Item Search

NameAudit NamePluginCategory
2.1.3 (L1) Ensure notifications for internal users sending malware is EnabledCIS Microsoft 365 Foundations v6.0.1 L1 E5microsoft_azure

INCIDENT RESPONSE

AIOS-16-709200 - Apple iOS/iPadOS 16 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.MobileIron - DISA Apple iOS/iPadOS BYOAD 16 v1r2MDM

SYSTEM AND COMMUNICATIONS PROTECTION

AIOS-17-709200 - Apple iOS/iPadOS 17 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.MobileIron - DISA Apple iOS/iPadOS BYOAD 17 v1r2MDM

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-001340 - AlmaLinux OS 9 must prevent a user from overriding the session idle-delay setting for the graphical user interface.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

ACCESS CONTROL

ALMA-09-001560 - AlmaLinux OS 9 must prevent a user from overriding the session lock-delay setting for the graphical user interface.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

ACCESS CONTROL

ALMA-09-003650 - AlmaLinux OS 9 must force a frequent session key renegotiation for SSH connections to the server.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

ACCESS CONTROL

ALMA-09-004750 - AlmaLinux OS 9 must automatically expire temporary accounts within 72 hours.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

ACCESS CONTROL

ALMA-09-004970 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

ALMA-09-005410 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

ALMA-09-006290 - AlmaLinux OS 9 must require a boot loader password.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

ACCESS CONTROL

ALMA-09-006400 - AlmaLinux OS 9 must require a unique superuser's name upon booting into single-user and maintenance modes.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

ACCESS CONTROL

ALMA-09-006730 - The Ctrl-Alt-Delete key sequence must be disabled on AlmaLinux OS 9.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

ACCESS CONTROL

ALMA-09-007060 - AlmaLinux OS 9 must enable kernel parameters to enforce discretionary access control on hardlinks.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

ACCESS CONTROL

ALMA-09-008710 - AlmaLinux OS 9 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a command line user logon.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

ACCESS CONTROL

ALMA-09-034890 - AlmaLinux OS 9 must disable the graphical user interface automount function unless required.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-035440 - AlmaLinux OS 9 must block unauthorized peripherals before establishing a connection.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-035770 - AlmaLinux OS 9 must enforce password complexity by requiring that at least one lowercase character be used.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-036210 - AlmaLinux OS 9 must enforce password complexity by requiring that at least one uppercase character be used.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-036540 - AlmaLinux OS 9 passwords must be created with a minimum of 15 characters.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-037310 - AlmaLinux OS 9 must be configured so that libuser is configured to store only encrypted representations of passwords.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-037420 - AlmaLinux OS 9 must be configured so that the system's shadow file is configured to store only encrypted representations of passwords.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-040060 - AlmaLinux OS 9 must implement a FIPS 140-3-compliant systemwide cryptographic policy.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-040390 - AlmaLinux OS 9 must enable the Pluggable Authentication Module (PAM) interface for SSHD.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

MAINTENANCE

ALMA-09-041600 - AlmaLinux OS 9 local disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at rest protection.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-041930 - AlmaLinux OS 9 must use a Linux Security Module configured to enforce limits on system services.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-042040 - AlmaLinux OS 9 must have the policycoreutils package installed.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-042260 - A sticky bit must be set on all AlmaLinux OS 9 public directories.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-042810 - All AlmaLinux OS 9 networked systems must implement SSH to protect the confidentiality and integrity of transmitted and received information, including information being prepared for transmission.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-042920 - All AlmaLinux OS 9 networked systems must have the OpenSSH server installed.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-043140 - AlmaLinux OS 9 must implement DOD-approved encryption in the bind package.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-044130 - AlmaLinux OS 9 /var/log/messages file must be owned by root.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

SYSTEM AND INFORMATION INTEGRITY

ALMA-09-044240 - AlmaLinux OS 9 /var/log/messages file must have mode 0640 or less permissive.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

SYSTEM AND INFORMATION INTEGRITY

ALMA-09-045450 - AlmaLinux OS 9 must routinely check the baseline configuration for unauthorized changes and notify the system administrator when anomalies in the operation of any security functions are discovered.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

ALMA-09-046220 - AlmaLinux OS 9 must generate audit records for any use of the "poweroff" command.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-046880 - AlmaLinux OS 9 must produce audit records containing information to establish the identity of any individual or process associated with the event.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-047100 - The audit package must be installed on AlmaLinux OS 9.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

ALMA-09-048640 - AlmaLinux OS 9 must audit all uses of the chown, fchown, fchownat, and lchown system calls.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

ALMA-09-048970 - AlmaLinux OS 9 must audit all uses of the rename, unlink, rmdir, renameat, and unlinkat system calls.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

ALMA-09-049520 - AlmaLinux OS 9 must generate audit records for any use of the "passwd" command.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

ALMA-09-049630 - AlmaLinux OS 9 must generate audit records for any use of the "postdrop" command.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

ALMA-09-050730 - AlmaLinux OS 9 must generate audit records for any use of the "sudoedit" command.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

ALMA-09-051830 - AlmaLinux OS 9 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-052490 - AlmaLinux OS 9 must be configured to offload audit records onto a different system from the system being audited via syslog.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-052600 - AlmaLinux OS 9 must authenticate the remote logging server for offloading audit logs via rsyslog.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-053260 - AlmaLinux OS 9 must take action when allocated audit record storage volume reaches 95 percent of the audit record storage capacity.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-053920 - AlmaLinux OS 9 must have mail aliases to notify the information system security officer (ISSO) and system administrator (SA) (at a minimum) in the event of an audit processing failure.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-054360 - AlmaLinux OS 9 audit system must make full use of the audit storage space.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-054470 - AlmaLinux OS 9 audit system must take appropriate action when the audit files have reached maximum size.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-054690 - AlmaLinux OS 9 must periodically flush audit records to disk to prevent the loss of audit records.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-055680 - AlmaLinux OS 9 audit log directory must be owned by root to prevent unauthorized read access.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY