CCI|CCI-002824

Title

Implement organization-defined controls to protect its memory from unauthorized code execution.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.5.1 Ensure randomize_va_space is configuredUnixCIS Ubuntu Linux 22.04 LTS v3.0.0 L1 Server
1.5.1 Ensure randomize_va_space is configuredUnixCIS Ubuntu Linux 22.04 LTS v3.0.0 L1 Workstation
1.5.8 Ensure kernel.randomize_va_space is configuredUnixCIS Rocky Linux 10 v1.0.0 L1 Workstation
1.5.8 Ensure kernel.randomize_va_space is configuredUnixCIS Rocky Linux 10 v1.0.0 L1 Server
1.5.9 Ensure kernel.randomize_va_space is configuredUnixCIS Debian Linux 13 v1.0.0 L1 Workstation
1.5.9 Ensure kernel.randomize_va_space is configuredUnixCIS Debian Linux 13 v1.0.0 L1 Server
1.6 UBTU-22-213020UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.7 UBTU-22-213025UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.18 RHEL-09-212045UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.19 RHEL-09-212050UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT III
1.24 RHEL-09-213025UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.31 WN10-00-000145WindowsCIS Microsoft Windows 10 STIG v1.0.0 CAT I
1.32 WN10-00-000150WindowsCIS Microsoft Windows 10 STIG v1.0.0 CAT I
1.33 RHEL-09-213070UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.41 RHEL-09-213110UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.75 OL08-00-010420UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.80 OL08-00-010430UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.124 WN22-CC-000310WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT II
1.124 WN22-CC-000310WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT II
1.128 UBTU-24-700300UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.129 UBTU-24-700310UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.145 WN10-CC-000215WindowsCIS Microsoft Windows 10 STIG v1.0.0 CAT II
1.269 WN22-UR-000160WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT II
1.269 WN22-UR-000160WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT II
AIX7-00-003096 - AIX must set Stack Execution Disable (SED) system wide mode to all.UnixDISA STIG AIX 7.x v3r1
ALMA-09-044570 - AlmaLinux OS 9 must implement nonexecutable data to protect its memory from unauthorized code execution.UnixDISA Cloud Linux AlmaLinux OS 9 STIG v1r5
ALMA-09-044680 - AlmaLinux OS 9 must enable mitigations against processor-based vulnerabilities.UnixDISA Cloud Linux AlmaLinux OS 9 STIG v1r5
ALMA-09-044790 - AlmaLinux OS 9 must clear memory when it is freed to prevent use-after-free attacks.UnixDISA Cloud Linux AlmaLinux OS 9 STIG v1r5
ALMA-09-044900 - AlmaLinux OS 9 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution.UnixDISA Cloud Linux AlmaLinux OS 9 STIG v1r5
AZLX-23-000210 - Amazon Linux 2023 must restrict exposed kernel pointer addresses access.UnixDISA Amazon Linux 2023 STIG v1r2
AZLX-23-000225 - Amazon Linux 2023 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution.UnixDISA Amazon Linux 2023 STIG v1r2
AZLX-23-002610 - Amazon Linux 2023 must implement nonexecutable data to protect its memory from unauthorized code execution.UnixDISA Amazon Linux 2023 STIG v1r2
Big Sur - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
Big Sur - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Big Sur v1.4.0 - All Profiles
Big Sur - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Big Sur - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Big Sur v1.4.0 - 800-53r4 High
Big Sur - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Catalina - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Catalina v1.5.0 - 800-53r5 Moderate
Catalina - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Catalina v1.5.0 - 800-53r4 Moderate
Catalina - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
Monterey - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Monterey v1.0.0 - 800-53r5 Moderate
Monterey - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Monterey v1.0.0 - CNSSI 1253
Monterey - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Monterey v1.0.0 - 800-53r4 Moderate
Monterey - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Monterey v1.0.0 - 800-53r5 High
Monterey - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Monterey v1.0.0 - 800-53r4 High
Monterey - Configure the System to Protect Memory from Unauthorized Code ExecutionUnixNIST macOS Monterey v1.0.0 - All Profiles