CCI|CCI-002234

Title

Log the execution of privileged functions.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
4.1.3.32 Ensure auditing of all privileged functions - setgid 32 bitUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
4.1.3.32 Ensure auditing of all privileged functions - setgid 64 bitUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
4.1.3.32 Ensure auditing of all privileged functions - setuid 32 bitUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
4.1.3.32 Ensure auditing of all privileged functions - setuid 64 bitUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
AIX7-00-002016 - AIX must provide audit record generation functionality for DoD-defined auditable events.UnixDISA STIG AIX 7.x v2r9
APPL-14-001001 - The macOS system must be configured to audit all administrative action events.UnixDISA Apple macOS 14 (Sonoma) STIG v2r1
APPL-15-001001 - The macOS system must be configured to audit all administrative action events.UnixDISA Apple macOS 15 (Sequoia) STIG v1r1
ARST-ND-000150 - The Arista network device must be configured to audit all administrator activity.AristaDISA STIG Arista MLS EOS 4.2x NDM v2r1
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Low
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - 800-171
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Low
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - All Profiles
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - 800-53r4 High
Big Sur - Configure System to Audit All Administrative Action EventsUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
CASA-ND-000910 - The Cisco ASA must be configured to audit the execution of privileged functions - Buffer EnabledCiscoDISA STIG Cisco ASA NDM v2r1
CASA-ND-000910 - The Cisco ASA must be configured to audit the execution of privileged functions - logging enabledCiscoDISA STIG Cisco ASA NDM v2r1
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - 800-171
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - 800-53r4 Low
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - 800-53r4 Moderate
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - 800-53r5 Low
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
Catalina - Configure System to Audit All Administrative Action EventsUnixNIST macOS Catalina v1.5.0 - 800-53r5 Moderate
CISC-ND-000210 - The Cisco device must be configured to audit all administrator activity.CiscoDISA STIG Cisco IOS Router NDM v3r1
CISC-ND-000210 - The Cisco device must be configured to audit all administrator activity.CiscoDISA STIG Cisco IOS XE Switch NDM v3r1
CISC-ND-000210 - The Cisco device must be configured to audit all administrator activity.CiscoDISA STIG Cisco IOS Switch NDM v3r1
CISC-ND-000210 - The Cisco device must be configured to audit all administrator activity.CiscoDISA STIG Cisco IOS XE Router NDM v3r1
CISC-ND-000940 - The Cisco switch must be configured to audit the execution of privileged functions.CiscoDISA STIG Cisco NX-OS Switch NDM v3r1
DKER-EE-001080 - The audit log configuration level must be set to request in the Universal Control Plane (UCP) component of Docker Enterprise.UnixDISA STIG Docker Enterprise 2.x Linux/Unix UCP v2r2
DKER-EE-001090 - The host operating systems auditing policies for the Docker Engine - Enterprise component of Docker Enterprise must be set - docker pathsUnixDISA STIG Docker Enterprise 2.x Linux/Unix v2r2
DKER-EE-001090 - The host operating systems auditing policies for the Docker Engine - Enterprise component of Docker Enterprise must be set - docker servicesUnixDISA STIG Docker Enterprise 2.x Linux/Unix v2r2
DKER-EE-003230 - An appropriate Docker Engine - Enterprise log driver plugin must be configured to collect audit events from Universal Control Plane (UCP) and Docker Trusted Registry (DTR).UnixDISA STIG Docker Enterprise 2.x Linux/Unix v2r2
FGFW-ND-000040 - The FortiGate device must audit the execution of privileged functionsFortiGateDISA Fortigate Firewall NDM STIG v1r4
GEN002820-9 - The audit system must be configured to audit all discretionary access control permission modifications - 'lsetxattr'UnixDISA STIG for Oracle Linux 5 v2r1
GEN002820-9 - The audit system must be configured to audit all discretionary access control permission modifications - 'lsetxattr'UnixDISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit
JBOS-AS-000480 - The JBoss server must be configured to log all admin activity.UnixDISA RedHat JBoss EAP 6.3 STIG v2r4
JUNI-ND-000930 - The Juniper router must be configured to audit the execution of privileged functions.JuniperDISA STIG Juniper Router NDM v3r1
JUSX-DM-000029 - The Juniper SRX Services Gateway must generate a log event when privileged commands are executed.JuniperDISA Juniper SRX Services Gateway NDM v3r1
Monterey - Configure System to Audit All Administrative Action EventsUnixNIST macOS Monterey v1.0.0 - 800-53r4 High
Monterey - Configure System to Audit All Administrative Action EventsUnixNIST macOS Monterey v1.0.0 - All Profiles
Monterey - Configure System to Audit All Administrative Action EventsUnixNIST macOS Monterey v1.0.0 - 800-53r4 Moderate
Monterey - Configure System to Audit All Administrative Action EventsUnixNIST macOS Monterey v1.0.0 - 800-53r5 High
Monterey - Configure System to Audit All Administrative Action EventsUnixNIST macOS Monterey v1.0.0 - CNSSI 1253
Monterey - Configure System to Audit All Administrative Action EventsUnixNIST macOS Monterey v1.0.0 - 800-171
Monterey - Configure System to Audit All Administrative Action EventsUnixNIST macOS Monterey v1.0.0 - 800-53r4 Low