SRG-OS-000004-GPOS-00004 Controls

STIG IDVersionTitleProduct
ALMA-09-004970V1R1AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.
ALMA-09-005080V1R1AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
ALMA-09-005190V1R1AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
ALMA-09-005300V1R1AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.
ALMA-09-005410V1R1AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
ALMA-09-005960V1R1AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
ALMA-09-006070V1R1AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect the files within /etc/sudoers.d/
UBTU-20-010100V1R9The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
UBTU-20-010101V1R9The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
UBTU-20-010102V1R9The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
UBTU-20-010103V1R9The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
UBTU-20-010104V1R9The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
UBTU-24-200280V1R1Ubuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
UBTU-24-200290V1R1Ubuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
UBTU-24-200300V1R1Ubuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
UBTU-24-200310V1R1Ubuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
UBTU-24-200320V1R1Ubuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
WN22-AU-000100V2R1Windows Server 2022 must be configured to audit Account Management - Security Group Management successes.
WN22-AU-000110V2R1Windows Server 2022 must be configured to audit Account Management - User Account Management successes.
WN22-AU-000120V2R1Windows Server 2022 must be configured to audit Account Management - User Account Management failures.
WN22-DC-000230V2R1Windows Server 2022 must be configured to audit Account Management - Computer Account Management successes.
WN10-AU-000030V2R8The system must be configured to audit Account Management - Security Group Management successes.
WN10-AU-000035V2R8The system must be configured to audit Account Management - User Account Management failures.
WN10-AU-000040V2R8The system must be configured to audit Account Management - User Account Management successes.
APPL-15-001001V1R1The macOS system must be configured to audit all administrative action events.
APPL-14-001001V2R1The macOS system must be configured to audit all administrative action events.
UBTU-22-654130V2R1Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
UBTU-22-654135V2R1Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
UBTU-22-654140V2R1Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
UBTU-22-654145V2R1Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
UBTU-22-654150V2R1Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
RHEL-07-030870V3R8The Red Hat Enterprise Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
RHEL-07-030871V3R8The Red Hat Enterprise Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
RHEL-07-030872V3R8The Red Hat Enterprise Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
RHEL-07-030873V3R8The Red Hat Enterprise Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
RHEL-07-030874V3R8The Red Hat Enterprise Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.
RHEL-09-654215V2R1RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.
RHEL-09-654220V2R1RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory.
RHEL-09-654225V2R1RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
RHEL-09-654230V2R1RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
RHEL-09-654235V2R1RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
RHEL-09-654240V2R1RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
RHEL-09-654245V2R1RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
OL09-00-000500V1R1OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.
OL09-00-000505V1R1OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory.
OL09-00-000510V1R1OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
OL09-00-000515V1R1OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
OL09-00-000520V1R1OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
OL09-00-000525V1R1OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
OL09-00-000530V1R1OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
WN16-AU-000120V2R10Windows Server 2016 must be configured to audit Account Management - Security Group Management successes.
WN16-AU-000140V2R10Windows Server 2016 must be configured to audit Account Management - User Account Management successes.
WN16-AU-000150V2R10Windows Server 2016 must be configured to audit Account Management - User Account Management failures.
WN16-DC-000230V2R10Windows Server 2016 must be configured to audit Account Management - Computer Account Management successes.
SLES-15-030000V1R9The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
SLES-15-030010V1R9The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
SLES-15-030020V1R9The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
SLES-15-030030V1R9The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.
SLES-15-030040V1R9The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
SLES-12-020200V2R13The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
SLES-12-020210V2R13The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
SLES-12-020220V2R13The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
SLES-12-020230V2R13The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
SLES-12-020590V2R13The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
OL07-00-030870V2R14The Oracle Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
OL07-00-030871V2R14The Oracle Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
OL07-00-030872V2R14The Oracle Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
OL07-00-030873V2R14The Oracle Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
OL07-00-030874V2R14The Oracle Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.
WN19-AU-000100V2R8Windows Server 2019 must be configured to audit Account Management - Security Group Management successes.
WN19-AU-000110V2R8Windows Server 2019 must be configured to audit Account Management - User Account Management successes.
WN19-AU-000120V2R8Windows Server 2019 must be configured to audit Account Management - User Account Management failures.
WN19-DC-000230V2R8Windows Server 2019 must be configured to audit Account Management - Computer Account Management successes.
OL08-00-030130V1R9OL 8 must generate audit records for all account creation events that affect "/etc/shadow".
OL08-00-030140V1R9OL 8 must generate audit records for all account creation events that affect "/etc/security/opasswd".
OL08-00-030150V1R9OL 8 must generate audit records for all account creation events that affect "/etc/passwd".
OL08-00-030160V1R9OL 8 must generate audit records for all account creation events that affect "/etc/gshadow".
OL08-00-030170V1R9OL 8 must generate audit records for all account creation events that affect "/etc/group".
OL08-00-030171V1R9OL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/sudoers".
OL08-00-030172V1R9OL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/sudoers.d/".