SRG-OS-000057-GPOS-00027 Controls

STIG IDVersionTitleProduct
ALMA-09-055680V1R1AlmaLinux OS 9 audit log directory must be owned by root to prevent unauthorized read access.
ALMA-09-055790V1R1AlmaLinux OS 9 audit log directory must have 0700 permissions to prevent unauthorized read access.
ALMA-09-055900V1R1AlmaLinux OS 9 audit logs must be owned by the root group to prevent unauthorized read access.
ALMA-09-056010V1R1AlmaLinux OS 9 audit logs must be owned by root to prevent unauthorized read access.
ALMA-09-056120V1R1AlmaLinux OS 9 audit logs must have 0600 permissions to prevent unauthorized read access.
UBTU-20-010122V1R9The Ubuntu operating system must be configured so that audit log files are not read or write-accessible by unauthorized users.
UBTU-20-010123V1R9The Ubuntu operating system must be configured to permit only authorized users ownership of the audit log files.
UBTU-20-010124V1R9The Ubuntu operating system must permit only authorized groups ownership of the audit log files.
UBTU-24-901300V1R1Ubuntu 24.04 LTS must be configured so that audit log files are not read or write-accessible by unauthorized users.
UBTU-24-901310V1R1Ubuntu 24.04 LTS must be configured to permit only authorized users ownership of the audit log files.
UBTU-24-901350V1R1Ubuntu 24.04 LTS must permit only authorized groups ownership of the audit log files.
WN22-AU-000030V2R1Windows Server 2022 permissions for the Application event log must prevent access by nonprivileged accounts.
WN22-AU-000040V2R1Windows Server 2022 permissions for the Security event log must prevent access by nonprivileged accounts.
WN22-AU-000050V2R1Windows Server 2022 permissions for the System event log must prevent access by nonprivileged accounts.
WN22-UR-000170V2R1Windows Server 2022 manage auditing and security log user right must only be assigned to the Administrators group.
WN10-AU-000515V2R8Windows 10 permissions for the Application event log must prevent access by non-privileged accounts.
WN10-AU-000520V2R8Windows 10 permissions for the Security event log must prevent access by non-privileged accounts.
WN10-AU-000525V2R8Windows 10 permissions for the System event log must prevent access by non-privileged accounts.
WN10-UR-000130V2R8The Manage auditing and security log user right must only be assigned to the Administrators group.
APPL-15-000030V1R1The macOS system must configure audit log files to not contain access control lists (ACLs).
APPL-15-000031V1R1The macOS system must configure the audit log folder to not contain access control lists (ACLs).
APPL-15-001012V1R1The macOS system must configure audit log files to be owned by root.
APPL-15-001013V1R1The macOS system must configure audit log folders to be owned by root.
APPL-15-001014V1R1The macOS system must configure the audit log files group to wheel.
APPL-15-001015V1R1The macOS system must configure the audit log folders group to wheel.
APPL-15-001016V1R1The macOS system must configure audit log files to mode 440 or less permissive.
APPL-15-001017V1R1The macOS system must configure audit log folders to mode 700 or less permissive.
APPL-15-001020V1R1The macOS system must be configured to audit all deletions of object attributes.
APPL-15-001021V1R1The macOS system must be configured to audit all changes of object attributes.
APPL-15-001022V1R1The macOS system must be configured to audit all failed read actions on the system.
APPL-15-001023V1R1The macOS system must be configured to audit all failed write actions on the system.
APPL-15-001110V1R1The macOS system must configure audit_control group to wheel.
APPL-15-001120V1R1The macOS system must configure audit_control owner to root.
APPL-15-001130V1R1The macOS system must configure audit_control owner to mode 440 or less permissive.
APPL-15-001140V1R1The macOS system must configure audit_control to not contain access control lists (ACLs).
APPL-14-000030V2R1The macOS system must configure audit log files to not contain access control lists.
APPL-14-000031V2R1The macOS system must configure audit log folders to not contain access control lists.
APPL-14-001012V2R1The macOS system must configure audit log files to be owned by root.
APPL-14-001013V2R1The macOS system must configure audit log folders to be owned by root.
APPL-14-001014V2R1The macOS system must configure audit log files group to wheel.
APPL-14-001015V2R1The macOS system must configure audit log folders group to wheel.
APPL-14-001016V2R1The macOS system must configure audit log files to mode 440 or less permissive.
APPL-14-001017V2R1The macOS system must configure audit log folders to mode 700 or less permissive.
APPL-14-001020V2R1The macOS system must be configured to audit all deletions of object attributes.
APPL-14-001021V2R1The macOS system must be configured to audit all changes of object attributes.
APPL-14-001110V2R1The macOS system must configure audit_control group to wheel.
APPL-14-001120V2R1The macOS system must configure audit_control owner to root.
APPL-14-001130V2R1The macOS system must configure audit_control to mode 440 or less permissive.
APPL-14-001140V2R1The macOS system must configure audit_control to not contain access control lists.
WN11-AU-000515V2R1Windows 11 permissions for the Application event log must prevent access by non-privileged accounts.
WN11-AU-000520V2R1Windows 11 permissions for the Security event log must prevent access by non-privileged accounts.
WN11-AU-000525V2R1Windows 11 permissions for the System event log must prevent access by non-privileged accounts.
WN11-UR-000130V2R1The "Manage auditing and security log" user right must only be assigned to the Administrators group.
UBTU-22-653045V2R1Ubuntu 22.04 LTS must be configured so that audit log files are not read- or write-accessible by unauthorized users.
UBTU-22-653050V2R1Ubuntu 22.04 LTS must be configured to permit only authorized users ownership of the audit log files.
UBTU-22-653055V2R1Ubuntu 22.04 LTS must permit only authorized groups ownership of the audit log files.
RHEL-08-030070V1R9RHEL 8 audit logs must have a mode of 0600 or less permissive to prevent unauthorized read access.
RHEL-08-030080V1R9RHEL 8 audit logs must be owned by root to prevent unauthorized read access.
RHEL-08-030090V1R9RHEL 8 audit logs must be group-owned by root to prevent unauthorized read access.
RHEL-08-030100V1R9RHEL 8 audit log directory must be owned by root to prevent unauthorized read access.
RHEL-08-030110V1R9RHEL 8 audit log directory must be group-owned by root to prevent unauthorized read access.
RHEL-08-030120V1R9RHEL 8 audit log directory must have a mode of 0700 or less permissive to prevent unauthorized read access.
RHEL-08-030121V1R9RHEL 8 audit system must protect auditing rules from unauthorized change.
RHEL-08-030122V1R9RHEL 8 audit system must protect logon UIDs from unauthorized change.
RHEL-07-910055V3R8The Red Hat Enterprise Linux operating system must protect audit information from unauthorized read, modification, or deletion.
RHEL-09-653080V2R1RHEL 9 audit logs must be group-owned by root or by a restricted logging group to prevent unauthorized read access.
RHEL-09-653085V2R1RHEL 9 audit log directory must be owned by root to prevent unauthorized read access.
RHEL-09-653090V2R1RHEL 9 audit logs file must have mode 0600 or less permissive to prevent unauthorized access to the audit log.
RHEL-09-654275V2R1RHEL 9 audit system must protect auditing rules from unauthorized change.
OL09-00-000785V1R1OL 9 audit logs must be group-owned by root or by a restricted logging group to prevent unauthorized read access.
OL09-00-000790V1R1OL 9 audit log directory must be owned by root to prevent unauthorized read access.
OL09-00-000795V1R1OL 9 audit logs file must have mode 0600 or less permissive to prevent unauthorized access to the audit log.
OL09-00-008005V1R1OL 9 audit system must protect auditing rules from unauthorized change.
WN16-AU-000030V2R10Permissions for the Application event log must prevent access by non-privileged accounts.
WN16-AU-000040V2R10Permissions for the Security event log must prevent access by non-privileged accounts.
WN16-AU-000050V2R10Permissions for the System event log must prevent access by non-privileged accounts.
WN16-UR-000260V2R10The Manage auditing and security log user right must only be assigned to the Administrators group.
SLES-15-030600V1R9The SUSE operating system must protect audit rules from unauthorized modification.
SLES-12-020120V2R13The SUSE operating system must protect audit rules from unauthorized modification.
OL07-00-910055V2R14The Oracle Linux operating system must protect audit information from unauthorized read, modification, or deletion.
WN19-AU-000030V2R8Windows Server 2019 permissions for the Application event log must prevent access by non-privileged accounts.
WN19-AU-000040V2R8Windows Server 2019 permissions for the Security event log must prevent access by non-privileged accounts.
WN19-AU-000050V2R8Windows Server 2019 permissions for the System event log must prevent access by non-privileged accounts.
WN19-UR-000170V2R8Windows Server 2019 Manage auditing and security log user right must only be assigned to the Administrators group.
OL08-00-030070V1R9OL 8 audit logs must have a mode of "0600" or less permissive to prevent unauthorized read access.
OL08-00-030080V1R9OL 8 audit logs must be owned by root to prevent unauthorized read access.
OL08-00-030090V1R9OL 8 audit logs must be group-owned by root to prevent unauthorized read access.
OL08-00-030100V1R9The OL 8 audit log directory must be owned by root to prevent unauthorized read access.
OL08-00-030110V1R9The OL 8 audit log directory must be group-owned by root to prevent unauthorized read access.
OL08-00-030120V1R9The OL 8 audit log directory must have a mode of 0700 or less permissive to prevent unauthorized read access.
OL08-00-030121V1R9The OL 8 audit system must protect auditing rules from unauthorized change.
OL08-00-030122V1R9The OL 8 audit system must protect logon UIDs from unauthorized change.