CCI|CCI-003980

Title

Allow user installation of software only with explicit privileged status.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
AIX7-00-003102 - AIX must turn on enhanced Role-Based Access Control (RBAC) to isolate security functions from nonsecurity functions, to grant system privileges to other operating system admins, and prohibit user installation of system software without explicit privileged status.UnixDISA STIG AIX 7.x v3r1
APPL-14-005080 - The macOS system must prohibit user installation of software into /users/.UnixDISA Apple macOS 14 (Sonoma) STIG v2r2
APPL-15-005080 - The macOS system must prohibit user installation of software into /users/.UnixDISA Apple macOS 15 (Sequoia) STIG v1r1
CD12-00-008400 - PostgreSQL must prohibit user installation of logic modules (functions, trigger procedures, views, etc.) without explicit privileged status.UnixDISA STIG Crunchy Data PostgreSQL OS v3r1
CNTR-R2-001270 Rancher RKE2 must prohibit the installation of patches, updates, and instantiation of container images without explicit privileged status.UnixDISA Rancher Government Solutions RKE2 STIG v2r2
EDGE-00-000039 - URLs must be allowlisted for plugin use if used.WindowsDISA STIG Edge v2r2
EPAS-00-008400 - The EDB Postgres Advanced Server must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.PostgreSQLDBEnterpriseDB PostgreSQL Advanced Server DB v2r1
EX19-ED-000195 - The Exchange application directory must be protected from unauthorized access.WindowsDISA Microsoft Exchange 2019 Edge Server STIG v2r1
EX19-MB-000194 - The Exchange application directory must be protected from unauthorized access.WindowsDISA Microsoft Exchange 2019 Mailbox Server STIG v2r2
JUEX-NM-000450 - The Juniper EX switch must be configured to prohibit installation of software without explicit privileged status.JuniperDISA Juniper EX Series Network Device Management v2r2
JUNI-ND-001060 - The Juniper router must be configured to prohibit installation of software without explicit privileged status.JuniperDISA STIG Juniper Router NDM v3r1
JUSX-DM-000077 - The Juniper SRX Services Gateway must implement logon roles to ensure only authorized roles are allowed to install software and updates.JuniperDISA Juniper SRX Services Gateway NDM v3r2
MADB-10-007800 - MariaDB must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.MySQLDBDISA MariaDB Enterprise 10.x v2r2 DB
MYS8-00-009100 - The MySQL Database Server 8.0 must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.MySQLDBDISA Oracle MySQL 8.0 v2r2 DB
SQL6-D0-003000 - SQL Server must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.MS_SQLDBDISA STIG SQL Server 2016 Database Audit v3r2
WN10-CC-000310 - Users must be prevented from changing installation options.WindowsDISA Windows 10 STIG v3r2
WN10-CC-000315 - The Windows Installer Always install with elevated privileges must be disabled.WindowsDISA Windows 10 STIG v3r2
WN11-CC-000310 - Users must be prevented from changing installation options.WindowsDISA Windows 11 STIG v2r2
WN11-CC-000315 - The Windows Installer feature 'Always install with elevated privileges' must be disabled.WindowsDISA Windows 11 STIG v2r2
WN19-CC-000420 - Windows Server 2019 must prevent users from changing installation options.WindowsDISA Windows Server 2019 STIG v3r2
WN19-CC-000430 - Windows Server 2019 must disable the Windows Installer Always install with elevated privileges option.WindowsDISA Windows Server 2019 STIG v3r2
WN22-CC-000420 - Windows Server 2022 must prevent users from changing installation options.WindowsDISA Windows Server 2022 STIG v2r2
WN22-CC-000430 - Windows Server 2022 must disable the Windows Installer Always install with elevated privileges option.WindowsDISA Windows Server 2022 STIG v2r2