Capacity
CCI-001464
Initiates session audits automatically at system start-up.
Choose one
1
Rule
Severity: High
Enable audit Service
29
Rule
Severity: Medium
Ensure the audit Subsystem is Installed
30
Rule
Severity: Medium
Enable auditd Service
3
Rule
Severity: Medium
Ensure the audit-libs package as a part of audit Subsystem is Installed
19
Rule
Severity: Low
Enable Auditing for Processes Which Start Prior to the Audit Daemon
1
Rule
Severity: Medium
Enable Auditing for Processes Which Start Prior to the Audit Daemon
2
Rule
Severity: Medium
Ensure the libaudit1 package as a part of audit Subsystem is Installed
4
Rule
Severity: Medium
The Apache web server must generate, at a minimum, log records for system startup and shutdown, system access, and system authentication events.
2
Rule
Severity: Medium
The application server must initiate session logging upon startup.
2
Rule
Severity: Medium
The application must initiate session auditing upon startup.
2
Rule
Severity: Low
The Central Log Server must initiate session auditing upon startup.
1
Rule
Severity: Low
The DBN-6300 must initiate session auditing upon startup.
1
Rule
Severity: Medium
The audit log configuration level must be set to request in the Universal Control Plane (UCP) component of Docker Enterprise.
1
Rule
Severity: Medium
The host operating systems auditing policies for the Docker Engine - Enterprise component of Docker Enterprise must be set.
1
Rule
Severity: Low
The HP FlexFabric Switch must initiate session auditing upon startup.
1
Rule
Severity: Medium
The HYCU server must initiate session auditing upon startup and produce audit log records containing sufficient information to establish what type of event occurred.
1
Rule
Severity: Medium
DB2 must initiate session auditing upon startup.
2
Rule
Severity: Medium
The WebSphere Liberty Server must generate log records for authentication and authorization events.
1
Rule
Severity: Medium
The WebSphere Application Server security auditing must be enabled.
1
Rule
Severity: Medium
The IBM z/VM JOURNALING statement must be coded on the configuration file.
2
Rule
Severity: Medium
JBoss must be configured to initiate session logging upon startup.
2
Rule
Severity: Medium
The Mainframe Product must initiate session auditing upon startup.
2
Rule
Severity: Medium
Azure SQL Database must initiate session auditing upon startup.
2
Rule
Severity: Medium
The network device must initiate session auditing upon startup.
1
Rule
Severity: Medium
Nutanix AOS must initiate session audits at system start-up.
2
Rule
Severity: High
The Riverbed NetProfiler must be configured to automatically generate DOD-required audit records with sufficient information to support incident reporting to a central log server.
2
Rule
Severity: Medium
Rancher MCM must generate audit records for all DoD-defined auditable events within all components in the platform.
1
Rule
Severity: Medium
Innoslate must generate comprehensive audit records.
2
Rule
Severity: Medium
The UEM server must initiate session auditing upon startup.
1
Rule
Severity: Medium
The macOS system must initiate session audits at system startup, using internal clocks with time stamps for audit records that meet a minimum granularity of one second and can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT), in order to generate audit records containing information to establish what type of events occurred, the identity of any individual or process associated with the event, including individual identities of group account users, establish where the events occurred, source of the event, and outcome of the events including all account enabling actions, full-text recording of privileged commands, and information about the use of encryption for access wireless access to and from the system.
3
Rule
Severity: Medium
The macOS system must produce audit records containing information to establish when, where, what type, the source, and the outcome for all DOD-defined auditable events and actions.
3
Rule
Severity: Medium
The macOS system must enable security auditing.
1
Rule
Severity: Medium
The Ubuntu operating system must initiate session audits at system startup.
2
Rule
Severity: Medium
The Ubuntu operating system must initiate session audits at system start-up.
4
Rule
Severity: Medium
PostgreSQL must initiate session auditing upon startup.
2
Rule
Severity: Medium
The DBMS must initiate session auditing upon startup.
2
Rule
Severity: Medium
The Cisco ISE must initiate session auditing upon startup.
2
Rule
Severity: Medium
The container platform must initiate session auditing upon startup.
3
Rule
Severity: Medium
The EDB Postgres Advanced Server must initiate support of session auditing upon startup.
2
Rule
Severity: Medium
The operating system must initiate session audits at system start-up.
2
Rule
Severity: Medium
SSMC web server must generate, at a minimum, log records for system startup and shutdown, system access, and system authentication events.
2
Rule
Severity: Medium
SSMC web server must initiate session logging upon start up.
2
Rule
Severity: Medium
AIX must start audit at boot.
4
Rule
Severity: Medium
IBM z/OS must specify SMF data options to assure appropriate activation.
2
Rule
Severity: Medium
IBM z/OS must specify SMF data options to ensure appropriate activation.
2
Rule
Severity: Medium
The Kubernetes API Server must have an audit log path set.
2
Rule
Severity: Medium
MarkLogic Server must initiate session auditing upon startup.
2
Rule
Severity: Medium
MariaDB must initiate session auditing upon startup.
2
Rule
Severity: Medium
MongoDB must provide audit record generation for DoD-defined auditable events within all DBMS/database components.
2
Rule
Severity: Medium
Both the log file and Event Tracing for Windows (ETW) for each IIS 10.0 website must be enabled.
2
Rule
Severity: Medium
Both the log file and Event Tracing for Windows (ETW) for the IIS 10.0 web server must be enabled.
2
Rule
Severity: Medium
SQL Server must initiate session auditing upon startup.
2
Rule
Severity: Medium
OL 8 audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.
2
Rule
Severity: Medium
The Oracle Linux operating system must be configured so that auditing is configured to produce records containing information to establish what type of events occurred, where the events occurred, the source of the events, and the outcome of the events. These audit records must also identify individual identities of group account users.
2
Rule
Severity: Medium
The MySQL Database Server 8.0 must initiate session auditing upon startup.
2
Rule
Severity: Medium
Rancher RKE2 components must be configured in accordance with the security configuration settings based on DOD security configuration or implementation guidance, including SRGs, STIGs, NSA configuration guides, CTOs, and DTMs.
2
Rule
Severity: High
Red Hat Enterprise Linux CoreOS (RHCOS) must initiate session audits at system startup.
2
Rule
Severity: Medium
OpenShift components must provide the ability to send audit logs to a central enterprise repository for review and analysis.
2
Rule
Severity: Low
RHEL 9 must enable auditing of processes that start prior to the audit daemon.
4
Rule
Severity: Medium
SUSE operating system audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.
2
Rule
Severity: Medium
RHEL 9 audit package must be installed.
2
Rule
Severity: Medium
RHEL 9 audit service must be enabled.
2
Rule
Severity: Low
RHEL 9 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.
2
Rule
Severity: Medium
The VMM must initiate session audits at system startup.
1
Rule
Severity: Medium
Performance Charts must generate log records for system startup and shutdown.
1
Rule
Severity: Medium
ESX Agent Manager must record user access in a format that enables monitoring of remote access.
1
Rule
Severity: Medium
Lookup Service must generate log records for system startup and shutdown.
1
Rule
Severity: Medium
The Photon operating system must initiate auditing as part of the boot process.
3
Rule
Severity: Medium
The vCenter ESX Agent Manager service must initiate session logging upon startup.
1
Rule
Severity: Medium
VMware Postgres must have log collection enabled.
1
Rule
Severity: Medium
The Security Token Service must generate log records during Java startup and shutdown.
3
Rule
Severity: Medium
The vCenter Lookup service must initiate session logging upon startup.
1
Rule
Severity: Medium
vSphere UI must generate log records for system startup and shutdown.
3
Rule
Severity: Medium
The vCenter Perfcharts service must initiate session logging upon startup.
3
Rule
Severity: Medium
The Photon operating system must initiate session audits at system startup.
3
Rule
Severity: Medium
The vCenter PostgreSQL service must initiate session auditing upon startup.
3
Rule
Severity: Medium
The vCenter STS service must initiate session logging upon startup.
3
Rule
Severity: Medium
The vCenter UI service must initiate session logging upon startup.
2
Rule
Severity: Medium
The web server must initiate session logging upon start up.
1
Rule
Severity: Medium
Ubuntu 22.04 LTS must initiate session audits at system startup.
1
Rule
Severity: Medium
Audit logging must be enabled on MKE.
1
Rule
Severity: Medium
MongoDB must provide audit record generation for DOD-defined auditable events within all DBMS/database components.
1
Rule
Severity: Medium
The OL 8 audit package must be installed.
1
Rule
Severity: Medium
SLEM 5 audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.
1
Rule
Severity: Medium
TOSS audit records must contain information to establish what type of events occurred, when the events occurred, the source of events, where events occurred, and the outcome of events.
Patternfly
PatternFly elements
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.
Modules
66%