800-53|SI-11b.

Title

ERROR HANDLING

Description

Reveals error messages only to [Assignment: organization-defined personnel or roles].

Reference Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

Family: SYSTEM AND INFORMATION INTEGRITY

Baseline Impact: MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
2.5 Disable client-facing stack traces (check for defined exception type)UnixCIS Apache Tomcat 7 L1 v1.1.0
2.5 Disable client-facing stack traces (check for defined exception type)UnixCIS Apache Tomcat 7 L1 v1.1.0 Middleware
4.1.4.1 Ensure Audit logs are owned by root and mode 0600 or less permissiveUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
18.8.47.5.1 Ensure 'Microsoft Support Diagnostic Tool: Turn on MSDT interactive communication with support provider' is set to 'Disabled'WindowsCIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0
18.8.47.5.1 Ensure 'Microsoft Support Diagnostic Tool: Turn on MSDT interactive communication with support provider' is set to 'Disabled'WindowsCIS Windows 7 Workstation Level 2 v3.2.0
AIX7-00-002070 - AIX log files must be owned by a system account.UnixDISA STIG AIX 7.x v2r9
AIX7-00-002071 - AIX log files must be owned by a system group.UnixDISA STIG AIX 7.x v2r9
AIX7-00-003006 - AIX log files must have mode 0640 or less permissive.UnixDISA STIG AIX 7.x v2r9
AIX7-00-003007 - AIX log files must not have extended ACLs, except as needed to support authorized software.UnixDISA STIG AIX 7.x v2r9
AOSX-13-002105 - The macOS system must be configured with system log files owned by root and group-owned by wheel or admin - aslUnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-13-002105 - The macOS system must be configured with system log files owned by root and group-owned by wheel or admin - newsyslogUnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-13-002106 - The macOS system must be configured with system log files set to mode 640 or less permissive - aslUnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-13-002106 - The macOS system must be configured with system log files set to mode 640 or less permissive - newsyslogUnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-13-002107 - The macOS system must be configured with access control lists (ACLs) for system log files to be set correctly - aslUnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-13-002107 - The macOS system must be configured with access control lists (ACLs) for system log files to be set correctly - newsyslogUnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-14-000030 - The macOS system must be configured so that log files must not contain access control lists (ACLs).UnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-004001 - The macOS system must be configured with system log files owned by root and group-owned by wheel or admin - ASLUnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-004001 - The macOS system must be configured with system log files owned by root and group-owned by wheel or admin - NewsyslogUnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-004002 - The macOS system must be configured with system log files set to mode 640 or less permissive - ASLUnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-004002 - The macOS system must be configured with system log files set to mode 640 or less permissive - NewsyslogUnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-15-000030 - The macOS system must be configured so that log files must not contain access control lists (ACLs).UnixDISA STIG Apple Mac OSX 10.15 v1r10
AOSX-15-004001 - The macOS system must be configured with system log files owned by root and group-owned by wheel or admin - ASLUnixDISA STIG Apple Mac OSX 10.15 v1r10
AOSX-15-004001 - The macOS system must be configured with system log files owned by root and group-owned by wheel or admin - NewsyslogUnixDISA STIG Apple Mac OSX 10.15 v1r10
AOSX-15-004002 - The macOS system must be configured with system log files set to mode 640 or less permissive - ASLUnixDISA STIG Apple Mac OSX 10.15 v1r10
AOSX-15-004002 - The macOS system must be configured with system log files set to mode 640 or less permissive - NewsyslogUnixDISA STIG Apple Mac OSX 10.15 v1r10
APPL-11-000030 - The macOS system must be configured so that log files must not contain access control lists (ACLs).UnixDISA STIG Apple macOS 11 v1r5
APPL-11-000030 - The macOS system must be configured so that log files must not contain access control lists (ACLs).UnixDISA STIG Apple macOS 11 v1r8
APPL-11-004001 - The macOS system must be configured with system log files owned by root and group-owned by wheel or admin - aslUnixDISA STIG Apple macOS 11 v1r5
APPL-11-004001 - The macOS system must be configured with system log files owned by root and group-owned by wheel or admin - aslUnixDISA STIG Apple macOS 11 v1r8
APPL-11-004001 - The macOS system must be configured with system log files owned by root and group-owned by wheel or admin - newsyslogUnixDISA STIG Apple macOS 11 v1r5
APPL-11-004001 - The macOS system must be configured with system log files owned by root and group-owned by wheel or admin - newsyslogUnixDISA STIG Apple macOS 11 v1r8
APPL-11-004002 - The macOS system must be configured with system log files set to mode 640 or less permissive - aslUnixDISA STIG Apple macOS 11 v1r5
APPL-11-004002 - The macOS system must be configured with system log files set to mode 640 or less permissive - aslUnixDISA STIG Apple macOS 11 v1r8
APPL-11-004002 - The macOS system must be configured with system log files set to mode 640 or less permissive - newsyslogUnixDISA STIG Apple macOS 11 v1r8
APPL-11-004002 - The macOS system must be configured with system log files set to mode 640 or less permissive - newsyslogUnixDISA STIG Apple macOS 11 v1r5
APPL-12-000030 - The macOS system must be configured so that log files must not contain access control lists (ACLs).UnixDISA STIG Apple macOS 12 v1r9
APPL-12-004001 - The macOS system must be configured with system log files owned by root and group-owned by wheel or admin.UnixDISA STIG Apple macOS 12 v1r9
APPL-12-004002 - The macOS system must be configured with system log files set to mode 640 or less permissive.UnixDISA STIG Apple macOS 12 v1r9
APPL-13-000030 - The macOS system must be configured so that log files do not contain access control lists (ACLs).UnixDISA STIG Apple macOS 13 v1r4
APPL-13-004001 - The macOS system must be configured with system log files owned by root and group-owned by wheel or admin.UnixDISA STIG Apple macOS 13 v1r4
APPL-13-004002 - The macOS system must be configured with system log files set to mode 640 or less permissive.UnixDISA STIG Apple macOS 13 v1r4
APPL-14-002021 - The macOS system must disable sending diagnostic and usage data to Apple.UnixDISA Apple macOS 14 (Sonoma) STIG v2r1
APPL-14-004001 - The macOS system must configure Apple System Log files to be owned by root and group to wheel.UnixDISA Apple macOS 14 (Sonoma) STIG v2r1
APPL-14-004002 - The macOS system must configure Apple System Log files to mode 640 or less permissive.UnixDISA Apple macOS 14 (Sonoma) STIG v2r1
APPL-14-004030 - The macOS system must configure system log files to be owned by root and group to wheel.UnixDISA Apple macOS 14 (Sonoma) STIG v2r1
APPL-14-004040 - The macOS system must configure system log files to mode 640 or less permissive.UnixDISA Apple macOS 14 (Sonoma) STIG v2r1
APPL-15-002021 - The macOS system must disable sending diagnostic and usage data to Apple.UnixDISA Apple macOS 15 (Sequoia) STIG v1r1
APPL-15-004001 - The macOS system must configure Apple System Log (ASL) files owned by root and group to wheel.UnixDISA Apple macOS 15 (Sequoia) STIG v1r1
APPL-15-004002 - The macOS system must configure Apple System Log (ASL) files to mode 640 or less permissive.UnixDISA Apple macOS 15 (Sequoia) STIG v1r1
APPL-15-004030 - The macOS system must configure system log files owned by root and group to wheel.UnixDISA Apple macOS 15 (Sequoia) STIG v1r1