SRG-OS-000327-GPOS-00127 Controls

STIG IDVersionTitleProduct
ALMA-09-007280V1R1AlmaLinux OS 9 must audit uses of the "execve" system call.
ALMA-09-031920V1R1AlmaLinux OS 9 must require users to provide authentication for privilege escalation.
ALMA-09-032030V1R1AlmaLinux OS 9 must require users to provide a password for privilege escalation.
ALMA-09-032140V1R1AlmaLinux OS 9 must not be configured to bypass password requirements for privilege escalation.
ALMA-09-032250V1R1AlmaLinux OS 9 must require reauthentication when using the "sudo" command.
WN22-AU-000090V2R1Windows Server 2022 must be configured to audit Account Management - Other Account Management Events successes.
WN22-AU-000140V2R1Windows Server 2022 must be configured to audit Detailed Tracking - Process Creation successes.
WN22-AU-000260V2R1Windows Server 2022 must be configured to audit Policy Change - Audit Policy Change successes.
WN22-AU-000270V2R1Windows Server 2022 must be configured to audit Policy Change - Audit Policy Change failures.
WN22-AU-000280V2R1Windows Server 2022 must be configured to audit Policy Change - Authentication Policy Change successes.
WN22-AU-000290V2R1Windows Server 2022 must be configured to audit Policy Change - Authorization Policy Change successes.
WN22-AU-000300V2R1Windows Server 2022 must be configured to audit Privilege Use - Sensitive Privilege Use successes.
WN22-AU-000310V2R1Windows Server 2022 must be configured to audit Privilege Use - Sensitive Privilege Use failures.
WN22-AU-000320V2R1Windows Server 2022 must be configured to audit System - IPsec Driver successes.
WN22-AU-000330V2R1Windows Server 2022 must be configured to audit System - IPsec Driver failures.
WN22-AU-000340V2R1Windows Server 2022 must be configured to audit System - Other System Events successes.
WN22-AU-000350V2R1Windows Server 2022 must be configured to audit System - Other System Events failures.
WN22-AU-000360V2R1Windows Server 2022 must be configured to audit System - Security State Change successes.
WN22-AU-000370V2R1Windows Server 2022 must be configured to audit System - Security System Extension successes.
WN22-AU-000380V2R1Windows Server 2022 must be configured to audit System - System Integrity successes.
WN22-AU-000390V2R1Windows Server 2022 must be configured to audit System - System Integrity failures.
WN22-DC-000170V2R1Windows Server 2022 Active Directory Group Policy objects must be configured with proper audit settings.
WN22-DC-000180V2R1Windows Server 2022 Active Directory Domain object must be configured with proper audit settings.
WN22-DC-000190V2R1Windows Server 2022 Active Directory Infrastructure object must be configured with proper audit settings.
WN22-DC-000200V2R1Windows Server 2022 Active Directory Domain Controllers Organizational Unit (OU) object must be configured with proper audit settings.
WN22-DC-000210V2R1Windows Server 2022 Active Directory AdminSDHolder object must be configured with proper audit settings.
WN22-DC-000220V2R1Windows Server 2022 Active Directory RID Manager$ object must be configured with proper audit settings.
WN22-DC-000240V2R1Windows Server 2022 must be configured to audit DS Access - Directory Service Access successes.
WN22-DC-000250V2R1Windows Server 2022 must be configured to audit DS Access - Directory Service Access failures.
WN22-DC-000260V2R1Windows Server 2022 must be configured to audit DS Access - Directory Service Changes successes.
WN10-AU-000105V2R8The system must be configured to audit Policy Change - Authentication Policy Change successes.
WN10-AU-000110V2R8The system must be configured to audit Privilege Use - Sensitive Privilege Use failures.
WN10-AU-000115V2R8The system must be configured to audit Privilege Use - Sensitive Privilege Use successes.
WN10-AU-000140V2R8The system must be configured to audit System - Security State Change successes.
WN10-AU-000150V2R8The system must be configured to audit System - Security System Extension successes.
WN10-AU-000155V2R8The system must be configured to audit System - System Integrity failures.
WN10-AU-000160V2R8The system must be configured to audit System - System Integrity successes.
WN11-AU-000110V2R1The system must be configured to audit Privilege Use - Sensitive Privilege Use failures.
RHEL-07-030360V3R8The Red Hat Enterprise Linux operating system must audit all executions of privileged functions.
OL09-00-002362V1R1OL 9 must require users to reauthenticate for privilege escalation.
OL09-00-002363V1R1OL 9 must require users to provide a password for privilege escalation.
OL09-00-002364V1R1OL 9 must not be configured to bypass password requirements for privilege escalation.
WN16-AU-000100V2R10Windows Server 2016 must be configured to audit Account Management - Other Account Management Events successes.
WN16-AU-000170V2R10Windows Server 2016 must be configured to audit Detailed Tracking - Process Creation successes.
WN16-AU-000310V2R10Windows Server 2016 must be configured to audit Policy Change - Audit Policy Change successes.
WN16-AU-000320V2R10Windows Server 2016 must be configured to audit Policy Change - Audit Policy Change failures.
WN16-AU-000330V2R10Windows Server 2016 must be configured to audit Policy Change - Authentication Policy Change successes.
WN16-AU-000340V2R10Windows Server 2016 must be configured to audit Policy Change - Authorization Policy Change successes.
WN16-AU-000350V2R10Windows Server 2016 must be configured to audit Privilege Use - Sensitive Privilege Use successes.
WN16-AU-000360V2R10Windows Server 2016 must be configured to audit Privilege Use - Sensitive Privilege Use failures.
WN16-AU-000370V2R10Windows Server 2016 must be configured to audit System - IPsec Driver successes.
WN16-AU-000380V2R10Windows Server 2016 must be configured to audit System - IPsec Driver failures.
WN16-AU-000390V2R10Windows Server 2016 must be configured to audit System - Other System Events successes.
WN16-AU-000400V2R10Windows Server 2016 must be configured to audit System - Other System Events failures.
WN16-AU-000410V2R10Windows Server 2016 must be configured to audit System - Security State Change successes.
WN16-AU-000420V2R10Windows Server 2016 must be configured to audit System - Security System Extension successes.
WN16-AU-000440V2R10Windows Server 2016 must be configured to audit System - System Integrity successes.
WN16-AU-000450V2R10Windows Server 2016 must be configured to audit System - System Integrity failures.
WN16-DC-000170V2R10Active Directory Group Policy objects must be configured with proper audit settings.
WN16-DC-000180V2R10The Active Directory Domain object must be configured with proper audit settings.
WN16-DC-000190V2R10The Active Directory Infrastructure object must be configured with proper audit settings.
WN16-DC-000200V2R10The Active Directory Domain Controllers Organizational Unit (OU) object must be configured with proper audit settings.
WN16-DC-000210V2R10The Active Directory AdminSDHolder object must be configured with proper audit settings.
WN16-DC-000220V2R10The Active Directory RID Manager$ object must be configured with proper audit settings.
WN16-DC-000240V2R10Windows Server 2016 must be configured to audit DS Access - Directory Service Access successes.
WN16-DC-000250V2R10Windows Server 2016 must be configured to audit DS Access - Directory Service Access failures.
WN16-DC-000260V2R10Windows Server 2016 must be configured to audit DS Access - Directory Service Changes successes.
SLES-15-030640V1R9The SUSE operating system must generate audit records for all uses of the privileged functions.
SLES-12-020240V2R13The SUSE operating system must generate audit records for all uses of the privileged functions.
OL07-00-030360V2R14The Oracle Linux operating system must audit all executions of privileged functions.
WN19-AU-000090V2R8Windows Server 2019 must be configured to audit Account Management - Other Account Management Events successes.
WN19-AU-000140V2R8Windows Server 2019 must be configured to audit Detailed Tracking - Process Creation successes.
WN19-AU-000260V2R8Windows Server 2019 must be configured to audit Policy Change - Audit Policy Change successes.
WN19-AU-000270V2R8Windows Server 2019 must be configured to audit Policy Change - Audit Policy Change failures.
WN19-AU-000280V2R8Windows Server 2019 must be configured to audit Policy Change - Authentication Policy Change successes.
WN19-AU-000290V2R8Windows Server 2019 must be configured to audit Policy Change - Authorization Policy Change successes.
WN19-AU-000300V2R8Windows Server 2019 must be configured to audit Privilege Use - Sensitive Privilege Use successes.
WN19-AU-000310V2R8Windows Server 2019 must be configured to audit Privilege Use - Sensitive Privilege Use failures.
WN19-AU-000320V2R8Windows Server 2019 must be configured to audit System - IPsec Driver successes.
WN19-AU-000330V2R8Windows Server 2019 must be configured to audit System - IPsec Driver failures.
WN19-AU-000340V2R8Windows Server 2019 must be configured to audit System - Other System Events successes.
WN19-AU-000350V2R8Windows Server 2019 must be configured to audit System - Other System Events failures.
WN19-AU-000360V2R8Windows Server 2019 must be configured to audit System - Security State Change successes.
WN19-AU-000370V2R8Windows Server 2019 must be configured to audit System - Security System Extension successes.
WN19-AU-000380V2R8Windows Server 2019 must be configured to audit System - System Integrity successes.
WN19-AU-000390V2R8Windows Server 2019 must be configured to audit System - System Integrity failures.
WN19-DC-000170V2R8Windows Server 2019 Active Directory Group Policy objects must be configured with proper audit settings.
WN19-DC-000180V2R8Windows Server 2019 Active Directory Domain object must be configured with proper audit settings.
WN19-DC-000190V2R8Windows Server 2019 Active Directory Infrastructure object must be configured with proper audit settings.
WN19-DC-000200V2R8Windows Server 2019 Active Directory Domain Controllers Organizational Unit (OU) object must be configured with proper audit settings.
WN19-DC-000210V2R8Windows Server 2019 Active Directory AdminSDHolder object must be configured with proper audit settings.
WN19-DC-000220V2R8Windows Server 2019 Active Directory RID Manager$ object must be configured with proper audit settings.
WN19-DC-000240V2R8Windows Server 2019 must be configured to audit DS Access - Directory Service Access successes.
WN19-DC-000250V2R8Windows Server 2019 must be configured to audit DS Access - Directory Service Access failures.
WN19-DC-000260V2R8Windows Server 2019 must be configured to audit DS Access - Directory Service Changes successes.