
stig://rule/SV-258231r1069375_rule
SV-258232r1045440_rule - RHEL 9 IP tunnels must use FIPS 140-3 approved cryptographic algorithms.
rhel9 · medium (CAT II)
stig://rule/SV-258232r1045440_rule
SV-258233r1015136_rule - RHEL 9 pam_unix.so module must be configured in the password-auth file to use a FIPS 140-3 approved cryptographic hashing algorithm for system authentication.
rhel9 · medium (CAT II)
stig://rule/SV-258233r1015136_rule
SV-258234r1051250_rule - RHEL 9 must have the crypto-policies package installed.
rhel9 · medium (CAT II)
stig://rule/SV-258234r1051250_rule
SV-258236r1101920_rule - RHEL 9 cryptographic policy must not be overridden.
rhel9 · high (CAT I)
stig://rule/SV-258236r1101920_rule
SV-258241r1106302_rule - RHEL 9 must implement a FIPS 140-3-compliant systemwide cryptographic policy.
rhel9 · medium (CAT II)
stig://rule/SV-258241r1106302_rule
SV-258242r958908_rule - RHEL 9 must implement DOD-approved encryption in the bind package.
rhel9 · medium (CAT II)
stig://rule/SV-258242r958908_rule
SV-270174r1044831_rule - RHEL 9 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a graphical user logon.
rhel9 · medium (CAT II)
stig://rule/SV-270174r1044831_rule
SV-270175r1117265_rule - RHEL 9 "/etc/audit/" must be owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-270175r1117265_rule
SV-270176r1117265_rule - RHEL 9 "/etc/audit/" must be group-owned by root.
rhel9 · medium (CAT II)
stig://rule/SV-270176r1117265_rule
SV-270177r1051237_rule - The RHEL 9 SSH client must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.
rhel9 · medium (CAT II)
stig://rule/SV-270177r1051237_rule
SV-270178r1051243_rule - The RHEL 9 SSH client must be configured to use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.
rhel9 · medium (CAT II)
stig://rule/SV-270178r1051243_rule
SV-270180r1045182_rule - The RHEL 9 fapolicy module must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
rhel9 · medium (CAT II)
stig://rule/SV-270180r1045182_rule
SV-272488r1082178_rule - RHEL 9 must have the Postfix package installed.
rhel9 · medium (CAT II)
stig://rule/SV-272488r1082178_rule
SV-272496r1134956_rule - RHEL 9 must elevate the SELinux context when an administrator calls the sudo command.
rhel9 · medium (CAT II)
stig://rule/SV-272496r1134956_rule
SV-253254r991589_rule - Domain-joined systems must use Windows 11 Enterprise Edition 64-bit version.
windows11 · medium (CAT II)
stig://rule/SV-253254r991589_rule
SV-253255r1117271_rule - Windows 11 domain-joined systems must have a Trusted Platform Module (TPM) enabled.
windows11 · medium (CAT II)
stig://rule/SV-253255r1117271_rule
SV-253256r1117271_rule - Windows 11 systems must have Unified Extensible Firmware Interface (UEFI) firmware and be configured to run in UEFI mode, not Legacy BIOS.
windows11 · medium (CAT II)
stig://rule/SV-253256r1117271_rule
SV-253257r1117271_rule - Secure Boot must be enabled on Windows 11 systems.
windows11 · medium (CAT II)
stig://rule/SV-253257r1117271_rule
SV-253258r1000099_rule - Windows 11 must employ automated mechanisms to determine the state of system components with regard to flaw remediation using the following frequency: Continuously, where ESS is used; 30 days, for any additional internal network scans not covered by ESS; and annually, for external scans by Computer Network Defense Service Provider (CNDSP).
windows11 · medium (CAT II)
stig://rule/SV-253258r1000099_rule
SV-253259r958870_rule - Windows 11 information systems must use BitLocker to encrypt all disks to protect the confidentiality and integrity of all information at rest.
windows11 · high (CAT I)
stig://rule/SV-253259r958870_rule
SV-253260r958872_rule - Windows 11 systems must use a BitLocker PIN for pre-boot authentication.
windows11 · high (CAT I)
stig://rule/SV-253260r958872_rule
SV-253261r958504_rule - Windows 11 systems must use a BitLocker PIN with a minimum length of six digits for pre-boot authentication.
windows11 · medium (CAT II)
stig://rule/SV-253261r958504_rule
SV-253262r958808_rule - The operating system must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
windows11 · medium (CAT II)
stig://rule/SV-253262r958808_rule
SV-253263r1016364_rule - Windows 11 systems must be maintained at a supported servicing level.
windows11 · high (CAT I)
stig://rule/SV-253263r1016364_rule
SV-253264r991589_rule - The Windows 11 system must use an antivirus program.
windows11 · high (CAT I)
stig://rule/SV-253264r991589_rule
SV-253265r1137691_rule - Local volumes must be formatted using NTFS.
windows11 · high (CAT I)
stig://rule/SV-253265r1137691_rule
SV-253266r991589_rule - Alternate operating systems must not be permitted on the same system.
windows11 · medium (CAT II)
stig://rule/SV-253266r991589_rule
SV-253267r1137695_rule - Non-system-created file shares on a system must limit access to groups that require it.
windows11 · medium (CAT II)
stig://rule/SV-253267r1137695_rule
SV-253268r1051039_rule - Unused accounts must be disabled or removed from the system after 35 days of inactivity.
windows11 · low (CAT III)
stig://rule/SV-253268r1051039_rule
SV-253269r958702_rule - Only accounts responsible for the administration of a system must have Administrator rights on the system.
windows11 · high (CAT I)
stig://rule/SV-253269r958702_rule
SV-253270r991589_rule - Only accounts responsible for the backup operations must be members of the Backup Operators group.
windows11 · medium (CAT II)
stig://rule/SV-253270r991589_rule
SV-253271r958702_rule - Only authorized user accounts must be allowed to create or run virtual machines on Windows 11 systems.
windows11 · medium (CAT II)
stig://rule/SV-253271r958702_rule
SV-253272r991589_rule - Standard local user accounts must not exist on a system in a domain.
windows11 · low (CAT III)
stig://rule/SV-253272r991589_rule
SV-253273r1051040_rule - Accounts must be configured to require password expiration.
windows11 · medium (CAT II)
stig://rule/SV-253273r1051040_rule
SV-253274r1016661_rule - Permissions for system files and directories must conform to minimum requirements.
windows11 · medium (CAT II)
stig://rule/SV-253274r1016661_rule
SV-253275r958478_rule - Internet Information System (IIS) or its subcomponents must not be installed on a workstation.
windows11 · high (CAT I)
stig://rule/SV-253275r958478_rule
SV-253276r958480_rule - Simple Network Management Protocol (SNMP) must not be installed on the system.
windows11 · medium (CAT II)
stig://rule/SV-253276r958480_rule
SV-253277r958478_rule - Simple TCP/IP Services must not be installed on the system.
windows11 · medium (CAT II)
stig://rule/SV-253277r958478_rule
SV-253278r958480_rule - The Telnet Client must not be installed on the system.
windows11 · medium (CAT II)
stig://rule/SV-253278r958480_rule
SV-253279r958480_rule - The TFTP Client must not be installed on the system.
windows11 · medium (CAT II)
stig://rule/SV-253279r958480_rule
SV-253280r991589_rule - Software certificate installation files must be removed from Windows 11.
windows11 · medium (CAT II)
stig://rule/SV-253280r991589_rule
SV-253281r991589_rule - A host-based firewall must be installed and enabled on the system.
windows11 · medium (CAT II)
stig://rule/SV-253281r991589_rule
SV-253282r991593_rule - Inbound exceptions to the firewall on Windows 11 domain workstations must only allow authorized remote management hosts.
windows11 · medium (CAT II)
stig://rule/SV-253282r991593_rule
SV-253284r958928_rule - Structured Exception Handling Overwrite Protection (SEHOP) must be enabled.
windows11 · high (CAT I)
stig://rule/SV-253284r958928_rule
SV-253285r958478_rule - The Windows PowerShell 2.0 feature must be disabled on the system.
windows11 · medium (CAT II)
stig://rule/SV-253285r958478_rule
SV-253286r958478_rule - The Server Message Block (SMB) v1 protocol must be disabled on the system.
windows11 · medium (CAT II)
stig://rule/SV-253286r958478_rule
SV-253287r958478_rule - The Server Message Block (SMB) v1 protocol must be disabled on the SMB server.
windows11 · medium (CAT II)
stig://rule/SV-253287r958478_rule
SV-253288r958478_rule - The Server Message Block (SMB) v1 protocol must be disabled on the SMB client.
windows11 · medium (CAT II)
stig://rule/SV-253288r958478_rule
SV-253289r958478_rule - The Secondary Logon service must be disabled on Windows 11.
windows11 · medium (CAT II)
stig://rule/SV-253289r958478_rule
SV-253290r991589_rule - Orphaned security identifiers (SIDs) must be removed from user rights on Windows 11.
windows11 · medium (CAT II)
stig://rule/SV-253290r991589_rule
SV-253291r958478_rule - Bluetooth must be turned off unless approved by the organization.
windows11 · medium (CAT II)
stig://rule/SV-253291r958478_rule
SV-253292r958478_rule - Bluetooth must be turned off when not in use.
windows11 · medium (CAT II)
stig://rule/SV-253292r958478_rule
SV-253293r991589_rule - The system must notify the user when a Bluetooth device attempts to connect.
windows11 · medium (CAT II)
stig://rule/SV-253293r991589_rule
SV-253294r991589_rule - Administrative accounts must not be used with applications that access the internet, such as web browsers, or with potential internet sources, such as email.
windows11 · high (CAT I)
stig://rule/SV-253294r991589_rule
SV-253295r958552_rule - Windows 11 nonpersistent VM sessions must not exceed 24 hours.
windows11 · medium (CAT II)
stig://rule/SV-253295r958552_rule
SV-253296r1051041_rule - The Windows 11 time service must synchronize with an appropriate DOD time source.
windows11 · low (CAT III)
stig://rule/SV-253296r1051041_rule
SV-253297r958736_rule - Windows 11 account lockout duration must be configured to 15 minutes or greater.
windows11 · medium (CAT II)
stig://rule/SV-253297r958736_rule
SV-253298r958388_rule - The number of allowed bad logon attempts must be configured to three or less.
windows11 · medium (CAT II)
stig://rule/SV-253298r958388_rule
SV-253299r958388_rule - The period of time before the bad logon counter is reset must be configured to 15 minutes.
windows11 · medium (CAT II)
stig://rule/SV-253299r958388_rule
SV-253300r1000103_rule - The password history must be configured to 24 passwords remembered.
windows11 · medium (CAT II)
stig://rule/SV-253300r1000103_rule
SV-253301r1051042_rule - The maximum password age must be configured to 60 days or less.
windows11 · medium (CAT II)
stig://rule/SV-253301r1051042_rule
SV-253302r1051043_rule - The minimum password age must be configured to at least 1 day.
windows11 · medium (CAT II)
stig://rule/SV-253302r1051043_rule
SV-253303r1051044_rule - Passwords must, at a minimum, be 14 characters.
windows11 · medium (CAT II)
stig://rule/SV-253303r1051044_rule
SV-253304r1051045_rule - The built-in Microsoft password complexity filter must be enabled.
windows11 · medium (CAT II)
stig://rule/SV-253304r1051045_rule
SV-253305r1051046_rule - Reversible password encryption must be disabled.
windows11 · high (CAT I)
stig://rule/SV-253305r1051046_rule
SV-253306r991570_rule - The system must be configured to audit Account Logon - Credential Validation failures.
windows11 · medium (CAT II)
stig://rule/SV-253306r991570_rule
SV-253307r991570_rule - The system must be configured to audit Account Logon - Credential Validation successes.
windows11 · medium (CAT II)
stig://rule/SV-253307r991570_rule
SV-253308r971541_rule - The system must be configured to audit Account Management - Security Group Management successes.
windows11 · medium (CAT II)
stig://rule/SV-253308r971541_rule
SV-253309r958566_rule - The system must be configured to audit Account Management - User Account Management failures.
windows11 · medium (CAT II)
stig://rule/SV-253309r958566_rule
SV-253310r991551_rule - The system must be configured to audit Account Management - User Account Management successes.
windows11 · medium (CAT II)
stig://rule/SV-253310r991551_rule
SV-253311r1051047_rule - The system must be configured to audit Detailed Tracking - PNP Activity successes.
windows11 · medium (CAT II)
stig://rule/SV-253311r1051047_rule
SV-253312r1051048_rule - The system must be configured to audit Detailed Tracking - Process Creation successes.
windows11 · medium (CAT II)
stig://rule/SV-253312r1051048_rule
SV-253313r991578_rule - The system must be configured to audit Logon/Logoff - Account Lockout failures.
windows11 · medium (CAT II)
stig://rule/SV-253313r991578_rule
SV-253314r991570_rule - The system must be configured to audit Logon/Logoff - Group Membership successes.
windows11 · medium (CAT II)
stig://rule/SV-253314r991570_rule
SV-253315r958406_rule - The system must be configured to audit Logon/Logoff - Logoff successes.
windows11 · medium (CAT II)
stig://rule/SV-253315r958406_rule
SV-253316r991581_rule - The system must be configured to audit Logon/Logoff - Logon failures.
windows11 · medium (CAT II)
stig://rule/SV-253316r991581_rule
SV-253317r991581_rule - The system must be configured to audit Logon/Logoff - Logon successes.
windows11 · medium (CAT II)
stig://rule/SV-253317r991581_rule
SV-253318r991578_rule - The system must be configured to audit Logon/Logoff - Special Logon successes.
windows11 · medium (CAT II)
stig://rule/SV-253318r991578_rule
SV-253319r991572_rule - Windows 11 must be configured to audit Object Access - File Share failures.
windows11 · medium (CAT II)
stig://rule/SV-253319r991572_rule
SV-253320r991572_rule - Windows 11 must be configured to audit Object Access - File Share successes.
windows11 · medium (CAT II)
stig://rule/SV-253320r991572_rule
SV-253321r991572_rule - Windows 11 must be configured to audit Object Access - Other Object Access Events successes.
windows11 · medium (CAT II)
stig://rule/SV-253321r991572_rule
SV-253322r991572_rule - Windows 11 must be configured to audit Object Access - Other Object Access Events failures.
windows11 · medium (CAT II)
stig://rule/SV-253322r991572_rule
SV-253323r991583_rule - The system must be configured to audit Object Access - Removable Storage failures.
windows11 · medium (CAT II)
stig://rule/SV-253323r991583_rule
SV-253324r991583_rule - The system must be configured to audit Object Access - Removable Storage successes.
windows11 · medium (CAT II)
stig://rule/SV-253324r991583_rule
SV-253325r991572_rule - The system must be configured to audit Policy Change - Audit Policy Change successes.
windows11 · medium (CAT II)
stig://rule/SV-253325r991572_rule
SV-253326r991572_rule - The system must be configured to audit Policy Change - Authentication Policy Change successes.
windows11 · medium (CAT II)
stig://rule/SV-253326r991572_rule
SV-253327r991572_rule - The system must be configured to audit Policy Change - Authorization Policy Change successes.
windows11 · medium (CAT II)
stig://rule/SV-253327r991572_rule
SV-253328r958732_rule - The system must be configured to audit Privilege Use - Sensitive Privilege Use failures.
windows11 · medium (CAT II)
stig://rule/SV-253328r958732_rule
SV-253329r991575_rule - The system must be configured to audit Privilege Use - Sensitive Privilege Use successes.
windows11 · medium (CAT II)
stig://rule/SV-253329r991575_rule
SV-253330r991586_rule - The system must be configured to audit System - IPsec Driver failures.
windows11 · medium (CAT II)
stig://rule/SV-253330r991586_rule
SV-253331r991579_rule - The system must be configured to audit System - Other System Events successes.
windows11 · medium (CAT II)
stig://rule/SV-253331r991579_rule
SV-253332r991579_rule - The system must be configured to audit System - Other System Events failures.
windows11 · medium (CAT II)
stig://rule/SV-253332r991579_rule
SV-253333r991575_rule - The system must be configured to audit System - Security State Change successes.
windows11 · medium (CAT II)
stig://rule/SV-253333r991575_rule
SV-253334r991575_rule - The system must be configured to audit System - Security System Extension successes.
windows11 · medium (CAT II)
stig://rule/SV-253334r991575_rule
SV-253335r991573_rule - The system must be configured to audit System - System Integrity failures.
windows11 · medium (CAT II)
stig://rule/SV-253335r991573_rule
SV-253336r991573_rule - The system must be configured to audit System - System Integrity successes.
windows11 · medium (CAT II)
stig://rule/SV-253336r991573_rule
SV-253337r958752_rule - The Application event log size must be configured to 32768 KB or greater.
windows11 · medium (CAT II)
stig://rule/SV-253337r958752_rule
SV-253338r958752_rule - The Security event log size must be configured to 1024000 KB or greater.
windows11 · medium (CAT II)
stig://rule/SV-253338r958752_rule
SV-253339r958752_rule - The System event log size must be configured to 32768 KB or greater.
windows11 · medium (CAT II)
stig://rule/SV-253339r958752_rule
SV-253340r958434_rule - Windows 11 permissions for the Application event log must prevent access by non-privileged accounts.
windows11 · medium (CAT II)
stig://rule/SV-253340r958434_rule
SV-253341r958434_rule - Windows 11 permissions for the Security event log must prevent access by non-privileged accounts.
windows11 · medium (CAT II)
stig://rule/SV-253341r958434_rule
SV-253342r958434_rule - Windows 11 permissions for the System event log must prevent access by non-privileged accounts.
windows11 · medium (CAT II)
stig://rule/SV-253342r958434_rule
SV-253343r958412_rule - Windows 11 must be configured to audit Other Policy Change Events Successes.
windows11 · medium (CAT II)
stig://rule/SV-253343r958412_rule
SV-253344r958412_rule - Windows 11 must be configured to audit Other Policy Change Events Failures.
windows11 · medium (CAT II)
stig://rule/SV-253344r958412_rule
SV-253345r958412_rule - Windows 11 must be configured to audit other Logon/Logoff Events Successes.
windows11 · medium (CAT II)
stig://rule/SV-253345r958412_rule
SV-253346r958412_rule - Windows 11 must be configured to audit other Logon/Logoff Events Failures.
windows11 · medium (CAT II)
stig://rule/SV-253346r958412_rule
SV-253347r958412_rule - Windows 11 must be configured to audit Detailed File Share Failures.
windows11 · medium (CAT II)
stig://rule/SV-253347r958412_rule
SV-253348r958412_rule - Windows 11 must be configured to audit MPSSVC Rule-Level Policy Change Successes.
windows11 · medium (CAT II)
stig://rule/SV-253348r958412_rule
SV-253349r958412_rule - Windows 11 must be configured to audit MPSSVC Rule-Level Policy Change Failures.
windows11 · medium (CAT II)
stig://rule/SV-253349r958412_rule
SV-253350r958478_rule - Camera access from the lock screen must be disabled.
windows11 · medium (CAT II)
stig://rule/SV-253350r958478_rule
SV-253351r1106508_rule - Windows 11 must cover or disable the built-in or attached camera when not in use.
windows11 · medium (CAT II)
stig://rule/SV-253351r1106508_rule
SV-253352r958478_rule - The display of slide shows on the lock screen must be disabled.
windows11 · medium (CAT II)
stig://rule/SV-253352r958478_rule
SV-253353r991589_rule - IPv6 source routing must be configured to highest protection.
windows11 · medium (CAT II)
stig://rule/SV-253353r991589_rule
SV-253354r991589_rule - The system must be configured to prevent IP source routing.
windows11 · medium (CAT II)
stig://rule/SV-253354r991589_rule
SV-253355r991589_rule - The system must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF) generated routes.
windows11 · low (CAT III)
stig://rule/SV-253355r991589_rule
SV-253356r958902_rule - The system must be configured to ignore NetBIOS name release requests except from WINS servers.
windows11 · low (CAT III)
stig://rule/SV-253356r958902_rule
SV-253357r958518_rule - Local administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain systems.
windows11 · medium (CAT II)
stig://rule/SV-253357r958518_rule
SV-253358r958478_rule - WDigest Authentication must be disabled.
windows11 · medium (CAT II)
stig://rule/SV-253358r958478_rule
SV-253359r958478_rule - Run as different user must be removed from context menus.
windows11 · medium (CAT II)
stig://rule/SV-253359r958478_rule
SV-253360r991589_rule - Insecure logons to an SMB server must be disabled.
windows11 · medium (CAT II)
stig://rule/SV-253360r991589_rule
SV-253361r958478_rule - Internet connection sharing must be disabled.
windows11 · medium (CAT II)
stig://rule/SV-253361r958478_rule
SV-253362r991589_rule - Hardened UNC Paths must be defined to require mutual authentication and integrity for at least the \\*\SYSVOL and \\*\NETLOGON shares.
windows11 · medium (CAT II)
stig://rule/SV-253362r991589_rule
SV-253363r971535_rule - Windows 11 must be configured to prioritize ECC Curves with longer key lengths first.
windows11 · medium (CAT II)
stig://rule/SV-253363r971535_rule
SV-253364r958358_rule - Simultaneous connections to the internet or a Windows domain must be limited.
windows11 · medium (CAT II)
stig://rule/SV-253364r958358_rule
SV-253365r991589_rule - Connections to non-domain networks when connected to a domain authenticated network must be blocked.
windows11 · medium (CAT II)
stig://rule/SV-253365r991589_rule
SV-253366r991589_rule - Wi-Fi Sense must be disabled.
windows11 · medium (CAT II)
stig://rule/SV-253366r991589_rule
SV-253367r958422_rule - Command line data must be included in process creation events.
windows11 · medium (CAT II)
stig://rule/SV-253367r958422_rule
SV-253368r991589_rule - Windows 11 must be configured to enable Remote host allows delegation of non-exportable credentials.
windows11 · medium (CAT II)
stig://rule/SV-253368r991589_rule
SV-253369r991589_rule - Virtualization-based Security must be enabled on Windows 11 with the platform security level configured to Secure Boot or Secure Boot with DMA Protection.
windows11 · medium (CAT II)
stig://rule/SV-253369r991589_rule
SV-253370r991589_rule - Credential Guard must be running on Windows 11 domain-joined systems.
windows11 · high (CAT I)
stig://rule/SV-253370r991589_rule
SV-253371r991589_rule - Virtualization-based protection of code integrity must be enabled.
windows11 · medium (CAT II)
stig://rule/SV-253371r991589_rule
SV-253372r991589_rule - Early Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers.
windows11 · medium (CAT II)
stig://rule/SV-253372r991589_rule
SV-253373r991589_rule - Group Policy objects must be reprocessed even if they have not changed.
windows11 · medium (CAT II)
stig://rule/SV-253373r991589_rule
SV-253374r958478_rule - Downloading print driver packages over HTTP must be prevented.
windows11 · medium (CAT II)
stig://rule/SV-253374r958478_rule
SV-253375r958478_rule - Web publishing and online ordering wizards must be prevented from downloading a list of providers.
windows11 · medium (CAT II)
stig://rule/SV-253375r958478_rule
SV-253376r958478_rule - Printing over HTTP must be prevented.
windows11 · medium (CAT II)
stig://rule/SV-253376r958478_rule
SV-253377r991589_rule - Systems must at least attempt device authentication using certificates.
windows11 · medium (CAT II)
stig://rule/SV-253377r991589_rule
SV-253378r958478_rule - The network selection user interface (UI) must not be displayed on the logon screen.
windows11 · medium (CAT II)
stig://rule/SV-253378r958478_rule
SV-253379r958478_rule - Local users on domain-joined computers must not be enumerated.
windows11 · medium (CAT II)
stig://rule/SV-253379r958478_rule
SV-253380r1051049_rule - Users must be prompted for a password on resume from sleep (on battery).
windows11 · medium (CAT II)
stig://rule/SV-253380r1051049_rule
SV-253381r1051050_rule - The user must be prompted for a password on resume from sleep (plugged in).
windows11 · medium (CAT II)
stig://rule/SV-253381r1051050_rule
SV-253382r1137695_rule - Solicited Remote Assistance must not be allowed.
windows11 · high (CAT I)
stig://rule/SV-253382r1137695_rule
SV-253383r971545_rule - Unauthenticated RPC clients must be restricted from connecting to the RPC server.
windows11 · medium (CAT II)
stig://rule/SV-253383r971545_rule
SV-253384r991589_rule - The setting to allow Microsoft accounts to be optional for modern style apps must be enabled.
windows11 · low (CAT III)
stig://rule/SV-253384r991589_rule
SV-253385r958478_rule - The Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft.
windows11 · low (CAT III)
stig://rule/SV-253385r958478_rule
SV-253386r958804_rule - Autoplay must be turned off for non-volume devices.
windows11 · high (CAT I)
stig://rule/SV-253386r958804_rule
SV-253387r958804_rule - The default autorun behavior must be configured to prevent autorun commands.
windows11 · high (CAT I)
stig://rule/SV-253387r958804_rule
SV-253388r958804_rule - Autoplay must be disabled for all drives.
windows11 · high (CAT I)
stig://rule/SV-253388r958804_rule
SV-253389r991589_rule - Enhanced anti-spoofing for facial recognition must be enabled on Windows 11.
windows11 · medium (CAT II)
stig://rule/SV-253389r991589_rule
SV-253390r958478_rule - Microsoft consumer experiences must be turned off.
windows11 · low (CAT III)
stig://rule/SV-253390r958478_rule
SV-253391r958518_rule - Administrator accounts must not be enumerated during elevation.
windows11 · medium (CAT II)
stig://rule/SV-253391r958518_rule
SV-253392r991589_rule - Enhanced diagnostic data must be limited to the minimum required to support Windows Analytics.
windows11 · medium (CAT II)
stig://rule/SV-253392r991589_rule
SV-253393r958564_rule - Windows Telemetry must not be configured to Full.
windows11 · medium (CAT II)
stig://rule/SV-253393r958564_rule
SV-253394r991589_rule - Windows Update must not obtain updates from other PCs on the internet.
windows11 · low (CAT III)
stig://rule/SV-253394r991589_rule
SV-253395r958478_rule - The Microsoft Defender SmartScreen for Explorer must be enabled.
windows11 · medium (CAT II)
stig://rule/SV-253395r958478_rule
SV-253396r958928_rule - Explorer Data Execution Prevention must be enabled.
windows11 · medium (CAT II)
stig://rule/SV-253396r958928_rule
SV-253397r958902_rule - File Explorer heap termination on corruption must be disabled.
windows11 · low (CAT III)
stig://rule/SV-253397r958902_rule
SV-253398r991589_rule - File Explorer shell protocol must run in protected mode.
windows11 · medium (CAT II)
stig://rule/SV-253398r991589_rule
SV-253399r958478_rule - Windows 11 must be configured to disable Windows Game Recording and Broadcasting.
windows11 · medium (CAT II)
stig://rule/SV-253399r958478_rule
SV-253400r991589_rule - The use of a hardware security device with Windows Hello for Business must be enabled.
windows11 · medium (CAT II)
stig://rule/SV-253400r991589_rule
SV-253401r991589_rule - Windows 11 must be configured to require a minimum pin length of six characters or greater.
windows11 · medium (CAT II)
stig://rule/SV-253401r991589_rule
SV-253402r1051051_rule - Passwords must not be saved in the Remote Desktop Client.
windows11 · medium (CAT II)
stig://rule/SV-253402r1051051_rule
SV-253403r1137695_rule - Local drives must be prevented from sharing with Remote Desktop Session Hosts.
windows11 · medium (CAT II)
stig://rule/SV-253403r1137695_rule
SV-253404r1051052_rule - Remote Desktop Services must always prompt a client for passwords upon connection.
windows11 · medium (CAT II)
stig://rule/SV-253404r1051052_rule
SV-253405r991554_rule - The Remote Desktop Session Host must require secure RPC communications.
windows11 · medium (CAT II)
stig://rule/SV-253405r991554_rule
SV-253406r958408_rule - Remote Desktop Services must be configured with the client connection encryption set to the required level.
windows11 · medium (CAT II)
stig://rule/SV-253406r958408_rule
SV-253407r991589_rule - Attachments must be prevented from being downloaded from RSS feeds.
windows11 · medium (CAT II)
stig://rule/SV-253407r991589_rule
SV-253408r958478_rule - Basic authentication for RSS feeds over HTTP must not be used.
windows11 · medium (CAT II)
stig://rule/SV-253408r958478_rule
SV-253409r958478_rule - Indexing of encrypted files must be turned off.
windows11 · medium (CAT II)
stig://rule/SV-253409r958478_rule
SV-253410r1051053_rule - Users must be prevented from changing installation options.
windows11 · medium (CAT II)
stig://rule/SV-253410r1051053_rule
SV-253411r1051054_rule - The Windows Installer feature "Always install with elevated privileges" must be disabled.
windows11 · high (CAT I)
stig://rule/SV-253411r1051054_rule
SV-253412r991589_rule - Users must be notified if a web-based program attempts to install software.
windows11 · medium (CAT II)
stig://rule/SV-253412r991589_rule
SV-253413r991591_rule - Automatically signing in the last interactive user after a system-initiated restart must be disabled.
windows11 · medium (CAT II)
stig://rule/SV-253413r991591_rule
SV-253414r958422_rule - PowerShell script block logging must be enabled on Windows 11.
windows11 · medium (CAT II)
stig://rule/SV-253414r958422_rule
SV-253415r958420_rule - PowerShell Transcription must be enabled on Windows 11.
windows11 · medium (CAT II)
stig://rule/SV-253415r958420_rule
SV-253416r958510_rule - The Windows Remote Management (WinRM) client must not use Basic authentication.
windows11 · high (CAT I)
stig://rule/SV-253416r958510_rule
SV-253417r958848_rule - The Windows Remote Management (WinRM) client must not allow unencrypted traffic.
windows11 · medium (CAT II)
stig://rule/SV-253417r958848_rule
SV-253418r958510_rule - The Windows Remote Management (WinRM) service must not use Basic authentication.
windows11 · high (CAT I)
stig://rule/SV-253418r958510_rule
SV-253419r958850_rule - The Windows Remote Management (WinRM) service must not allow unencrypted traffic.
windows11 · medium (CAT II)
stig://rule/SV-253419r958850_rule
SV-253420r1051055_rule - The Windows Remote Management (WinRM) service must not store RunAs credentials.
windows11 · medium (CAT II)
stig://rule/SV-253420r1051055_rule
SV-253421r958510_rule - The Windows Remote Management (WinRM) client must not use Digest authentication.
windows11 · medium (CAT II)
stig://rule/SV-253421r958510_rule
SV-253422r958400_rule - Windows 11 must be configured to prevent Windows apps from being activated by voice while the system is locked.
windows11 · medium (CAT II)
stig://rule/SV-253422r958400_rule
SV-253423r958478_rule - The convenience PIN for Windows 11 must be disabled.
windows11 · medium (CAT II)
stig://rule/SV-253423r958478_rule
SV-253424r958404_rule - Windows Ink Workspace must be configured to disallow access above the lock.
windows11 · medium (CAT II)
stig://rule/SV-253424r958404_rule
SV-253425r958478_rule - Windows 11 must be configured to prevent users from receiving suggestions for third-party or additional applications.
windows11 · low (CAT III)
stig://rule/SV-253425r958478_rule
SV-253426r991580_rule - Windows 11 Kernel (Direct Memory Access) DMA Protection must be enabled.
windows11 · medium (CAT II)
stig://rule/SV-253426r991580_rule
SV-253427r958448_rule - The DoD Root CA certificates must be installed in the Trusted Root Store.
windows11 · medium (CAT II)
stig://rule/SV-253427r958448_rule
SV-253428r958448_rule - The External Root CA certificates must be installed in the Trusted Root Store on unclassified systems.
windows11 · medium (CAT II)
stig://rule/SV-253428r958448_rule
SV-253429r958448_rule - The DoD Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems.
windows11 · medium (CAT II)
stig://rule/SV-253429r958448_rule
SV-253430r1081058_rule - The US DOD CCEB Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems.
windows11 · medium (CAT II)
stig://rule/SV-253430r1081058_rule
SV-253431r958726_rule - Default permissions for the HKEY_LOCAL_MACHINE registry hive must be maintained.
windows11 · medium (CAT II)
stig://rule/SV-253431r958726_rule
SV-253432r958482_rule - The built-in administrator account must be disabled.
windows11 · medium (CAT II)
stig://rule/SV-253432r958482_rule
SV-253433r958504_rule - The built-in guest account must be disabled.
windows11 · medium (CAT II)
stig://rule/SV-253433r958504_rule
SV-253434r991589_rule - Local accounts with blank passwords must be restricted to prevent access from the network.
windows11 · medium (CAT II)
stig://rule/SV-253434r991589_rule
SV-253435r991589_rule - The built-in administrator account must be renamed.
windows11 · medium (CAT II)
stig://rule/SV-253435r991589_rule
SV-253436r991589_rule - The built-in guest account must be renamed.
windows11 · medium (CAT II)
stig://rule/SV-253436r991589_rule
SV-253437r958442_rule - Audit policy using subcategories must be enabled.
windows11 · medium (CAT II)
stig://rule/SV-253437r958442_rule
SV-253438r958908_rule - Outgoing secure channel traffic must be encrypted or signed.
windows11 · medium (CAT II)
stig://rule/SV-253438r958908_rule
SV-253439r958908_rule - Outgoing secure channel traffic must be encrypted.
windows11 · medium (CAT II)
stig://rule/SV-253439r958908_rule
SV-253440r958908_rule - Outgoing secure channel traffic must be signed.
windows11 · medium (CAT II)
stig://rule/SV-253440r958908_rule
SV-253441r991589_rule - The computer account password must not be prevented from being reset.
windows11 · low (CAT III)
stig://rule/SV-253441r991589_rule
SV-253442r991589_rule - The maximum age for machine account passwords must be configured to 30 days or less.
windows11 · low (CAT III)
stig://rule/SV-253442r991589_rule
SV-253443r958908_rule - The system must be configured to require a strong session key.
windows11 · medium (CAT II)
stig://rule/SV-253443r958908_rule
SV-253444r958636_rule - The machine inactivity limit must be set to 15 minutes, locking the system with the screensaver.
windows11 · medium (CAT II)
stig://rule/SV-253444r958636_rule
SV-253445r958392_rule - The required legal notice must be configured to display before console logon.
windows11 · medium (CAT II)
stig://rule/SV-253445r958392_rule
SV-253446r958586_rule - The Windows message title for the legal notice must be configured.
windows11 · low (CAT III)
stig://rule/SV-253446r958586_rule
SV-253447r991589_rule - Caching of logon credentials must be limited.
windows11 · low (CAT III)
stig://rule/SV-253447r991589_rule
SV-253448r991589_rule - The Smart Card removal option must be configured to Force Logoff or Lock Workstation.
windows11 · medium (CAT II)
stig://rule/SV-253448r991589_rule
SV-253449r958908_rule - The Windows SMB client must be configured to always perform SMB packet signing.
windows11 · medium (CAT II)
stig://rule/SV-253449r958908_rule
SV-253450r987796_rule - Unencrypted passwords must not be sent to third-party SMB Servers.
windows11 · medium (CAT II)
stig://rule/SV-253450r987796_rule
SV-253451r958908_rule - The Windows SMB server must be configured to always perform SMB packet signing.
windows11 · medium (CAT II)
stig://rule/SV-253451r958908_rule
SV-253452r991589_rule - Anonymous SID/Name translation must not be allowed.
windows11 · high (CAT I)
stig://rule/SV-253452r991589_rule
SV-253453r991589_rule - Anonymous enumeration of SAM accounts must not be allowed.
windows11 · high (CAT I)
stig://rule/SV-253453r991589_rule
SV-253454r1137695_rule - Anonymous enumeration of shares must be restricted.
windows11 · high (CAT I)
stig://rule/SV-253454r1137695_rule
SV-253455r991589_rule - The system must be configured to prevent anonymous users from having the same rights as the Everyone group.
windows11 · medium (CAT II)
stig://rule/SV-253455r991589_rule
SV-253456r1137695_rule - Anonymous access to Named Pipes and Shares must be restricted.
windows11 · high (CAT I)
stig://rule/SV-253456r1137695_rule
SV-253457r1081060_rule - Remote calls to the Security Account Manager (SAM) must be restricted to Administrators.
windows11 · medium (CAT II)
stig://rule/SV-253457r1081060_rule
SV-253458r991589_rule - NTLM must be prevented from falling back to a Null session.
windows11 · medium (CAT II)
stig://rule/SV-253458r991589_rule
SV-253459r991589_rule - PKU2U authentication using online identities must be prevented.
windows11 · medium (CAT II)
stig://rule/SV-253459r991589_rule
SV-253460r971535_rule - Kerberos encryption types must be configured to prevent the use of DES and RC4 encryption suites.
windows11 · medium (CAT II)
stig://rule/SV-253460r971535_rule
SV-253461r1051056_rule - The system must be configured to prevent the storage of the LAN Manager hash of passwords.
windows11 · high (CAT I)
stig://rule/SV-253461r1051056_rule
SV-253462r991589_rule - The LanMan authentication level must be set to send NTLMv2 response only, and to refuse LM and NTLM.
windows11 · high (CAT I)
stig://rule/SV-253462r991589_rule
SV-253463r991589_rule - The system must be configured to the required LDAP client signing level.
windows11 · medium (CAT II)
stig://rule/SV-253463r991589_rule
SV-253464r991589_rule - The system must be configured to meet the minimum session security requirement for NTLM SSP based clients.
windows11 · medium (CAT II)
stig://rule/SV-253464r991589_rule
SV-253465r991589_rule - The system must be configured to meet the minimum session security requirement for NTLM SSP based servers.
windows11 · medium (CAT II)
stig://rule/SV-253465r991589_rule
SV-253466r1137699_rule - The system must be configured to use FIPS-compliant algorithms for encryption, hashing, and signing.
windows11 · medium (CAT II)
stig://rule/SV-253466r1137699_rule
SV-253467r991589_rule - The default permissions of global system objects must be increased.
windows11 · low (CAT III)
stig://rule/SV-253467r991589_rule
SV-253468r1051057_rule - User Account Control approval mode for the built-in Administrator must be enabled.
windows11 · medium (CAT II)
stig://rule/SV-253468r1051057_rule
SV-253469r958518_rule - User Account Control must prompt administrators for consent on the secure desktop.
windows11 · medium (CAT II)
stig://rule/SV-253469r958518_rule
SV-253470r1106510_rule - Windows 11 must use multifactor authentication for local and network access to privileged and nonprivileged accounts.
windows11 · medium (CAT II)
stig://rule/SV-253470r1106510_rule
SV-253471r1051058_rule - User Account Control must automatically deny elevation requests for standard users.
windows11 · medium (CAT II)
stig://rule/SV-253471r1051058_rule
SV-253472r958518_rule - User Account Control must be configured to detect application installations and prompt for elevation.
windows11 · medium (CAT II)
stig://rule/SV-253472r958518_rule
SV-253473r958518_rule - User Account Control must only elevate UIAccess applications that are installed in secure locations.
windows11 · medium (CAT II)
stig://rule/SV-253473r958518_rule
SV-253474r1051059_rule - User Account Control must run all administrators in Admin Approval Mode, enabling UAC.
windows11 · medium (CAT II)
stig://rule/SV-253474r1051059_rule
SV-253475r958518_rule - User Account Control must virtualize file and registry write failures to per-user locations.
windows11 · medium (CAT II)
stig://rule/SV-253475r958518_rule
SV-253476r1051060_rule - Passwords for enabled local Administrator accounts must be changed at least every 60 days.
windows11 · medium (CAT II)
stig://rule/SV-253476r1051060_rule
SV-253477r958478_rule - Toast notifications to the lock screen must be turned off.
windows11 · low (CAT III)
stig://rule/SV-253477r958478_rule
SV-253478r991589_rule - Zone information must be preserved when saving attachments.
windows11 · medium (CAT II)
stig://rule/SV-253478r991589_rule
SV-253479r958726_rule - The "Access Credential Manager as a trusted caller" user right must not be assigned to any groups or accounts.
windows11 · medium (CAT II)
stig://rule/SV-253479r958726_rule
SV-253480r1137691_rule - The "Access this computer from the network" user right must only be assigned to the Administrators and Remote Desktop Users groups.
windows11 · medium (CAT II)
stig://rule/SV-253480r1137691_rule
SV-253481r958726_rule - The "Act as part of the operating system" user right must not be assigned to any groups or accounts.
windows11 · high (CAT I)
stig://rule/SV-253481r958726_rule
SV-253482r1137691_rule - The "Allow log on locally" user right must only be assigned to the Administrators and Users groups.
windows11 · medium (CAT II)
stig://rule/SV-253482r1137691_rule
SV-253483r958726_rule - The "Back up files and directories" user right must only be assigned to the Administrators group.
windows11 · medium (CAT II)
stig://rule/SV-253483r958726_rule
SV-253484r958726_rule - The "Change the system time" user right must only be assigned to Administrators and Local Service.
windows11 · medium (CAT II)
stig://rule/SV-253484r958726_rule
SV-253485r958726_rule - The "Create a pagefile" user right must only be assigned to the Administrators group.
windows11 · medium (CAT II)
stig://rule/SV-253485r958726_rule
SV-253486r958726_rule - The "Create a token object" user right must not be assigned to any groups or accounts.
windows11 · high (CAT I)
stig://rule/SV-253486r958726_rule
SV-253487r958726_rule - The "Create global objects" user right must only be assigned to Administrators, Service, Local Service, and Network Service.
windows11 · medium (CAT II)
stig://rule/SV-253487r958726_rule
SV-253488r958726_rule - The "Create permanent shared objects" user right must not be assigned to any groups or accounts.
windows11 · medium (CAT II)
stig://rule/SV-253488r958726_rule
SV-253489r958726_rule - The "Create symbolic links" user right must only be assigned to the Administrators group.
windows11 · medium (CAT II)
stig://rule/SV-253489r958726_rule
SV-253490r958726_rule - The "Debug programs" user right must only be assigned to the Administrators group.
windows11 · high (CAT I)
stig://rule/SV-253490r958726_rule
SV-253491r1137691_rule - The "Deny access to this computer from the network" user right on workstations must be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems.
windows11 · medium (CAT II)
stig://rule/SV-253491r1137691_rule
SV-253492r1137691_rule - The "Deny log on as a batch job" user right on domain-joined workstations must be configured to prevent access from highly privileged domain accounts.
windows11 · medium (CAT II)
stig://rule/SV-253492r1137691_rule
SV-253493r1137691_rule - The "Deny log on as a service" user right on Windows 11 domain-joined workstations must be configured to prevent access from highly privileged domain accounts.
windows11 · medium (CAT II)
stig://rule/SV-253493r1137691_rule
SV-253494r1137691_rule - The "Deny log on locally" user right on workstations must be configured to prevent access from highly privileged domain accounts on domain systems and unauthenticated access on all systems.
windows11 · medium (CAT II)
stig://rule/SV-253494r1137691_rule
SV-253495r1137691_rule - The "Deny log on through Remote Desktop Services" user right on Windows 11 workstations must be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems.
windows11 · medium (CAT II)
stig://rule/SV-253495r1137691_rule
SV-253496r958726_rule - The "Enable computer and user accounts to be trusted for delegation" user right must not be assigned to any groups or accounts.
windows11 · medium (CAT II)
stig://rule/SV-253496r958726_rule
SV-253497r958726_rule - The "Force shutdown from a remote system" user right must only be assigned to the Administrators group.
windows11 · medium (CAT II)
stig://rule/SV-253497r958726_rule
SV-253498r1138526_rule - The "Impersonate a client after authentication" user right must only be assigned to Administrators, Service, Local Service, and Network Service.
windows11 · medium (CAT II)
stig://rule/SV-253498r1138526_rule
SV-253499r958726_rule - The "Load and unload device drivers" user right must only be assigned to the Administrators group.
windows11 · medium (CAT II)
stig://rule/SV-253499r958726_rule
SV-253500r958726_rule - The "Lock pages in memory" user right must not be assigned to any groups or accounts.
windows11 · medium (CAT II)
stig://rule/SV-253500r958726_rule
SV-253501r958434_rule - The "Manage auditing and security log" user right must only be assigned to the Administrators group.
windows11 · medium (CAT II)
stig://rule/SV-253501r958434_rule
SV-253502r958726_rule - The "Modify firmware environment values" user right must only be assigned to the Administrators group.
windows11 · medium (CAT II)
stig://rule/SV-253502r958726_rule
SV-253503r958726_rule - The "Perform volume maintenance tasks" user right must only be assigned to the Administrators group.
windows11 · medium (CAT II)
stig://rule/SV-253503r958726_rule
SV-253504r958726_rule - The "Profile single process" user right must only be assigned to the Administrators group.
windows11 · medium (CAT II)
stig://rule/SV-253504r958726_rule
SV-253505r958726_rule - The "Restore files and directories" user right must only be assigned to the Administrators group.
windows11 · medium (CAT II)
stig://rule/SV-253505r958726_rule
SV-253506r958726_rule - The "Take ownership of files or other objects" user right must only be assigned to the Administrators group.
windows11 · medium (CAT II)
stig://rule/SV-253506r958726_rule
SV-256893r958552_rule - Internet Explorer must be disabled for Windows 11.
windows11 · medium (CAT II)
stig://rule/SV-256893r958552_rule
SV-257592r991589_rule - Windows 11 must not have portproxy enabled or in use.
windows11 · medium (CAT II)
stig://rule/SV-257592r991589_rule
SV-257770r958412_rule - Windows 11 must have command line process auditing events enabled for failures.
windows11 · medium (CAT II)
stig://rule/SV-257770r958412_rule
SV-268317r1135320_rule - Copilot must be disabled for Windows 11.
windows11 · medium (CAT II)
stig://rule/SV-268317r1135320_rule
SV-268318r1135322_rule - Windows 11 systems must use either Group Policy or an approved Mobile Device Management (MDM) product to enforce STIG compliance.
windows11 · medium (CAT II)
stig://rule/SV-268318r1135322_rule
SV-278926r1135296_rule - Windows 11 must be configured to audit file system failures.
windows11 · medium (CAT II)
stig://rule/SV-278926r1135296_rule
SV-278927r1135299_rule - Windows 11 must be configured to audit file system successes.
windows11 · medium (CAT II)
stig://rule/SV-278927r1135299_rule
SV-278928r1135302_rule - Windows 11 must be configured to audit handle manipulation failures.
windows11 · medium (CAT II)
stig://rule/SV-278928r1135302_rule
SV-278929r1135305_rule - Windows 11 must be configured to audit handle manipulation successes.
windows11 · medium (CAT II)
stig://rule/SV-278929r1135305_rule
SV-278930r1135308_rule - Windows 11 must be configured to audit registry failures.
windows11 · medium (CAT II)
stig://rule/SV-278930r1135308_rule
SV-278931r1135311_rule - Windows 11 must be configured to audit registry successes.
windows11 · medium (CAT II)
stig://rule/SV-278931r1135311_rule
SV-278932r1141916_rule - Windows 11 must be configured to audit sensitive privilege use successes.
windows11 · medium (CAT II)
stig://rule/SV-278932r1141916_rule
SV-278933r1141919_rule - Windows 11 must be configured to audit sensitive privilege use failures.
windows11 · medium (CAT II)
stig://rule/SV-278933r1141919_rule
SV-254238r991589_rule - Windows Server 2022 users with Administrative privileges must have separate accounts for administrative duties and normal operational tasks.
windows2022 · medium (CAT II)
stig://rule/SV-254238r991589_rule
SV-254239r1081067_rule - Windows Server 2022 passwords for the built-in Administrator account must be changed at least every 60 days.
windows2022 · medium (CAT II)
stig://rule/SV-254239r1081067_rule
SV-254240r991589_rule - Windows Server 2022 administrative accounts must not be used with applications that access the internet, such as web browsers, or with potential internet sources, such as email.
windows2022 · high (CAT I)
stig://rule/SV-254240r991589_rule
SV-254241r991589_rule - Windows Server 2022 members of the Backup Operators group must have separate accounts for backup duties and normal operational tasks.
windows2022 · medium (CAT II)
stig://rule/SV-254241r991589_rule
SV-254242r1051087_rule - Windows Server 2022 manually managed application account passwords must be at least 14 characters in length.
windows2022 · medium (CAT II)
stig://rule/SV-254242r1051087_rule
SV-254243r991589_rule - Windows Server 2022 manually managed application account passwords must be changed at least annually or when a system administrator with knowledge of the password leaves the organization.
windows2022 · medium (CAT II)
stig://rule/SV-254243r991589_rule
SV-254244r958482_rule - Windows Server 2022 shared user accounts must not be permitted.
windows2022 · medium (CAT II)
stig://rule/SV-254244r958482_rule
SV-254245r958808_rule - Windows Server 2022 must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
windows2022 · medium (CAT II)
stig://rule/SV-254245r958808_rule
SV-254246r991589_rule - Windows Server 2022 domain-joined systems must have a Trusted Platform Module (TPM) enabled and ready for use.
windows2022 · medium (CAT II)
stig://rule/SV-254246r991589_rule
SV-254247r991589_rule - Windows Server 2022 must be maintained at a supported servicing level.
windows2022 · medium (CAT II)
stig://rule/SV-254247r991589_rule
SV-254248r991589_rule - Windows Server 2022 must use an antivirus program.
windows2022 · medium (CAT II)
stig://rule/SV-254248r991589_rule
SV-254249r991589_rule - Windows Server 2022 must have a host-based intrusion detection or prevention system.
windows2022 · medium (CAT II)
stig://rule/SV-254249r991589_rule
SV-254250r1137691_rule - Windows Server 2022 local volumes must use a format that supports NTFS attributes.
windows2022 · high (CAT I)
stig://rule/SV-254250r1137691_rule
SV-254251r958702_rule - Windows Server 2022 permissions for the system drive root directory (usually C:\) must conform to minimum requirements.
windows2022 · medium (CAT II)
stig://rule/SV-254251r958702_rule
SV-254252r958702_rule - Windows Server 2022 permissions for program file directories must conform to minimum requirements.
windows2022 · medium (CAT II)
stig://rule/SV-254252r958702_rule
SV-254253r958702_rule - Windows Server 2022 permissions for the Windows installation directory must conform to minimum requirements.
windows2022 · medium (CAT II)
stig://rule/SV-254253r958702_rule
SV-254254r958726_rule - Windows Server 2022 default permissions for the HKEY_LOCAL_MACHINE registry hive must be maintained.
windows2022 · medium (CAT II)
stig://rule/SV-254254r958726_rule
SV-254255r1137691_rule - Windows Server 2022 nonadministrative accounts or groups must only have print permissions on printer shares.
windows2022 · low (CAT III)
stig://rule/SV-254255r1137691_rule
SV-254256r1051088_rule - Windows Server 2022 outdated or unused accounts must be removed or disabled.
windows2022 · medium (CAT II)
stig://rule/SV-254256r1051088_rule
SV-254257r958482_rule - Windows Server 2022 accounts must require passwords.
windows2022 · medium (CAT II)
stig://rule/SV-254257r958482_rule
SV-254258r1051089_rule - Windows Server 2022 passwords must be configured to expire.
windows2022 · medium (CAT II)
stig://rule/SV-254258r1051089_rule
SV-254259r958794_rule - Windows Server 2022 system files must be monitored for unauthorized changes.
windows2022 · medium (CAT II)
stig://rule/SV-254259r958794_rule
SV-254260r1137695_rule - Windows Server 2022 nonsystem-created file shares must limit access to groups that require it.
windows2022 · medium (CAT II)
stig://rule/SV-254260r1137695_rule
SV-254261r991589_rule - Windows Server 2022 must have software certificate installation files removed.
windows2022 · medium (CAT II)
stig://rule/SV-254261r991589_rule
SV-254262r958552_rule - Windows Server 2022 systems requiring data at rest protections must employ cryptographic mechanisms to prevent unauthorized disclosure and modification of the information at rest.
windows2022 · high (CAT I)
stig://rule/SV-254262r958552_rule
SV-254263r958912_rule - Windows Server 2022 must implement protection methods such as TLS, encrypted VPNs, or IPsec if the data owner has a strict requirement for ensuring data integrity and confidentiality is maintained at every step of the data transfer and handling process.
windows2022 · medium (CAT II)
stig://rule/SV-254263r958912_rule
SV-254264r958478_rule - Windows Server 2022 must have the roles and features required by the system documented.
windows2022 · medium (CAT II)
stig://rule/SV-254264r958478_rule
SV-254265r991589_rule - Windows Server 2022 must have a host-based firewall installed and enabled.
windows2022 · medium (CAT II)
stig://rule/SV-254265r991589_rule
SV-254266r1000154_rule - Windows Server 2022 must employ automated mechanisms to determine the state of system components with regard to flaw remediation using the following frequency: continuously, where Endpoint Security Solution (ESS) is used; 30 days, for any additional internal network scans not covered by ESS; and annually, for external scans by Computer Network Defense Service Provider (CNDSP).
windows2022 · medium (CAT II)
stig://rule/SV-254266r1000154_rule
SV-254267r958364_rule - Windows Server 2022 must automatically remove or disable temporary user accounts after 72 hours.
windows2022 · medium (CAT II)
stig://rule/SV-254267r958364_rule
SV-254268r958508_rule - Windows Server 2022 must automatically remove or disable emergency accounts after the crisis is resolved or within 72 hours.
windows2022 · medium (CAT II)
stig://rule/SV-254268r958508_rule
SV-254269r958478_rule - Windows Server 2022 must not have the Fax Server role installed.
windows2022 · medium (CAT II)
stig://rule/SV-254269r958478_rule
SV-254270r958480_rule - Windows Server 2022 must not have the Microsoft FTP service installed unless required by the organization.
windows2022 · medium (CAT II)
stig://rule/SV-254270r958480_rule
SV-254271r958478_rule - Windows Server 2022 must not have the Peer Name Resolution Protocol installed.
windows2022 · medium (CAT II)
stig://rule/SV-254271r958478_rule
SV-254272r958478_rule - Windows Server 2022 must not have Simple TCP/IP Services installed.
windows2022 · medium (CAT II)
stig://rule/SV-254272r958478_rule
SV-254273r958480_rule - Windows Server 2022 must not have the Telnet Client installed.
windows2022 · medium (CAT II)
stig://rule/SV-254273r958480_rule
SV-254274r958478_rule - Windows Server 2022 must not have the TFTP Client installed.
windows2022 · medium (CAT II)
stig://rule/SV-254274r958478_rule
SV-254275r958478_rule - Windows Server 2022 must not the Server Message Block (SMB) v1 protocol installed.
windows2022 · medium (CAT II)
stig://rule/SV-254275r958478_rule
SV-254276r958478_rule - Windows Server 2022 must have the Server Message Block (SMB) v1 protocol disabled on the SMB server.
windows2022 · medium (CAT II)
stig://rule/SV-254276r958478_rule
SV-254277r958478_rule - Windows Server 2022 must have the Server Message Block (SMB) v1 protocol disabled on the SMB client.
windows2022 · medium (CAT II)
stig://rule/SV-254277r958478_rule
SV-254278r958478_rule - Windows Server 2022 must not have Windows PowerShell 2.0 installed.
windows2022 · medium (CAT II)
stig://rule/SV-254278r958478_rule
SV-254279r991589_rule - Windows Server 2022 FTP servers must be configured to prevent anonymous logons.
windows2022 · medium (CAT II)
stig://rule/SV-254279r991589_rule
SV-254280r991589_rule - Windows Server 2022 FTP servers must be configured to prevent access to the system drive.
windows2022 · medium (CAT II)
stig://rule/SV-254280r991589_rule
SV-254281r1051090_rule - The Windows Server 2022 time service must synchronize with an appropriate DOD time source.
windows2022 · low (CAT III)
stig://rule/SV-254281r1051090_rule
SV-254282r991589_rule - Windows Server 2022 must have orphaned security identifiers (SIDs) removed from user rights.
windows2022 · medium (CAT II)
stig://rule/SV-254282r991589_rule
SV-254283r991589_rule - Windows Server 2022 systems must have Unified Extensible Firmware Interface (UEFI) firmware and be configured to run in UEFI mode, not Legacy BIOS.
windows2022 · medium (CAT II)
stig://rule/SV-254283r991589_rule
SV-254284r991589_rule - Windows Server 2022 must have Secure Boot enabled.
windows2022 · medium (CAT II)
stig://rule/SV-254284r991589_rule
SV-254285r958736_rule - Windows Server 2022 account lockout duration must be configured to 15 minutes or greater.
windows2022 · medium (CAT II)
stig://rule/SV-254285r958736_rule
SV-254286r958388_rule - Windows Server 2022 must have the number of allowed bad logon attempts configured to three or less.
windows2022 · medium (CAT II)
stig://rule/SV-254286r958388_rule
SV-254287r958388_rule - Windows Server 2022 must have the period of time before the bad logon counter is reset configured to 15 minutes or greater.
windows2022 · medium (CAT II)
stig://rule/SV-254287r958388_rule
SV-254288r1000156_rule - Windows Server 2022 password history must be configured to 24 passwords remembered.
windows2022 · medium (CAT II)
stig://rule/SV-254288r1000156_rule
SV-254289r1051091_rule - Windows Server 2022 maximum password age must be configured to 60 days or less.
windows2022 · medium (CAT II)
stig://rule/SV-254289r1051091_rule
SV-254290r1051092_rule - Windows Server 2022 minimum password age must be configured to at least one day.
windows2022 · medium (CAT II)
stig://rule/SV-254290r1051092_rule
SV-254291r1051093_rule - Windows Server 2022 minimum password length must be configured to 14 characters.
windows2022 · medium (CAT II)
stig://rule/SV-254291r1051093_rule
SV-254292r1051094_rule - Windows Server 2022 must have the built-in Windows password complexity policy enabled.
windows2022 · medium (CAT II)
stig://rule/SV-254292r1051094_rule
SV-254293r1051095_rule - Windows Server 2022 reversible password encryption must be disabled.
windows2022 · high (CAT I)
stig://rule/SV-254293r1051095_rule
SV-254294r958754_rule - Windows Server 2022 audit records must be backed up to a different system or media than the system being audited.
windows2022 · medium (CAT II)
stig://rule/SV-254294r958754_rule
SV-254295r959008_rule - Windows Server 2022 must, at a minimum, offload audit records of interconnected systems in real time and offload standalone or nondomain-joined systems weekly.
windows2022 · medium (CAT II)
stig://rule/SV-254295r959008_rule
SV-254296r958434_rule - Windows Server 2022 permissions for the Application event log must prevent access by nonprivileged accounts.
windows2022 · medium (CAT II)
stig://rule/SV-254296r958434_rule
SV-254297r958434_rule - Windows Server 2022 permissions for the Security event log must prevent access by nonprivileged accounts.
windows2022 · medium (CAT II)
stig://rule/SV-254297r958434_rule
SV-254298r958434_rule - Windows Server 2022 permissions for the System event log must prevent access by nonprivileged accounts.
windows2022 · medium (CAT II)
stig://rule/SV-254298r958434_rule
SV-254299r991558_rule - Windows Server 2022 Event Viewer must be protected from unauthorized modification and deletion.
windows2022 · medium (CAT II)
stig://rule/SV-254299r991558_rule
SV-254300r991578_rule - Windows Server 2022 must be configured to audit Account Logon - Credential Validation successes.
windows2022 · medium (CAT II)
stig://rule/SV-254300r991578_rule
SV-254301r991578_rule - Windows Server 2022 must be configured to audit Account Logon - Credential Validation failures.
windows2022 · medium (CAT II)
stig://rule/SV-254301r991578_rule
SV-254302r958732_rule - Windows Server 2022 must be configured to audit Account Management - Other Account Management Events successes.
windows2022 · medium (CAT II)
stig://rule/SV-254302r958732_rule
SV-254303r958368_rule - Windows Server 2022 must be configured to audit Account Management - Security Group Management successes.
windows2022 · medium (CAT II)
stig://rule/SV-254303r958368_rule
SV-254304r958368_rule - Windows Server 2022 must be configured to audit Account Management - User Account Management successes.
windows2022 · medium (CAT II)
stig://rule/SV-254304r958368_rule
SV-254305r958368_rule - Windows Server 2022 must be configured to audit Account Management - User Account Management failures.
windows2022 · medium (CAT II)
stig://rule/SV-254305r958368_rule
SV-254306r991583_rule - Windows Server 2022 must be configured to audit Detailed Tracking - Plug and Play Events successes.
windows2022 · medium (CAT II)
stig://rule/SV-254306r991583_rule
SV-254307r958732_rule - Windows Server 2022 must be configured to audit Detailed Tracking - Process Creation successes.
windows2022 · medium (CAT II)
stig://rule/SV-254307r958732_rule
SV-254309r991552_rule - Windows Server 2022 must be configured to audit Logon/Logoff - Account Lockout failures.
windows2022 · medium (CAT II)
stig://rule/SV-254309r991552_rule
SV-254310r991578_rule - Windows Server 2022 must be configured to audit Logon/Logoff - Group Membership successes.
windows2022 · medium (CAT II)
stig://rule/SV-254310r991578_rule
SV-254311r991581_rule - Windows Server 2022 must be configured to audit logoff successes.
windows2022 · medium (CAT II)
stig://rule/SV-254311r991581_rule
SV-254312r958406_rule - Windows Server 2022 must be configured to audit logon successes.
windows2022 · medium (CAT II)
stig://rule/SV-254312r958406_rule
SV-254313r958406_rule - Windows Server 2022 must be configured to audit logon failures.
windows2022 · medium (CAT II)
stig://rule/SV-254313r958406_rule
SV-254314r991578_rule - Windows Server 2022 must be configured to audit Logon/Logoff - Special Logon successes.
windows2022 · medium (CAT II)
stig://rule/SV-254314r991578_rule
SV-254315r991578_rule - Windows Server 2022 must be configured to audit Object Access - Other Object Access Events successes.
windows2022 · medium (CAT II)
stig://rule/SV-254315r991578_rule
SV-254316r991578_rule - Windows Server 2022 must be configured to audit Object Access - Other Object Access Events failures.
windows2022 · medium (CAT II)
stig://rule/SV-254316r991578_rule
SV-254317r991583_rule - Windows Server 2022 must be configured to audit Object Access - Removable Storage successes.
windows2022 · medium (CAT II)
stig://rule/SV-254317r991583_rule
SV-254318r991583_rule - Windows Server 2022 must be configured to audit Object Access - Removable Storage failures.
windows2022 · medium (CAT II)
stig://rule/SV-254318r991583_rule
SV-254319r958732_rule - Windows Server 2022 must be configured to audit Policy Change - Audit Policy Change successes.
windows2022 · medium (CAT II)
stig://rule/SV-254319r958732_rule
SV-254320r958732_rule - Windows Server 2022 must be configured to audit Policy Change - Audit Policy Change failures.
windows2022 · medium (CAT II)
stig://rule/SV-254320r958732_rule
SV-254321r958732_rule - Windows Server 2022 must be configured to audit Policy Change - Authentication Policy Change successes.
windows2022 · medium (CAT II)
stig://rule/SV-254321r958732_rule
SV-254322r958732_rule - Windows Server 2022 must be configured to audit Policy Change - Authorization Policy Change successes.
windows2022 · medium (CAT II)
stig://rule/SV-254322r958732_rule
SV-254323r958732_rule - Windows Server 2022 must be configured to audit Privilege Use - Sensitive Privilege Use successes.
windows2022 · medium (CAT II)
stig://rule/SV-254323r958732_rule
SV-254324r958732_rule - Windows Server 2022 must be configured to audit Privilege Use - Sensitive Privilege Use failures.
windows2022 · medium (CAT II)
stig://rule/SV-254324r958732_rule
SV-254325r958732_rule - Windows Server 2022 must be configured to audit System - IPsec Driver successes.
windows2022 · medium (CAT II)
stig://rule/SV-254325r958732_rule
SV-254326r958732_rule - Windows Server 2022 must be configured to audit System - IPsec Driver failures.
windows2022 · medium (CAT II)
stig://rule/SV-254326r958732_rule
SV-254327r958732_rule - Windows Server 2022 must be configured to audit System - Other System Events successes.
windows2022 · medium (CAT II)
stig://rule/SV-254327r958732_rule
SV-254328r958732_rule - Windows Server 2022 must be configured to audit System - Other System Events failures.
windows2022 · medium (CAT II)
stig://rule/SV-254328r958732_rule
SV-254329r958732_rule - Windows Server 2022 must be configured to audit System - Security State Change successes.
windows2022 · medium (CAT II)
stig://rule/SV-254329r958732_rule
SV-254330r958732_rule - Windows Server 2022 must be configured to audit System - Security System Extension successes.
windows2022 · medium (CAT II)
stig://rule/SV-254330r958732_rule
SV-254331r958732_rule - Windows Server 2022 must be configured to audit System - System Integrity successes.
windows2022 · medium (CAT II)
stig://rule/SV-254331r958732_rule
SV-254332r958732_rule - Windows Server 2022 must be configured to audit System - System Integrity failures.
windows2022 · medium (CAT II)
stig://rule/SV-254332r958732_rule
SV-254333r958478_rule - Windows Server 2022 must prevent the display of slide shows on the lock screen.
windows2022 · medium (CAT II)
stig://rule/SV-254333r958478_rule
SV-254334r958478_rule - Windows Server 2022 must have WDigest Authentication disabled.
windows2022 · medium (CAT II)
stig://rule/SV-254334r958478_rule
SV-254335r991589_rule - Windows Server 2022 Internet Protocol version 6 (IPv6) source routing must be configured to the highest protection level to prevent IP source routing.
windows2022 · low (CAT III)
stig://rule/SV-254335r991589_rule
SV-254336r991589_rule - Windows Server 2022 source routing must be configured to the highest protection level to prevent Internet Protocol (IP) source routing.
windows2022 · low (CAT III)
stig://rule/SV-254336r991589_rule
SV-254337r991589_rule - Windows Server 2022 must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF)-generated routes.
windows2022 · low (CAT III)
stig://rule/SV-254337r991589_rule
SV-254338r958902_rule - Windows Server 2022 must be configured to ignore NetBIOS name release requests except from WINS servers.
windows2022 · low (CAT III)
stig://rule/SV-254338r958902_rule
SV-254339r991589_rule - Windows Server 2022 insecure logons to an SMB server must be disabled.
windows2022 · medium (CAT II)
stig://rule/SV-254339r991589_rule
SV-254340r991589_rule - Windows Server 2022 hardened Universal Naming Convention (UNC) paths must be defined to require mutual authentication and integrity for at least the \\*\SYSVOL and \\*\NETLOGON shares.
windows2022 · medium (CAT II)
stig://rule/SV-254340r991589_rule
SV-254341r958422_rule - Windows Server 2022 command line data must be included in process creation events.
windows2022 · medium (CAT II)
stig://rule/SV-254341r958422_rule
SV-254342r991589_rule - Windows Server 2022 must be configured to enable Remote host allows delegation of nonexportable credentials.
windows2022 · medium (CAT II)
stig://rule/SV-254342r991589_rule
SV-254343r991589_rule - Windows Server 2022 virtualization-based security must be enabled with the platform security level configured to Secure Boot or Secure Boot with DMA Protection.
windows2022 · medium (CAT II)
stig://rule/SV-254343r991589_rule
SV-254344r991589_rule - Windows Server 2022 Early Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers identified as bad.
windows2022 · medium (CAT II)
stig://rule/SV-254344r991589_rule
SV-254345r1135378_rule - Windows Server 2022 group policy objects must be reprocessed even if they have not changed.
windows2022 · medium (CAT II)
stig://rule/SV-254345r1135378_rule
SV-254346r958478_rule - Windows Server 2022 downloading print driver packages over HTTP must be turned off.
windows2022 · medium (CAT II)
stig://rule/SV-254346r958478_rule
SV-254347r958478_rule - Windows Server 2022 printing over HTTP must be turned off.
windows2022 · medium (CAT II)
stig://rule/SV-254347r958478_rule
SV-254348r958478_rule - Windows Server 2022 network selection user interface (UI) must not be displayed on the logon screen.
windows2022 · medium (CAT II)
stig://rule/SV-254348r958478_rule
SV-254349r991589_rule - Windows Server 2022 users must be prompted to authenticate when the system wakes from sleep (on battery).
windows2022 · medium (CAT II)
stig://rule/SV-254349r991589_rule
SV-254350r991589_rule - Windows Server 2022 users must be prompted to authenticate when the system wakes from sleep (plugged in).
windows2022 · medium (CAT II)
stig://rule/SV-254350r991589_rule
SV-254351r958478_rule - Windows Server 2022 Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft.
windows2022 · low (CAT III)
stig://rule/SV-254351r958478_rule
SV-254352r958804_rule - Windows Server 2022 Autoplay must be turned off for nonvolume devices.
windows2022 · high (CAT I)
stig://rule/SV-254352r958804_rule
SV-254353r958804_rule - Windows Server 2022 default AutoRun behavior must be configured to prevent AutoRun commands.
windows2022 · high (CAT I)
stig://rule/SV-254353r958804_rule
SV-254354r958804_rule - Windows Server 2022 AutoPlay must be disabled for all drives.
windows2022 · high (CAT I)
stig://rule/SV-254354r958804_rule
SV-254355r958518_rule - Windows Server 2022 administrator accounts must not be enumerated during elevation.
windows2022 · medium (CAT II)
stig://rule/SV-254355r958518_rule
SV-254356r991589_rule - Windows Server 2022 Diagnostic Data must be configured to send "required diagnostic data" or "optional diagnostic data".
windows2022 · medium (CAT II)
stig://rule/SV-254356r991589_rule
SV-254357r991589_rule - Windows Server 2022 Windows Update must not obtain updates from other PCs on the internet.
windows2022 · low (CAT III)
stig://rule/SV-254357r991589_rule
SV-254358r958752_rule - Windows Server 2022 Application event log size must be configured to 32768 KB or greater.
windows2022 · medium (CAT II)
stig://rule/SV-254358r958752_rule
SV-254359r958752_rule - Windows Server 2022 Security event log size must be configured to 196608 KB or greater.
windows2022 · medium (CAT II)
stig://rule/SV-254359r958752_rule
SV-254360r958752_rule - Windows Server 2022 System event log size must be configured to 32768 KB or greater.
windows2022 · medium (CAT II)
stig://rule/SV-254360r958752_rule
SV-254361r958478_rule - Windows Server 2022 Microsoft Defender antivirus SmartScreen must be enabled.
windows2022 · medium (CAT II)
stig://rule/SV-254361r958478_rule
SV-254362r958928_rule - Windows Server 2022 Explorer Data Execution Prevention must be enabled.
windows2022 · medium (CAT II)
stig://rule/SV-254362r958928_rule
SV-254363r991589_rule - Windows Server 2022 Turning off File Explorer heap termination on corruption must be disabled.
windows2022 · low (CAT III)
stig://rule/SV-254363r991589_rule
SV-254364r991589_rule - Windows Server 2022 File Explorer shell protocol must run in protected mode.
windows2022 · medium (CAT II)
stig://rule/SV-254364r991589_rule
SV-254365r1051096_rule - Windows Server 2022 must not save passwords in the Remote Desktop Client.
windows2022 · medium (CAT II)
stig://rule/SV-254365r1051096_rule
SV-254366r1137695_rule - Windows Server 2022 Remote Desktop Services must prevent drive redirection.
windows2022 · medium (CAT II)
stig://rule/SV-254366r1137695_rule
SV-254367r1051097_rule - Windows Server 2022 Remote Desktop Services must always prompt a client for passwords upon connection.
windows2022 · medium (CAT II)
stig://rule/SV-254367r1051097_rule
SV-254368r958408_rule - Windows Server 2022 Remote Desktop Services must require secure Remote Procedure Call (RPC) communications.
windows2022 · medium (CAT II)
stig://rule/SV-254368r958408_rule
SV-254369r958408_rule - Windows Server 2022 Remote Desktop Services must be configured with the client connection encryption set to High Level.
windows2022 · medium (CAT II)
stig://rule/SV-254369r958408_rule
SV-254370r991589_rule - Windows Server 2022 must prevent attachments from being downloaded from RSS feeds.
windows2022 · medium (CAT II)
stig://rule/SV-254370r991589_rule
SV-254371r958478_rule - Windows Server 2022 must disable Basic authentication for RSS feeds over HTTP.
windows2022 · medium (CAT II)
stig://rule/SV-254371r958478_rule
SV-254372r958478_rule - Windows Server 2022 must prevent Indexing of encrypted files.
windows2022 · medium (CAT II)
stig://rule/SV-254372r958478_rule
SV-254373r1051098_rule - Windows Server 2022 must prevent users from changing installation options.
windows2022 · medium (CAT II)
stig://rule/SV-254373r1051098_rule
SV-254374r1051099_rule - Windows Server 2022 must disable the Windows Installer Always install with elevated privileges option.
windows2022 · high (CAT I)
stig://rule/SV-254374r1051099_rule
SV-254375r991589_rule - Windows Server 2022 users must be notified if a web-based program attempts to install software.
windows2022 · medium (CAT II)
stig://rule/SV-254375r991589_rule
SV-254376r991591_rule - Windows Server 2022 must disable automatically signing in the last interactive user after a system-initiated restart.
windows2022 · medium (CAT II)
stig://rule/SV-254376r991591_rule
SV-254377r958422_rule - Windows Server 2022 PowerShell script block logging must be enabled.
windows2022 · medium (CAT II)
stig://rule/SV-254377r958422_rule
SV-254378r958510_rule - Windows Server 2022 Windows Remote Management (WinRM) client must not use Basic authentication.
windows2022 · high (CAT I)
stig://rule/SV-254378r958510_rule
SV-254379r958848_rule - Windows Server 2022 Windows Remote Management (WinRM) client must not allow unencrypted traffic.
windows2022 · medium (CAT II)
stig://rule/SV-254379r958848_rule
SV-254380r958510_rule - Windows Server 2022 Windows Remote Management (WinRM) client must not use Digest authentication.
windows2022 · medium (CAT II)
stig://rule/SV-254380r958510_rule
SV-254381r958510_rule - Windows Server 2022 Windows Remote Management (WinRM) service must not use Basic authentication.
windows2022 · high (CAT I)
stig://rule/SV-254381r958510_rule
SV-254382r958848_rule - Windows Server 2022 Windows Remote Management (WinRM) service must not allow unencrypted traffic.
windows2022 · medium (CAT II)
stig://rule/SV-254382r958848_rule
SV-254383r1051100_rule - Windows Server 2022 Windows Remote Management (WinRM) service must not store RunAs credentials.
windows2022 · medium (CAT II)
stig://rule/SV-254383r1051100_rule
SV-254384r958420_rule - Windows Server 2022 must have PowerShell Transcription enabled.
windows2022 · medium (CAT II)
stig://rule/SV-254384r958420_rule
SV-254385r958726_rule - Windows Server 2022 must only allow administrators responsible for the domain controller to have Administrator rights on the system.
windows2022 · high (CAT I)
stig://rule/SV-254385r958726_rule
SV-254386r1051101_rule - Windows Server 2022 Kerberos user logon restrictions must be enforced.
windows2022 · medium (CAT II)
stig://rule/SV-254386r1051101_rule
SV-254387r1051102_rule - Windows Server 2022 Kerberos service ticket maximum lifetime must be limited to 600 minutes or less.
windows2022 · medium (CAT II)
stig://rule/SV-254387r1051102_rule
SV-254388r1051103_rule - Windows Server 2022 Kerberos user ticket lifetime must be limited to 10 hours or less.
windows2022 · medium (CAT II)
stig://rule/SV-254388r1051103_rule
SV-254389r1051104_rule - Windows Server 2022 Kerberos policy user ticket renewal maximum lifetime must be limited to seven days or less.
windows2022 · medium (CAT II)
stig://rule/SV-254389r1051104_rule
SV-254390r1051105_rule - Windows Server 2022 computer clock synchronization tolerance must be limited to five minutes or less.
windows2022 · medium (CAT II)
stig://rule/SV-254390r1051105_rule
SV-254391r958726_rule - Windows Server 2022 permissions on the Active Directory data files must only allow System and Administrators access.
windows2022 · high (CAT I)
stig://rule/SV-254391r958726_rule
SV-254392r958726_rule - Windows Server 2022 Active Directory SYSVOL directory must have the proper access control permissions.
windows2022 · high (CAT I)
stig://rule/SV-254392r958726_rule
SV-254393r1081073_rule - Windows Server 2022 Active Directory Group Policy objects must have proper access control permissions.
windows2022 · high (CAT I)
stig://rule/SV-254393r1081073_rule
SV-254394r958726_rule - Windows Server 2022 Active Directory Domain Controllers Organizational Unit (OU) object must have the proper access control permissions.
windows2022 · high (CAT I)
stig://rule/SV-254394r958726_rule
SV-254395r958726_rule - Windows Server 2022 organization created Active Directory Organizational Unit (OU) objects must have proper access control permissions.
windows2022 · high (CAT I)
stig://rule/SV-254395r958726_rule
SV-254396r1137695_rule - Windows Server 2022 data files owned by users must be on a different logical partition from the directory server data files.
windows2022 · medium (CAT II)
stig://rule/SV-254396r1137695_rule
SV-254397r958478_rule - Windows Server 2022 domain controllers must run on a machine dedicated to that function.
windows2022 · medium (CAT II)
stig://rule/SV-254397r958478_rule
SV-254398r987791_rule - Windows Server 2022 must use separate, NSA-approved (Type 1) cryptography to protect the directory data in transit for directory service implementations at a classified confidentiality level when replication data traverses a network cleared to a lower level than the data.
windows2022 · medium (CAT II)
stig://rule/SV-254398r987791_rule
SV-254399r991589_rule - Windows Server 2022 directory data (outside the root DSE) of a nonpublic directory must be configured to prevent anonymous access.
windows2022 · high (CAT I)
stig://rule/SV-254399r991589_rule
SV-254400r970703_rule - Windows Server 2022 directory service must be configured to terminate LDAP-based network connections to the directory server after five minutes of inactivity.
windows2022 · low (CAT III)
stig://rule/SV-254400r970703_rule
SV-254401r958732_rule - Windows Server 2022 Active Directory Group Policy objects must be configured with proper audit settings.
windows2022 · medium (CAT II)
stig://rule/SV-254401r958732_rule
SV-254402r958732_rule - Windows Server 2022 Active Directory Domain object must be configured with proper audit settings.
windows2022 · medium (CAT II)
stig://rule/SV-254402r958732_rule
SV-254403r958732_rule - Windows Server 2022 Active Directory Infrastructure object must be configured with proper audit settings.
windows2022 · medium (CAT II)
stig://rule/SV-254403r958732_rule
SV-254404r958732_rule - Windows Server 2022 Active Directory Domain Controllers Organizational Unit (OU) object must be configured with proper audit settings.
windows2022 · medium (CAT II)
stig://rule/SV-254404r958732_rule
SV-254405r958732_rule - Windows Server 2022 Active Directory AdminSDHolder object must be configured with proper audit settings.
windows2022 · medium (CAT II)
stig://rule/SV-254405r958732_rule
SV-254406r958732_rule - Windows Server 2022 Active Directory RID Manager$ object must be configured with proper audit settings.
windows2022 · medium (CAT II)
stig://rule/SV-254406r958732_rule
SV-254407r958368_rule - Windows Server 2022 must be configured to audit Account Management - Computer Account Management successes.
windows2022 · medium (CAT II)
stig://rule/SV-254407r958368_rule
SV-254408r958732_rule - Windows Server 2022 must be configured to audit DS Access - Directory Service Access successes.
windows2022 · medium (CAT II)
stig://rule/SV-254408r958732_rule
SV-254409r958732_rule - Windows Server 2022 must be configured to audit DS Access - Directory Service Access failures.
windows2022 · medium (CAT II)
stig://rule/SV-254409r958732_rule
SV-254410r958732_rule - Windows Server 2022 must be configured to audit DS Access - Directory Service Changes successes.
windows2022 · medium (CAT II)
stig://rule/SV-254410r958732_rule
SV-254412r958448_rule - Windows Server 2022 domain controllers must have a PKI server certificate.
windows2022 · medium (CAT II)
stig://rule/SV-254412r958448_rule
SV-254413r958448_rule - Windows Server 2022 domain Controller PKI certificates must be issued by the DoD PKI or an approved External Certificate Authority (ECA).
windows2022 · high (CAT I)
stig://rule/SV-254413r958448_rule
SV-254414r958448_rule - Windows Server 2022 PKI certificates associated with user accounts must be issued by a DoD PKI or an approved External Certificate Authority (ECA).
windows2022 · high (CAT I)
stig://rule/SV-254414r958448_rule
SV-254415r1081074_rule - Windows Server 2022 Active Directory user accounts, including administrators, must be configured to require the use of a Common Access Card (CAC), Personal Identity Verification (PIV)-compliant hardware token, or Alternate Logon Token (ALT) for user authentication.
windows2022 · medium (CAT II)
stig://rule/SV-254415r1081074_rule
SV-254416r958908_rule - Windows Server 2022 domain controllers must require LDAP access signing.
windows2022 · medium (CAT II)
stig://rule/SV-254416r958908_rule
SV-254417r991589_rule - Windows Server 2022 domain controllers must be configured to allow reset of machine account passwords.
windows2022 · medium (CAT II)
stig://rule/SV-254417r991589_rule
SV-254418r1137691_rule - Windows Server 2022 Access this computer from the network user right must only be assigned to the Administrators, Authenticated Users, and
Enterprise Domain Controllers groups on domain controllers.
windows2022 · medium (CAT II)
stig://rule/SV-254418r1137691_rule
SV-254419r958726_rule - Windows Server 2022 Add workstations to domain user right must only be assigned to the Administrators group on domain controllers.
windows2022 · medium (CAT II)
stig://rule/SV-254419r958726_rule
SV-254420r1137691_rule - Windows Server 2022 Allow log on through Remote Desktop Services user right must only be assigned to the Administrators group on domain controllers.
windows2022 · medium (CAT II)
stig://rule/SV-254420r1137691_rule
SV-254421r1137691_rule - Windows Server 2022 Deny access to this computer from the network user right on domain controllers must be configured to prevent unauthenticated access.
windows2022 · medium (CAT II)
stig://rule/SV-254421r1137691_rule
SV-254422r1137691_rule - Windows Server 2022 Deny log on as a batch job user right on domain controllers must be configured to prevent unauthenticated access.
windows2022 · medium (CAT II)
stig://rule/SV-254422r1137691_rule
SV-254423r1137691_rule - Windows Server 2022 Deny log on as a service user right must be configured to include no accounts or groups (blank) on domain controllers.
windows2022 · medium (CAT II)
stig://rule/SV-254423r1137691_rule
SV-254424r1137691_rule - Windows Server 2022 Deny log on locally user right on domain controllers must be configured to prevent unauthenticated access.
windows2022 · medium (CAT II)
stig://rule/SV-254424r1137691_rule
SV-254425r958672_rule - Windows Server 2022 Deny log on through Remote Desktop Services user right on domain controllers must be configured to prevent unauthenticated access.
windows2022 · medium (CAT II)
stig://rule/SV-254425r958672_rule
SV-254426r958726_rule - Windows Server 2022 Enable computer and user accounts to be trusted for delegation user right must only be assigned to the Administrators group on domain controllers.
windows2022 · medium (CAT II)
stig://rule/SV-254426r958726_rule
SV-254427r991589_rule - The password for the krbtgt account on a domain must be reset at least every 180 days.
windows2022 · medium (CAT II)
stig://rule/SV-254427r991589_rule
SV-254428r958726_rule - Windows Server 2022 must only allow administrators responsible for the member server or standalone or nondomain-joined system to have Administrator rights on the system.
windows2022 · high (CAT I)
stig://rule/SV-254428r958726_rule
SV-254429r958518_rule - Windows Server 2022 local administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain-joined member servers.
windows2022 · medium (CAT II)
stig://rule/SV-254429r958518_rule
SV-254430r958478_rule - Windows Server 2022 local users on domain-joined member servers must not be enumerated.
windows2022 · medium (CAT II)
stig://rule/SV-254430r958478_rule
SV-254431r971545_rule - Windows Server 2022 must restrict unauthenticated Remote Procedure Call (RPC) clients from connecting to the RPC server on domain-joined member servers and standalone or nondomain-joined systems.
windows2022 · medium (CAT II)
stig://rule/SV-254431r971545_rule
SV-254432r991589_rule - Windows Server 2022 must limit the caching of logon credentials to four or less on domain-joined member servers.
windows2022 · medium (CAT II)
stig://rule/SV-254432r991589_rule
SV-254433r1106522_rule - Windows Server 2022 must restrict remote calls to the Security Account Manager (SAM) to Administrators on domain-joined member servers and standalone or nondomain-joined systems.
windows2022 · medium (CAT II)
stig://rule/SV-254433r1106522_rule
SV-254434r1137691_rule - Windows Server 2022 Access this computer from the network user right must only be assigned to the Administrators and Authenticated Users groups on domain-joined member servers and standalone or nondomain-joined systems.
windows2022 · medium (CAT II)
stig://rule/SV-254434r1137691_rule
SV-254435r1137691_rule - Windows Server 2022 Deny access to this computer from the network user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and local accounts and from unauthenticated access on all systems.
windows2022 · medium (CAT II)
stig://rule/SV-254435r1137691_rule
SV-254436r1137691_rule - Windows Server 2022 Deny log on as a batch job user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and from unauthenticated access on all systems.
windows2022 · medium (CAT II)
stig://rule/SV-254436r1137691_rule
SV-254437r1137691_rule - Windows Server 2022 Deny log on as a service user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts. No other groups or accounts must be assigned this right.
windows2022 · medium (CAT II)
stig://rule/SV-254437r1137691_rule
SV-254438r1137691_rule - Windows Server 2022 Deny log on locally user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and from unauthenticated access on all systems.
windows2022 · medium (CAT II)
stig://rule/SV-254438r1137691_rule
SV-254439r958672_rule - Windows Server 2022 Deny log on through Remote Desktop Services user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and all local accounts and from unauthenticated access on all systems.
windows2022 · medium (CAT II)
stig://rule/SV-254439r958672_rule
SV-254440r958726_rule - Windows Server 2022 Enable computer and user accounts to be trusted for delegation user right must not be assigned to any groups or accounts on domain-joined member servers and standalone or nondomain-joined systems.
windows2022 · medium (CAT II)
stig://rule/SV-254440r958726_rule
SV-254441r991589_rule - Windows Server 2022 must be running Credential Guard on domain-joined member servers.
windows2022 · high (CAT I)
stig://rule/SV-254441r991589_rule
SV-254442r958448_rule - Windows Server 2022 must have the DoD Root Certificate Authority (CA) certificates installed in the Trusted Root Store.
windows2022 · medium (CAT II)
stig://rule/SV-254442r958448_rule
SV-254443r958448_rule - Windows Server 2022 must have the DoD Interoperability Root Certificate Authority (CA) cross-certificates installed in the Untrusted Certificates Store on unclassified systems.
windows2022 · medium (CAT II)
stig://rule/SV-254443r958448_rule
SV-254444r1081077_rule - Windows Server 2022 must have the US DOD CCEB Interoperability Root CA cross-certificates in the Untrusted Certificates Store on unclassified systems.
windows2022 · medium (CAT II)
stig://rule/SV-254444r1081077_rule
SV-254445r958504_rule - Windows Server 2022 must have the built-in guest account disabled.
windows2022 · medium (CAT II)
stig://rule/SV-254445r958504_rule
SV-254446r991589_rule - Windows Server 2022 must prevent local accounts with blank passwords from being used from the network.
windows2022 · high (CAT I)
stig://rule/SV-254446r991589_rule
SV-254447r991589_rule - Windows Server 2022 built-in administrator account must be renamed.
windows2022 · medium (CAT II)
stig://rule/SV-254447r991589_rule
SV-254448r991589_rule - Windows Server 2022 built-in guest account must be renamed.
windows2022 · medium (CAT II)
stig://rule/SV-254448r991589_rule
SV-254449r958442_rule - Windows Server 2022 must force audit policy subcategory settings to override audit policy category settings.
windows2022 · medium (CAT II)
stig://rule/SV-254449r958442_rule
SV-254450r958908_rule - Windows Server 2022 setting Domain member: Digitally encrypt or sign secure channel data (always) must be configured to Enabled.
windows2022 · medium (CAT II)
stig://rule/SV-254450r958908_rule
SV-254451r958908_rule - Windows Server 2022 setting Domain member: Digitally encrypt secure channel data (when possible) must be configured to Enabled.
windows2022 · medium (CAT II)
stig://rule/SV-254451r958908_rule
SV-254452r958908_rule - Windows Server 2022 setting Domain member: Digitally sign secure channel data (when possible) must be configured to Enabled.
windows2022 · medium (CAT II)
stig://rule/SV-254452r958908_rule
SV-254453r971545_rule - Windows Server 2022 computer account password must not be prevented from being reset.
windows2022 · medium (CAT II)
stig://rule/SV-254453r971545_rule
SV-254454r991589_rule - Windows Server 2022 maximum age for machine account passwords must be configured to 30 days or less.
windows2022 · medium (CAT II)
stig://rule/SV-254454r991589_rule
SV-254455r958908_rule - Windows Server 2022 must be configured to require a strong session key.
windows2022 · medium (CAT II)
stig://rule/SV-254455r958908_rule
SV-254456r958400_rule - Windows Server 2022 machine inactivity limit must be set to 15 minutes or less, locking the system with the screen saver.
windows2022 · medium (CAT II)
stig://rule/SV-254456r958400_rule
SV-254457r958390_rule - Windows Server 2022 required legal notice must be configured to display before console logon.
windows2022 · medium (CAT II)
stig://rule/SV-254457r958390_rule
SV-254458r958390_rule - Windows Server 2022 title for legal banner dialog box must be configured with the appropriate text.
windows2022 · low (CAT III)
stig://rule/SV-254458r958390_rule
SV-254459r991589_rule - Windows Server 2022 Smart Card removal option must be configured to Force Logoff or Lock Workstation.
windows2022 · medium (CAT II)
stig://rule/SV-254459r991589_rule
SV-254460r958908_rule - Windows Server 2022 setting Microsoft network client: Digitally sign communications (always) must be configured to Enabled.
windows2022 · medium (CAT II)
stig://rule/SV-254460r958908_rule
SV-254461r958908_rule - Windows Server 2022 setting Microsoft network client: Digitally sign communications (if server agrees) must be configured to Enabled.
windows2022 · medium (CAT II)
stig://rule/SV-254461r958908_rule
SV-254462r987796_rule - Windows Server 2022 unencrypted passwords must not be sent to third-party Server Message Block (SMB) servers.
windows2022 · medium (CAT II)
stig://rule/SV-254462r987796_rule
SV-254463r958908_rule - Windows Server 2022 setting Microsoft network server: Digitally sign communications (always) must be configured to Enabled.
windows2022 · medium (CAT II)
stig://rule/SV-254463r958908_rule
SV-254464r958908_rule - Windows Server 2022 setting Microsoft network server: Digitally sign communications (if client agrees) must be configured to Enabled.
windows2022 · medium (CAT II)
stig://rule/SV-254464r958908_rule
SV-254465r991589_rule - Windows Server 2022 must not allow anonymous SID/Name translation.
windows2022 · high (CAT I)
stig://rule/SV-254465r991589_rule
SV-254466r991589_rule - Windows Server 2022 must not allow anonymous enumeration of Security Account Manager (SAM) accounts.
windows2022 · high (CAT I)
stig://rule/SV-254466r991589_rule
SV-254467r1137695_rule - Windows Server 2022 must not allow anonymous enumeration of shares.
windows2022 · high (CAT I)
stig://rule/SV-254467r1137695_rule
SV-254468r991589_rule - Windows Server 2022 must be configured to prevent anonymous users from having the same permissions as the Everyone group.
windows2022 · medium (CAT II)
stig://rule/SV-254468r991589_rule
SV-254469r1137695_rule - Windows Server 2022 must restrict anonymous access to Named Pipes and Shares.
windows2022 · high (CAT I)
stig://rule/SV-254469r1137695_rule
SV-254470r991589_rule - Windows Server 2022 services using Local System that use Negotiate when reverting to NTLM authentication must use the computer identity instead of authenticating anonymously.
windows2022 · medium (CAT II)
stig://rule/SV-254470r991589_rule
SV-254471r991589_rule - Windows Server 2022 must prevent NTLM from falling back to a Null session.
windows2022 · medium (CAT II)
stig://rule/SV-254471r991589_rule
SV-254472r991589_rule - Windows Server 2022 must prevent PKU2U authentication using online identities.
windows2022 · medium (CAT II)
stig://rule/SV-254472r991589_rule
SV-254473r971535_rule - Windows Server 2022 Kerberos encryption types must be configured to prevent the use of DES and RC4 encryption suites.
windows2022 · medium (CAT II)
stig://rule/SV-254473r971535_rule
SV-254474r1051107_rule - Windows Server 2022 must be configured to prevent the storage of the LAN Manager hash of passwords.
windows2022 · high (CAT I)
stig://rule/SV-254474r1051107_rule
SV-254475r991589_rule - Windows Server 2022 LAN Manager authentication level must be configured to send NTLMv2 response only and to refuse LM and NTLM.
windows2022 · high (CAT I)
stig://rule/SV-254475r991589_rule
SV-254476r991589_rule - Windows Server 2022 must be configured to at least negotiate signing for LDAP client signing.
windows2022 · medium (CAT II)
stig://rule/SV-254476r991589_rule
SV-254477r991589_rule - Windows Server 2022 session security for NTLM SSP-based clients must be configured to require NTLMv2 session security and 128-bit encryption.
windows2022 · medium (CAT II)
stig://rule/SV-254477r991589_rule
SV-254478r991589_rule - Windows Server 2022 session security for NTLM SSP-based servers must be configured to require NTLMv2 session security and 128-bit encryption.
windows2022 · medium (CAT II)
stig://rule/SV-254478r991589_rule
SV-254479r958450_rule - Windows Server 2022 users must be required to enter a password to access private keys stored on the computer.
windows2022 · medium (CAT II)
stig://rule/SV-254479r958450_rule
SV-254480r1137699_rule - Windows Server 2022 must be configured to use FIPS-compliant algorithms for encryption, hashing, and signing.
windows2022 · medium (CAT II)
stig://rule/SV-254480r1137699_rule
SV-254481r991589_rule - Windows Server 2022 default permissions of global system objects must be strengthened.
windows2022 · low (CAT III)
stig://rule/SV-254481r991589_rule
SV-254482r1051108_rule - Windows Server 2022 User Account Control (UAC) approval mode for the built-in Administrator must be enabled.
windows2022 · medium (CAT II)
stig://rule/SV-254482r1051108_rule
SV-254483r958518_rule - Windows Server 2022 UIAccess applications must not be allowed to prompt for elevation without using the secure desktop.
windows2022 · medium (CAT II)
stig://rule/SV-254483r958518_rule
SV-254484r958518_rule - Windows Server 2022 User Account Control (UAC) must, at a minimum, prompt administrators for consent on the secure desktop.
windows2022 · medium (CAT II)
stig://rule/SV-254484r958518_rule
SV-254485r1051109_rule - Windows Server 2022 User Account Control (UAC) must automatically deny standard user requests for elevation.
windows2022 · medium (CAT II)
stig://rule/SV-254485r1051109_rule
SV-254486r958518_rule - Windows Server 2022 User Account Control (UAC) must be configured to detect application installations and prompt for elevation.
windows2022 · medium (CAT II)
stig://rule/SV-254486r958518_rule
SV-254487r958518_rule - Windows Server 2022 User Account Control (UAC) must only elevate UIAccess applications that are installed in secure locations.
windows2022 · medium (CAT II)
stig://rule/SV-254487r958518_rule
SV-254488r1051110_rule - Windows Server 2022 User Account Control (UAC) must run all administrators in Admin Approval Mode, enabling UAC.
windows2022 · medium (CAT II)
stig://rule/SV-254488r1051110_rule
SV-254489r958518_rule - Windows Server 2022 User Account Control (UAC) must virtualize file and registry write failures to per-user locations.
windows2022 · medium (CAT II)
stig://rule/SV-254489r958518_rule
SV-254490r991589_rule - Windows Server 2022 must preserve zone information when saving attachments.
windows2022 · medium (CAT II)
stig://rule/SV-254490r991589_rule
SV-254491r958726_rule - Windows Server 2022 Access Credential Manager as a trusted caller user right must not be assigned to any groups or accounts.
windows2022 · medium (CAT II)
stig://rule/SV-254491r958726_rule
SV-254492r958726_rule - Windows Server 2022 Act as part of the operating system user right must not be assigned to any groups or accounts.
windows2022 · high (CAT I)
stig://rule/SV-254492r958726_rule
SV-254493r1137691_rule - Windows Server 2022 Allow log on locally user right must only be assigned to the Administrators group.
windows2022 · medium (CAT II)
stig://rule/SV-254493r1137691_rule
SV-254494r958726_rule - Windows Server 2022 back up files and directories user right must only be assigned to the Administrators group.
windows2022 · medium (CAT II)
stig://rule/SV-254494r958726_rule
SV-254495r958726_rule - Windows Server 2022 create a pagefile user right must only be assigned to the Administrators group.
windows2022 · medium (CAT II)
stig://rule/SV-254495r958726_rule
SV-254496r958726_rule - Windows Server 2022 create a token object user right must not be assigned to any groups or accounts.
windows2022 · high (CAT I)
stig://rule/SV-254496r958726_rule
SV-254497r958726_rule - Windows Server 2022 create global objects user right must only be assigned to Administrators, Service, Local Service, and Network Service.
windows2022 · medium (CAT II)
stig://rule/SV-254497r958726_rule
SV-254498r958726_rule - Windows Server 2022 create permanent shared objects user right must not be assigned to any groups or accounts.
windows2022 · medium (CAT II)
stig://rule/SV-254498r958726_rule
SV-254499r958726_rule - Windows Server 2022 create symbolic links user right must only be assigned to the Administrators group.
windows2022 · medium (CAT II)
stig://rule/SV-254499r958726_rule
SV-254500r958726_rule - Windows Server 2022 debug programs user right must only be assigned to the Administrators group.
windows2022 · high (CAT I)
stig://rule/SV-254500r958726_rule
SV-254501r958726_rule - Windows Server 2022 force shutdown from a remote system user right must only be assigned to the Administrators group.
windows2022 · medium (CAT II)
stig://rule/SV-254501r958726_rule
SV-254502r958726_rule - Windows Server 2022 generate security audits user right must only be assigned to Local Service and Network Service.
windows2022 · medium (CAT II)
stig://rule/SV-254502r958726_rule
SV-254503r958726_rule - Windows Server 2022 impersonate a client after authentication user right must only be assigned to Administrators, Service, Local Service, and Network Service.
windows2022 · medium (CAT II)
stig://rule/SV-254503r958726_rule
SV-254504r958726_rule - Windows Server 2022 increase scheduling priority: user right must only be assigned to the Administrators group.
windows2022 · medium (CAT II)
stig://rule/SV-254504r958726_rule
SV-254505r958726_rule - Windows Server 2022 load and unload device drivers user right must only be assigned to the Administrators group.
windows2022 · medium (CAT II)
stig://rule/SV-254505r958726_rule
SV-254506r958726_rule - Windows Server 2022 lock pages in memory user right must not be assigned to any groups or accounts.
windows2022 · medium (CAT II)
stig://rule/SV-254506r958726_rule
SV-254507r958434_rule - Windows Server 2022 manage auditing and security log user right must only be assigned to the Administrators group.
windows2022 · medium (CAT II)
stig://rule/SV-254507r958434_rule
SV-254508r958726_rule - Windows Server 2022 modify firmware environment values user right must only be assigned to the Administrators group.
windows2022 · medium (CAT II)
stig://rule/SV-254508r958726_rule
SV-254509r958726_rule - Windows Server 2022 perform volume maintenance tasks user right must only be assigned to the Administrators group.
windows2022 · medium (CAT II)
stig://rule/SV-254509r958726_rule
SV-254510r958726_rule - Windows Server 2022 profile single process user right must only be assigned to the Administrators group.
windows2022 · medium (CAT II)
stig://rule/SV-254510r958726_rule
SV-254511r958726_rule - Windows Server 2022 restore files and directories user right must only be assigned to the Administrators group.
windows2022 · medium (CAT II)
stig://rule/SV-254511r958726_rule
SV-254512r958726_rule - Windows Server 2022 take ownership of files or other objects user right must only be assigned to the Administrators group.
windows2022 · medium (CAT II)
stig://rule/SV-254512r958726_rule
SV-271426r1137691_rule - Windows Server 2022 must be configured for certificate-based authentication for domain controllers.
windows2022 · medium (CAT II)
stig://rule/SV-271426r1137691_rule
SV-271427r1137691_rule - Windows Server 2022 must be configured for name-based strong mappings for certificates.
windows2022 · medium (CAT II)
stig://rule/SV-271427r1137691_rule
SV-278942r1135355_rule - Windows Server 2022 must be configured to audit file system failures.
windows2022 · medium (CAT II)
stig://rule/SV-278942r1135355_rule
SV-278943r1135358_rule - Windows Server 2022 must be configured to audit file system successes.
windows2022 · medium (CAT II)
stig://rule/SV-278943r1135358_rule
SV-278944r1135361_rule - Windows Server 2022 must be configured to audit handle manipulation failures.
windows2022 · medium (CAT II)
stig://rule/SV-278944r1135361_rule
SV-278945r1135364_rule - Windows Server 2022 must be configured to audit handle manipulation successes.
windows2022 · medium (CAT II)
stig://rule/SV-278945r1135364_rule
SV-278946r1135367_rule - Windows Server 2022 must be configured to audit registry failures.
windows2022 · medium (CAT II)
stig://rule/SV-278946r1135367_rule
SV-278947r1135370_rule - Windows Server 2022 must be configured to audit registry successes.
windows2022 · medium (CAT II)
stig://rule/SV-278947r1135370_rule
SV-278948r1141928_rule - Windows Server 2022 must be configured to audit sensitive privilege use successes.
windows2022 · medium (CAT II)
stig://rule/SV-278948r1141928_rule
SV-278949r1141931_rule - Windows Server 2022 must be configured to audit sensitive privilege use failures.
windows2022 · medium (CAT II)
stig://rule/SV-278949r1141931_rule