SRG-OS-000057-GPOS-00027 Controls

STIG IDVersionTitleProduct
RHEL-08-030070V1R6RHEL 8 audit logs must have a mode of 0600 or less permissive to prevent unauthorized read access.
RHEL-08-030080V1R6RHEL 8 audit logs must be owned by root to prevent unauthorized read access.
RHEL-08-030090V1R6RHEL 8 audit logs must be group-owned by root to prevent unauthorized read access.
RHEL-08-030100V1R6RHEL 8 audit log directory must be owned by root to prevent unauthorized read access.
RHEL-08-030110V1R6RHEL 8 audit log directory must be group-owned by root to prevent unauthorized read access.
RHEL-08-030120V1R6RHEL 8 audit log directory must have a mode of 0700 or less permissive to prevent unauthorized read access.
RHEL-08-030121V1R6RHEL 8 audit system must protect auditing rules from unauthorized change.
RHEL-08-030122V1R6RHEL 8 audit system must protect logon UIDs from unauthorized change.
SLES-15-030600V1R4The SUSE operating system must protect audit rules from unauthorized modification.
WN19-AU-000030V3R1Windows Server 2019 permissions for the Application event log must prevent access by non-privileged accounts.
WN19-AU-000040V3R1Windows Server 2019 permissions for the Security event log must prevent access by non-privileged accounts.
WN19-AU-000050V3R1Windows Server 2019 permissions for the System event log must prevent access by non-privileged accounts.
WN19-UR-000170V3R1Windows Server 2019 Manage auditing and security log user right must only be assigned to the Administrators group.
UBTU-20-010122V1R6The Ubuntu operating system must be configured so that audit log files are not read or write-accessible by unauthorized users.
UBTU-20-010123V1R6The Ubuntu operating system must be configured to permit only authorized users ownership of the audit log files.
UBTU-20-010124V1R6The Ubuntu operating system must permit only authorized groups ownership of the audit log files.
APPL-14-000030V1R1The macOS system must configure audit log files to not contain access control lists.
APPL-14-000031V1R1The macOS system must configure audit log folders to not contain access control lists.
APPL-14-001012V1R1The macOS system must configure audit log files to be owned by root.
APPL-14-001013V1R1The macOS system must configure audit log folders to be owned by root.
APPL-14-001014V1R1The macOS system must configure audit log files group to wheel.
APPL-14-001015V1R1The macOS system must configure audit log folders group to wheel.
APPL-14-001016V1R1The macOS system must configure audit log files to mode 440 or less permissive.
APPL-14-001017V1R1The macOS system must configure audit log folders to mode 700 or less permissive.
APPL-14-001020V1R1The macOS system must be configured to audit all deletions of object attributes.
APPL-14-001021V1R1The macOS system must be configured to audit all changes of object attributes.
APPL-14-001110V1R1The macOS system must configure audit_control group to wheel.
APPL-14-001120V1R1The macOS system must configure audit_control owner to root.
APPL-14-001130V1R1The macOS system must configure audit_control to mode 440 or less permissive.
APPL-14-001140V1R1The macOS system must configure audit_control to not contain access control lists.
APPL-13-000030V1R5The macOS system must be configured so that log files do not contain access control lists (ACLs).
APPL-13-000031V1R5The macOS system must be configured so that log folders do not contain access control lists (ACLs).
APPL-13-001012V1R5The macOS system must be configured with audit log files owned by root.
APPL-13-001013V1R5The macOS system must be configured with audit log folders owned by root.
APPL-13-001014V1R5The macOS system must be configured with audit log files group-owned by wheel.
APPL-13-001015V1R5The macOS system must be configured with audit log folders group-owned by wheel.
APPL-13-001016V1R5The macOS system must be configured with audit log files set to mode 440 or less permissive.
APPL-13-001017V1R5The macOS system must be configured with audit log folders set to mode 700 or less permissive.
OL07-00-910055V3R1The Oracle Linux operating system must protect audit information from unauthorized read, modification, or deletion.
RHEL-07-910055V3R6The Red Hat Enterprise Linux operating system must protect audit information from unauthorized read, modification, or deletion.
SLES-12-020120V3R1The SUSE operating system must protect audit rules from unauthorized modification.
APPL-15-000030V1R1The macOS system must configure audit log files to not contain access control lists (ACLs).
APPL-15-000031V1R1The macOS system must configure the audit log folder to not contain access control lists (ACLs).
APPL-15-001012V1R1The macOS system must configure audit log files to be owned by root.
APPL-15-001013V1R1The macOS system must configure audit log folders to be owned by root.
APPL-15-001014V1R1The macOS system must configure the audit log files group to wheel.
APPL-15-001015V1R1The macOS system must configure the audit log folders group to wheel.
APPL-15-001016V1R1The macOS system must configure audit log files to mode 440 or less permissive.
APPL-15-001017V1R1The macOS system must configure audit log folders to mode 700 or less permissive.
APPL-15-001020V1R1The macOS system must be configured to audit all deletions of object attributes.
APPL-15-001021V1R1The macOS system must be configured to audit all changes of object attributes.
APPL-15-001022V1R1The macOS system must be configured to audit all failed read actions on the system.
APPL-15-001023V1R1The macOS system must be configured to audit all failed write actions on the system.
APPL-15-001110V1R1The macOS system must configure audit_control group to wheel.
APPL-15-001120V1R1The macOS system must configure audit_control owner to root.
APPL-15-001130V1R1The macOS system must configure audit_control owner to mode 440 or less permissive.
APPL-15-001140V1R1The macOS system must configure audit_control to not contain access control lists (ACLs).
ALMA-09-055680V1R1AlmaLinux OS 9 audit log directory must be owned by root to prevent unauthorized read access.
ALMA-09-055790V1R1AlmaLinux OS 9 audit log directory must have 0700 permissions to prevent unauthorized read access.
ALMA-09-055900V1R1AlmaLinux OS 9 audit logs must be owned by the root group to prevent unauthorized read access.
ALMA-09-056010V1R1AlmaLinux OS 9 audit logs must be owned by root to prevent unauthorized read access.
ALMA-09-056120V1R1AlmaLinux OS 9 audit logs must have 0600 permissions to prevent unauthorized read access.
OL08-00-030070V1R6OL 8 audit logs must have a mode of "0600" or less permissive to prevent unauthorized read access.
OL08-00-030080V1R6OL 8 audit logs must be owned by root to prevent unauthorized read access.
OL08-00-030090V1R6OL 8 audit logs must be group-owned by root to prevent unauthorized read access.
OL08-00-030100V1R6The OL 8 audit log directory must be owned by root to prevent unauthorized read access.
OL08-00-030110V1R6The OL 8 audit log directory must be group-owned by root to prevent unauthorized read access.
OL08-00-030120V1R6The OL 8 audit log directory must have a mode of 0700 or less permissive to prevent unauthorized read access.
OL08-00-030121V1R6The OL 8 audit system must protect auditing rules from unauthorized change.
OL08-00-030122V1R6The OL 8 audit system must protect logon UIDs from unauthorized change.
OL09-00-000785V1R1OL 9 audit logs must be group-owned by root or by a restricted logging group to prevent unauthorized read access.
OL09-00-000790V1R1OL 9 audit log directory must be owned by root to prevent unauthorized read access.
OL09-00-000795V1R1OL 9 audit logs file must have mode 0600 or less permissive to prevent unauthorized access to the audit log.
OL09-00-008005V1R1OL 9 audit system must protect auditing rules from unauthorized change.
UBTU-24-901300V1R1Ubuntu 24.04 LTS must be configured so that audit log files are not read or write-accessible by unauthorized users.
UBTU-24-901310V1R1Ubuntu 24.04 LTS must be configured to permit only authorized users ownership of the audit log files.
UBTU-24-901350V1R1Ubuntu 24.04 LTS must permit only authorized groups ownership of the audit log files.
UBTU-22-653045V1R1Ubuntu 22.04 LTS must be configured so that audit log files are not read- or write-accessible by unauthorized users.
UBTU-22-653050V1R1Ubuntu 22.04 LTS must be configured to permit only authorized users ownership of the audit log files.
UBTU-22-653055V1R1Ubuntu 22.04 LTS must permit only authorized groups ownership of the audit log files.
WN11-AU-000515V1R6Windows 11 permissions for the Application event log must prevent access by non-privileged accounts.
WN11-AU-000520V1R6Windows 11 permissions for the Security event log must prevent access by non-privileged accounts.
WN11-AU-000525V1R6Windows 11 permissions for the System event log must prevent access by non-privileged accounts.
WN11-UR-000130V1R6The "Manage auditing and security log" user right must only be assigned to the Administrators group.
RHEL-09-653080V2R5RHEL 9 audit logs must be group-owned by root or by a restricted logging group to prevent unauthorized read access.
RHEL-09-653085V2R5RHEL 9 audit log directory must be owned by root to prevent unauthorized read access.
RHEL-09-653090V2R5RHEL 9 audit logs file must have mode 0600 or less permissive to prevent unauthorized access to the audit log.
RHEL-09-654275V2R5RHEL 9 audit system must protect auditing rules from unauthorized change.
WN10-AU-000515V3R1Windows 10 permissions for the Application event log must prevent access by non-privileged accounts.
WN10-AU-000520V3R1Windows 10 permissions for the Security event log must prevent access by non-privileged accounts.
WN10-AU-000525V3R1Windows 10 permissions for the System event log must prevent access by non-privileged accounts.
WN10-UR-000130V3R1The Manage auditing and security log user right must only be assigned to the Administrators group.
WN16-AU-000030V2R9Permissions for the Application event log must prevent access by non-privileged accounts.
WN16-AU-000040V2R9Permissions for the Security event log must prevent access by non-privileged accounts.
WN16-AU-000050V2R9Permissions for the System event log must prevent access by non-privileged accounts.
WN16-UR-000260V2R9The Manage auditing and security log user right must only be assigned to the Administrators group.
WN22-AU-000030V2R5Windows Server 2022 permissions for the Application event log must prevent access by nonprivileged accounts.
WN22-AU-000040V2R5Windows Server 2022 permissions for the Security event log must prevent access by nonprivileged accounts.
WN22-AU-000050V2R5Windows Server 2022 permissions for the System event log must prevent access by nonprivileged accounts.
WN22-UR-000170V2R5Windows Server 2022 manage auditing and security log user right must only be assigned to the Administrators group.