Capacity
CCI-001876
Provide an audit reduction capability that supports on-demand reporting requirements.
Choose one
33
Rule
Severity: Medium
Ensure the audit Subsystem is Installed
35
Rule
Severity: Medium
Enable auditd Service
7
Rule
Severity: Medium
Ensure the audit-libs package as a part of audit Subsystem is Installed
2
Rule
Severity: Medium
Ensure the libaudit1 package as a part of audit Subsystem is Installed
2
Rule
Severity: Medium
The application server must provide a log reduction capability that supports on-demand reporting requirements.
2
Rule
Severity: Medium
The application must provide an audit reduction capability that supports on-demand reporting requirements.
2
Rule
Severity: Medium
The Central Log Server must be configured to perform audit reduction that supports on-demand reporting requirements.
1
Rule
Severity: Medium
The MQ Appliance messaging server must provide a log reduction capability that supports on-demand reporting requirements.
2
Rule
Severity: Medium
The Mainframe Product must provide an audit reduction capability that supports on-demand reporting requirements.
1
Rule
Severity: Medium
Nutanix AOS must provide the capability to centrally review and analyze audit records from multiple components within the system.
2
Rule
Severity: Medium
Prisma Cloud Compute must be configured to send events to the hosts' syslog.
2
Rule
Severity: Medium
Rancher MCM must allocate audit record storage and generate audit records associated with events, users, and groups.
1
Rule
Severity: Medium
The macOS system must enable System Integrity Protection.
3
Rule
Severity: High
The macOS system must enable System Integrity Protection.
3
Rule
Severity: High
The macOS system must ensure System Integrity Protection is enabled.
3
Rule
Severity: Medium
The Ubuntu operating system must produce audit records and reports containing information to establish when, where, what type, the source, and the outcome for all DoD-defined auditable events and actions in near real time.
2
Rule
Severity: Medium
The container platform must provide an audit reduction capability that supports on-demand reporting requirements.
2
Rule
Severity: Medium
The operating system must provide an audit reduction capability that supports on-demand reporting requirements.
2
Rule
Severity: Medium
AIX must provide the function to filter audit records for events of interest based upon all audit fields within audit records, support on-demand reporting requirements, and an audit reduction function that supports on-demand audit review and analysis and after-the-fact investigations of security incidents.
2
Rule
Severity: Medium
IBM z/OS system administrator must develop a procedure to provide an audit reduction capability that supports on-demand reporting requirements.
2
Rule
Severity: Medium
OL 8 audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.
2
Rule
Severity: Medium
Automation Controller must use external log providers that can collect user activity logs in independent, protected repositories to prevent modification or repudiation.
4
Rule
Severity: Medium
SUSE operating system audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.
2
Rule
Severity: Medium
RHEL 9 audit package must be installed.
2
Rule
Severity: Medium
RHEL 9 audit service must be enabled.
2
Rule
Severity: Medium
The VMM must support an audit reduction capability that supports on-demand reporting requirements.
1
Rule
Severity: Medium
Ubuntu 22.04 LTS must have the "auditd" package installed.
1
Rule
Severity: Medium
Ubuntu 22.04 LTS must produce audit records and reports containing information to establish when, where, what type, the source, and the outcome for all DOD-defined auditable events and actions in near real time.
1
Rule
Severity: Medium
The OL 8 audit package must be installed.
1
Rule
Severity: Medium
SLEM 5 audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.
Patternfly
PatternFly elements
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.
Modules
66%