| Checked | Name | Title |
|---|
| ☐ | SV-269102r1049984_rule | AlmaLinux OS 9 must limit the number of concurrent sessions to ten for all accounts and/or account types. |
| ☐ | SV-269103r1208304_rule | AlmaLinux OS 9 must automatically lock graphical user sessions after 10 minutes of inactivity. |
| ☐ | SV-269104r1049986_rule | AlmaLinux OS 9 must conceal, via the session lock, information previously visible on the display with a publicly viewable image. |
| ☐ | SV-269105r1101820_rule | AlmaLinux OS 9 must prevent a user from overriding the session idle-delay setting for the graphical user interface. |
| ☐ | SV-269106r1049988_rule | AlmaLinux OS 9 must initiate a session lock for graphical user interfaces when the screensaver is activated. |
| ☐ | SV-269107r1049989_rule | AlmaLinux OS 9 must prevent a user from overriding the session lock-delay setting for the graphical user interface. |
| ☐ | SV-269108r1049990_rule | AlmaLinux OS 9 must automatically exit interactive command shell user sessions after 10 minutes of inactivity. |
| ☐ | SV-269109r1049991_rule | AlmaLinux OS 9 must be able to directly initiate a session lock for all connection types using smart card when the smart card is removed. |
| ☐ | SV-269110r1049992_rule | AlmaLinux OS 9 must prevent a user from overriding the disabling of the graphical user smart card removal action. |
| ☐ | SV-269111r1050605_rule | AlmaLinux OS 9 must log SSH connection attempts and failures to the server. |
| ☐ | SV-269112r1050606_rule | All AlmaLinux OS 9 remote access methods must be monitored. |
| ☐ | SV-269113r1184081_rule | AlmaLinux OS 9 SSH client must be configured to use only encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. |
| ☐ | SV-269115r1184083_rule | AlmaLinux OS 9 SSH client must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms. |
| ☐ | SV-269116r1184084_rule | The AlmaLinux 9 SSH server must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections. |
| ☐ | SV-269118r1050609_rule | AlmaLinux OS 9 must implement DOD-approved systemwide cryptographic policies to protect the confidentiality of SSH server connections. |
| ☐ | SV-269119r1184085_rule | The AlmaLinux OS 9 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections. |
| ☐ | SV-269120r1050610_rule | AlmaLinux OS 9 must force a frequent session key renegotiation for SSH connections to the server. |
| ☐ | SV-269122r1184087_rule | AlmaLinux OS 9 IP tunnels must use FIPS 140-3 approved cryptographic algorithms. |
| ☐ | SV-269125r1107616_rule | AlmaLinux OS 9 must use the TuxCare ESU repository. |
| ☐ | SV-269126r1107617_rule | AlmaLinux OS 9 must use the TuxCare FIPS packages and not the default encryption packages. |
| ☐ | SV-269127r1155256_rule | AlmaLinux OS 9 must enable FIPS mode. |
| ☐ | SV-269128r1050010_rule | AlmaLinux OS 9 must automatically expire temporary accounts within 72 hours. |
| ☐ | SV-269129r1050011_rule | AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers. |
| ☐ | SV-269130r1050012_rule | AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group. |
| ☐ | SV-269131r1050013_rule | AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow. |
| ☐ | SV-269132r1050014_rule | AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd. |
| ☐ | SV-269133r1050015_rule | AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd. |
| ☐ | SV-269134r1050016_rule | AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow. |
| ☐ | SV-269135r1050017_rule | AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect the files within /etc/sudoers.d/ |
| ☐ | SV-269136r1137691_rule | AlmaLinux OS 9 must require authentication to access emergency mode. |
| ☐ | SV-269137r1137691_rule | AlmaLinux OS 9 must require a boot loader password. |
| ☐ | SV-269138r1137691_rule | AlmaLinux OS 9 must require a unique superuser's name upon booting into single-user and maintenance modes. |
| ☐ | SV-269139r1137691_rule | AlmaLinux OS 9 must require authentication to access single-user mode. |
| ☐ | SV-269140r1050022_rule | The systemd Ctrl-Alt-Delete burst key sequence in AlmaLinux OS 9 must be disabled. |
| ☐ | SV-269141r1101851_rule | The Ctrl-Alt-Delete key sequence must be disabled on AlmaLinux OS 9. |
| ☐ | SV-269142r1050024_rule | AlmaLinux OS 9 must have the sudo package installed. |
| ☐ | SV-269143r1050025_rule | The AlmaLinux OS 9 debug-shell systemd service must be disabled. |
| ☐ | SV-269144r1050026_rule | AlmaLinux OS 9 must enable kernel parameters to enforce discretionary access control on hardlinks. |
| ☐ | SV-269145r1050027_rule | AlmaLinux OS 9 must enable kernel parameters to enforce discretionary access control (DAC) on symlinks. |
| ☐ | SV-269146r1050028_rule | AlmaLinux OS 9 must audit uses of the "execve" system call. |
| ☐ | SV-269147r1050029_rule | AlmaLinux OS 9 must automatically lock an account when three unsuccessful logon attempts occur. |
| ☐ | SV-269148r1050030_rule | AlmaLinux OS 9 must automatically lock the root account until the root account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period. |
| ☐ | SV-269149r1184091_rule | AlmaLinux OS 9 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period. |
| ☐ | SV-269150r1050032_rule | AlmaLinux OS 9 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file. |
| ☐ | SV-269151r1050033_rule | AlmaLinux OS 9 must configure the use of the pam_faillock.so module in the /etc/pam.d/password-auth file. |
| ☐ | SV-269152r1050034_rule | AlmaLinux OS 9 must log username information when unsuccessful logon attempts occur. |
| ☐ | SV-269153r1050035_rule | AlmaLinux OS 9 must maintain an account lock until the locked account is manually released by an administrator; and not automatically after a set time. |
| ☐ | SV-269154r1050036_rule | AlmaLinux OS 9 must ensure account locks persist across reboots. |
| ☐ | SV-269155r1050037_rule | AlmaLinux OS 9 must configure the appropriate SELinux context on the nondefault faillock tally directory. |
| ☐ | SV-269156r1050038_rule | AlmaLinux OS 9 must prevent users from disabling the Standard Mandatory DOD Notice and Consent Banner for graphical user interfaces. |
| ☐ | SV-269157r1050039_rule | AlmaLinux OS 9 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a graphical user logon. |
| ☐ | SV-269158r1050040_rule | AlmaLinux OS 9 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a command line user logon. |
| ☐ | SV-269159r1050041_rule | AlmaLinux OS 9 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via an SSH user logon. |
| ☐ | SV-269160r1050042_rule | AlmaLinux OS 9 must have the s-nail package installed. |
| ☐ | SV-269161r1050043_rule | AlmaLinux OS 9 SSH daemon must not allow Generic Security Service Application Program Interface (GSSAPI) authentication. |
| ☐ | SV-269162r1050044_rule | AlmaLinux OS 9 SSH daemon must not allow Kerberos authentication. |
| ☐ | SV-269163r1050045_rule | AlmaLinux OS 9 must check the GPG signature of software packages originating from external software repositories before installation. |
| ☐ | SV-269164r1050046_rule | AlmaLinux OS 9 must ensure cryptographic verification of vendor software packages. |
| ☐ | SV-269165r1050047_rule | AlmaLinux OS 9 must check the GPG signature of locally installed software packages before installation. |
| ☐ | SV-269166r1050048_rule | AlmaLinux OS 9 must check the GPG signature of repository metadata before package installation. |
| ☐ | SV-269167r1050049_rule | AlmaLinux OS 9 must have GPG signature verification enabled for all software repositories. |
| ☐ | SV-269168r1155267_rule | AlmaLinux OS 9 must prevent the loading of a new kernel for later execution. |
| ☐ | SV-269169r1208309_rule | AlmaLinux OS 9 system commands must be group-owned by root or a system account. |
| ☐ | SV-269170r1050052_rule | AlmaLinux OS 9 system commands must be owned by root. |
| ☐ | SV-269171r1050053_rule | AlmaLinux OS 9 system commands must have mode 755 or less permissive. |
| ☐ | SV-269172r1050054_rule | AlmaLinux OS 9 library directories must be group-owned by root or a system account. |
| ☐ | SV-269173r1050055_rule | AlmaLinux OS 9 library directories must be owned by root. |
| ☐ | SV-269174r1050056_rule | AlmaLinux OS 9 library directories must have mode 755 or less permissive. |
| ☐ | SV-269175r1101800_rule | AlmaLinux OS 9 library files must be group-owned by root or a system account. |
| ☐ | SV-269176r1101803_rule | AlmaLinux OS 9 library files must be owned by root. |
| ☐ | SV-269177r1101806_rule | AlmaLinux OS 9 library files must have mode 755 or less permissive. |
| ☐ | SV-269178r1156418_rule | AlmaLinux OS 9 must disable core dumps for all users. |
| ☐ | SV-269179r1050061_rule | AlmaLinux OS 9 must disable acquiring, saving, and processing core dumps. |
| ☐ | SV-269180r1050062_rule | AlmaLinux OS 9 must disable storing core dumps. |
| ☐ | SV-269181r1050063_rule | AlmaLinux OS 9 must disable core dump backtraces. |
| ☐ | SV-269182r1050064_rule | AlmaLinux OS 9 must disable the kernel.core_pattern. |
| ☐ | SV-269183r1050065_rule | AlmaLinux OS 9 cron configuration files directory must be group-owned by root. |
| ☐ | SV-269184r1050066_rule | AlmaLinux OS 9 cron configuration files directory must be owned by root. |
| ☐ | SV-269185r1050067_rule | AlmaLinux OS 9 cron configuration directories must have a mode of 0700 or less permissive. |
| ☐ | SV-269186r1050068_rule | AlmaLinux OS 9 /etc/crontab file must have mode 0600. |
| ☐ | SV-269187r1050069_rule | AlmaLinux OS 9 must disable the ability of a user to accidentally press Ctrl-Alt-Del and cause a system to shut down or reboot. |
| ☐ | SV-269188r1184093_rule | AlmaLinux OS 9 must prevent a user from overriding the Ctrl-Alt-Del sequence settings for the graphical user interface. |
| ☐ | SV-269189r1050071_rule | All AlmaLinux OS 9 local files and directories must have a valid group owner. |
| ☐ | SV-269190r1050072_rule | All AlmaLinux OS 9 local files and directories must have a valid owner. |
| ☐ | SV-269191r1050073_rule | AlmaLinux OS 9 /etc/group- file must be group owned by root. |
| ☐ | SV-269192r1050074_rule | AlmaLinux OS 9 /etc/group- file must be owned by root. |
| ☐ | SV-269193r1050075_rule | AlmaLinux OS 9 /etc/group- file must have mode 0644 or less permissive to prevent unauthorized access. |
| ☐ | SV-269194r1050076_rule | AlmaLinux OS 9 /etc/group file must be group owned by root. |
| ☐ | SV-269195r1050077_rule | AlmaLinux OS 9 /etc/group file must be owned by root. |
| ☐ | SV-269196r1050078_rule | AlmaLinux OS 9 /etc/group file must have mode 0644 or less permissive to prevent unauthorized access. |
| ☐ | SV-269197r1050079_rule | The /boot/grub2/grub.cfg file must be group-owned by root. |
| ☐ | SV-269198r1050779_rule | The /boot/grub2/grub.cfg file must be owned by root. |
| ☐ | SV-269199r1050081_rule | AlmaLinux OS 9 must disable the ability of systemd to spawn an interactive boot process. |
| ☐ | SV-269200r1050082_rule | AlmaLinux OS 9 /etc/gshadow- file must be group-owned by root. |
| ☐ | SV-269201r1050083_rule | AlmaLinux OS 9 /etc/gshadow- file must be owned by root. |
| ☐ | SV-269202r1050084_rule | AlmaLinux OS 9 /etc/gshadow- file must have mode 0000 or less permissive to prevent unauthorized access. |
| ☐ | SV-269203r1050085_rule | AlmaLinux OS 9 /etc/gshadow file must be group-owned by root. |
| ☐ | SV-269204r1050086_rule | AlmaLinux OS 9 /etc/gshadow file must be owned by root. |
| ☐ | SV-269205r1050087_rule | AlmaLinux OS 9 /etc/gshadow file must have mode 0000 or less permissive to prevent unauthorized access. |
| ☐ | SV-269206r1050088_rule | The graphical display manager must not be the default target on AlmaLinux OS 9 unless approved. |
| ☐ | SV-269207r1050089_rule | AlmaLinux OS 9 must disable the user list at logon for graphical user interfaces. |
| ☐ | SV-269208r1050090_rule | All AlmaLinux OS 9 local interactive user accounts must be assigned a home directory upon creation. |
| ☐ | SV-269209r1050091_rule | All AlmaLinux OS 9 local interactive user home directories defined in the /etc/passwd file must exist. |
| ☐ | SV-269210r1050092_rule | All AlmaLinux OS 9 local interactive user home directories must be group-owned by the home directory owner's primary group. |
| ☐ | SV-269211r1050093_rule | AlmaLinux OS 9 must prevent code from being executed on file systems that contain user home directories. |
| ☐ | SV-269212r1050094_rule | A separate file system must be used for user home directories (such as /home or an equivalent). |
| ☐ | SV-269213r1050095_rule | All AlmaLinux OS 9 local interactive users must have a home directory assigned in the /etc/passwd file. |
| ☐ | SV-269214r1050096_rule | Executable search paths within the initialization files of all local interactive AlmaLinux OS 9 users must only contain paths that resolve to the system default or the users home directory. |
| ☐ | SV-269215r1050097_rule | All AlmaLinux OS 9 local interactive user home directories must have mode 0750 or less permissive. |
| ☐ | SV-269216r1050098_rule | AlmaLinux OS 9 must not allow unattended or automatic logon via the graphical user interface. |
| ☐ | SV-269217r1050099_rule | AlmaLinux OS 9 must enforce a delay of at least four seconds between logon prompts following a failed logon attempt. |
| ☐ | SV-269218r1050100_rule | AlmaLinux OS 9 must not allow blank or null passwords. |
| ☐ | SV-269219r1050101_rule | AlmaLinux OS 9 must not have accounts configured with blank or null passwords. |
| ☐ | SV-269220r1050102_rule | AlmaLinux OS 9 /etc/passwd- file must be group-owned by root. |
| ☐ | SV-269221r1050103_rule | AlmaLinux OS 9 /etc/passwd- file must be owned by root. |
| ☐ | SV-269222r1050104_rule | AlmaLinux OS 9 /etc/passwd- file must have mode 0644 or less permissive to prevent unauthorized access. |
| ☐ | SV-269223r1050105_rule | AlmaLinux OS 9 /etc/passwd file must be group-owned by root. |
| ☐ | SV-269224r1050106_rule | AlmaLinux OS 9 /etc/passwd file must be owned by root. |
| ☐ | SV-269225r1050107_rule | AlmaLinux OS 9 /etc/passwd file must have mode 0644 or less permissive to prevent unauthorized access. |
| ☐ | SV-269226r1050108_rule | AlmaLinux OS 9 /etc/shadow- file must be group-owned by root. |
| ☐ | SV-269227r1050109_rule | AlmaLinux OS 9 /etc/shadow- file must be owned by root. |
| ☐ | SV-269228r1050110_rule | AlmaLinux OS 9 /etc/shadow- file must have mode 0000 or less permissive to prevent unauthorized access. |
| ☐ | SV-269229r1050111_rule | AlmaLinux OS 9 /etc/shadow file must be group-owned by root. |
| ☐ | SV-269230r1050112_rule | AlmaLinux OS 9 /etc/shadow file must be owned by root. |
| ☐ | SV-269231r1050113_rule | AlmaLinux OS 9 /etc/shadow file must have mode 0000 to prevent unauthorized access. |
| ☐ | SV-269232r1101826_rule | AlmaLinux OS 9 must restrict privilege elevation to authorized personnel. |
| ☐ | SV-269233r1050115_rule | AlmaLinux OS 9 must use the invoking user's password for privilege escalation when using "sudo". |
| ☐ | SV-269234r1050116_rule | AlmaLinux OS 9 must set the umask value to 077 for all local interactive user accounts. |
| ☐ | SV-269235r1050117_rule | AlmaLinux OS 9 must define default permissions for all authenticated users in such a way that the user can only read and modify their own files. |
| ☐ | SV-269236r1050118_rule | AlmaLinux OS 9 must define default permissions for PAM users. |
| ☐ | SV-269237r1050119_rule | AlmaLinux OS 9 must define default permissions for logon and nonlogon shells. |
| ☐ | SV-269238r1050120_rule | AlmaLinux OS 9 must not have unauthorized accounts. |
| ☐ | SV-269239r1050121_rule | AlmaLinux OS 9 must be configured so that the file integrity tool verifies Access Control Lists (ACLs). |
| ☐ | SV-269240r1050122_rule | AlmaLinux OS 9 must use a file integrity tool that is configured to use FIPS 140-3-approved cryptographic hashes for validating file contents and directories. |
| ☐ | SV-269241r1050123_rule | AlmaLinux OS 9 must be configured so that the file integrity tool verifies extended attributes. |
| ☐ | SV-269242r1050124_rule | AlmaLinux OS 9 must prevent the use of dictionary words for passwords. |
| ☐ | SV-269243r1050125_rule | AlmaLinux OS 9 must not accept router advertisements on all IPv6 interfaces. |
| ☐ | SV-269244r1050126_rule | AlmaLinux OS 9 must ignore Internet Control Message Protocol (ICMP) redirect messages. |
| ☐ | SV-269245r1050613_rule | The firewalld service on AlmaLinux OS 9 must be active. |
| ☐ | SV-269246r1050780_rule | AlmaLinux OS 9 firewall must employ a deny-all, allow-by-exception policy for allowing connections to other systems. |
| ☐ | SV-269247r1050129_rule | AlmaLinux OS 9 must limit the number of bogus Internet Control Message Protocol (ICMP) response errors logs. |
| ☐ | SV-269248r1050130_rule | AlmaLinux OS 9 must not respond to Internet Control Message Protocol (ICMP) echoes sent to a broadcast address. |
| ☐ | SV-269249r1050131_rule | AlmaLinux OS 9 must not enable IP packet forwarding unless the system is a router. |
| ☐ | SV-269250r1050132_rule | AlmaLinux OS 9 must not have unauthorized IP tunnels configured. |
| ☐ | SV-269251r1050133_rule | AlmaLinux OS 9 must log packets with impossible addresses. |
| ☐ | SV-269252r1050134_rule | AlmaLinux OS 9 must be configured to prevent unrestricted mail relaying. |
| ☐ | SV-269253r1101817_rule | AlmaLinux OS 9 must have the nss-tools package installed. |
| ☐ | SV-269254r1050136_rule | AlmaLinux OS 9 network interfaces must not be in promiscuous mode. |
| ☐ | SV-269255r1050137_rule | AlmaLinux OS 9 must use reverse path filtering on all IP interfaces. |
| ☐ | SV-269256r1050138_rule | AlmaLinux OS 9 must not send Internet Control Message Protocol (ICMP) redirects. |
| ☐ | SV-269257r1050139_rule | There must be no .shosts files on AlmaLinux OS 9. |
| ☐ | SV-269258r1050140_rule | There must be no shosts.equiv files on AlmaLinux OS 9. |
| ☐ | SV-269259r1107619_rule | Alma Linux OS 9 must not accept IPv4 source-routed packets by default. |
| ☐ | SV-269261r1050143_rule | The AlmaLinux OS 9 SSH server configuration file must be group-owned by root. |
| ☐ | SV-269262r1050144_rule | The AlmaLinux OS 9 SSH server configuration file must be owned by root. |
| ☐ | SV-269263r1050145_rule | AlmaLinux OS 9 SSH server configuration files must have mode 0600 or less permissive. |
| ☐ | SV-269264r1050146_rule | AlmaLinux OS 9 must not allow a noncertificate trusted host SSH logon to the system. |
| ☐ | SV-269265r1208312_rule | AlmaLinux OS 9 SSH private host key files must have mode 0600 or less permissive. |
| ☐ | SV-269266r1050148_rule | AlmaLinux OS 9 SSH public host key files must have mode 0644 or less permissive. |
| ☐ | SV-269267r1050149_rule | AlmaLinux OS 9 SSH daemon must not allow known hosts authentication. |
| ☐ | SV-269268r1050150_rule | AlmaLinux OS 9 SSH daemon must display the date and time of the last successful account logon upon an SSH logon. |
| ☐ | SV-269269r1050151_rule | AlmaLinux OS 9 SSH daemon must not allow rhosts authentication. |
| ☐ | SV-269270r1050152_rule | AlmaLinux OS 9 SSH daemon must disable remote X connections for interactive users. |
| ☐ | SV-269271r1050153_rule | AlmaLinux OS 9 SSH daemon must prevent remote hosts from connecting to the proxy display. |
| ☐ | SV-269272r1050154_rule | If the Trivial File Transfer Protocol (TFTP) server is required, the TFTP daemon must be configured to operate in secure mode. |
| ☐ | SV-269273r1050155_rule | AlmaLinux OS 9 must enable hardening for the Berkeley Packet Filter (BPF) just-in-time (JIT) compiler. |
| ☐ | SV-269274r1050156_rule | AlmaLinux OS 9 effective dconf policy must match the policy keyfiles. |
| ☐ | SV-269275r1050157_rule | AlmaLinux OS 9 must be configured so that all system device files are correctly labeled to prevent unauthorized modification. |
| ☐ | SV-269276r1050158_rule | All AlmaLinux OS 9 local initialization files must have mode 0740 or less permissive. |
| ☐ | SV-269277r1050159_rule | AlmaLinux OS 9 must have the gnutls-utils package installed. |
| ☐ | SV-269278r1050160_rule | The kdump service on AlmaLinux OS 9 must be disabled. |
| ☐ | SV-269279r1050161_rule | AlmaLinux OS 9 must disable the ability of a user to restart the system from the login screen. |
| ☐ | SV-269280r1050162_rule | AlmaLinux OS 9 must prevent a user from overriding the disable-restart-buttons setting for the graphical user interface. |
| ☐ | SV-269281r1050163_rule | AlmaLinux OS 9 must prevent special devices on file systems that are used with removable media. |
| ☐ | SV-269282r1050164_rule | AlmaLinux OS 9 must prevent code from being executed on file systems that are used with removable media. |
| ☐ | SV-269283r1050165_rule | AlmaLinux OS 9 must prevent files with the setuid and setgid bit set from being executed on file systems that are used with removable media. |
| ☐ | SV-269284r1101813_rule | AlmaLinux OS 9 must disable the use of user namespaces. |
| ☐ | SV-269285r1050167_rule | AlmaLinux OS 9 must prevent special devices on file systems that are imported via Network File System (NFS). |
| ☐ | SV-269286r1050168_rule | AlmaLinux OS 9 must prevent code execution on file systems that are imported via Network File System (NFS). |
| ☐ | SV-269287r1050169_rule | AlmaLinux OS 9 must prevent files with the setuid and setgid bit set from being executed on file systems that are imported via Network File System (NFS). |
| ☐ | SV-269288r1050170_rule | AlmaLinux OS 9 must configure a DNS processing mode set be Network Manager. |
| ☐ | SV-269289r1050171_rule | AlmaLinux OS 9 systems using Domain Name Servers (DNS) resolution must have at least two name servers configured. |
| ☐ | SV-269290r1184095_rule | AlmaLinux OS 9 must prevent special devices on nonroot local partitions. |
| ☐ | SV-269291r1050173_rule | The root account must be the only account having unrestricted access to an AlmaLinux OS 9 system. |
| ☐ | SV-269292r1050174_rule | AlmaLinux OS 9 must be configured so that the cryptographic hashes of system files match vendor values. |
| ☐ | SV-269293r1050175_rule | AlmaLinux OS 9 must clear the page allocator to prevent use-after-free attacks. |
| ☐ | SV-269295r1050177_rule | AlmaLinux OS 9 security patches and updates must be installed and up to date. |
| ☐ | SV-269296r1050178_rule | AlmaLinux OS 9 policycoreutils-python-utils package must be installed. |
| ☐ | SV-269297r1050179_rule | AlmaLinux OS 9 must enable the hardware random number generator entropy gatherer service. |
| ☐ | SV-269298r1050180_rule | AlmaLinux OS 9 must have the rng-tools package installed. |
| ☐ | SV-269299r1050181_rule | The SSH daemon must perform strict mode checking of home directory configuration files. |
| ☐ | SV-269300r1050182_rule | AlmaLinux OS 9 system accounts must not have an interactive login shell. |
| ☐ | SV-269301r1050183_rule | AlmaLinux OS 9 must use a separate file system for /tmp. |
| ☐ | SV-269303r1050185_rule | AlmaLinux OS 9 must use a separate file system for /var/log. |
| ☐ | SV-269304r1050186_rule | AlmaLinux OS 9 must use a separate file system for /var. |
| ☐ | SV-269305r1050187_rule | AlmaLinux OS 9 must use a separate file system for /var/tmp. |
| ☐ | SV-269306r1050188_rule | AlmaLinux OS 9 must disable virtual system calls. |
| ☐ | SV-269307r1050189_rule | AlmaLinux OS 9 must use cron logging. |
| ☐ | SV-269308r1184097_rule | AlmaLinux OS 9 must be configured so that the rsyslog daemon does not accept log messages from other servers unless the server is being used for log aggregation. |
| ☐ | SV-269309r1050191_rule | AlmaLinux OS 9 must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories. |
| ☐ | SV-269310r1050192_rule | AlmaLinux OS 9 must prevent device files from being interpreted on file systems that contain user home directories. |
| ☐ | SV-269311r1184099_rule | AlmaLinux OS 9 must prevent files with the setuid and setgid bit set from being executed on the /boot/efi directory. |
| ☐ | SV-269312r1050194_rule | AlmaLinux OS 9 must mount /boot with the nodev option. |
| ☐ | SV-269313r1050195_rule | AlmaLinux OS 9 must prevent files with the setuid and setgid bit set from being executed on the /boot directory. |
| ☐ | SV-269314r1050196_rule | AlmaLinux OS 9 must mount /dev/shm with the nodev option. |
| ☐ | SV-269315r1050197_rule | AlmaLinux OS 9 must mount /dev/shm with the noexec option. |
| ☐ | SV-269316r1050198_rule | AlmaLinux OS 9 must mount /dev/shm with the nosuid option. |
| ☐ | SV-269317r1050199_rule | AlmaLinux OS 9 must mount /tmp with the nodev option. |
| ☐ | SV-269318r1050200_rule | AlmaLinux OS 9 must mount /tmp with the noexec option. |
| ☐ | SV-269319r1050201_rule | AlmaLinux OS 9 must mount /tmp with the nosuid option. |
| ☐ | SV-269320r1050202_rule | AlmaLinux OS 9 must mount /var/log/audit with the nodev option. |
| ☐ | SV-269321r1050203_rule | AlmaLinux OS 9 must mount /var/log/audit with the noexec option. |
| ☐ | SV-269322r1050204_rule | AlmaLinux OS 9 must mount /var/log/audit with the nosuid option. |
| ☐ | SV-269323r1050205_rule | AlmaLinux OS 9 must mount /var/log with the nodev option. |
| ☐ | SV-269324r1050206_rule | AlmaLinux OS 9 must mount /var/log with the noexec option. |
| ☐ | SV-269325r1050207_rule | AlmaLinux OS 9 must mount /var/log with the nosuid option. |
| ☐ | SV-269326r1050208_rule | AlmaLinux OS 9 must mount /var with the nodev option. |
| ☐ | SV-269327r1050209_rule | AlmaLinux OS 9 must mount /var/tmp with the nodev option. |
| ☐ | SV-269328r1050210_rule | AlmaLinux OS 9 must mount /var/tmp with the noexec option. |
| ☐ | SV-269329r1050211_rule | AlmaLinux OS 9 must mount /var/tmp with the nosuid option. |
| ☐ | SV-269330r1050212_rule | AlmaLinux OS 9 fapolicy module must be enabled. |
| ☐ | SV-269331r1050213_rule | AlmaLinux OS 9 fapolicy module must be installed. |
| ☐ | SV-269332r1050214_rule | AlmaLinux OS 9 must disable remote management of the chrony daemon. |
| ☐ | SV-269333r1050215_rule | AlmaLinux OS 9 must prevent the chrony daemon from acting as a server. |
| ☐ | SV-269334r1050216_rule | AlmaLinux OS 9 must not have the iprutils package installed. |
| ☐ | SV-269335r1050217_rule | AlmaLinux OS 9 must not have the quagga package installed. |
| ☐ | SV-269336r1050218_rule | AlmaLinux OS 9 must not have the sendmail package installed. |
| ☐ | SV-269338r1050220_rule | AlmaLinux OS 9 must not have a Trivial File Transfer Protocol (TFTP) client package installed. |
| ☐ | SV-269339r1050221_rule | AlmaLinux OS 9 must not have the cups package installed. |
| ☐ | SV-269340r1184101_rule | AlmaLinux OS 9 must not have the gssproxy package installed. |
| ☐ | SV-269341r1050223_rule | AlmaLinux OS 9 must disable the Asynchronous Transfer Mode (ATM) kernel module. |
| ☐ | SV-269342r1050224_rule | AlmaLinux OS 9 must be configured to disable Bluetooth. |
| ☐ | SV-269343r1050225_rule | AlmaLinux OS 9 must disable the Controller Area Network (CAN) kernel module. |
| ☐ | SV-269344r1050226_rule | AlmaLinux OS 9 must disable mounting of cramfs. |
| ☐ | SV-269345r1050227_rule | AlmaLinux OS 9 must disable the Stream Control Transmission Protocol (SCTP) kernel module. |
| ☐ | SV-269346r1050228_rule | AlmaLinux OS 9 must disable mounting of squashfs. |
| ☐ | SV-269347r1050229_rule | AlmaLinux OS 9 must disable the Transparent Inter Process Communication (TIPC) kernel module. |
| ☐ | SV-269348r1050230_rule | AlmaLinux OS 9 must disable mounting of udf. |
| ☐ | SV-269349r1050232_rule | Cameras must be disabled or covered when not in use. |
| ☐ | SV-269350r1050233_rule | AlmaLinux OS 9 must not have the nfs-utils package installed. |
| ☐ | SV-269351r1050234_rule | AlmaLinux OS 9 must not have the rsh package installed. |
| ☐ | SV-269352r1134829_rule | AlmaLinux OS 9 must not install packages from the Extra Packages for Enterprise Linux (EPEL) repository. |
| ☐ | SV-269353r1050236_rule | AlmaLinux OS 9 must not have the tuned package installed. |
| ☐ | SV-269354r1050237_rule | A graphical display manager must not be installed on AlmaLinux OS 9 unless approved. |
| ☐ | SV-269355r1155253_rule | AlmaLinux OS 9 must not have the ypserv package installed. |
| ☐ | SV-269356r1050239_rule | AlmaLinux OS 9 must not have the avahi package installed. |
| ☐ | SV-269357r1050240_rule | AlmaLinux OS 9 must be configured to disable USB mass storage. |
| ☐ | SV-269358r1050241_rule | AlmaLinux OS 9 must have the firewalld package installed. |
| ☐ | SV-269359r1101824_rule | AlmaLinux OS 9 must require users to provide authentication for privilege escalation. |
| ☐ | SV-269360r1101822_rule | AlmaLinux OS 9 must require users to provide a password for privilege escalation. |
| ☐ | SV-269361r1050244_rule | AlmaLinux OS 9 must not be configured to bypass password requirements for privilege escalation. |
| ☐ | SV-269362r1050245_rule | AlmaLinux OS 9 must require reauthentication when using the "sudo" command. |
| ☐ | SV-269363r1050246_rule | AlmaLinux OS 9 must restrict the use of the "su" command. |
| ☐ | SV-269364r1050247_rule | Groups must have unique Group IDs (GIDs). |
| ☐ | SV-269365r1050248_rule | Duplicate User IDs (UIDs) must not exist for interactive users. |
| ☐ | SV-269366r1050249_rule | All AlmaLinux OS 9 interactive users must have a primary group that exists. |
| ☐ | SV-269367r1050250_rule | AlmaLinux OS 9 SSHD must accept public key authentication. |
| ☐ | SV-269368r1050614_rule | AlmaLinux OS 9 must have the opensc package installed. |
| ☐ | SV-269369r1208307_rule | The pcscd socket on AlmaLinux OS 9 must be active. |
| ☐ | SV-269370r1050616_rule | AlmaLinux OS 9 must have the pcsc-lite package installed. |
| ☐ | SV-269371r1050254_rule | AlmaLinux OS 9 must implement certificate status checking for multifactor authentication. |
| ☐ | SV-269372r1050617_rule | AlmaLinux OS 9 must enable certificate based smart card authentication. |
| ☐ | SV-269373r1050256_rule | AlmaLinux OS 9 must have the openssl-pkcs11 package installed. |
| ☐ | SV-269374r1050257_rule | AlmaLinux OS 9 SSHD must not allow blank passwords. |
| ☐ | SV-269375r1050258_rule | AlmaLinux OS 9 must use the CAC smart card driver. |
| ☐ | SV-269376r1050259_rule | AlmaLinux OS 9 must not permit direct logons to the root account using remote access via SSH. |
| ☐ | SV-269377r1050260_rule | AlmaLinux OS 9 must disable the graphical user interface automount function unless required. |
| ☐ | SV-269378r1050261_rule | AlmaLinux OS 9 must prevent a user from overriding the disabling of the graphical user interface automount function. |
| ☐ | SV-269379r1050262_rule | AlmaLinux OS 9 must prevent a user from overriding the disabling of the graphical user interface autorun function. |
| ☐ | SV-269380r1050263_rule | AlmaLinux OS 9 must have the USBGuard package installed. |
| ☐ | SV-269381r1050264_rule | AlmaLinux OS 9 must have the USBGuard package enabled. |
| ☐ | SV-269382r1050265_rule | AlmaLinux OS 9 must block unauthorized peripherals before establishing a connection. |
| ☐ | SV-269383r1050266_rule | AlmaLinux OS 9 must not have the autofs package installed. |
| ☐ | SV-269384r1050267_rule | AlmaLinux OS 9 must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity. |
| ☐ | SV-269385r1050268_rule | AlmaLinux OS 9 must enforce password complexity by requiring that at least one lowercase character be used. |
| ☐ | SV-269386r1050269_rule | AlmaLinux OS 9 must ensure the password complexity module is enabled in the password-auth file. |
| ☐ | SV-269387r1050270_rule | AlmaLinux OS 9 must ensure the password complexity module in the system-auth file is configured for three retries or less. |
| ☐ | SV-269388r1155272_rule | AlmaLinux OS 9 must enforce password complexity rules for the root account. |
| ☐ | SV-269389r1050272_rule | AlmaLinux OS 9 must enforce password complexity by requiring that at least one uppercase character be used. |
| ☐ | SV-269390r1155274_rule | AlmaLinux OS 9 must enforce password complexity by requiring that at least one special character be used. |
| ☐ | SV-269392r1050275_rule | AlmaLinux OS 9 passwords must be created with a minimum of 15 characters. |
| ☐ | SV-269393r1050276_rule | AlmaLinux OS 9 must enforce password complexity by requiring that at least one numeric character be used. |
| ☐ | SV-269394r1050277_rule | AlmaLinux OS 9 must require the change of at least four character classes when passwords are changed. |
| ☐ | SV-269395r1050278_rule | AlmaLinux OS 9 must require the maximum number of repeating characters be limited to three when passwords are changed. |
| ☐ | SV-269396r1050279_rule | AlmaLinux OS 9 must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed. |
| ☐ | SV-269397r1050280_rule | AlmaLinux OS 9 must require the change of at least eight characters when passwords are changed. |
| ☐ | SV-269398r1050281_rule | AlmaLinux OS 9 PAM must be configured to use a sufficient number of password hashing rounds. |
| ☐ | SV-269399r1050282_rule | AlmaLinux OS 9 must be configured so that libuser is configured to store only encrypted representations of passwords. |
| ☐ | SV-269400r1050283_rule | AlmaLinux OS 9 must be configured so that the system's shadow file is configured to store only encrypted representations of passwords. |
| ☐ | SV-269401r1050284_rule | AlmaLinux OS 9 must be configured so that the Pluggable Authentication Module is configured to store only encrypted representations of passwords. |
| ☐ | SV-269402r1050285_rule | AlmaLinux OS 9 must be configured so that interactive user account passwords are using strong password hashes. |
| ☐ | SV-269403r1050286_rule | AlmaLinux OS 9 must not have any File Transfer Protocol (FTP) packages installed. |
| ☐ | SV-269404r1050287_rule | AlmaLinux OS 9 must not have any telnet packages installed. |
| ☐ | SV-269405r1050288_rule | Passwords for existing users must have a 60-day maximum password lifetime restriction in /etc/shadow. |
| ☐ | SV-269406r1050619_rule | Passwords for new users or password changes must have a 60-day maximum password lifetime restriction in /etc/login.defs. |
| ☐ | SV-269407r1050290_rule | Passwords for existing users must have a 24-hour minimum password lifetime restriction in /etc/shadow. |
| ☐ | SV-269408r1050291_rule | Passwords for new users or password changes must have a 24-hour minimum password lifetime restriction in /etc/login.defs. |
| ☐ | SV-269409r1050292_rule | AlmaLinux OS 9 must prohibit the use of cached authenticators after one day. |
| ☐ | SV-269410r1050293_rule | For PKI-based authentication, AlmaLinux OS 9 must enforce authorized access to the corresponding private key. |
| ☐ | SV-269411r1050294_rule | AlmaLinux OS 9 must map the authenticated identity to the user or group account for PKI-based authentication. |
| ☐ | SV-269412r1155277_rule | AlmaLinux OS 9, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor. |
| ☐ | SV-269415r1101853_rule | The libreswan package must be installed. |
| ☐ | SV-269416r1050299_rule | AlmaLinux OS 9 must have the packages required for encrypting offloaded audit logs installed. |
| ☐ | SV-269419r1050302_rule | AlmaLinux OS 9 must be configured so that all network connections associated with SSH traffic are terminated after 10 minutes of becoming unresponsive. |
| ☐ | SV-269420r1050303_rule | AlmaLinux OS 9 must enable the Pluggable Authentication Module (PAM) interface for SSHD. |
| ☐ | SV-269421r1155259_rule | AlmaLinux OS 9 must terminate idle user sessions. |
| ☐ | SV-269422r1198253_rule | AlmaLinux OS 9 must disable access to network bpf system call from nonprivileged processes. |
| ☐ | SV-269423r1198253_rule | AlmaLinux OS 9 must restrict exposed kernel pointer addresses access. |
| ☐ | SV-269424r1198253_rule | AlmaLinux OS 9 must restrict usage of ptrace to descendant processes. |
| ☐ | SV-269425r1198253_rule | AlmaLinux OS 9 must restrict access to the kernel message buffer. |
| ☐ | SV-269426r1198253_rule | AlmaLinux OS 9 must prevent kernel profiling by nonprivileged users. |
| ☐ | SV-269427r1050310_rule | AlmaLinux OS 9 must only allow the use of DOD PKI-established certificate authorities for authentication in the establishment of protected sessions to the operating system. |
| ☐ | SV-269428r1050311_rule | AlmaLinux OS 9 systemd-journald service must be enabled. |
| ☐ | SV-269429r1050312_rule | AlmaLinux OS 9 local disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at rest protection. |
| ☐ | SV-269430r1050313_rule | AlmaLinux OS 9 must use a Linux Security Module configured to enforce limits on system services. |
| ☐ | SV-269431r1050314_rule | AlmaLinux OS 9 must have the policycoreutils package installed. |
| ☐ | SV-269432r1137695_rule | Any AlmaLinux OS 9 world-writable directories must be owned by root, sys, bin, or an application user. |
| ☐ | SV-269433r1137695_rule | A sticky bit must be set on all AlmaLinux OS 9 public directories. |
| ☐ | SV-269434r1050317_rule | AlmaLinux OS 9 must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring rate-limiting measures on impacted network interfaces are implemented. |
| ☐ | SV-269435r1050318_rule | AlmaLinux OS 9 must be configured to use TCP syncookies. |
| ☐ | SV-269436r1208315_rule | All AlmaLinux OS 9 networked systems must have the OpenSSH client package installed. |
| ☐ | SV-269437r1117271_rule | All AlmaLinux OS 9 networked systems must implement SSH to protect the confidentiality and integrity of transmitted and received information, including information being prepared for transmission. |
| ☐ | SV-269438r1117271_rule | All AlmaLinux OS 9 networked systems must have the OpenSSH server installed. |
| ☐ | SV-269439r1050322_rule | AlmaLinux OS 9 must not allow users to override SSH environment variables. |
| ☐ | SV-269441r1050324_rule | AlmaLinux OS 9 wireless network adapters must be disabled. |
| ☐ | SV-269442r1050325_rule | AlmaLinux OS 9 must not show boot up messages. |
| ☐ | SV-269443r1050326_rule | AlmaLinux OS 9 /var/log directory must be group-owned by root. |
| ☐ | SV-269444r1050327_rule | AlmaLinux OS 9 /var/log/messages file must be group-owned by root. |
| ☐ | SV-269445r1050328_rule | AlmaLinux OS 9 /var/log/messages file must be owned by root. |
| ☐ | SV-269446r1050329_rule | AlmaLinux OS 9 /var/log/messages file must have mode 0640 or less permissive. |
| ☐ | SV-269447r1050330_rule | AlmaLinux OS 9 /var/log directory must be owned by root. |
| ☐ | SV-269448r1050331_rule | AlmaLinux OS 9 /var/log directory must have mode 0755 or less permissive. |
| ☐ | SV-269449r1050620_rule | AlmaLinux OS 9 must implement nonexecutable data to protect its memory from unauthorized code execution. |
| ☐ | SV-269450r1050333_rule | AlmaLinux OS 9 must enable mitigations against processor-based vulnerabilities. |
| ☐ | SV-269451r1069342_rule | AlmaLinux OS 9 must clear memory when it is freed to prevent use-after-free attacks. |
| ☐ | SV-269452r1208318_rule | AlmaLinux OS 9 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution. |
| ☐ | SV-269453r1050336_rule | AlmaLinux OS 9 must remove all software components after updated versions have been installed. |
| ☐ | SV-269454r1184107_rule | AlmaLinux OS 9 must be a supported release. |
| ☐ | SV-269455r1050338_rule | AlmaLinux OS 9 must enable the SELinux targeted policy. |
| ☐ | SV-269456r1050339_rule | AlmaLinux OS 9 must have the Advanced Intrusion Detection Environment (AIDE) package installed. |
| ☐ | SV-269457r1050340_rule | AlmaLinux OS 9 must routinely check the baseline configuration for unauthorized changes and notify the system administrator when anomalies in the operation of any security functions are discovered. |
| ☐ | SV-269458r1050341_rule | AlmaLinux OS 9 audit system must audit local events. |
| ☐ | SV-269459r1050342_rule | AlmaLinux OS 9 /etc/audit/auditd.conf file must have 0640 or less permissive to prevent unauthorized access. |
| ☐ | SV-269460r1050343_rule | AlmaLinux OS 9 must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited. |
| ☐ | SV-269461r1050344_rule | Successful/unsuccessful uses of the init command in AlmaLinux OS 9 must generate an audit record. |
| ☐ | SV-269462r1050345_rule | AlmaLinux OS 9 must generate audit records for any use of the "poweroff" command. |
| ☐ | SV-269463r1050346_rule | AlmaLinux OS 9 must generate audit records for any use of the "reboot" command. |
| ☐ | SV-269464r1050347_rule | AlmaLinux must generate audit records for any use of the "shutdown" command. |
| ☐ | SV-269465r1050348_rule | AlmaLinux OS 9 must enable Linux audit logging for the USBGuard daemon. |
| ☐ | SV-269466r1050349_rule | AlmaLinux OS 9 must audit all uses of the delete_module, init_module and finit_module system calls. |
| ☐ | SV-269467r1050350_rule | AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/tallylog. |
| ☐ | SV-269468r1050351_rule | AlmaLinux OS 9 must produce audit records containing information to establish the identity of any individual or process associated with the event. |
| ☐ | SV-269469r1050352_rule | The audit package must be installed on AlmaLinux OS 9. |
| ☐ | SV-269470r1050353_rule | AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/lastlog. |
| ☐ | SV-269471r1050354_rule | AlmaLinux OS 9 must generate audit records for any use of the "mount" command. |
| ☐ | SV-269472r1050355_rule | AlmaLinux OS 9 must generate audit records for any use of the "umount" command. |
| ☐ | SV-269473r1050356_rule | Successful/unsuccessful uses of the umount2 system call in AlmaLinux OS 9 must generate an audit record. |
| ☐ | SV-269474r1050357_rule | AlmaLinux OS 9 must enable auditing of processes that start prior to the audit daemon. |
| ☐ | SV-269475r1134834_rule | AlmaLinux OS 9 must audit all uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls. |
| ☐ | SV-269476r1050359_rule | AlmaLinux OS 9 must generate audit records for any use of the "chacl" command. |
| ☐ | SV-269477r1050360_rule | AlmaLinux OS 9 must generate audit records for any use of the "chage" command. |
| ☐ | SV-269478r1050361_rule | AlmaLinux OS 9 must generate audit records for any use of the "chcon" command. |
| ☐ | SV-269479r1050362_rule | AlmaLinux OS 9 must audit all uses of the chmod, fchmod, and fchmodat system calls. |
| ☐ | SV-269480r1050363_rule | AlmaLinux OS 9 must audit all uses of the chown, fchown, fchownat, and lchown system calls. |
| ☐ | SV-269481r1050364_rule | AlmaLinux OS 9 must generate audit records for any use of the "chsh" command. |
| ☐ | SV-269482r1050365_rule | AlmaLinux OS 9 must generate audit records for any use of the "crontab" command. |
| ☐ | SV-269483r1134836_rule | AlmaLinux OS 9 must audit all uses of the rename, unlink, rmdir, renameat, and unlinkat system calls. |
| ☐ | SV-269484r1050367_rule | AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/faillock. |
| ☐ | SV-269485r1050368_rule | AlmaLinux OS 9 must generate audit records for any use of the "gpasswd" command. |
| ☐ | SV-269486r1050369_rule | AlmaLinux OS 9 must audit all uses of the kmod command. |
| ☐ | SV-269487r1050370_rule | AlmaLinux OS 9 must generate audit records for any use of the "newgrp" command. |
| ☐ | SV-269488r1050371_rule | AlmaLinux OS 9 must generate audit records for any use of the "passwd" command. |
| ☐ | SV-269489r1050372_rule | AlmaLinux OS 9 must generate audit records for any use of the "postdrop" command. |
| ☐ | SV-269490r1050373_rule | AlmaLinux OS 9 must generate audit records for any use of the "postqueue" command. |
| ☐ | SV-269491r1050374_rule | AlmaLinux OS 9 must generate audit records for any use of the "su" command. |
| ☐ | SV-269492r1050375_rule | AlmaLinux OS 9 must generate audit records for any use of the "sudo" command. |
| ☐ | SV-269493r1050376_rule | AlmaLinux OS 9 must generate audit records for any use of the "semanage" command. |
| ☐ | SV-269494r1050377_rule | AlmaLinux OS 9 must generate audit records for any use of the "setfacl" command. |
| ☐ | SV-269495r1050378_rule | AlmaLinux OS 9 must generate audit records for any use of the "setfiles" command. |
| ☐ | SV-269496r1050379_rule | AlmaLinux OS 9 must generate audit records for any use of the "setsebool" command. |
| ☐ | SV-269497r1050380_rule | AlmaLinux OS 9 must generate audit records for any use of the "ssh-agent" command. |
| ☐ | SV-269498r1155270_rule | AlmaLinux OS 9 must generate audit records for any use of the "ssh-keysign" command. |
| ☐ | SV-269499r1050382_rule | AlmaLinux OS 9 must generate audit records for any use of the "sudoedit" command. |
| ☐ | SV-269500r1050383_rule | AlmaLinux OS 9 must generate audit records for any use of the "pam_timestamp_check" command. |
| ☐ | SV-269501r1050384_rule | AlmaLinux OS 9 must generate audit records for any use of the "unix_chkpwd" command. |
| ☐ | SV-269502r1050385_rule | AlmaLinux OS 9 must generate audit records for any use of the "unix_update" command. |
| ☐ | SV-269503r1050386_rule | AlmaLinux OS 9 must generate audit records for any use of the "userhelper" command. |
| ☐ | SV-269504r1050387_rule | AlmaLinux OS 9 must generate audit records for any use of the "usermod" command. |
| ☐ | SV-269505r1050388_rule | AlmaLinux OS 9 must audit all uses of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls. |
| ☐ | SV-269506r1101808_rule | AlmaLinux OS 9 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon. |
| ☐ | SV-269507r1050390_rule | AlmaLinux OS 9 must use a separate file system for the system audit data path. |
| ☐ | SV-269508r1050391_rule | AlmaLinux OS 9 must allocate audit record storage capacity to store at least one week's worth of audit records. |
| ☐ | SV-269509r1050392_rule | AlmaLinux OS 9 audispd-plugins package must be installed. |
| ☐ | SV-269510r1050393_rule | AlmaLinux OS 9 must label all offloaded audit logs before sending them to the central log server. |
| ☐ | SV-269511r1050394_rule | AlmaLinux OS 9 must take appropriate action when the internal event queue is full. |
| ☐ | SV-269512r1050395_rule | AlmaLinux OS 9 must be configured to offload audit records onto a different system from the system being audited via syslog. |
| ☐ | SV-269513r1050396_rule | AlmaLinux OS 9 must authenticate the remote logging server for offloading audit logs via rsyslog. |
| ☐ | SV-269514r1050397_rule | AlmaLinux OS 9 must encrypt the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog. |
| ☐ | SV-269515r1050398_rule | AlmaLinux OS 9 must encrypt, via the gtls driver, the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog. |
| ☐ | SV-269516r1050399_rule | AlmaLinux OS 9 must have the rsyslog package installed. |
| ☐ | SV-269517r1050400_rule | AlmaLinux OS 9 must be configured to forward audit records via TCP to a different system or media from the system being audited via rsyslog. |
| ☐ | SV-269518r1050401_rule | The rsyslog service on AlmaLinux OS 9 must be active. |
| ☐ | SV-269519r1050402_rule | AlmaLinux OS 9 must take action when allocated audit record storage volume reaches 95 percent of the audit record storage capacity. |
| ☐ | SV-269520r1050403_rule | AlmaLinux OS 9 must take action when allocated audit record storage volume reaches 95 percent of the repository maximum audit record storage capacity. |
| ☐ | SV-269521r1101829_rule | AlmaLinux OS 9 must take action when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity. |
| ☐ | SV-269522r1050604_rule | AlmaLinux OS 9 must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume reaches 75 percent usage. |
| ☐ | SV-269523r1050406_rule | AlmaLinux OS 9 System Administrator (SA) and/or information system security officer (ISSO) (at a minimum) must be alerted of an audit processing failure event. |
| ☐ | SV-269524r1050407_rule | AlmaLinux OS 9 must have mail aliases to notify the information system security officer (ISSO) and system administrator (SA) (at a minimum) in the event of an audit processing failure. |
| ☐ | SV-269525r1050408_rule | AlmaLinux OS 9 audit system must take appropriate action when an error writing to the audit storage volume occurs. |
| ☐ | SV-269526r1050409_rule | AlmaLinux OS 9 audit system must take appropriate action when the audit storage volume is full. |
| ☐ | SV-269527r1050410_rule | AlmaLinux OS 9 must take appropriate action when a critical audit processing failure occurs. |
| ☐ | SV-269528r1050411_rule | AlmaLinux OS 9 audit system must make full use of the audit storage space. |
| ☐ | SV-269529r1050412_rule | AlmaLinux OS 9 audit system must take appropriate action when the audit files have reached maximum size. |
| ☐ | SV-269530r1050413_rule | AlmaLinux OS 9 audit system must retain an optimal number of audit records. |
| ☐ | SV-269531r1050414_rule | AlmaLinux OS 9 must periodically flush audit records to disk to prevent the loss of audit records. |
| ☐ | SV-269532r1050415_rule | The auditd service must be enabled on AlmaLinux OS 9. |
| ☐ | SV-269533r1050416_rule | The chronyd service must be enabled. |
| ☐ | SV-269534r1050417_rule | AlmaLinux OS 9 must have the chrony package installed. |
| ☐ | SV-269535r1050418_rule | AlmaLinux OS 9 must securely compare internal information system clocks at least every 24 hours. |
| ☐ | SV-269536r1050419_rule | AlmaLinux OS 9 audit log directory must be owned by root to prevent unauthorized read access. |
| ☐ | SV-269537r1050420_rule | AlmaLinux OS 9 audit log directory must have 0700 permissions to prevent unauthorized read access. |
| ☐ | SV-269538r1050421_rule | AlmaLinux OS 9 audit logs must be owned by the root group to prevent unauthorized read access. |
| ☐ | SV-269539r1050422_rule | AlmaLinux OS 9 audit logs must be owned by root to prevent unauthorized read access. |
| ☐ | SV-269540r1050423_rule | AlmaLinux OS 9 audit logs must have 0600 permissions to prevent unauthorized read access. |
| ☐ | SV-269541r1050424_rule | AlmaLinux OS 9 audit tools must be group-owned by root. |
| ☐ | SV-269542r1050425_rule | AlmaLinux OS 9 audit tools must be owned by root. |
| ☐ | SV-269543r1050426_rule | AlmaLinux OS 9 audit tools must have a mode of 0755 or less permissive. |
| ☐ | SV-269544r1050427_rule | AlmaLinux OS 9 audit system must protect logon UIDs from unauthorized change. |
| ☐ | SV-269545r1050428_rule | AlmaLinux OS 9 must use cryptographic mechanisms to protect the integrity of audit tools. |
| ☐ | SV-269546r1050429_rule | AlmaLinux OS 9 audit system must protect auditing rules from unauthorized change. |
| ☐ | SV-272485r1155265_rule | AlmaLinux OS 9 must have the postfix package installed. |
| ☐ | SV-274874r1101856_rule | AlmaLinux OS 9 must audit any script or executable called by cron as root or by any privileged user. |
| ☐ | SV-283453r1188503_rule | AlmaLinux 9 cryptographic policy must not be overridden. |
| ☐ | SV-283454r1188506_rule | AlmaLinux OS 9 must have the crypto-policies package installed. |
| ☐ | SV-283455r1188509_rule | AlmaLinux OS 9 must implement a FIPS 140-3-compliant systemwide cryptographic policy. |
| ☐ | SV-283456r1188512_rule | AlmaLinux OS 9 must implement DOD-approved encryption in the bind package. |
| ☐ | SV-283675r1193286_rule | AlmaLinux OS 9 must implement DOD-approved encryption ciphers to protect the confidentiality of SSH connections. |
| ☐ | SV-283676r1193289_rule | AlmaLinux OS 9 must implement DOD-approved encryption in the OpenSSL package. |