Skip to content

Canonical Ubuntu 20.04 LTS Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • The Ubuntu operating system must generate audit records for successful/unsuccessful uses of the chfn command.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-OS-000064-GPOS-00033

    Group
  • The Ubuntu operating system must generate audit records for successful/unsuccessful uses of the mount command.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-OS-000064-GPOS-00033

    Group
  • SRG-OS-000064-GPOS-00033

    Group
  • The Ubuntu operating system must generate audit records for successful/unsuccessful uses of the ssh-agent command.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-OS-000064-GPOS-00033

    Group
  • The Ubuntu operating system must generate audit records for successful/unsuccessful uses of the ssh-keysign command.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-OS-000064-GPOS-00033

    Group
  • SRG-OS-000064-GPOS-00033

    Group
  • The Ubuntu operating system must generate audit records for successful/unsuccessful uses of the chown, fchown, fchownat, and lchown system calls.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-OS-000064-GPOS-00033

    Group
  • SRG-OS-000064-GPOS-00033

    Group
  • The Ubuntu operating system must generate audit records for successful/unsuccessful uses of the creat, open, openat, open_by_handle_at, truncate, and ftruncate system calls.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-OS-000064-GPOS-00033

    Group
  • The Ubuntu operating system must generate audit records for successful/unsuccessful uses of the sudo command.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-OS-000064-GPOS-00033

    Group
  • The Ubuntu operating system must generate audit records for successful/unsuccessful uses of the sudoedit command.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-OS-000064-GPOS-00033

    Group
  • The Ubuntu operating system must generate audit records for successful/unsuccessful uses of the chsh command.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-OS-000064-GPOS-00033

    Group
  • SRG-OS-000064-GPOS-00033

    Group
  • The Ubuntu operating system must generate audit records for successful/unsuccessful uses of the chcon command.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-OS-000064-GPOS-00033

    Group
  • The Ubuntu operating system must generate audit records for successful/unsuccessful uses of the apparmor_parser command.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-OS-000064-GPOS-00033

    Group
  • The Ubuntu operating system must generate audit records for successful/unsuccessful uses of the setfacl command.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-OS-000064-GPOS-00033

    Group
  • The Ubuntu operating system must generate audit records for successful/unsuccessful uses of the chacl command.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-OS-000064-GPOS-00033

    Group
  • The Ubuntu operating system must generate audit records for the use and modification of the tallylog file.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-OS-000064-GPOS-00033

    Group
  • SRG-OS-000064-GPOS-00033

    Group
  • The Ubuntu operating system must generate audit records for the use and modification of the lastlog file.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-OS-000064-GPOS-00033

    Group
  • The Ubuntu operating system must generate audit records for successful/unsuccessful uses of the passwd command.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-OS-000064-GPOS-00033

    Group
  • The Ubuntu operating system must generate audit records for successful/unsuccessful uses of the unix_update command.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-OS-000064-GPOS-00033

    Group
  • The Ubuntu operating system must generate audit records for successful/unsuccessful uses of the gpasswd command.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-OS-000064-GPOS-00033

    Group
  • The Ubuntu operating system must generate audit records for successful/unsuccessful uses of the chage command.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-OS-000064-GPOS-00033

    Group
  • The Ubuntu operating system must generate audit records for successful/unsuccessful uses of the usermod command.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-OS-000064-GPOS-00033

    Group
  • The Ubuntu operating system must initiate session audits at system start-up.

    If auditing is enabled late in the start-up process, the actions of some start-up processes may not be audited. Some audit systems also maintain state information only available if auditing is enab...
    Rule Medium Severity
  • SRG-OS-000064-GPOS-00033

    Group
  • The Ubuntu operating system must generate audit records for successful/unsuccessful uses of the pam_timestamp_check command.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-OS-000064-GPOS-00033

    Group
  • SRG-OS-000064-GPOS-00033

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules