CCI-001314
Reveal error messages only to organization-defined personnel or roles.
The A10 Networks ADC must reveal error messages only to authorized individuals (ISSO, ISSM, and SA).
2 rules found Severity: Medium

1 rule found Severity: High

The Arista Multilayer Switch must reveal error messages only to authorized individuals (ISSO, ISSM, and SA).
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

A policy set using the built-in role-based access control (RBAC) capabilities in the Universal Control Plane (UCP) component of Docker Enterprise must be configured.
1 rule found Severity: Medium

A policy set using the built-in role-based access control (RBAC) capabilities in the Docker Trusted Registry (DTR) component of Docker Enterprise must be set.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

SQL Server must reveal detailed error messages only to the ISSO, ISSM (or their designees), SA and DBA.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The macOS system must be configured with system log files owned by root and group-owned by wheel or admin.
2 rules found Severity: Medium

2 rules found Severity: Medium

2 rules found Severity: Medium

2 rules found Severity: Medium

The Ubuntu operating system must configure the /var/log directory to have mode 0755 or less permissive.
1 rule found Severity: Medium

2 rules found Severity: Medium

2 rules found Severity: Medium

2 rules found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The Red Hat Enterprise Linux operating system must protect audit information from unauthorized read, modification, or deletion.
1 rule found Severity: Medium

The EDB Postgres Advanced Server must reveal detailed error messages only to the ISSO, ISSM, SA, and DBA.
2 rules found Severity: Medium

The application must be configured to reveal error messages only to authorized individuals (ISSO, ISSM, and SA).
1 rule found Severity: Medium

1 rule found Severity: Medium

Custom database code and associated application code must reveal detailed error messages only to the Information System Security Officer (ISSO), Information System Security manager (ISSM), Systems Administrator (SA), and Database Administrator (DBA).
1 rule found Severity: Medium

The Ubuntu operating system must configure the /var/log directory to have mode "0755" or less permissive.
1 rule found Severity: Medium

1 rule found Severity: Medium

PostgreSQL must reveal detailed error messages only to the information system security officer (ISSO), information system security manager (ISSM), system administrator (SA), and database administrator (DBA).
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

MongoDB must reveal detailed error messages only to the information system security officer (ISSO), information system security manager (ISSM), system administrator (SA), and database administrator (DBA).
1 rule found Severity: Medium

1 rule found Severity: Medium

The Oracle Linux operating system must protect audit information from unauthorized read, modification, or deletion.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The Tanium application must reveal error messages only to the information system security officer (ISSO), information system security manager (ISSM), and system administrator (SA).
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

Ubuntu 22.04 LTS must configure the directories used by the system journal to be group-owned by "systemd-journal".
1 rule found Severity: Medium

1 rule found Severity: Medium

Ubuntu 22.04 LTS must configure the files used by the system journal to be group-owned by "systemd-journal".
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

CA-ACF2 must limit access to data sets used to back up and/or dump SMF collection files to appropriate users and/or batch jobs that perform SMF dump processing.
1 rule found Severity: Medium

IBM z/OS SMF collection files (i.e., SYS1.MANx) access must be limited to appropriate users and/or batch jobs that perform SMF dump processing.
1 rule found Severity: Medium

IBM RACF must limit access to data sets used to back up and/or dump SMF collection files to appropriate users and/or batch jobs that perform SMF dump processing.
1 rule found Severity: Medium

IBM z/OS must limit access for SMF collection files (i.e., SYS1.MANx) to appropriate users and/or batch jobs that perform SMF dump processing.
2 rules found Severity: Medium

CA-TSS must limit access to data sets used to back up and/or dump SMF collection files to appropriate users and/or batch jobs that perform SMF dump processing.
1 rule found Severity: Medium

The Mainframe Product must reveal full-text detail error messages only to system programmers and/or security administrators.
1 rule found Severity: Medium

The Juniper SRX Services Gateway must generate alerts to the management console and generate a log record that can be forwarded to the ISSO and designated system administrators when the local accounts (i.e., the account of last resort or root account) are deleted.
1 rule found Severity: Medium

SQL Server must reveal detailed error messages only to documented and approved individuals or roles.
1 rule found Severity: Medium

Windows Server 2022 permissions on the Active Directory data files must only allow System and Administrators access.
1 rule found Severity: High

1 rule found Severity: Medium

1 rule found Severity: Medium

The Palo Alto Networks security platform must block traceroutes and ICMP probes originating from untrusted networks (e.g., ISP and other non-DoD networks).
1 rule found Severity: Medium

1 rule found Severity: Medium

Administrators in the role of Security Administrator, Cryptographic Administrator, or Audit Administrator must not also have the role of Audit Administrator.
1 rule found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

RHEL 9 audit logs must be group-owned by root or by a restricted logging group to prevent unauthorized read access.
1 rule found Severity: Medium

1 rule found Severity: Medium

RHEL 9 audit logs file must have mode 0600 or less permissive to prevent unauthorized access to the audit log.
1 rule found Severity: Medium

2 rules found Severity: Low

The UEM server must reveal error messages only to the Information System Security Manager (ISSM) and Information System Security Officer (ISSO).
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium
