SRG-OS-000004-GPOS-00004 Controls

STIG IDVersionTitleProduct
SLES-15-030000V1R4The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
SLES-15-030010V1R4The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
SLES-15-030020V1R4The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
SLES-15-030030V1R4The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.
SLES-15-030040V1R4The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
WN19-AU-000100V3R1Windows Server 2019 must be configured to audit Account Management - Security Group Management successes.
WN19-AU-000110V3R1Windows Server 2019 must be configured to audit Account Management - User Account Management successes.
WN19-AU-000120V3R1Windows Server 2019 must be configured to audit Account Management - User Account Management failures.
WN19-DC-000230V3R1Windows Server 2019 must be configured to audit Account Management - Computer Account Management successes.
UBTU-20-010100V1R6The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
UBTU-20-010101V1R6The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
UBTU-20-010102V1R6The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
UBTU-20-010103V1R6The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
UBTU-20-010104V1R6The Ubuntu operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
APPL-14-001001V1R1The macOS system must be configured to audit all administrative action events.
APPL-13-001001V1R5The macOS system must generate audit records for all account creations, modifications, disabling, and termination events; privileged activities or other system-level access; all kernel module load, unload, and restart actions; all program initiations; and organizationally defined events for all nonlocal maintenance and diagnostic sessions.
OL07-00-030870V3R1The Oracle Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
OL07-00-030871V3R1The Oracle Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
OL07-00-030872V3R1The Oracle Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
OL07-00-030873V3R1The Oracle Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
OL07-00-030874V3R1The Oracle Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.
RHEL-07-030870V3R6The Red Hat Enterprise Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
RHEL-07-030871V3R6The Red Hat Enterprise Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
RHEL-07-030872V3R6The Red Hat Enterprise Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
RHEL-07-030873V3R6The Red Hat Enterprise Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
RHEL-07-030874V3R6The Red Hat Enterprise Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.
SLES-12-020200V3R1The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
SLES-12-020210V3R1The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
SLES-12-020220V3R1The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
SLES-12-020230V3R1The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
SLES-12-020590V3R1The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
APPL-15-001001V1R1The macOS system must be configured to audit all administrative action events.
ALMA-09-004970V1R1AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.
ALMA-09-005080V1R1AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
ALMA-09-005190V1R1AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
ALMA-09-005300V1R1AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.
ALMA-09-005410V1R1AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
ALMA-09-005960V1R1AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
ALMA-09-006070V1R1AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect the files within /etc/sudoers.d/
OL08-00-030130V1R6OL 8 must generate audit records for all account creation events that affect "/etc/shadow".
OL08-00-030140V1R6OL 8 must generate audit records for all account creation events that affect "/etc/security/opasswd".
OL08-00-030150V1R6OL 8 must generate audit records for all account creation events that affect "/etc/passwd".
OL08-00-030160V1R6OL 8 must generate audit records for all account creation events that affect "/etc/gshadow".
OL08-00-030170V1R6OL 8 must generate audit records for all account creation events that affect "/etc/group".
OL08-00-030171V1R6OL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/sudoers".
OL08-00-030172V1R6OL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/sudoers.d/".
OL09-00-000500V1R1OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.
OL09-00-000505V1R1OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory.
OL09-00-000510V1R1OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
OL09-00-000515V1R1OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
OL09-00-000520V1R1OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
OL09-00-000525V1R1OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
OL09-00-000530V1R1OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
UBTU-24-200280V1R1Ubuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
UBTU-24-200290V1R1Ubuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
UBTU-24-200300V1R1Ubuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
UBTU-24-200310V1R1Ubuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
UBTU-24-200320V1R1Ubuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
UBTU-22-654130V1R1Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
UBTU-22-654135V1R1Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
UBTU-22-654140V1R1Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
UBTU-22-654145V1R1Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
UBTU-22-654150V1R1Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
RHEL-09-654215V2R5RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.
RHEL-09-654220V2R5RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory.
RHEL-09-654225V2R5RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
RHEL-09-654230V2R5RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
RHEL-09-654235V2R5RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
RHEL-09-654240V2R5RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
RHEL-09-654245V2R5RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
WN10-AU-000030V3R1The system must be configured to audit Account Management - Security Group Management successes.
WN10-AU-000035V3R1The system must be configured to audit Account Management - User Account Management failures.
WN10-AU-000040V3R1The system must be configured to audit Account Management - User Account Management successes.
WN16-AU-000120V2R9Windows Server 2016 must be configured to audit Account Management - Security Group Management successes.
WN16-AU-000140V2R9Windows Server 2016 must be configured to audit Account Management - User Account Management successes.
WN16-AU-000150V2R9Windows Server 2016 must be configured to audit Account Management - User Account Management failures.
WN16-DC-000230V2R9Windows Server 2016 must be configured to audit Account Management - Computer Account Management successes.
WN22-AU-000100V2R5Windows Server 2022 must be configured to audit Account Management - Security Group Management successes.
WN22-AU-000110V2R5Windows Server 2022 must be configured to audit Account Management - User Account Management successes.
WN22-AU-000120V2R5Windows Server 2022 must be configured to audit Account Management - User Account Management failures.
WN22-DC-000230V2R5Windows Server 2022 must be configured to audit Account Management - Computer Account Management successes.