Skip to content

I - Mission Critical Public

Rules and Groups employed by this XCCDF Profile

  • SRG-OS-000134-GPOS-00068

    Group
  • RHEL 8 must have policycoreutils package installed.

    Without verification of the security functions, security functions may not operate correctly and the failure may go unnoticed. Security function is defined as the hardware, software, and/or firmwar...
    Rule Low Severity
  • SRG-OS-000138-GPOS-00069

    Group
  • A sticky bit must be set on all RHEL 8 public directories to prevent unauthorized and unintended information transferred via shared system resources.

    Preventing unauthorized information transfers mitigates the risk of information, including encrypted representations of information, produced by the actions of prior users/roles (or the actions of ...
    Rule Medium Severity
  • SRG-OS-000163-GPOS-00072

    Group
  • RHEL 8 must be configured so that all network connections associated with SSH traffic terminate after becoming unresponsive.

    Terminating an unresponsive SSH session within a short time period reduces the window of opportunity for unauthorized personnel to take control of a management session enabled on the console or con...
    Rule Medium Severity
  • SRG-OS-000206-GPOS-00084

    Group
  • The RHEL 8 /var/log/messages file must have mode 0640 or less permissive.

    Only authorized personnel should be aware of errors and the details of the errors. Error messages are an indicator of an organization's operational state or can identify the RHEL 8 system or platfo...
    Rule Medium Severity
  • SRG-OS-000206-GPOS-00084

    Group
  • The RHEL 8 /var/log/messages file must be owned by root.

    Only authorized personnel should be aware of errors and the details of the errors. Error messages are an indicator of an organization's operational state or can identify the RHEL 8 system or platfo...
    Rule Medium Severity
  • SRG-OS-000206-GPOS-00084

    Group
  • The RHEL 8 /var/log/messages file must be group-owned by root.

    Only authorized personnel should be aware of errors and the details of the errors. Error messages are an indicator of an organization's operational state or can identify the RHEL 8 system or platfo...
    Rule Medium Severity
  • SRG-OS-000206-GPOS-00084

    Group
  • The RHEL 8 /var/log directory must have mode 0755 or less permissive.

    Only authorized personnel should be aware of errors and the details of the errors. Error messages are an indicator of an organization's operational state or can identify the RHEL 8 system or platfo...
    Rule Medium Severity
  • SRG-OS-000206-GPOS-00084

    Group
  • The RHEL 8 /var/log directory must be owned by root.

    Only authorized personnel should be aware of errors and the details of the errors. Error messages are an indicator of an organization's operational state or can identify the RHEL 8 system or platfo...
    Rule Medium Severity
  • SRG-OS-000206-GPOS-00084

    Group
  • The RHEL 8 /var/log directory must be group-owned by root.

    Only authorized personnel should be aware of errors and the details of the errors. Error messages are an indicator of an organization's operational state or can identify the RHEL 8 system or platfo...
    Rule Medium Severity
  • SRG-OS-000250-GPOS-00093

    Group
  • The RHEL 8 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms.

    Without cryptographic integrity protections, information can be altered by unauthorized users without detection. Remote access (e.g., RDP) is access to DOD nonpublic information systems by an auth...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules