SRG-OS-000062-GPOS-00031 Controls

STIG IDVersionTitleProduct
ALMA-09-045670V1R1AlmaLinux OS 9 audit system must audit local events.
WN22-SO-000050V2R1Windows Server 2022 must force audit policy subcategory settings to override audit policy category settings.
WN10-SO-000030V2R8Audit policy using subcategories must be enabled.
WN11-SO-000030V2R1Audit policy using subcategories must be enabled.
RHEL-08-030130V1R9RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
RHEL-08-030140V1R9RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.
RHEL-08-030150V1R9RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
RHEL-08-030160V1R9RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
RHEL-08-030170V1R9RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
RHEL-08-030171V1R9RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.
RHEL-08-030172V1R9RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/.
RHEL-08-030180V1R9The RHEL 8 audit package must be installed.
RHEL-08-030190V1R9Successful/unsuccessful uses of the su command in RHEL 8 must generate an audit record.
RHEL-08-030200V1R9The RHEL 8 audit system must be configured to audit any usage of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls.
RHEL-08-030250V1R9Successful/unsuccessful uses of the chage command in RHEL 8 must generate an audit record.
RHEL-08-030260V1R9Successful/unsuccessful uses of the chcon command in RHEL 8 must generate an audit record.
RHEL-08-030280V1R9Successful/unsuccessful uses of the ssh-agent in RHEL 8 must generate an audit record.
RHEL-08-030290V1R9Successful/unsuccessful uses of the passwd command in RHEL 8 must generate an audit record.
RHEL-08-030300V1R9Successful/unsuccessful uses of the mount command in RHEL 8 must generate an audit record.
RHEL-08-030301V1R9Successful/unsuccessful uses of the umount command in RHEL 8 must generate an audit record.
RHEL-08-030302V1R9Successful/unsuccessful uses of the mount syscall in RHEL 8 must generate an audit record.
RHEL-08-030310V1R9Successful/unsuccessful uses of the unix_update in RHEL 8 must generate an audit record.
RHEL-08-030311V1R9Successful/unsuccessful uses of postdrop in RHEL 8 must generate an audit record.
RHEL-08-030312V1R9Successful/unsuccessful uses of postqueue in RHEL 8 must generate an audit record.
RHEL-08-030313V1R9Successful/unsuccessful uses of semanage in RHEL 8 must generate an audit record.
RHEL-08-030314V1R9Successful/unsuccessful uses of setfiles in RHEL 8 must generate an audit record.
RHEL-08-030315V1R9Successful/unsuccessful uses of userhelper in RHEL 8 must generate an audit record.
RHEL-08-030316V1R9Successful/unsuccessful uses of setsebool in RHEL 8 must generate an audit record.
RHEL-08-030317V1R9Successful/unsuccessful uses of unix_chkpwd in RHEL 8 must generate an audit record.
RHEL-08-030320V1R9Successful/unsuccessful uses of the ssh-keysign in RHEL 8 must generate an audit record.
RHEL-08-030330V1R9Successful/unsuccessful uses of the setfacl command in RHEL 8 must generate an audit record.
RHEL-08-030340V1R9Successful/unsuccessful uses of the pam_timestamp_check command in RHEL 8 must generate an audit record.
RHEL-08-030350V1R9Successful/unsuccessful uses of the newgrp command in RHEL 8 must generate an audit record.
RHEL-08-030360V1R9Successful/unsuccessful uses of the init_module and finit_module system calls in RHEL 8 must generate an audit record.
RHEL-08-030361V1R9Successful/unsuccessful uses of the rename, unlink, rmdir, renameat, and unlinkat system calls in RHEL 8 must generate an audit record.
RHEL-08-030370V1R9Successful/unsuccessful uses of the gpasswd command in RHEL 8 must generate an audit record.
RHEL-08-030390V1R9Successful/unsuccessful uses of the delete_module command in RHEL 8 must generate an audit record.
RHEL-08-030400V1R9Successful/unsuccessful uses of the crontab command in RHEL 8 must generate an audit record.
RHEL-08-030410V1R9Successful/unsuccessful uses of the chsh command in RHEL 8 must generate an audit record.
RHEL-08-030420V1R9Successful/unsuccessful uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls in RHEL 8 must generate an audit record.
RHEL-08-030480V1R9Successful/unsuccessful uses of the chown, fchown, fchownat, and lchown system calls in RHEL 8 must generate an audit record.
RHEL-08-030490V1R9Successful/unsuccessful uses of the chmod, fchmod, and fchmodat system calls in RHEL 8 must generate an audit record.
RHEL-08-030550V1R9Successful/unsuccessful uses of the sudo command in RHEL 8 must generate an audit record.
RHEL-08-030560V1R9Successful/unsuccessful uses of the usermod command in RHEL 8 must generate an audit record.
RHEL-08-030570V1R9Successful/unsuccessful uses of the chacl command in RHEL 8 must generate an audit record.
RHEL-08-030580V1R9Successful/unsuccessful uses of the kmod command in RHEL 8 must generate an audit record.
RHEL-08-030590V1R9Successful/unsuccessful modifications to the faillock log file in RHEL 8 must generate an audit record.
RHEL-08-030600V1R9Successful/unsuccessful modifications to the lastlog file in RHEL 8 must generate an audit record.
RHEL-08-030601V1R9RHEL 8 must enable auditing of processes that start prior to the audit daemon.
RHEL-08-030603V1R9RHEL 8 must enable Linux audit logging for the USBGuard daemon.
RHEL-08-030181V1R9RHEL 8 audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.
RHEL-09-291025V2R1RHEL 9 must enable Linux audit logging for the USBGuard daemon.
RHEL-09-653010V2R1RHEL 9 audit package must be installed.
RHEL-09-653015V2R1RHEL 9 audit service must be enabled.
RHEL-09-653075V2R1RHEL 9 audit system must audit local events.
OL09-00-000440V1R1OL 9 must have the audit package installed.
OL09-00-000441V1R1OL 9 audit service must be enabled.
OL09-00-000760V1R1OL 9 audit system must take appropriate action when an error writing to the audit storage volume occurs.
OL09-00-000765V1R1OL 9 audit system must take appropriate action when the audit storage volume is full.
OL09-00-000770V1R1OL 9 audit system must take appropriate action when the audit files have reached maximum size.
OL09-00-000800V1R1OL 9 audit system must audit local events.
OL09-00-002330V1R1OL 9 must enable Linux audit logging for the USBGuard daemon.
WN16-SO-000050V2R10Audit policy using subcategories must be enabled.
WN19-SO-000050V2R8Windows Server 2019 must force audit policy subcategory settings to override audit policy category settings.
OL08-00-030313V1R9OL 8 must generate audit records for any use of the "semanage" command.
OL08-00-030314V1R9OL 8 must generate audit records for any use of the "setfiles" command.
OL08-00-030315V1R9OL 8 must generate audit records for any use of the "userhelper" command.