SRG-OS-000341-GPOS-00132 Controls

STIG IDVersionTitleProduct
ALMA-09-051830V1R1AlmaLinux OS 9 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.
ALMA-09-051940V1R1AlmaLinux OS 9 must use a separate file system for the system audit data path.
ALMA-09-052050V1R1AlmaLinux OS 9 must allocate audit record storage capacity to store at least one week's worth of audit records.
UBTU-18-010314V2R15The Ubuntu operating system must allocate audit record storage capacity to store at least one weeks worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
UBTU-20-010215V1R9The Ubuntu operating system must allocate audit record storage capacity to store at least one weeks' worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
UBTU-24-900920V1R1Ubuntu 24.04 LTS must allocate audit record storage capacity to store at least one week's worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
WN22-CC-000270V2R1Windows Server 2022 Application event log size must be configured to 32768 KB or greater.
WN22-CC-000280V2R1Windows Server 2022 Security event log size must be configured to 196608 KB or greater.
WN22-CC-000290V2R1Windows Server 2022 System event log size must be configured to 32768 KB or greater.
WN10-AU-000500V2R8The Application event log size must be configured to 32768 KB or greater.
WN10-AU-000505V2R8The Security event log size must be configured to 1024000 KB or greater.
WN10-AU-000510V2R8The System event log size must be configured to 32768 KB or greater.
APPL-15-001029V1R1The macOS system must configure audit retention to seven days.
APPL-15-004050V1R1The macOS system must configure install.log retention to 365.
APPL-14-001029V2R1The macOS system must configure audit retention to seven days.
APPL-14-004050V2R1The macOS system must configure install.log retention to 365.
WN11-AU-000500V2R1The Application event log size must be configured to 32768 KB or greater.
WN11-AU-000505V2R1The Security event log size must be configured to 1024000 KB or greater.
WN11-AU-000510V2R1The System event log size must be configured to 32768 KB or greater.
UBTU-22-653035V2R1Ubuntu 22.04 LTS must allocate audit record storage capacity to store at least one weeks' worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
RHEL-08-030602V1R9RHEL 8 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.
RHEL-08-030660V1R9RHEL 8 must allocate audit record storage capacity to store at least one week of audit records, when audit records are not immediately sent to a central audit record storage facility.
RHEL-09-231030V2R1RHEL 9 must use a separate file system for the system audit data path.
RHEL-09-653030V2R1RHEL 9 must allocate audit record storage capacity to store at least one week's worth of audit records.
OL09-00-000002V1R1OL 9 must use a separate file system for the system audit data path.
OL09-00-000850V1R1OL 9 must allocate audit record storage capacity to store at least one week's worth of audit records.
WN16-CC-000300V2R10The Application event log size must be configured to 32768 KB or greater.
WN16-CC-000310V2R10The Security event log size must be configured to 196608 KB or greater.
WN16-CC-000320V2R10The System event log size must be configured to 32768 KB or greater.
SLES-15-030660V1R9The SUSE operating system must allocate audit record storage capacity to store at least one week of audit records when audit records are not immediately sent to a central audit record storage facility.
SLES-12-020020V2R13The SUSE operating system must allocate audit record storage capacity to store at least one weeks worth of audit records when audit records are not immediately sent to a central audit record storage facility.
OL07-00-021330V2R14The Oracle Linux operating system must use a separate file system for the system audit data path large enough to hold at least one week of audit data.
WN19-CC-000270V2R8Windows Server 2019 Application event log size must be configured to 32768 KB or greater.
WN19-CC-000280V2R8Windows Server 2019 Security event log size must be configured to 196608 KB or greater.
WN19-CC-000290V2R8Windows Server 2019 System event log size must be configured to 32768 KB or greater.
OL08-00-030660V1R9OL 8 must allocate audit record storage capacity to store at least one week of audit records when audit records are not immediately sent to a central audit record storage facility.