CCI|CCI-002824

Title

Implement organization-defined controls to protect its memory from unauthorized code execution.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
AIX7-00-003096 - AIX must set Stack Execution Disable (SED) system wide mode to all.UnixDISA STIG AIX 7.x v3r1
Big Sur - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Big Sur v1.4.0 - 800-53r4 High
Big Sur - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Big Sur - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
Big Sur - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Big Sur v1.4.0 - All Profiles
Catalina - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Catalina v1.5.0 - 800-53r4 Moderate
Catalina - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
Catalina - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Catalina v1.5.0 - 800-53r5 Moderate
Monterey - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Monterey v1.0.0 - 800-53r4 Moderate
Monterey - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Monterey v1.0.0 - All Profiles
Monterey - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Monterey v1.0.0 - 800-53r5 High
Monterey - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Monterey v1.0.0 - 800-53r4 High
Monterey - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Monterey v1.0.0 - 800-53r5 Moderate
Monterey - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Monterey v1.0.0 - CNSSI 1253
OL08-00-010420 - OL 8 must implement non-executable data to protect its memory from unauthorized code execution.UnixDISA Oracle Linux 8 STIG v2r2
PHTN-30-000065 - The Photon operating system must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution.UnixDISA STIG VMware vSphere 7.0 Photon OS v1r3
PHTN-67-000069 - The Photon operating system must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution.UnixDISA STIG VMware vSphere 6.7 Photon OS v1r6
RHEL-08-010420 - RHEL 8 must implement non-executable data to protect its memory from unauthorized code execution.UnixDISA Red Hat Enterprise Linux 8 STIG v2r1
RHEL-09-213025 - RHEL 9 must restrict exposed kernel pointer addresses access.UnixDISA Red Hat Enterprise Linux 9 STIG v2r2
RHEL-09-213070 - RHEL 9 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution.UnixDISA Red Hat Enterprise Linux 9 STIG v2r2
RHEL-09-213110 - RHEL 9 must implement nonexecutable data to protect its memory from unauthorized code execution.UnixDISA Red Hat Enterprise Linux 9 STIG v2r2
UBTU-16-030130 - The Ubuntu operating system must implement non-executable data to protect its memory from unauthorized code execution.UnixDISA STIG Ubuntu 16.04 LTS v2r3
UBTU-16-030140 - The Ubuntu operating system must implement address space layout randomization to protect its memory from unauthorized code execution.UnixDISA STIG Ubuntu 16.04 LTS v2r3
UBTU-18-010513 - The Ubuntu operating system must implement non-executable data to protect its memory from unauthorized code execution.UnixDISA STIG Ubuntu 18.04 LTS v2r15
UBTU-20-010447 - The Ubuntu operating system must implement nonexecutable data to protect its memory from unauthorized code execution.UnixDISA STIG Ubuntu 20.04 LTS v2r1
UBTU-22-213025 - Ubuntu 22.04 LTS must implement nonexecutable data to protect its memory from unauthorized code execution.UnixDISA STIG Canonical Ubuntu 22.04 LTS v2r2
WN10-00-000145 - Data Execution Prevention (DEP) must be configured to at least OptOut.WindowsDISA Windows 10 STIG v3r2
WN10-00-000150 - Structured Exception Handling Overwrite Protection (SEHOP) must be enabled.WindowsDISA Windows 10 STIG v3r2
WN10-CC-000215 - Explorer Data Execution Prevention must be enabled.WindowsDISA Windows 10 STIG v3r2
WN11-00-000145 - Data Execution Prevention (DEP) must be configured to at least OptOut.WindowsDISA Windows 11 STIG v2r2
WN11-00-000150 - Structured Exception Handling Overwrite Protection (SEHOP) must be enabled.WindowsDISA Windows 11 STIG v2r2
WN11-CC-000215 - Explorer Data Execution Prevention must be enabled.WindowsDISA Windows 11 STIG v2r2
WN12-CC-000089 - Explorer Data Execution Prevention must be enabled.WindowsDISA Windows Server 2012 and 2012 R2 MS STIG v3r7
WN12-CC-000089 - Explorer Data Execution Prevention must be enabled.WindowsDISA Windows Server 2012 and 2012 R2 DC STIG v3r7
WN16-CC-000340 - Explorer Data Execution Prevention must be enabled.WindowsDISA Windows Server 2016 STIG v2r9
WN19-CC-000310 - Windows Server 2019 Explorer Data Execution Prevention must be enabled.WindowsDISA Windows Server 2019 STIG v3r2
WN22-CC-000310 - Windows Server 2022 Explorer Data Execution Prevention must be enabled.WindowsDISA Windows Server 2022 STIG v2r2
WN22-UR-000160 - Windows Server 2022 lock pages in memory user right must not be assigned to any groups or accounts.WindowsDISA Windows Server 2022 STIG v2r2