SRG-OS-000363-GPOS-00150 Controls

STIG IDVersionTitleProduct
RHEL-08-010360V1R6The RHEL 8 file integrity tool must notify the system administrator when changes to the baseline configuration or anomalies in the operation of any security functions are discovered within an organizationally defined frequency.
SLES-15-010420V1R4Advanced Intrusion Detection Environment (AIDE) must verify the baseline SUSE operating system configuration at least weekly.
WN19-00-000220V3R1Windows Server 2019 system files must be monitored for unauthorized changes.
UBTU-18-010508V2R12The Ubuntu operating system must notify designated personnel if baseline configurations are changed in an unauthorized manner. The file integrity tool must notify the system administrator when changes to the baseline configuration or anomalies in the operation of any security functions are discovered.
UBTU-20-010437V1R6The Ubuntu operating system must notify designated personnel if baseline configurations are changed in an unauthorized manner. The file integrity tool must notify the System Administrator when changes to the baseline configuration or anomalies in the oper
OL07-00-020030V3R1The Oracle Linux operating system must be configured so that a file integrity tool verifies the baseline operating system configuration at least weekly.
OL07-00-020040V3R1The Oracle Linux operating system must be configured so that designated personnel are notified if baseline configurations are changed in an unauthorized manner.
OL07-00-020028V3R1The Oracle Linux operating system must be configured to allow sending email notifications of unauthorized configuration changes to designated personnel.
RHEL-07-020030V3R6The Red Hat Enterprise Linux operating system must be configured so that a file integrity tool verifies the baseline operating system configuration at least weekly.
RHEL-07-020040V3R6The Red Hat Enterprise Linux operating system must be configured so that designated personnel are notified if baseline configurations are changed in an unauthorized manner.
SLES-12-010500V3R1Advanced Intrusion Detection Environment (AIDE) must verify the baseline SUSE operating system configuration at least weekly.
SLES-12-010499V3R1The SUSE operating system must use a file integrity tool to verify correct operation of all security functions.
SLES-12-010498V3R1The SUSE operating system must be configured to allow sending email notifications of unauthorized configuration changes to designated personnel.
ALMA-09-009260V1R1AlmaLinux OS 9 must have the s-nail package installed.
OL08-00-010360V1R6The OL 8 file integrity tool must notify the System Administrator (SA) when changes to the baseline configuration or anomalies in the operation of any security functions are discovered within an organizationally defined frequency.
OL08-00-010358V1R6OL 8 must be configured to allow sending email notifications of unauthorized configuration changes to designated personnel.
OL09-00-000290V1R1OL 9 must have the s-nail package installed.
OL09-00-000300V1R1OL 9 must have the Advanced Intrusion Detection Environment (AIDE) package installed.
OL09-00-000301V1R1OL 9 must routinely check the baseline configuration for unauthorized changes and notify the system administrator (SA) when anomalies in the operation of any security functions are discovered.
UBTU-22-651020V1R1Ubuntu 22.04 LTS must notify designated personnel if baseline configurations are changed in an unauthorized manner. The file integrity tool must notify the system administrator when changes to the baseline configuration or anomalies in the operation of any security functions are discovered.
RHEL-09-215095V2R5RHEL 9 must have the s-nail package installed.
RHEL-09-651010V2R5RHEL 9 must have the AIDE package installed.
RHEL-09-651015V2R5RHEL 9 must routinely check the baseline configuration for unauthorized changes and notify the system administrator when anomalies in the operation of any security functions are discovered.
WN16-00-000240V2R9System files must be monitored for unauthorized changes.
WN22-00-000220V2R5Windows Server 2022 system files must be monitored for unauthorized changes.