CCI|CCI-000163

Title

Protect audit information from unauthorized modification.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.126 UBTU-22-653045UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.127 UBTU-22-653050UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.128 UBTU-22-653055UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.184 UBTU-24-901300UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.185 UBTU-24-901310UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.186 UBTU-24-901350UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.188 UBTU-24-909000UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.214 OL08-00-030070UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.215 OL08-00-030080UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.216 OL08-00-030090UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.217 OL08-00-030100UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.218 OL08-00-030110UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.219 OL08-00-030120UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.220 OL08-00-030121UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.221 OL08-00-030122UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.381 RHEL-09-653080UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.382 RHEL-09-653085UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.383 RHEL-09-653090UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.444 RHEL-09-654270UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.445 RHEL-09-654275UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
2.001 - Permissions for event logs must conform to minimum requirements - application.evtxWindowsDISA Windows Vista STIG v6r41
2.001 - Permissions for event logs must conform to minimum requirements - security.evtxWindowsDISA Windows Vista STIG v6r41
2.001 - Permissions for event logs must conform to minimum requirements - system.evtxWindowsDISA Windows Vista STIG v6r41
4.1.4.1 Ensure Audit logs are owned by root and mode 0600 or less permissiveUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
AIX7-00-002013 - Audit logs on the AIX system must be owned by root.UnixDISA STIG AIX 7.x v3r1
AIX7-00-002014 - Audit logs on the AIX system must be group-owned by system.UnixDISA STIG AIX 7.x v3r1
AIX7-00-002015 - Audit logs on the AIX system must be set to 660 or less permissive.UnixDISA STIG AIX 7.x v3r1
ALMA-09-056780 - AlmaLinux OS 9 audit system must protect logon UIDs from unauthorized change.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-057110 - AlmaLinux OS 9 audit system must protect auditing rules from unauthorized change.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
AOSX-13-000336 - The macOS system must be configured with audit log folders set to mode 700 or less permissive.UnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-14-001017 - The macOS system must be configured with audit log folders set to mode 700 or less permissive.UnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-15-001017 - The macOS system must be configured with audit log folders set to mode 700 or less permissive.UnixDISA STIG Apple Mac OSX 10.15 v1r10
APPL-11-001017 - The macOS system must be configured with audit log folders set to mode 700 or less permissive.UnixDISA STIG Apple macOS 11 v1r5
APPL-11-001017 - The macOS system must be configured with audit log folders set to mode 700 or less permissive.UnixDISA STIG Apple macOS 11 v1r8
APPL-12-001017 - The macOS system must be configured with audit log folders set to mode 700 or less permissive.UnixDISA STIG Apple macOS 12 v1r9
APPL-13-001017 - The macOS system must be configured with audit log folders set to mode 700 or less permissive.UnixDISA STIG Apple macOS 13 v1r5
APPL-14-000030 The macOS system must configure audit log files to not contain access control lists.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-000031 The macOS system must configure audit log folders to not contain access control lists.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-001012 The macOS system must configure audit log files to be owned by root.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-001013 The macOS system must configure audit log folders to be owned by root.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-001014 The macOS system must configure audit log files group to wheel.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-001015 The macOS system must configure audit log folders group to wheel.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-001016 The macOS system must configure audit log files to mode 440 or less permissive.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-001017 The macOS system must configure audit log folders to mode 700 or less permissive.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-001020 The macOS system must be configured to audit all deletions of object attributes.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-001021 The macOS system must be configured to audit all changes of object attributes.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-001110 The macOS system must configure audit_control group to wheel.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-001120 The macOS system must configure audit_control owner to root.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-001130 The macOS system must configure audit_control to mode 440 or less permissive.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-001140 The macOS system must configure audit_control to not contain access control lists.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3