CCI|CCI-001405

Title

Automatically audit account removal actions.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
AIX7-00-002016 - AIX must provide audit record generation functionality for DoD-defined auditable events.UnixDISA STIG AIX 7.x v2r9
AMLS-NM-000150 - The Arista Multilayer Switch must automatically audit account removal actions.AristaDISA STIG Arista MLS DCS-7000 Series NDM v1r4
APPL-14-001001 - The macOS system must be configured to audit all administrative action events.UnixDISA Apple macOS 14 (Sonoma) STIG v2r1
APPL-15-001001 - The macOS system must be configured to audit all administrative action events.UnixDISA Apple macOS 15 (Sequoia) STIG v1r1
ARST-ND-000150 - The Arista network device must be configured to audit all administrator activity.AristaDISA STIG Arista MLS EOS 4.2x NDM v2r1
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Low
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - 800-171
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Low
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - All Profiles
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - 800-53r4 High
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
CASA-ND-000120 - The Cisco ASA must be configured to automatically audit account removal actions - Buffer EnabledCiscoDISA STIG Cisco ASA NDM v2r1
CASA-ND-000120 - The Cisco ASA must be configured to automatically audit account removal actions - logging enabledCiscoDISA STIG Cisco ASA NDM v2r1
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - 800-171
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - 800-53r4 Low
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - 800-53r4 Moderate
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - 800-53r5 Low
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - 800-53r5 Moderate
CISC-ND-000120 - The Cisco router must be configured to automatically audit account removal actions.CiscoDISA STIG Cisco IOS XE Router NDM v3r1
CISC-ND-000120 - The Cisco router must be configured to automatically audit account removal actions.CiscoDISA STIG Cisco IOS Router NDM v3r1
CISC-ND-000120 - The Cisco switch must be configured to automatically audit account removal actions.CiscoDISA STIG Cisco NX-OS Switch NDM v3r1
CISC-ND-000120 - The Cisco switch must be configured to automatically audit account removal actions.CiscoDISA STIG Cisco IOS XE Switch NDM v3r1
CISC-ND-000120 - The Cisco switch must be configured to automatically audit account removal actions.CiscoDISA STIG Cisco IOS Switch NDM v3r1
F5BI-DM-000025 - The BIG-IP appliance must automatically audit account removal actions.F5DISA F5 BIG-IP Device Management STIG v2r3
FGFW-ND-000020 - The FortiGate device must automatically audit account removal actionsFortiGateDISA Fortigate Firewall NDM STIG v1r4
GEN002753 - The audit system must be configured to audit account termination - '/etc/security/audit/config USER_Remove exists'UnixDISA STIG AIX 5.3 v1r2
GEN002753 - The audit system must be configured to audit account termination - '/etc/security/audit/config USER_Remove exists'UnixDISA STIG AIX 6.1 v1r14
GEN002753 - The audit system must be configured to audit account termination - '/etc/security/audit/events USER_Remove exists'UnixDISA STIG AIX 6.1 v1r14
GEN002753 - The audit system must be configured to audit account termination - '/etc/security/audit/events USER_Remove exists'UnixDISA STIG AIX 5.3 v1r2
GEN002753 - The audit system must be configured to audit account termination - 'groupdel'UnixDISA STIG for Oracle Linux 5 v2r1
GEN002753 - The audit system must be configured to audit account termination - 'groupdel'UnixDISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit
GEN002753 - The audit system must be configured to audit account termination - 'User audit class assignments should be reviewed'UnixDISA STIG AIX 5.3 v1r2
GEN002753 - The audit system must be configured to audit account termination - 'User audit class assignments should be reviewed'UnixDISA STIG AIX 6.1 v1r14
GEN002753 - The audit system must be configured to audit account termination - 'userdel'UnixDISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit
GEN002753 - The audit system must be configured to audit account termination - 'userdel'UnixDISA STIG for Oracle Linux 5 v2r1
GEN002753 - The audit system must be configured to audit account termination - flags +ua and -uaUnixDISA STIG Solaris 10 X86 v2r4
GEN002753 - The audit system must be configured to audit account termination - flags +ua and -uaUnixDISA STIG Solaris 10 SPARC v2r4
GEN002753 - The audit system must be configured to audit account termination - flags uaUnixDISA STIG Solaris 10 SPARC v2r4
GEN002753 - The audit system must be configured to audit account termination - flags uaUnixDISA STIG Solaris 10 X86 v2r4
GEN002753 - The audit system must be configured to audit account termination - naflags +ua and -uaUnixDISA STIG Solaris 10 SPARC v2r4
GEN002753 - The audit system must be configured to audit account termination - naflags +ua and -uaUnixDISA STIG Solaris 10 X86 v2r4
GEN002753 - The audit system must be configured to audit account termination - naflags uaUnixDISA STIG Solaris 10 X86 v2r4
GEN002753 - The audit system must be configured to audit account termination - naflags uaUnixDISA STIG Solaris 10 SPARC v2r4