Capacity
CCI-002699
Perform verification of the correct operation of organization-defined security functions: when the system is in an organization-defined transitional state; upon command by a user with appropriate privileges; and/or on an organization-defined frequency.
Choose one
26
Rule
Severity: Medium
Install AIDE
20
Rule
Severity: Medium
Configure Periodic Execution of AIDE
13
Rule
Severity: Medium
Configure Notification of Post-AIDE Scan Details
2
Rule
Severity: Medium
The application must perform verification of the correct operation of security functions: upon system startup and/or restart; upon command by a user with privileged access; and/or every 30 days.
2
Rule
Severity: Medium
The DNS server implementation must perform verification of the correct operation of security functions: upon system start-up and/or restart; upon command by a user with privileged access; and/or every 30 days.
1
Rule
Severity: Medium
The MaaS360 MDM Agent must provide an alert via the trusted channel to the MDM server for the following event: change in enrollment state.
2
Rule
Severity: Medium
The Mainframe Product must perform verification of the correct operation of security functions upon system startup and/or restart; upon command by a user with privileged access; and/or every 30 days.
1
Rule
Severity: Medium
The Windows 2012 DNS Server must log the event and notify the system administrator when anomalies in the operation of the signed zone transfers are discovered.
1
Rule
Severity: Medium
Nutanix AOS must be configured to use SELinux Enforcing mode.
2
Rule
Severity: Medium
Configuration of Prisma Cloud Compute must be continuously verified.
2
Rule
Severity: Medium
The UEM server must run a suite of self-tests during initial start-up (power on) to demonstrate correct operation of the server.
2
Rule
Severity: Medium
The macOS system must ensure secure boot level set to full.
1
Rule
Severity: Medium
The Ubuntu operating system must be configured so that a file integrity tool verifies the correct operation of security functions every 30 days.
2
Rule
Severity: Medium
The Ubuntu operating system must be configured so that the script which runs each 30 days or less to check file integrity is the default one.
2
Rule
Severity: Medium
The container platform must perform verification of the correct operation of security functions: upon system startup and/or restart; upon command by a user with privileged access; and/or every 30 days. Security functionality includes, but is not limited to, establishing system accounts, configuring access authorizations (i.e., permissions, privileges), setting events to be audited, and setting intrusion detection parameters.
2
Rule
Severity: Medium
The operating system must perform verification of the correct operation of security functions: upon system start-up and/or restart; upon command by a user with privileged access; and/or every 30 days.
2
Rule
Severity: Medium
The Oracle Linux operating system must be configured so that a file integrity tool verifies the baseline operating system configuration at least weekly.
2
Rule
Severity: Medium
The OL 8 file integrity tool must notify the System Administrator (SA) when changes to the baseline configuration or anomalies in the operation of any security functions are discovered within an organizationally defined frequency.
2
Rule
Severity: Medium
OpenShift must perform verification of the correct operation of security functions: upon startup and/or restart; upon command by a user with privileged access; and/or every 30 days.
4
Rule
Severity: Medium
Advanced Intrusion Detection Environment (AIDE) must verify the baseline SUSE operating system configuration at least weekly.
2
Rule
Severity: Medium
RHEL 9 must routinely check the baseline configuration for unauthorized changes and notify the system administrator when anomalies in the operation of any security functions are discovered.
2
Rule
Severity: Medium
The VMM must perform verification of the correct operation of security functions: upon system startup and/or restart; upon command by a user with privileged access; and/or every 30 days.
4
Rule
Severity: Medium
The ESXi host must implement Secure Boot enforcement.
1
Rule
Severity: Medium
The Photon operating system must have the auditd service running.
3
Rule
Severity: Medium
The Photon operating system must enable the auditd service.
2
Rule
Severity: Medium
The Windows DNS Server must verify the correct operation of security functions upon startup and/or restart, upon command by a user with privileged access, and/or every 30 days.
2
Rule
Severity: Medium
The Windows DNS Server must verify the correct operation of security functions upon system startup and/or restart, upon command by a user with privileged access, and/or every 30 days.
2
Rule
Severity: Medium
Configure Systemd Timer Execution of AIDE
1
Rule
Severity: Medium
The macOS system must ensure Secure Boot level is set to "full".
1
Rule
Severity: Medium
Ubuntu 22.04 LTS must be configured so that the script that runs each 30 days or less to check file integrity is the default.
1
Rule
Severity: Medium
MKE must be configured to integrate with an Enterprise Identity Provider.
1
Rule
Severity: Medium
Advanced Intrusion Detection Environment (AIDE) must verify the baseline SLEM 5 configuration at least weekly.
1
Rule
Severity: Medium
The TOSS file integrity tool must notify the system administrator when changes to the baseline configuration or anomalies in the operation of any security functions are discovered within an organizationally defined frequency.
Patternfly
PatternFly elements
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.
Modules
66%