STIGQter STIGQter: STIG Summary:

Canonical Ubuntu 24.04 LTS Security Technical Implementation Guide

Version: 1

Release: 6 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-270645r1068357_ruleUbuntu 24.04 LTS must not have the "systemd-timesyncd" package installed.
SV-270646r1068358_ruleUbuntu 24.04 LTS must not have the "ntp" package installed.
SV-270647r1066430_ruleUbuntu 24.04 LTS must not have the telnet package installed.
SV-270648r1066433_ruleUbuntu 24.04 LTS must not have the rsh-server package installed.
SV-270649r1067136_ruleUbuntu 24.04 LTS must use a file integrity tool to verify correct operation of all security functions.
SV-270650r1155241_ruleUbuntu 24.04 LTS must configure AIDE to perform file integrity checking on the file system if installed.
SV-270651r1068395_ruleUbuntu 24.04 LTS must be configured so that the script which runs each 30 days or less to check file integrity is the default one.
SV-270652r1067138_ruleUbuntu 24.04 LTS must notify designated personnel if baseline configurations are changed in an unauthorized manner. The file integrity tool must notify the system administrator (SA) when changes to the baseline configuration or anomalies in the operation of any security functions are discovered.
SV-270653r1067141_ruleUbuntu 24.04 LTS must be configured to preserve log records from failure events.
SV-270654r1067143_ruleUbuntu 24.04 LTS must have an application firewall installed in order to control remote access methods.
SV-270655r1067145_ruleUbuntu 24.04 LTS must enable and run the Uncomplicated Firewall (ufw).
SV-270656r1067148_ruleUbuntu 24.04 LTS must have the "auditd" package installed.
SV-270657r1066460_ruleUbuntu 24.04 LTS must produce audit records and reports containing information to establish when, where, what type, the source, and the outcome for all DOD-defined auditable events and actions in near real time.
SV-270658r1067151_ruleUbuntu 24.04 LTS audit event multiplexor must be configured to offload audit logs onto a different system or storage media from the system being audited.
SV-270659r1066466_ruleUbuntu 24.04 LTS must have AppArmor installed.
SV-270660r1066469_ruleUbuntu 24.04 LTS must be configured to use AppArmor.
SV-270661r1067175_ruleUbuntu 24.04 LTS must have the "libpam-pwquality" package installed.
SV-270662r1067156_ruleUbuntu 24.04 LTS must have the "SSSD" package installed.
SV-270663r1066478_ruleUbuntu 24.04 LTS must use the "SSSD" package for multifactor authentication services.
SV-270664r1068359_ruleUbuntu 24.04 LTS must have the "chrony" package installed.
SV-270665r1067133_ruleUbuntu 24.04 LTS must have SSH installed.
SV-270666r1066487_ruleUbuntu 24.04 LTS must use SSH to protect the confidentiality and integrity of transmitted information.
SV-270667r1067107_ruleUbuntu 24.04 LTS must configure the SSH daemon to use FIPS 140-3 approved ciphers to prevent the unauthorized disclosure of information and/or detect changes to information during transmission.
SV-270668r1067110_ruleUbuntu 24.04 LTS must configure the SSH daemon to use Message Authentication Codes (MACs) employing FIPS 140-3 approved cryptographic hashes to prevent the unauthorized disclosure of information and/or detect changes to information during transmission.
SV-270669r1134804_ruleUbuntu 24.04 LTS SSH server must be configured to use only FIPS 140-3 validated key exchange algorithms.
SV-270670r1067115_ruleUbuntu 24.04 LTS must configure the SSH client to use FIPS 140-3 approved ciphers to prevent the unauthorized disclosure of information and/or detect changes to information during transmission.
SV-270671r1155244_ruleUbuntu 24.04 LTS SSH client must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms.
SV-270672r1067161_ruleUbuntu 24.04 LTS must accept Personal Identity Verification (PIV) credentials.
SV-270673r1067164_ruleUbuntu 24.04 LTS must accept Personal Identity Verification (PIV) credentials managed through the Privileged Access Management (PAM)  framework.
SV-270674r1067167_ruleUbuntu 24.04 LTS must allow users to directly initiate a session lock for all connection types.
SV-270675r1137691_ruleUbuntu 24.04 LTS when booted must require authentication upon booting into single-user and maintenance modes.
SV-270676r1155245_ruleUbuntu 24.04 LTS must initiate session audits at system startup.
SV-270677r1101774_ruleUbuntu 24.04 LTS must limit the number of concurrent sessions to 10 for all accounts and/or account types.
SV-270678r1101791_ruleUbuntu 24.04 LTS must initiate a graphical session lock after 10 minutes of inactivity.
SV-270679r1107295_ruleUbuntu 24.04 LTS must prevent a user from overriding the disabling of the graphical user interface automount function.
SV-270680r1066529_ruleUbuntu 24.04 LTS must automatically terminate a user session after inactivity timeouts have expired.
SV-270681r1134806_ruleUbuntu 24.04 LTS must monitor remote access methods.
SV-270682r1066535_ruleUbuntu 24.04 LTS must automatically remove or disable emergency accounts after 72 hours.
SV-270683r1066538_ruleUbuntu 24.04 LTS must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.
SV-270684r1066541_ruleUbuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
SV-270685r1066544_ruleUbuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
SV-270686r1066547_ruleUbuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
SV-270687r1066550_ruleUbuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
SV-270688r1066553_ruleUbuntu 24.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
SV-270689r1066556_ruleUbuntu 24.04 LTS must prevent all software from executing at higher privilege levels than users executing the software and the audit system must be configured to audit the execution of privileged functions.
SV-270690r1067126_ruleUbuntu 24.04 LTS must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts have been made.
SV-270691r1066562_ruleUbuntu 24.04 LTS must display the Standard Mandatory DOD Notice and Consent Banner before granting access to via an SSH logon.
SV-270692r1066565_ruleUbuntu 24.04 LTS must enable the graphical user logon banner to display the Standard Mandatory DOD Notice and Consent Banner before granting local access to the system via a graphical user logon.
SV-270693r1066568_ruleUbuntu 24.04 LTS must display the Standard Mandatory DOD Notice and Consent Banner before granting local access to the system via a graphical user logon.
SV-270694r1066571_ruleUbuntu 24.04 LTS must be configured to enforce the acknowledgement of the Standard Mandatory DOD Notice and Consent Banner for all SSH connections.
SV-270695r1066574_ruleUbuntu 24.04 LTS Advance Package Tool (APT) must be configured to prevent the installation of patches, service packs, device drivers, or Ubuntu 24.04 LTS components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.
SV-270696r1107306_ruleUbuntu 24.04 LTS library files must have mode 0755 or less permissive.
SV-270697r1107308_ruleUbuntu 24.04 LTS library files must be owned by root.
SV-270698r1101751_ruleUbuntu 24.04 LTS library directories must be owned by root.
SV-270699r1107310_ruleUbuntu 24.04 LTS library files must be group-owned by root or a system account.
SV-270700r1066589_ruleUbuntu 24.04 LTS library directories must be group-owned by root.
SV-270701r1066592_ruleUbuntu 24.04 LTS must have system commands set to a mode of 0755 or less permissive.
SV-270702r1066595_ruleUbuntu 24.04 LTS must have system commands owned by root or a system account.
SV-270703r1066598_ruleUbuntu 24.04 LTS must have system commands group-owned by root or a system account.
SV-270704r1066601_ruleUbuntu 24.04 LTS must prevent the use of dictionary words for passwords.
SV-270705r1066604_ruleUbuntu 24.04 LTS must be configured so that when passwords are changed or new passwords are established, pwquality must be used.
SV-270706r1068361_ruleUbuntu 24.04 LTS must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
SV-270707r1101786_ruleUbuntu 24.04 LTS must require users to reauthenticate for privilege escalation or when changing roles.
SV-270708r1208697_ruleUbuntu 24.04 LTS must be configured so that remote X connections are disabled, unless to fulfill documented and validated mission requirements.
SV-270709r1208698_ruleUbuntu 24.04 LTS SSH daemon must prevent remote hosts from connecting to the proxy display.
SV-270711r1184069_ruleUbuntu 24.04 LTS must disable the x86 Ctrl-Alt-Delete key sequence if a graphical user interface is installed.
SV-270712r1068363_ruleUbuntu 24.04 LTS must disable the x86 Ctrl-Alt-Delete key sequence.
SV-270713r1066628_ruleUbuntu 24.04 LTS must not have accounts configured with blank or null passwords.
SV-270714r1208699_ruleUbuntu 24.04 LTS must not allow accounts configured in Pluggable Authentication Modules (PAM) with blank or null passwords.
SV-270715r1066634_ruleUbuntu 24.04 LTS must generate audit records for all events that affect the systemd journal files.
SV-270716r1066637_ruleUbuntu 24.04 LTS default filesystem permissions must be defined in such a way that all authenticated users can read and modify only their own files.
SV-270717r1208700_ruleUbuntu 24.04 LTS must not allow unattended or automatic login via SSH.
SV-270718r1134811_ruleUbuntu 24.04 LTS must disable automatic mounting of Universal Serial Bus (USB) mass storage driver.
SV-270719r1067172_ruleUbuntu 24.04 LTS must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL) and vulnerability assessments.
SV-270720r1066649_ruleUbuntu 24.04 LTS must uniquely identify interactive users.
SV-270721r1066652_ruleUbuntu 24.04 LTS must implement smart card logins for multifactor authentication for local and network access to privileged and nonprivileged accounts.
SV-270722r1067130_ruleUbuntu 24.04 LTS must implement smart card logins for multifactor authentication for local and network access to privileged and nonprivileged accounts over SSH.
SV-270723r1066658_ruleUbuntu 24.04 LTS must electronically verify Personal Identity Verification (PIV) credentials.
SV-270724r1066661_ruleUbuntu 24.04 LTS must prevent direct login to the root account.
SV-270725r1101789_ruleUbuntu 24.04 LTS must store only encrypted representations of passwords.
SV-270726r1066667_ruleUbuntu 24.04 LTS must enforce password complexity by requiring that at least one uppercase character be used.
SV-270727r1066670_ruleUbuntu 24.04 LTS must enforce password complexity by requiring that at least one lowercase character be used.
SV-270728r1066673_ruleUbuntu 24.04 LTS must enforce password complexity by requiring that at least one numeric character be used.
SV-270729r1066676_ruleUbuntu 24.04 LTS must require the change of at least eight characters when passwords are changed.
SV-270730r1066679_ruleUbuntu 24.04 LTS must enforce 24 hours/1 day as the minimum password lifetime. Passwords for new users must have a 24 hours/1 day minimum password lifetime restriction.
SV-270731r1066682_ruleUbuntu 24.04 LTS must enforce a 60-day maximum password lifetime restriction. Passwords for new users must have a 60-day maximum password lifetime restriction.
SV-270732r1066685_ruleUbuntu 24.04 LTS must enforce a minimum 15-character password length.
SV-270733r1066688_ruleUbuntu 24.04 LTS must enforce password complexity by requiring that at least one special character be used.
SV-270734r1155240_ruleUbuntu 24.04 LTS must be configured such that Pluggable Authentication Module (PAM) prohibits the use of cached authentications after one day.
SV-270735r1066694_ruleUbuntu 24.04 LTS, for PKI-based authentication, SSSD must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
SV-270736r1066697_ruleUbuntu 24.04 LTS must map the authenticated identity to the user or group account for PKI-based authentication.
SV-270737r1067178_ruleUbuntu 24.04 LTS, for PKI-based authentication, Privileged Access Management (PAM) must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
SV-270738r1066703_ruleUbuntu 24.04 LTS for PKI-based authentication, must implement a local cache of revocation data in case of the inability to access revocation information via the network.
SV-270739r1067124_ruleUbuntu 24.04 LTS must encrypt all stored passwords with a FIPS 140-3 approved cryptographic hashing algorithm.
SV-270740r1066709_ruleUbuntu 24.04 LTS must generate audit records for privileged activities, nonlocal maintenance, diagnostic sessions, and other system-level access.
SV-270741r1066712_ruleUbuntu 24.04 LTS must use strong authenticators in establishing nonlocal maintenance and diagnostic sessions.
SV-270742r1066715_ruleUbuntu 24.04 LTS must immediately terminate all network connections associated with SSH traffic after a period of inactivity.
SV-270743r1208702_ruleUbuntu 24.04 LTS must immediately terminate all network connections associated with SSH traffic at the end of the session or after 10 minutes of inactivity.
SV-270744r1137699_ruleUbuntu 24.04 LTS must implement NIST FIPS-validated cryptography to protect classified information and for the following: To provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
SV-270745r1066724_ruleUbuntu 24.04 LTS must use DOD PKI-established certificate authorities (CAs) for verification of the establishment of protected sessions.
SV-270746r1155242_ruleUbuntu 24.04 LTS must disable kernel core dumps.
SV-270747r1066730_ruleUbuntu 24.04 LTS handling data requiring "data at rest" protections must employ cryptographic mechanisms to prevent unauthorized disclosure and modification of the information at rest.
SV-270748r1066733_ruleUbuntu 24.04 LTS must ensure only users who need access to security functions are part of sudo group.
SV-270749r1137695_ruleUbuntu 24.04 LTS must restrict access to the kernel message buffer.
SV-270750r1137695_ruleUbuntu 24.04 LTS must set a sticky bit on all public directories to prevent unauthorized and unintended information transferred via shared system resources.
SV-270751r1066742_ruleUbuntu 24.04 LTS must compare internal information system clocks at least every 24 hours with an authoritative time server.
SV-270752r1068365_ruleUbuntu 24.04 LTS must synchronize internal information system clocks to the authoritative time source when the time difference is greater than one second.
SV-270753r1066748_ruleUbuntu 24.04 LTS must be configured to use TCP syncookies.
SV-270754r1066751_ruleUbuntu 24.04 LTS must configure the uncomplicated firewall to rate-limit impacted network interfaces.
SV-270755r1066754_ruleUbuntu 24.04 LTS must disable all wireless network adapters.
SV-270756r1134814_ruleUbuntu 24.04 LTS must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
SV-270757r1184072_ruleUbuntu 24.04 LTS must generate system journal entries without revealing information that could be exploited by adversaries.
SV-270758r1066763_ruleUbuntu 24.04 LTS must be configured so that the "journalctl" command is not accessible by unauthorized users.
SV-270759r1068367_ruleUbuntu 24.04 LTS must be configured so that the "journalctl" command is owned by "root".
SV-270760r1066769_ruleUbuntu 24.04 LTS must be configured so that the "journalctl" command is group-owned by "root".
SV-270761r1184074_ruleUbuntu 24.04 LTS must configure the directories used by the system journal to be group-owned by "systemd-journal".
SV-270762r1184076_ruleUbuntu 24.04 LTS must configure the files used by the system journal to be group-owned by "systemd-journal".
SV-270763r1184078_ruleUbuntu 24.04 LTS must configure the directories used by the system journal to be owned by "root".
SV-270764r1184080_ruleUbuntu 24.04 LTS must configure the files used by the system journal to be owned by "root"
SV-270765r1066784_ruleUbuntu 24.04 LTS must configure the /var/log directory to be group-owned by syslog.
SV-270766r1066787_ruleUbuntu 24.04 LTS must configure the /var/log directory to be owned by root.
SV-270767r1066790_ruleUbuntu 24.04 LTS must configure the /var/log directory to have mode "0755" or less permissive.
SV-270768r1066793_ruleUbuntu 24.04 LTS must configure the /var/log/syslog file to be group-owned by adm.
SV-270769r1066796_ruleUbuntu 24.04 LTS must configure /var/log/syslog file to be owned by syslog.
SV-270770r1066799_ruleUbuntu 24.04 LTS must configure /var/log/syslog file with mode "0640" or less permissive.
SV-270771r1066802_ruleUbuntu 24.04 LTS must implement nonexecutable data to protect its memory from unauthorized code execution.
SV-270772r1066805_ruleUbuntu 24.04 LTS must implement address space layout randomization to protect its memory from unauthorized code execution.
SV-270773r1066808_ruleUbuntu 24.04 LTS must be configured so that Advance Package Tool (APT) removes all software components after updated versions have been installed.
SV-270775r1068369_ruleUbuntu 24.04 LTS must be configured so that audit configuration files are not write-accessible by unauthorized users.
SV-270776r1066817_ruleUbuntu 24.04 LTS must permit only authorized accounts to own the audit configuration files.
SV-270777r1066820_ruleUbuntu 24.04 LTS must permit only authorized groups to own the audit configuration files.
SV-270778r1066823_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the su command.
SV-270779r1066826_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the chfn command.
SV-270780r1066829_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the mount command.
SV-270781r1066832_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the umount command.
SV-270782r1066835_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the ssh-agent command.
SV-270783r1066838_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the ssh-keysign command.
SV-270784r1068371_ruleUbuntu 24.04 LTS must generate audit records for any use of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls.
SV-270785r1068373_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the chown, fchown, fchownat, and lchown system calls.
SV-270786r1068375_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the chmod, fchmod, and fchmodat system calls.
SV-270787r1068378_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the creat, open, openat, open_by_handle_at, truncate, and ftruncate system calls.
SV-270788r1066853_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the sudo command.
SV-270789r1066856_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the sudoedit command.
SV-270790r1068380_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the chsh command.
SV-270791r1066862_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the newgrp command.
SV-270792r1066865_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the chcon command.
SV-270793r1066868_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the apparmor_parser command.
SV-270794r1066871_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the setfacl command.
SV-270795r1066874_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the chacl command.
SV-270796r1066877_ruleUbuntu 24.04 LTS must generate audit records for the use and modification of faillog file.
SV-270797r1066880_ruleUbuntu 24.04 LTS must generate audit records for the use and modification of the lastlog file.
SV-270798r1068382_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the passwd command.
SV-270799r1066886_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the unix_update command.
SV-270800r1066889_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the gpasswd command.
SV-270801r1066892_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the chage command.
SV-270802r1066895_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the usermod command.
SV-270803r1066898_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the crontab command.
SV-270804r1066901_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the pam_timestamp_check command.
SV-270805r1068384_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the init_module and finit_module syscalls.
SV-270806r1068386_ruleUbuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the delete_module syscall.
SV-270807r1066910_ruleUbuntu 24.04 LTS must generate audit records when successful/unsuccessful attempts to modify the /etc/sudoers file occur.
SV-270808r1067100_ruleUbuntu 24.04 LTS must generate audit records when successful/unsuccessful attempts to modify the /etc/sudoers.d directory occur.
SV-270809r1068388_ruleUbuntu 24.04 LTS must generate audit records for any successful/unsuccessful use of unlink, unlinkat, rename, renameat, and rmdir system calls.
SV-270810r1066919_ruleUbuntu 24.04 LTS must generate audit records for the /var/log/wtmp file.
SV-270811r1066922_ruleUbuntu 24.04 LTS must generate audit records for the /var/run/utmp file.
SV-270812r1066925_ruleUbuntu 24.04 LTS must generate audit records for the /var/log/btmp file.
SV-270813r1066928_ruleUbuntu 24.04 LTS must generate audit records when successful/unsuccessful attempts to use modprobe command.
SV-270814r1066931_ruleUbuntu 24.04 LTS must generate audit records when successful/unsuccessful attempts to use the kmod command.
SV-270815r1066934_ruleUbuntu 24.04 LTS must generate audit records when successful/unsuccessful attempts to use the fdisk command.
SV-270816r1066937_ruleUbuntu 24.04 LTS must allocate audit record storage capacity to store at least one week's worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
SV-270817r1066940_ruleUbuntu 24.04 LTS must have a crontab script running weekly to offload audit events of standalone systems.
SV-270818r1066943_ruleUbuntu 24.04 LTS must immediately notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity.
SV-270819r1068390_ruleUbuntu 24.04 LTS must alert the system administrator (SA) and information system security officer (ISSO) (at a minimum) in the event of an audit processing failure.
SV-270820r1066949_ruleUbuntu 24.04 LTS must record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).
SV-270821r1134818_ruleUbuntu 24.04 LTS must configure audit tools with a mode of "0755" or less permissive.
SV-270822r1134821_ruleUbuntu 24.04 LTS must configure audit tools to be owned by root.
SV-270823r1134824_ruleUbuntu 24.04 LTS must configure the audit tools to be group owned by root.
SV-270824r1066961_ruleUbuntu 24.04 LTS must have directories that contain system commands set to a mode of "0755" or less permissive.
SV-270825r1066964_ruleUbuntu 24.04 LTS must have directories that contain system commands owned by root.
SV-270826r1066967_ruleUbuntu 24.04 LTS must have directories that contain system commands group-owned by root.
SV-270827r1066970_ruleUbuntu 24.04 LTS must be configured so that audit log files are not read or write-accessible by unauthorized users.
SV-270828r1066973_ruleUbuntu 24.04 LTS must be configured to permit only authorized users ownership of the audit log files.
SV-270829r1066976_ruleUbuntu 24.04 LTS must permit only authorized groups ownership of the audit log files.
SV-270830r1068397_ruleUbuntu 24.04 LTS must be configured so that the audit log directory is not write-accessible by unauthorized users.
SV-270831r1135002_ruleUbuntu 24.04 LTS must use cryptographic mechanisms to protect the integrity of audit tools.
SV-270832r1068399_ruleUbuntu 24.04 LTS audit system must protect auditing rules from unauthorized change.
SV-274868r1107313_ruleUbuntu 24.04 LTS must require users to provide a password for privilege escalation.
SV-274869r1107312_ruleUbuntu 24.04 LTS must restrict privilege elevation to authorized personnel.
SV-274870r1155243_ruleUbuntu 24.04 LTS must audit any script or executable called by cron as root or by any privileged user.
SV-274871r1107302_ruleUbuntu 24.04 LTS must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
SV-274872r1107297_ruleUbuntu 24.04 LTS must prevent a user from overriding the disabling of the graphical user interface autorun function.
SV-274873r1107300_ruleUbuntu 24.04 LTS must prevent a user from overriding the disabling of the graphical user smart card removal action.
SV-278917r1155246_ruleUbuntu 24.04 LTS must be a vendor-supported release.
SV-279938r1156367_ruleUbuntu 24.04 LTS must not have the nfs-kernel-server package installed.