SRG-OS-000342-GPOS-00133 Controls

STIG IDVersionTitleProduct
ALMA-09-052930V1R1AlmaLinux OS 9 must have the rsyslog package installed.
ALMA-09-053040V1R1AlmaLinux OS 9 must be configured to forward audit records via TCP to a different system or media from the system being audited via rsyslog.
ALMA-09-053150V1R1The rsyslog service on AlmaLinux OS 9 must be active.
UBTU-18-010025V2R15The Ubuntu operating system audit event multiplexor must be configured to off-load audit logs onto a different system or storage media from the system being audited.
UBTU-20-010216V1R9The Ubuntu operating system audit event multiplexor must be configured to off-load audit logs onto a different system or storage media from the system being audited.
UBTU-24-100450V1R1Ubuntu 24.04 LTS audit event multiplexor must be configured to offload audit logs onto a different system or storage media from the system being audited.
WN22-AU-000010V2R1Windows Server 2022 audit records must be backed up to a different system or media than the system being audited.
UBTU-22-653020V2R1Ubuntu 22.04 LTS audit event multiplexor must be configured to offload audit logs onto a different system from the system being audited.
RHEL-08-030062V1R9RHEL 8 must label all off-loaded audit logs before sending them to the central log server.
RHEL-08-030690V1R9The RHEL 8 audit records must be off-loaded onto a different system or storage media from the system being audited.
RHEL-08-030700V1R9RHEL 8 must take appropriate action when the internal event queue is full.
RHEL-08-030710V1R9RHEL 8 must encrypt the transfer of audit records off-loaded onto a different system or media from the system being audited.
RHEL-08-030720V1R9RHEL 8 must authenticate the remote logging server for off-loading audit logs.
RHEL-07-030201V3R8The Red Hat Enterprise Linux operating system must be configured to off-load audit logs onto a different system or storage media from the system being audited.
RHEL-07-030210V3R8The Red Hat Enterprise Linux operating system must take appropriate action when the remote logging buffer is full.
RHEL-07-030211V3R8The Red Hat Enterprise Linux operating system must label all off-loaded audit logs before sending them to the central log server.
RHEL-07-030300V3R8The Red Hat Enterprise Linux operating system must off-load audit records onto a different system or media from the system being audited.
RHEL-07-030310V3R8The Red Hat Enterprise Linux operating system must encrypt the transfer of audit records off-loaded onto a different system or media from the system being audited.
RHEL-07-030320V3R8The Red Hat Enterprise Linux operating system must be configured so that the audit system takes appropriate action when the audit storage volume is full.
RHEL-07-030321V3R8The Red Hat Enterprise Linux operating system must be configured so that the audit system takes appropriate action when there is an error sending audit records to a remote system.
RHEL-09-652035V2R1RHEL 9 must be configured to offload audit records onto a different system from the system being audited via syslog.
RHEL-09-652040V2R1RHEL 9 must authenticate the remote logging server for offloading audit logs via rsyslog.
RHEL-09-652045V2R1RHEL 9 must encrypt the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog.
RHEL-09-652050V2R1RHEL 9 must encrypt via the gtls driver the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog.
RHEL-09-653065V2R1RHEL 9 must take appropriate action when the internal event queue is full.
RHEL-09-653130V2R1RHEL 9 audispd-plugins package must be installed.
OL09-00-000450V1R1OL 9 must have the audispd-plugins package installed.
OL09-00-000855V1R1OL 9 must be configured to offload audit records onto a different system from the system being audited via syslog.
OL09-00-000860V1R1OL 9 must take appropriate action when the internal event queue is full.
OL09-00-005015V1R1OL 9 must authenticate the remote logging server for offloading audit logs via rsyslog.
OL09-00-005020V1R1OL 9 must encrypt the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog.
OL09-00-005025V1R1OL 9 must encrypt via the gtls driver the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog.
WN16-AU-000010V2R10Audit records must be backed up to a different system or media than the system being audited.
SLES-15-030670V1R9The audit-audispd-plugins must be installed on the SUSE operating system.
SLES-15-030680V1R9The SUSE operating system audit event multiplexor must be configured to use Kerberos.
SLES-15-030690V1R9Audispd must off-load audit records onto a different system or media from the SUSE operating system being audited.
SLES-12-020070V2R13The audit-audispd-plugins must be installed on the SUSE operating system.
SLES-12-020080V2R13The SUSE operating system audit event multiplexor must be configured to use Kerberos.
SLES-12-020090V2R13Audispd must off-load audit records onto a different system or media from the SUSE operating system being audited.
OL07-00-030201V2R14The Oracle Linux operating system must be configured to off-load audit logs onto a different system or storage media from the system being audited.
OL07-00-030210V2R14The Oracle Linux operating system must take appropriate action when the remote logging buffer is full.
OL07-00-030211V2R14The Oracle Linux operating system must label all off-loaded audit logs before sending them to the central log server.
OL07-00-030300V2R14The Oracle Linux operating system must off-load audit records onto a different system or media from the system being audited.
OL07-00-030310V2R14The Oracle Linux operating system must encrypt the transfer of audit records off-loaded onto a different system or media from the system being audited.
OL07-00-030320V2R14The Oracle Linux operating system must be configured so that the audit system takes appropriate action when the audit storage volume is full.
OL07-00-030321V2R14The Oracle Linux operating system must be configured so that the audit system takes appropriate action when there is an error sending audit records to a remote system.
WN19-AU-000010V2R8Windows Server 2019 audit records must be backed up to a different system or media than the system being audited.
OL08-00-030062V1R9OL 8 must label all offloaded audit logs before sending them to the central log server.
OL08-00-030690V1R9The OL 8 audit records must be offloaded onto a different system or storage media from the system being audited.
OL08-00-030700V1R9OL 8 must take appropriate action when the internal event queue is full.
OL08-00-030710V1R9OL 8 must encrypt the transfer of audit records offloaded onto a different system or media from the system being audited.
OL08-00-030720V1R9OL 8 must authenticate the remote logging server for offloading audit logs.