Audits
Settings
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Theme
Light
Dark
Auto
Help
Plugins
Overview
Plugins Pipeline
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Release Notes
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Settings
Theme
Light
Dark
Auto
Detections
Plugins
Overview
Plugins Pipeline
Release Notes
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
Analytics
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Audits
References
CCI
CCI-003980
CCI
CCI|CCI-003980
Title
Allow user installation of software only with explicit privileged status.
Reference Item Details
Reference:
CCI - DISA Control Correlation Identifier
Category:
2024
Audit Items
View all Reference Audit Items
Name
Plugin
Audit Name
AIX7-00-003102 - AIX must turn on enhanced Role-Based Access Control (RBAC) to isolate security functions from nonsecurity functions, to grant system privileges to other operating system admins, and prohibit user installation of system software without explicit privileged status.
Unix
DISA STIG AIX 7.x v3r1
APPL-14-005080 - The macOS system must prohibit user installation of software into /users/.
Unix
DISA Apple macOS 14 (Sonoma) STIG v2r2
APPL-15-005080 - The macOS system must prohibit user installation of software into /users/.
Unix
DISA Apple macOS 15 (Sequoia) STIG v1r1
CD12-00-008400 - PostgreSQL must prohibit user installation of logic modules (functions, trigger procedures, views, etc.) without explicit privileged status.
Unix
DISA STIG Crunchy Data PostgreSQL OS v3r1
CNTR-R2-001270 Rancher RKE2 must prohibit the installation of patches, updates, and instantiation of container images without explicit privileged status.
Unix
DISA Rancher Government Solutions RKE2 STIG v2r2
EDGE-00-000039 - URLs must be allowlisted for plugin use if used.
Windows
DISA STIG Edge v2r2
EPAS-00-008400 - The EDB Postgres Advanced Server must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.
PostgreSQLDB
EnterpriseDB PostgreSQL Advanced Server DB v2r1
EX19-ED-000195 - The Exchange application directory must be protected from unauthorized access.
Windows
DISA Microsoft Exchange 2019 Edge Server STIG v2r1
EX19-MB-000194 - The Exchange application directory must be protected from unauthorized access.
Windows
DISA Microsoft Exchange 2019 Mailbox Server STIG v2r2
JUEX-NM-000450 - The Juniper EX switch must be configured to prohibit installation of software without explicit privileged status.
Juniper
DISA Juniper EX Series Network Device Management v2r2
JUNI-ND-001060 - The Juniper router must be configured to prohibit installation of software without explicit privileged status.
Juniper
DISA STIG Juniper Router NDM v3r1
JUSX-DM-000077 - The Juniper SRX Services Gateway must implement logon roles to ensure only authorized roles are allowed to install software and updates.
Juniper
DISA Juniper SRX Services Gateway NDM v3r2
MADB-10-007800 - MariaDB must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.
MySQLDB
DISA MariaDB Enterprise 10.x v2r2 DB
MYS8-00-009100 - The MySQL Database Server 8.0 must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.
MySQLDB
DISA Oracle MySQL 8.0 v2r2 DB
SQL6-D0-003000 - SQL Server must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.
MS_SQLDB
DISA STIG SQL Server 2016 Database Audit v3r2
WN10-CC-000310 - Users must be prevented from changing installation options.
Windows
DISA Windows 10 STIG v3r2
WN10-CC-000315 - The Windows Installer Always install with elevated privileges must be disabled.
Windows
DISA Windows 10 STIG v3r2
WN11-CC-000310 - Users must be prevented from changing installation options.
Windows
DISA Windows 11 STIG v2r2
WN11-CC-000315 - The Windows Installer feature 'Always install with elevated privileges' must be disabled.
Windows
DISA Windows 11 STIG v2r2
WN19-CC-000420 - Windows Server 2019 must prevent users from changing installation options.
Windows
DISA Windows Server 2019 STIG v3r2
WN19-CC-000430 - Windows Server 2019 must disable the Windows Installer Always install with elevated privileges option.
Windows
DISA Windows Server 2019 STIG v3r2
WN22-CC-000420 - Windows Server 2022 must prevent users from changing installation options.
Windows
DISA Windows Server 2022 STIG v2r2
WN22-CC-000430 - Windows Server 2022 must disable the Windows Installer Always install with elevated privileges option.
Windows
DISA Windows Server 2022 STIG v2r2