Skip to content

II - Mission Support Sensitive

Rules and Groups employed by this XCCDF Profile

  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • A separate RHEL 9 file system must be used for user home directories (such as /home or an equivalent).

    &lt;VulnDiscussion&gt;Ensuring that "/home" is mounted on its own partition enables the setting of more restrictive mount options, and also helps e...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • RHEL 9 must use a separate file system for /tmp.

    &lt;VulnDiscussion&gt;The "/tmp" partition is used as temporary storage by many programs. Placing "/tmp" in its own partition enables the setting o...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • RHEL 9 must use a separate file system for /var.

    &lt;VulnDiscussion&gt;Ensuring that "/var" is mounted on its own partition enables the setting of more restrictive mount options. This helps protec...
    Rule Low Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • RHEL 9 must use a separate file system for /var/log.

    &lt;VulnDiscussion&gt;Placing "/var/log" in its own partition enables better separation between log files and other files in "/var/".&lt;/VulnDiscu...
    Rule Low Severity
  • SRG-OS-000341-GPOS-00132

    <GroupDescription></GroupDescription>
    Group
  • RHEL 9 must use a separate file system for the system audit data path.

    &lt;VulnDiscussion&gt;Placing "/var/log/audit" in its own partition enables better separation between audit files and other system files, and helps...
    Rule Low Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules