II - Mission Support Classified
Rules and Groups employed by this XCCDF Profile
-
SRG-OS-000343-GPOS-00134
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must immediately notify the system administrator (SA) and information system security officer (ISSO) when the audit record storage volume reaches 25 percent remaining of the allocated capacity.
<VulnDiscussion>If security personnel are not notified immediately when storage volume reaches 25 percent remaining of the allocated capacity...Rule Low Severity -
SRG-OS-000057-GPOS-00027
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must be configured so that audit log files are not read- or write-accessible by unauthorized users.
<VulnDiscussion>Unauthorized disclosure of audit records can reveal system and configuration data to attackers, thus compromising its confide...Rule Medium Severity -
SRG-OS-000057-GPOS-00027
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must be configured to permit only authorized users ownership of the audit log files.
<VulnDiscussion>Unauthorized disclosure of audit records can reveal system and configuration data to attackers, thus compromising its confide...Rule Medium Severity -
SRG-OS-000057-GPOS-00027
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must permit only authorized groups ownership of the audit log files.
<VulnDiscussion>Unauthorized disclosure of audit records can reveal system and configuration data to attackers, thus compromising its confide...Rule Medium Severity -
SRG-OS-000059-GPOS-00029
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must be configured so that the audit log directory is not write-accessible by unauthorized users.
<VulnDiscussion>If audit information were to become compromised, then forensic analysis and discovery of the true source of potentially malic...Rule Medium Severity -
SRG-OS-000063-GPOS-00032
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must be configured so that audit configuration files are not write-accessible by unauthorized users.
<VulnDiscussion>Without the capability to restrict which roles and individuals can select which events are audited, unauthorized personnel ma...Rule Medium Severity -
SRG-OS-000063-GPOS-00032
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must permit only authorized accounts to own the audit configuration files.
<VulnDiscussion>Without the capability to restrict which roles and individuals can select which events are audited, unauthorized personnel ma...Rule Medium Severity -
SRG-OS-000063-GPOS-00032
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must permit only authorized groups to own the audit configuration files.
<VulnDiscussion>Without the capability to restrict which roles and individuals can select which events are audited, unauthorized personnel ma...Rule Medium Severity -
SRG-OS-000064-GPOS-00033
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the apparmor_parser command.
<VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to est...Rule Medium Severity -
SRG-OS-000064-GPOS-00033
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the chacl command.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-OS-000064-GPOS-00033
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the chage command.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-OS-000064-GPOS-00033
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the chcon command.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-OS-000064-GPOS-00033
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the chfn command.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-OS-000064-GPOS-00033
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the chsh command.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-OS-000064-GPOS-00033
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the crontab command.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-OS-000477-GPOS-00222
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful attempts to use the fdisk command.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-OS-000064-GPOS-00033
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the gpasswd command.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-OS-000477-GPOS-00222
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful attempts to use the kmod command.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-OS-000477-GPOS-00222
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful attempts to use modprobe command.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-OS-000064-GPOS-00033
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the mount command.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-OS-000064-GPOS-00033
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the newgrp command.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-OS-000064-GPOS-00033
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the pam_timestamp_check command.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-OS-000064-GPOS-00033
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the passwd command.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-OS-000064-GPOS-00033
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the setfacl command.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-OS-000064-GPOS-00033
<GroupDescription></GroupDescription>Group -
Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the ssh-agent command.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.