CCI|CCI-001404

Title

Automatically audit account disabling actions.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Low
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - 800-171
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Low
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - All Profiles
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - 800-53r4 High
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
CASA-ND-000110 - The Cisco ASA must be configured to automatically audit account-disabling actions.CiscoDISA STIG Cisco ASA NDM v2r2
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - 800-171
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - 800-53r4 Low
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - 800-53r4 Moderate
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - 800-53r5 Low
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - 800-53r5 Moderate
CISC-ND-000110 - The Cisco router must be configured to automatically audit account disabling actions.CiscoDISA STIG Cisco IOS Router NDM v3r2
CISC-ND-000110 - The Cisco router must be configured to automatically audit account disabling actions.CiscoDISA STIG Cisco IOS XE Router NDM v3r2
CISC-ND-000110 - The Cisco switch must be configured to automatically audit account disabling actions.CiscoDISA STIG Cisco IOS Switch NDM v3r2
CISC-ND-000110 - The Cisco switch must be configured to automatically audit account disabling actions.CiscoDISA STIG Cisco IOS XE Switch NDM v3r2
F5BI-DM-000023 - The BIG-IP appliance must automatically audit account-disabling actions.F5DISA F5 BIG-IP Device Management STIG v2r3
GEN002752 - The audit system must be configured to audit account disabling - '/etc/security/audit/config USER_Change exists'UnixDISA STIG AIX 5.3 v1r2
GEN002752 - The audit system must be configured to audit account disabling - '/etc/security/audit/config USER_Change exists'UnixDISA STIG AIX 6.1 v1r14
GEN002752 - The audit system must be configured to audit account disabling - '/etc/security/audit/config USER_Locked exists'UnixDISA STIG AIX 5.3 v1r2
GEN002752 - The audit system must be configured to audit account disabling - '/etc/security/audit/config USER_Locked exists'UnixDISA STIG AIX 6.1 v1r14
GEN002752 - The audit system must be configured to audit account disabling - '/etc/security/audit/events USER_Change exists'UnixDISA STIG AIX 6.1 v1r14
GEN002752 - The audit system must be configured to audit account disabling - '/etc/security/audit/events USER_Change exists'UnixDISA STIG AIX 5.3 v1r2
GEN002752 - The audit system must be configured to audit account disabling - flags +ua and -uaUnixDISA STIG Solaris 10 SPARC v2r4
GEN002752 - The audit system must be configured to audit account disabling - flags +ua and -uaUnixDISA STIG Solaris 10 X86 v2r4
GEN002752 - The audit system must be configured to audit account disabling - flags uaUnixDISA STIG Solaris 10 SPARC v2r4
GEN002752 - The audit system must be configured to audit account disabling - flags uaUnixDISA STIG Solaris 10 X86 v2r4
GEN002752 - The audit system must be configured to audit account disabling - naflags +ua and -uaUnixDISA STIG Solaris 10 SPARC v2r4
GEN002752 - The audit system must be configured to audit account disabling - naflags +ua and -uaUnixDISA STIG Solaris 10 X86 v2r4
GEN002752 - The audit system must be configured to audit account disabling - naflags uaUnixDISA STIG Solaris 10 X86 v2r4
GEN002752 - The audit system must be configured to audit account disabling - naflags uaUnixDISA STIG Solaris 10 SPARC v2r4
GEN002752 - The audit system must be configured to audit account disabling.UnixDISA STIG for Oracle Linux 5 v2r1
GEN002752 - The audit system must be configured to audit account disabling.UnixDISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit
Monterey - Configure System to Audit All Administrative Action EventsUnixNIST macOS Monterey v1.0.0 - 800-53r4 High
Monterey - Configure System to Audit All Administrative Action EventsUnixNIST macOS Monterey v1.0.0 - All Profiles
Monterey - Configure System to Audit All Administrative Action EventsUnixNIST macOS Monterey v1.0.0 - CNSSI 1253
Monterey - Configure System to Audit All Administrative Action EventsUnixNIST macOS Monterey v1.0.0 - 800-53r4 Moderate
Monterey - Configure System to Audit All Administrative Action EventsUnixNIST macOS Monterey v1.0.0 - 800-53r5 High
Monterey - Configure System to Audit All Administrative Action EventsUnixNIST macOS Monterey v1.0.0 - 800-171
Monterey - Configure System to Audit All Administrative Action EventsUnixNIST macOS Monterey v1.0.0 - 800-53r4 Low
Monterey - Configure System to Audit All Administrative Action EventsUnixNIST macOS Monterey v1.0.0 - 800-53r5 Moderate
Monterey - Configure System to Audit All Administrative Action EventsUnixNIST macOS Monterey v1.0.0 - 800-53r5 Low
OL6-00-000176 - The operating system must automatically audit account disabling actions - '/etc/group'UnixDISA STIG Oracle Linux 6 v2r7