CCI-003980
Allow user installation of software only with explicit privileged status.
PostgreSQL must prohibit user installation of logic modules (functions, trigger procedures, views, etc.) without explicit privileged status.
1 rule found Severity: Medium

The EDB Postgres Advanced Server must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.
1 rule found Severity: Medium

AIX must turn on enhanced Role-Based Access Control (RBAC) to isolate security functions from nonsecurity functions, to grant system privileges to other operating system admins, and prohibit user installation of system software without explicit privileged status.
1 rule found Severity: Medium

1 rule found Severity: High

The Juniper EX switch must be configured to prohibit installation of software without explicit privileged status.
1 rule found Severity: Medium

Least privilege access and need to know must be required to access MKE runtime and instantiate container images.
1 rule found Severity: High

Azure SQL Database must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.
1 rule found Severity: Medium

1 rule found Severity: High

1 rule found Severity: Medium

The MySQL Database Server 8.0 must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.
1 rule found Severity: Medium

Redis Enterprise DBMS must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.
1 rule found Severity: Medium

The SDN controller must be configured to prohibit user installation of software without explicit privileged status.
1 rule found Severity: Medium

The Tanium application must prohibit user installation of software without explicit privileged status.
2 rules found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

The container platform must prohibit the installation of patches and updates without explicit privileged status.
1 rule found Severity: Medium

The container platform runtime must prohibit the instantiation of container images without explicit privileged status.
1 rule found Severity: High

The container platform registry must prohibit installation or modification of container images without explicit privileged status.
1 rule found Severity: Medium

The DBMS must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.
1 rule found Severity: Medium

Forescout must prohibit installation of software without explicit privileged permission by only authorized individuals.
1 rule found Severity: Medium

The operating system must prohibit user installation of system software without explicit privileged status.
1 rule found Severity: Medium

The Juniper router must be configured to prohibit installation of software without explicit privileged status.
1 rule found Severity: Medium

The Juniper SRX Services Gateway must implement logon roles to ensure only authorized roles are allowed to install software and updates.
1 rule found Severity: Medium

MariaDB must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.
1 rule found Severity: Medium

The Mainframe product must prohibit user installation of software without explicit privileged status.
1 rule found Severity: Medium

2 rules found Severity: Medium

SQL Server must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.
1 rule found Severity: Medium

1 rule found Severity: High

1 rule found Severity: Medium

Windows Server 2019 must disable the Windows Installer Always install with elevated privileges option.
1 rule found Severity: High

1 rule found Severity: Medium

Windows Server 2022 must disable the Windows Installer Always install with elevated privileges option.
1 rule found Severity: High

Rancher RKE2 must prohibit the installation of patches, updates, and instantiation of container images without explicit privileged status.
1 rule found Severity: Medium

The UEM server must prohibit user installation of software by an administrator without the appropriate assigned permission for software installation.
1 rule found Severity: Medium

The UEM server must be configured to only allow enrolled devices that are compliant with UEM policies and assigned to a user in the application access group to download applications.
1 rule found Severity: Medium

1 rule found Severity: Medium

Rancher MCM must use a centralized user management solution to support account management functions. For accounts using password authentication, the container platform must use FIPS-validated SHA-2 or later protocol to protect the integrity of the password authentication process.
1 rule found Severity: High
