CSCv7|4.9

Title

Log and Alert on Unsuccessful Administrative Account Login

Description

Configure systems to issue a log entry and alert on unsuccessful logins to an administrative account.

Reference Item Details

Category: Controlled Use of Administrative Privileges

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.2.3 Limit SSH Login AttemptsCiscoCIS Cisco NX-OS L1 v1.1.0
1.2.5 Ensure Exec Timeout for Remote Administrative Sessions (VTY) is setCiscoCIS Cisco NX-OS L1 v1.1.0
1.2.6 Set the Maximum Number of VTY SessionsCiscoCIS Cisco NX-OS L1 v1.1.0
1.5.2 Log all Successful and Failed Administrative LoginsCiscoCIS Cisco NX-OS L1 v1.0.0
1.5.2 Log all Successful and Failed Administrative LoginsCiscoCIS Cisco NX-OS L2 v1.0.0
1.6.2 Log all Successful and Failed Administrative LoginsCiscoCIS Cisco NX-OS L2 v1.1.0
1.14 Ensure 'DNS interception checks enabled' is set to 'Enabled'WindowsCIS Google Chrome L1 v3.0.0
3.1 Ensure Security Auditing Is EnabledUnixCIS Apple macOS 13.0 Ventura v2.0.0 L1
3.1 Ensure Security Auditing Is EnabledUnixCIS Apple macOS 11 v2.1.0 L1
3.1 Ensure Security Auditing Is EnabledUnixCIS Apple macOS 13.0 Ventura Cloud-tailored v1.0.0 L1
3.1 Ensure Security Auditing Is EnabledUnixCIS Apple macOS 14.0 Sonoma Cloud-tailored v1.0.0 L1
3.1 Ensure Security Auditing Is EnabledUnixCIS Apple macOS 12.0 Monterey v2.1.0 L1
3.1 Ensure Security Auditing Is EnabledUnixCIS Apple macOS 12.0 Monterey v3.0.0 L1
3.1 Ensure Security Auditing Is EnabledUnixCIS Apple macOS 13.0 Ventura v1.0.0 L1
3.1 Ensure Security Auditing Is EnabledUnixCIS Apple macOS 14.0 Sonoma v1.0.0 L1
3.1 Ensure Security Auditing Is EnabledUnixCIS Apple macOS 10.15 v2.0.0 L1
3.1 Ensure Security Auditing Is EnabledUnixCIS Apple macOS 12.0 Monterey Cloud-tailored v1.0.0 L1
3.1 Ensure Security Auditing Is EnabledUnixCIS Apple macOS 10.14 v2.0.0 L1
3.1 Ensure Security Auditing Is EnabledUnixCIS Apple macOS 12.0 Monterey v2.0.0 L1
3.1 Ensure Security Auditing Is EnabledUnixCIS Apple macOS 10.15 Catalina v3.0.0 L1
3.1 Ensure Security Auditing Is EnabledUnixCIS Apple macOS 10.15 v2.1.0 L1
3.1 Ensure Security Auditing Is EnabledUnixCIS Apple macOS 11.0 Big Sur v3.0.0 L1
3.1 Ensure Security Auditing Is EnabledUnixCIS Apple macOS 11.0 Big Sur v4.0.0 L1
3.1 Ensure Security Auditing Is EnabledUnixCIS Apple macOS 11 v2.0.0 L1
3.1 Ensure Security Auditing Is EnabledUnixCIS Apple macOS 12.0 Monterey v1.0.0 L1
3.1 Ensure Security Auditing Is EnabledUnixCIS Apple macOS 12.0 Monterey v1.1.0 L1
4.1.10 Ensure session initiation information is collected - /var/log/btmpUnixCIS Amazon Linux 2 STIG v1.0.0 L2
4.1.10 Ensure session initiation information is collected - /var/log/wtmpUnixCIS Amazon Linux 2 STIG v1.0.0 L2
4.1.10 Ensure session initiation information is collected - /var/run/utmpUnixCIS Amazon Linux 2 STIG v1.0.0 L2
4.1.10 Ensure session initiation information is collected - auditctl /var/log/wtmpUnixCIS Amazon Linux 2 STIG v1.0.0 L2
4.1.10 Ensure session initiation information is collected - auditctl /var/run/btmpUnixCIS Amazon Linux 2 STIG v1.0.0 L2
4.1.10 Ensure session initiation information is collected - auditctl /var/run/utmpUnixCIS Amazon Linux 2 STIG v1.0.0 L2
4.1.10 Ensure session initiation information is collected - auditctl btmpUnixCIS Distribution Independent Linux Server L2 v2.0.0
4.1.10 Ensure session initiation information is collected - auditctl btmpUnixCIS Distribution Independent Linux Workstation L2 v2.0.0
4.1.10 Ensure session initiation information is collected - auditctl utmpUnixCIS Distribution Independent Linux Server L2 v2.0.0
4.1.10 Ensure session initiation information is collected - auditctl utmpUnixCIS Distribution Independent Linux Workstation L2 v2.0.0
4.1.10 Ensure session initiation information is collected - auditctl wtmpUnixCIS Distribution Independent Linux Server L2 v2.0.0
4.1.10 Ensure session initiation information is collected - auditctl wtmpUnixCIS Distribution Independent Linux Workstation L2 v2.0.0
4.1.10 Ensure session initiation information is collected - btmpUnixCIS Distribution Independent Linux Workstation L2 v2.0.0
4.1.10 Ensure session initiation information is collected - btmpUnixCIS Distribution Independent Linux Server L2 v2.0.0
4.1.10 Ensure session initiation information is collected - utmpUnixCIS Distribution Independent Linux Workstation L2 v2.0.0
4.1.10 Ensure session initiation information is collected - utmpUnixCIS Distribution Independent Linux Server L2 v2.0.0
4.1.10 Ensure session initiation information is collected - wtmpUnixCIS Distribution Independent Linux Workstation L2 v2.0.0
4.1.10 Ensure session initiation information is collected - wtmpUnixCIS Distribution Independent Linux Server L2 v2.0.0
4.1.15 Ensure kernel module loading and unloading is collected - auditctl init_module/delete_moduleUnixCIS Oracle Linux 8 Workstation L2 v1.0.0
4.1.15 Ensure kernel module loading and unloading is collected - auditctl init_module/delete_moduleUnixCIS Oracle Linux 8 Server L2 v1.0.0
4.1.15 Ensure kernel module loading and unloading is collected - auditctl insmodUnixCIS Oracle Linux 8 Workstation L2 v1.0.0
4.1.15 Ensure kernel module loading and unloading is collected - auditctl insmodUnixCIS Oracle Linux 8 Server L2 v1.0.0
4.1.15 Ensure kernel module loading and unloading is collected - auditctl modprobeUnixCIS Oracle Linux 8 Server L2 v1.0.0
4.1.15 Ensure kernel module loading and unloading is collected - auditctl modprobeUnixCIS Oracle Linux 8 Workstation L2 v1.0.0