Capacity
BP28(R73)
Choose one
4
Rule
Severity: Medium
Make the auditd Configuration Immutable
4
Rule
Severity: Medium
Record Events that Modify the System's Mandatory Access Controls
4
Rule
Severity: Medium
Ensure auditd Collects Information on Exporting to Media (successful)
4
Rule
Severity: Medium
Record Events that Modify the System's Network Environment
4
Rule
Severity: Medium
Record Attempts to Alter Process and Session Initiation Information
4
Rule
Severity: Medium
Ensure auditd Collects System Administrator Actions
3
Rule
Severity: Medium
Record Events that Modify User/Group Information - /etc/group
3
Rule
Severity: Medium
Record Events that Modify User/Group Information - /etc/gshadow
3
Rule
Severity: Medium
Record Events that Modify User/Group Information - /etc/security/opasswd
3
Rule
Severity: Medium
Record Events that Modify User/Group Information - /etc/passwd
3
Rule
Severity: Medium
Record Events that Modify User/Group Information - /etc/shadow
4
Rule
Severity: Medium
Record Events that Modify the System's Discretionary Access Controls - chmod
4
Rule
Severity: Medium
Record Events that Modify the System's Discretionary Access Controls - chown
4
Rule
Severity: Medium
Record Events that Modify the System's Discretionary Access Controls - fchmod
4
Rule
Severity: Medium
Record Events that Modify the System's Discretionary Access Controls - fchmodat
4
Rule
Severity: Medium
Record Events that Modify the System's Discretionary Access Controls - fchown
4
Rule
Severity: Medium
Record Events that Modify the System's Discretionary Access Controls - fchownat
4
Rule
Severity: Medium
Record Events that Modify the System's Discretionary Access Controls - fremovexattr
4
Rule
Severity: Medium
Record Events that Modify the System's Discretionary Access Controls - fsetxattr
4
Rule
Severity: Medium
Record Events that Modify the System's Discretionary Access Controls - lchown
4
Rule
Severity: Medium
Record Events that Modify the System's Discretionary Access Controls - lremovexattr
4
Rule
Severity: Medium
Record Events that Modify the System's Discretionary Access Controls - lsetxattr
4
Rule
Severity: Medium
Record Events that Modify the System's Discretionary Access Controls - removexattr
4
Rule
Severity: Medium
Record Events that Modify the System's Discretionary Access Controls - setxattr
4
Rule
Severity: Medium
Record Events that Modify the System's Discretionary Access Controls - umount2
4
Rule
Severity: Medium
Ensure auditd Collects File Deletion Events by User - rename
4
Rule
Severity: Medium
Ensure auditd Collects File Deletion Events by User - renameat
4
Rule
Severity: Medium
Ensure auditd Collects File Deletion Events by User - rmdir
4
Rule
Severity: Medium
Ensure auditd Collects File Deletion Events by User - unlink
4
Rule
Severity: Medium
Ensure auditd Collects File Deletion Events by User - unlinkat
4
Rule
Severity: Medium
Record Unsuccessful Access Attempts to Files - creat
4
Rule
Severity: Medium
Record Unsuccessful Access Attempts to Files - ftruncate
4
Rule
Severity: Medium
Record Unsuccessful Access Attempts to Files - open
4
Rule
Severity: Medium
Record Unsuccessful Access Attempts to Files - openat
4
Rule
Severity: Medium
Record Unsuccessful Access Attempts to Files - truncate
4
Rule
Severity: Medium
Ensure auditd Collects Information on Kernel Module Unloading - delete_module
4
Rule
Severity: Medium
Ensure auditd Collects Information on Kernel Module Loading and Unloading - finit_module
4
Rule
Severity: Medium
Ensure auditd Collects Information on Kernel Module Loading - init_module
4
Rule
Severity: Medium
Record Attempts to Alter Logon and Logout Events - faillock
4
Rule
Severity: Medium
Record Attempts to Alter Logon and Logout Events - lastlog
4
Rule
Severity: Medium
Ensure auditd Collects Information on the Use of Privileged Commands
3
Rule
Severity: Medium
Ensure auditd Collects Information on the Use of Privileged Commands - insmod
3
Rule
Severity: Medium
Ensure auditd Collects Information on the Use of Privileged Commands - kmod
3
Rule
Severity: Medium
Ensure auditd Collects Information on the Use of Privileged Commands - modprobe
3
Rule
Severity: Medium
Ensure auditd Collects Information on the Use of Privileged Commands - rmmod
4
Rule
Severity: Medium
Record attempts to alter time through adjtimex
4
Rule
Severity: Medium
Record Attempts to Alter Time Through clock_settime
4
Rule
Severity: Medium
Record Attempts to Alter Time Through stime
4
Rule
Severity: Medium
Record Attempts to Alter the localtime File
4
Rule
Severity: Medium
Ensure the audit Subsystem is Installed
4
Rule
Severity: Medium
Enable auditd Service
3
Rule
Severity: Medium
Record Attempts to perform maintenance activities
Patternfly
PatternFly elements
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.
Modules
66%