CIS Red Hat EL8 Workstation L2 v1.0.1

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS Red Hat EL8 Workstation L2 v1.0.1

Updated: 6/1/2022

Authority: Operating Systems and Applications

Plugin: Unix

Revision: 1.6

Estimated Item Count: 127

Audit Changelog

 
Revision 1.6

Jun 1, 2022

Miscellaneous
  • Audit deprecated.
  • Metadata updated.
  • References updated.
Revision 1.5

May 11, 2022

Functional Update
  • 1.1.22 Disable Automounting
  • 2.2.16 Ensure CUPS is not enabled
Revision 1.4

Apr 25, 2022

Miscellaneous
  • Metadata updated.
Revision 1.3

Mar 29, 2022

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.2

Mar 22, 2022

Miscellaneous
  • Metadata updated.
  • References updated.
Added
  • 4.1.4 Ensure login and logout events are collected - /var/run/faillock
  • 4.1.4 Ensure login and logout events are collected - auditctl /var/run/faillock
Removed
  • 4.1.4 Ensure login and logout events are collected - /var/log/faillock
  • 4.1.4 Ensure login and logout events are collected - auditctl /var/log/faillock
Revision 1.1

Oct 25, 2021

Informational Update
  • 3.6 Disable IPv6
  • 4.1.10 Ensure unsuccessful unauthorized file access attempts are collected - EACCES (64-bit)
  • 4.1.10 Ensure unsuccessful unauthorized file access attempts are collected - EPERM (64-bit)
  • 4.1.10 Ensure unsuccessful unauthorized file access attempts are collected - auditctl EACCES (64-bit)
  • 4.1.10 Ensure unsuccessful unauthorized file access attempts are collected - auditctl EPERM (64-bit)
  • 4.1.12 Ensure successful file system mounts are collected - auditctl (64-bit)
  • 4.1.8 Ensure events that modify the system's network environment are collected - auditctl sethostname (64-bit)
  • 4.1.8 Ensure events that modify the system's network environment are collected - sethostname (64-bit)
  • 4.1.9 Ensure discretionary access control permission modification events are collected - auditctl chmod/fchmod/fchmodat (64-bit)
  • 4.1.9 Ensure discretionary access control permission modification events are collected - auditctl chown/fchown/fchownat/lchown (64-bit)
  • 4.1.9 Ensure discretionary access control permission modification events are collected - auditctl xattr (64-bit)
  • 4.1.9 Ensure discretionary access control permission modification events are collected - chmod/fchmod/fchmodat (64-bit)
  • 4.1.9 Ensure discretionary access control permission modification events are collected - chown/fchown/fchownat/lchown (64-bit)
  • 4.1.9 Ensure discretionary access control permission modification events are collected - xattr (64-bit)
Added
  • 4.1.12 Ensure successful file system mounts are collected (64-bit)
  • 4.1.14 Ensure file deletion events by users are collected (32-bit)
  • 4.1.14 Ensure file deletion events by users are collected (64-bit)
  • 4.1.14 Ensure file deletion events by users are collected - auditctl (32-bit)
  • 4.1.14 Ensure file deletion events by users are collected - auditctl (64-bit)
  • 4.1.15 Ensure kernel module loading and unloading is collected - auditctl modules
  • 4.1.15 Ensure kernel module loading and unloading is collected - modules
  • 4.1.6 Ensure events that modify date and time information are collected - adjtimex (64-bit)
  • 4.1.6 Ensure events that modify date and time information are collected - auditctl adjtimex (64-bit)
  • 4.1.6 Ensure events that modify date and time information are collected - auditctl clock_settime (64-bit)
  • 4.1.6 Ensure events that modify date and time information are collected - clock_settime (64-bit)
Removed
  • 4.1.12 Ensure successful file system mounts are collected - b64
  • 4.1.14 Ensure file deletion events by users are collected - auditctl x64
  • 4.1.14 Ensure file deletion events by users are collected - auditctl x86
  • 4.1.14 Ensure file deletion events by users are collected - x64
  • 4.1.14 Ensure file deletion events by users are collected - x86
  • 4.1.15 Ensure kernel module loading and unloading is collected - b32 auditctl modules
  • 4.1.15 Ensure kernel module loading and unloading is collected - b32 modules
  • 4.1.15 Ensure kernel module loading and unloading is collected - b64 auditctl modules
  • 4.1.15 Ensure kernel module loading and unloading is collected - b64 modules
  • 4.1.6 Ensure events that modify date and time information are collected - adjtimex x64
  • 4.1.6 Ensure events that modify date and time information are collected - auditctl adjtimex x64
  • 4.1.6 Ensure events that modify date and time information are collected - auditctl clock_settime x64
  • 4.1.6 Ensure events that modify date and time information are collected - clock_settime x64