Capacity
CCI-003980
Allow user installation of software only with explicit privileged status.
Choose one
2
Rule
Severity: Medium
The macOS system must prohibit user installation of software into /users/.
1
Rule
Severity: Medium
The application must prohibit user installation of software without explicit privileged status.
1
Rule
Severity: Medium
PostgreSQL must prohibit user installation of logic modules (functions, trigger procedures, views, etc.) without explicit privileged status.
1
Rule
Severity: Medium
The container platform must prohibit the installation of patches and updates without explicit privileged status.
1
Rule
Severity: High
The container platform runtime must prohibit the instantiation of container images without explicit privileged status.
1
Rule
Severity: Medium
The container platform registry must prohibit installation or modification of container images without explicit privileged status.
1
Rule
Severity: Medium
The DBMS must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.
1
Rule
Severity: Medium
The EDB Postgres Advanced Server must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.
1
Rule
Severity: Medium
Forescout must prohibit installation of software without explicit privileged permission by only authorized individuals.
1
Rule
Severity: Medium
The operating system must prohibit user installation of system software without explicit privileged status.
1
Rule
Severity: Medium
CA-ACF2 Access to SYS1.LINKLIB must be properly protected.
3
Rule
Severity: High
IBM z/OS SYS1.PARMLIB must be properly protected.
1
Rule
Severity: Medium
AIX must turn on enhanced Role-Based Access Control (RBAC) to isolate security functions from nonsecurity functions, to grant system privileges to other operating system admins, and prohibit user installation of system software without explicit privileged status.
1
Rule
Severity: Medium
CA-TSS access to SYS1.LINKLIB must be properly protected.
1
Rule
Severity: Medium
IBM RACF access to SYS1.LINKLIB must be properly protected.
1
Rule
Severity: High
The ICS must be configured to prevent nonprivileged users from executing privileged functions.
1
Rule
Severity: Medium
The Juniper EX switch must be configured to prohibit installation of software without explicit privileged status.
1
Rule
Severity: Medium
The Juniper router must be configured to prohibit installation of software without explicit privileged status.
1
Rule
Severity: Medium
The Juniper SRX Services Gateway must implement logon roles to ensure only authorized roles are allowed to install software and updates.
1
Rule
Severity: Medium
The Mainframe product must prohibit user installation of software without explicit privileged status.
1
Rule
Severity: Medium
MariaDB must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.
1
Rule
Severity: High
Least privilege access and need to know must be required to access MKE runtime and instantiate container images.
1
Rule
Severity: Low
URLs must be allowlisted for plugin use if used.
1
Rule
Severity: Medium
Azure SQL Database must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.
2
Rule
Severity: Medium
The Exchange application directory must be protected from unauthorized access.
1
Rule
Severity: Medium
SQL Server must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.
2
Rule
Severity: Medium
Users must be prevented from changing installation options.
1
Rule
Severity: High
The Windows Installer Always install with elevated privileges must be disabled.
1
Rule
Severity: High
The Windows Installer feature "Always install with elevated privileges" must be disabled.
1
Rule
Severity: Medium
Windows Server 2019 must prevent users from changing installation options.
1
Rule
Severity: High
Windows Server 2019 must disable the Windows Installer Always install with elevated privileges option.
1
Rule
Severity: Medium
Windows Server 2022 must prevent users from changing installation options.
1
Rule
Severity: High
Windows Server 2022 must disable the Windows Installer Always install with elevated privileges option.
1
Rule
Severity: Medium
The network device must prohibit installation of software without explicit privileged status.
1
Rule
Severity: Medium
The MySQL Database Server 8.0 must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.
1
Rule
Severity: Medium
Redis Enterprise DBMS must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.
1
Rule
Severity: Medium
Rancher RKE2 must prohibit the installation of patches, updates, and instantiation of container images without explicit privileged status.
1
Rule
Severity: High
OpenShift RBAC access controls must be enforced.
1
Rule
Severity: Medium
The SDN controller must be configured to prohibit user installation of software without explicit privileged status.
2
Rule
Severity: Medium
The Tanium application must prohibit user installation of software without explicit privileged status.
1
Rule
Severity: Medium
The VMM must prohibit user installation of software without explicit privileged status.
1
Rule
Severity: Medium
The UEM server must prohibit user installation of software by an administrator without the appropriate assigned permission for software installation.
1
Rule
Severity: Medium
The UEM server must be configured to only allow enrolled devices that are compliant with UEM policies and assigned to a user in the application access group to download applications.
Patternfly
PatternFly elements
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.
Modules
66%