STIGQter STIGQter: STIG Summary:

Red Hat Enterprise Linux 10 Security Technical Implementation Guide

Version: 1

Release: 2 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-280094r1184607_ruleRHEL 10 must disable the debug-shell systemd service.
SV-280931r1197213_ruleRHEL 10 must ensure cryptographic verification of vendor software packages.
SV-280932r1197215_ruleRHEL 10 must check the GNU Privacy Guard (GPG) signature of software packages originating from external software repositories before installation.
SV-280933r1197217_ruleRHEL 10 must check the GNU Privacy Guard (GPG) signature of locally installed software packages before installation.
SV-280934r1165157_ruleRHEL 10 must have GNU Privacy Guard (GPG) signature verification enabled for all software repositories.
SV-280935r1184775_ruleRHEL 10 must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information on local disk partitions that requires at-rest protection.
SV-280936r1184726_ruleRHEL 10 must use a separate file system for the system audit data path.
SV-280937r1184727_ruleRHEL 10 must use a separate file system for user home directories (such as "/home" or an equivalent).
SV-280938r1184728_ruleRHEL 10 must use a separate file system for "/tmp".
SV-280939r1184729_ruleRHEL 10 must use a separate file system for "/var".
SV-280940r1184730_ruleRHEL 10 must use a separate file system for "/var/log".
SV-280941r1184731_ruleRHEL 10 must use a separate file system for "/var/tmp".
SV-280942r1165181_ruleRHEL 10 must remove all software components after updated versions have been installed.
SV-280943r1165184_ruleRHEL 10 must not have the "nfs-utils" package installed.
SV-280944r1184749_ruleRHEL 10 must not have the "telnet-server" package installed.
SV-280945r1184750_ruleRHEL 10 must not have the "gssproxy" package installed.
SV-280946r1184751_ruleRHEL 10 must not have the tuned package installed.
SV-280947r1165196_ruleRHEL 10 must not have a Trivial File Transfer Protocol (TFTP) server package installed unless it is required by the mission, and if required, the TFTP daemon must be configured to operate in secure mode.
SV-280948r1197218_ruleRHEL 10 must not have the unbound package installed.
SV-280949r1195338_ruleRHEL 10 must not have the "tftp" package installed.
SV-280950r1165205_ruleRHEL 10 must not have the "gdm" package installed.
SV-280951r1184744_ruleRHEL 10 must not have a File Transfer Protocol (FTP) server package installed.
SV-280952r1195340_ruleRHEL 10 must have the "subscription-manager" package installed.
SV-280953r1195342_ruleRHEL 10 must have the "nss-tools" package installed.
SV-280954r1195344_ruleRHEL 10 must have the "s-nail" package installed.
SV-280955r1208792_ruleRHEL 10 must have the "firewalld" package installed.
SV-280956r1165223_ruleRHEL 10 must have the "firewalld" service set to active.
SV-280957r1165226_ruleRHEL 10 must employ a deny-all, allow-by-exception policy for allowing connections to other systems.
SV-280958r1195348_ruleRHEL 10 must have the "chrony" package installed.
SV-280959r1165232_ruleRHEL 10 must enable the chronyd service.
SV-280960r1165235_ruleRHEL 10 must disable the chrony daemon from acting as a server.
SV-280961r1165238_ruleRHEL 10 must disable network management of the chrony daemon.
SV-280962r1195350_ruleRHEL 10 must have the USBGuard package installed.
SV-280963r1165244_ruleRHEL 10 must have the USBGuard package enabled.
SV-280964r1165247_ruleRHEL 10 must block unauthorized peripherals before establishing a connection.
SV-280965r1165250_ruleRHEL 10 must enable audit logging for the USBGuard daemon.
SV-280966r1195352_ruleRHEL 10 must have the "policycoreutils" package installed.
SV-280967r1195354_ruleRHEL 10 must have the "policycoreutils-python-utils" package installed.
SV-280968r1195356_ruleRHEL 10 must have the "sudo" package installed.
SV-280969r1195358_ruleRHEL 10 must have the "fapolicy" module installed.
SV-280970r1165265_ruleRHEL 10 must enable the "fapolicy" module.
SV-280971r1184780_ruleRHEL 10 must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
SV-280972r1195360_ruleRHEL 10 must have the "pcsc-lite" package installed.
SV-280973r1208793_ruleRHEL 10 must have the "pcscd" socket set to active.
SV-280974r1195362_ruleRHEL 10 must have the "pcsc-lite-ccid" package installed.
SV-280975r1195364_ruleRHEL 10 must have the "opensc" package installed.
SV-280976r1165283_ruleRHEL 10 must use the common access card (CAC) smart card driver.
SV-280977r1195366_ruleRHEL 10 must have the Advanced Intrusion Detection Environment (AIDE) package installed.
SV-280978r1165289_ruleRHEL 10 must use cryptographic mechanisms to protect the integrity of audit tools.
SV-280979r1165292_ruleRHEL 10 must use a file integrity tool that is configured to use FIPS 140-3-approved cryptographic hashes for validating file contents and directories.
SV-280980r1165295_ruleRHEL 10 must routinely check the baseline configuration for unauthorized changes and notify the system administrator when anomalies in the operation of any security functions are discovered.
SV-280981r1165298_ruleRHEL 10 must be configured so that the file integrity tool verifies Access Control Lists (ACLs).
SV-280982r1165301_ruleRHEL 10 must be configured so that the file integrity tool verifies extended attributes.
SV-280983r1195368_ruleRHEL 10 must have the "rsyslog" package installed.
SV-280984r1165307_ruleRHEL 10 must have the rsyslog service set to active.
SV-280985r1197221_ruleRHEL 10 must be configured to forward audit records via Transmission Control Protocol (TCP) to a different system or media from the system being audited via rsyslog.
SV-280986r1184782_ruleRHEL 10 must be configured so that the rsyslog daemon does not accept log messages from other servers unless the server is being used for log aggregation.
SV-280987r1195371_ruleRHEL 10 must authenticate the remote logging server for off-loading audit logs via "rsyslog".
SV-280988r1195374_ruleRHEL 10 must encrypt the transfer of audit records off-loaded onto a different system or media from the system being audited via rsyslog.
SV-280989r1197222_ruleRHEL 10 must encrypt, via the gtls driver, the transfer of audit records off-loaded onto a different system or media from the system being audited via rsyslog.
SV-280990r1165325_ruleRHEL 10 must monitor all remote access methods.
SV-280991r1165328_ruleRHEL 10 must use cron logging.
SV-280992r1195379_ruleRHEL 10 must have the packages required for encrypting off-loaded audit logs installed.
SV-280993r1195381_ruleRHEL 10 must have the "audit" package installed.
SV-280994r1165337_ruleRHEL 10 must enable the audit service.
SV-280995r1195383_ruleRHEL 10 must have the "audispd-plugins" package installed.
SV-280996r1195385_ruleRHEL 10 must have the "libreswan" package installed.
SV-280997r1195387_ruleRHEL 10 must notify designated personnel if baseline configurations are changed in an unauthorized manner.
SV-280998r1208794_ruleRHEL 10 must have mail aliases to notify the information system security officer (ISSO) and system administrator (SA) (at a minimum) of an audit processing failure.
SV-280999r1165352_ruleRHEL 10 must be configured to prevent unrestricted mail relaying.
SV-281000r1195389_ruleRHEL 10 must have the "cronie" package installed.
SV-281001r1195391_ruleRHEL 10 must have a Secure Shell (SSH) server installed for all networked systems.
SV-281002r1184641_ruleRHEL 10 must, for all networked systems, have and implement Secure Shell (SSH) to protect the confidentiality and integrity of transmitted and received information.
SV-281003r1195393_ruleRHEL 10 must have the "openssh-clients" package installed.
SV-281005r1195395_ruleRHEL 10 must have the "pkcs11-provider" package installed.
SV-281006r1195397_ruleRHEL 10 must have the "gnutls-utils" package installed.
SV-281007r1195399_ruleRHEL 10 must have the "crypto-policies" package installed.
SV-281008r1195401_ruleRHEL 10 must implement a FIPS 140-3-compliant systemwide cryptographic policy.
SV-281009r1184724_ruleRHEL 10 must enable FIPS mode.
SV-281010r1184643_ruleRHEL 10 must be configured so that Secure Shell (SSH) clients use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.
SV-281011r1184644_ruleRHEL 10 must be configured so that Secure Shell (SSH) servers use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.
SV-281012r1184645_ruleRHEL 10 must be configured so that Secure Shell (SSH) clients use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.
SV-281013r1184646_ruleRHEL 10 must be configured so that Secure Shell (SSH) servers use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.
SV-281014r1165397_ruleRHEL 10 must use FIPS 140-3-approved cryptographic algorithms for IP tunnels.
SV-281015r1184783_ruleRHEL 10 must implement DOD-approved encryption in the bind package.
SV-281016r1165403_ruleRHEL 10 cryptographic policy must not be overridden.
SV-281017r1165406_ruleRHEL 10 must be configured so that the "/etc/group" file is owned by root.
SV-281018r1165409_ruleRHEL 10 must be configured so that the "/etc/group" file is group-owned by "root".
SV-281019r1165412_ruleRHEL 10 must be configured so that the "/etc/group-" file is owned by "root".
SV-281020r1165415_ruleRHEL 10 must be configured so that the "/etc/group-" file is group-owned by "root".
SV-281021r1165418_ruleRHEL 10 must be configured so that the "/etc/gshadow" file is owned by "root".
SV-281022r1165421_ruleRHEL 10 must be configured so that the "/etc/gshadow" file is group-owned by "root".
SV-281023r1165424_ruleRHEL 10 must be configured so that the "/etc/gshadow-" file is owned by "root".
SV-281024r1165427_ruleRHEL 10 must be configured so that the "/etc/gshadow-" file is group-owned by "root".
SV-281025r1165430_ruleRHEL 10 must be configured so that the "/etc/passwd" file is owned by "root".
SV-281026r1165433_ruleRHEL 10 must be configured so that the "/etc/passwd" file is group-owned by "root".
SV-281027r1165436_ruleRHEL 10 must be configured so that the "/etc/passwd-" file is owned by "root".
SV-281028r1165439_ruleRHEL 10 must be configured so that the "/etc/passwd-" file is group-owned by "root".
SV-281029r1165442_ruleRHEL 10 must be configured so that the "/etc/shadow" file is owned by "root".
SV-281030r1165445_ruleRHEL 10 must be configured so that the "/etc/shadow" file is group-owned by "root".
SV-281031r1165448_ruleRHEL 10 must be configured so that the "/etc/shadow-" file is owned by "root".
SV-281032r1165451_ruleRHEL 10 must be configured so that the "/etc/shadow-" file is group-owned by "root".
SV-281033r1165454_ruleRHEL 10 must be configured so that the "/var/log" directory is owned by "root".
SV-281034r1165457_ruleRHEL 10 must be configured so that the "/var/log" directory is group-owned by "root".
SV-281035r1165460_ruleRHEL 10 must be configured so that the "/var/log/"messages file is owned by root.
SV-281036r1165463_ruleRHEL 10 must be configured so that the "/var/log/messages" file is group-owned by "root".
SV-281037r1165466_ruleRHEL 10 must be configured so that system commands are owned by "root".
SV-281038r1184683_ruleRHEL 10 must be configured so that system commands are group-owned by root or a system account.
SV-281039r1165472_ruleRHEL 10 must be configured so that library files are owned by "root".
SV-281040r1184734_ruleRHEL 10 must be configured so that library files are group-owned by "root" or a system account.
SV-281041r1165478_ruleRHEL 10 must be configured so that library directories are owned by "root".
SV-281042r1184676_ruleRHEL 10 must be configured so that library directories are group-owned by "root" or a system account.
SV-281043r1184617_ruleRHEL 10 must be configured so that cron configuration file directories are owned by root.
SV-281044r1184618_ruleRHEL 10 must be configured so that cron configuration files directories are group-owned by root.
SV-281045r1165490_ruleRHEL 10 must be configured so that world-writable directories are owned by root, sys, bin, or an application user.
SV-281046r1165493_ruleRHEL 10 must be configured so that all system device files are correctly labeled to prevent unauthorized modification.
SV-281047r1184647_ruleRHEL 10 must be configured so that the Secure Shell (SSH) server configuration file is group-owned by "root".
SV-281048r1184648_ruleRHEL 10 must be configured so that the Secure Shell (SSH) server configuration file is owned by "root".
SV-281049r1197223_ruleRHEL 10 must ensure that all local interactive user home directories are group-owned by the home directory owner's primary group.
SV-281050r1184685_ruleRHEL 10 must enforce group ownership of audit logs by "root" or by a restricted logging group to prevent unauthorized read access.
SV-281051r1165508_ruleRHEL 10 must enforce "root" ownership of the audit log directory to prevent unauthorized read access.
SV-281052r1165511_ruleRHEL 10 must enforce "root" ownership of audit logs to prevent unauthorized access.
SV-281053r1165514_ruleRHEL 10 must enforce group ownership by "root" or a restricted logging group for audit log files to prevent unauthorized access.
SV-281054r1197224_ruleRHEL 10 must set mode "0600" or less permissive for the audit logs file to prevent unauthorized access to the audit log.
SV-281055r1165520_ruleRHEL 10 must enforce the audit log directory to have a mode of "0750" or less permissive to prevent unauthorized read access.
SV-281056r1165523_ruleRHEL 10 must enforce root ownership of the "/etc/audit/" directory.
SV-281057r1165526_ruleRHEL 10 must enforce root group ownership of the "/etc/audit/" directory.
SV-281058r1165529_ruleRHEL 10 must enforce mode "755" or less permissive for system commands.
SV-281059r1165532_ruleRHEL 10 must enforce mode "755" or less permissive on library directories.
SV-281060r1165535_ruleRHEL 10 must enforce mode "755" or less permissive for library files.
SV-281061r1165538_ruleRHEL 10 must enforce mode "0755" or less permissive for the "/var/log" directory.
SV-281062r1165541_ruleRHEL 10 must enforce mode "0640" or less permissive for the "/var/log/messages" file.
SV-281063r1195403_ruleRHEL 10 must be configured to prohibit modification of permissions for cron configuration files and directories from the operating system defaults.
SV-281064r1165547_ruleRHEL 10 must enforce mode "0740" or less permissive for local initialization files.
SV-281065r1165550_ruleRHEL 10 must enforce mode "0750" or less permissive for local interactive user home directories.
SV-281066r1165553_ruleRHEL 10 must enforce mode "0644" or less permissive for the "/etc/group" file to prevent unauthorized access.
SV-281067r1165556_ruleRHEL 10 must enforce mode "0644" or less permissive for the "/etc/group-" file to prevent unauthorized access.
SV-281068r1165559_ruleRHEL 10 must enforce mode "0000" or less permissive for the "/etc/gshadow" file to prevent unauthorized access.
SV-281069r1165562_ruleRHEL 10 must enforce mode "0000" or less permissive for the "/etc/gshadow-" file to prevent unauthorized access.
SV-281070r1165565_ruleRHEL 10 must enforce mode "0644" or less permissive for the "/etc/passwd" file to prevent unauthorized access.
SV-281071r1165568_ruleRHEL 10 must enforce mode "0644" or less permissive for "/etc/passwd-" file to prevent unauthorized access.
SV-281072r1165571_ruleRHEL 10 must enforce mode "0000" or less permissive for "/etc/shadow-" file to prevent unauthorized access.
SV-281073r1165574_ruleRHEL 10 must be configured so that a sticky bit is set on all public directories.
SV-281074r1165577_ruleRHEL 10 must be configured so that all local files and directories have a valid group owner.
SV-281075r1165580_ruleRHEL 10 must be configured so that all local files and directories must have a valid owner.
SV-281076r1165583_ruleRHEL 10 must enforce mode "0000" for "/etc/shadow" to prevent unauthorized access.
SV-281077r1165586_ruleRHEL 10 must be configured so that audit tools are owned by "root".
SV-281078r1165589_ruleRHEL 10 must be configured so that audit tools are group-owned by "root".
SV-281079r1165592_ruleRHEL 10 must set the umask value to "077" for all local interactive user accounts.
SV-281080r1184687_ruleRHEL 10 must define default permissions for the bash shell.
SV-281081r1184682_ruleRHEL 10 must define default permissions for the c shell.
SV-281082r1195406_ruleRHEL 10 must define default permissions for all authenticated users in such a way that the user can read and modify only their own files.
SV-281083r1184689_ruleRHEL 10 must define default permissions for the system default profile.
SV-281084r1165607_ruleRHEL 10 must enforce that all local initialization files configured by systemd-tmpfiles have mode "0600" or less permissive.
SV-281085r1195409_ruleRHEL 10 must enforce mode "0600" or less permissive for Secure Shell (SSH) private host key files.
SV-281086r1165613_ruleRHEL 10 must enforce "root" group ownership of the "/boot/grub2/grub.cfg" file.
SV-281087r1165616_ruleRHEL 10 must enforce "root" ownership of the "/boot/grub2/grub.cfg" file.
SV-281088r1165619_ruleRHEL 10 must prevent device files from being interpreted on file systems that contain user home directories.
SV-281089r1165622_ruleRHEL 10 must prevent files with the "setuid" and "setgid" bit set from being executed on file systems that contain user home directories.
SV-281090r1165625_ruleRHEL 10 must prevent code from being executed on file systems that contain user home directories.
SV-281091r1165628_ruleRHEL 10 must mount "/var/log/audit" with the "nodev" option.
SV-281092r1165631_ruleRHEL 10 must mount "/var/log/audit" with the "noexec" option.
SV-281093r1165634_ruleRHEL 10 must mount "/var/log/audit" with the "nosuid" option.
SV-281094r1165637_ruleRHEL 10 must enforce a mode of "0755" or less permissive for audit tools.
SV-281095r1184678_ruleRHEL 10 must prohibit local initialization files from executing world-writable programs.
SV-281096r1165643_ruleRHEL 10 must enable the systemd-journald service.
SV-281097r1165646_ruleRHEL 10 must enable auditing of processes that start prior to the audit daemon.
SV-281098r1165649_ruleRHEL 10 must audit local events.
SV-281099r1165652_ruleRHEL 10 must write audit records to disk.
SV-281100r1165655_ruleRHEL 10 must log username information when unsuccessful login attempts occur.
SV-281101r1195411_ruleRHEL 10 must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.
SV-281102r1195414_ruleRHEL 10 must allocate an "audit_backlog_limit" of sufficient size to capture processes that start prior to the audit daemon.
SV-281103r1166261_ruleRHEL 10 must take appropriate action when a critical audit processing failure occurs.
SV-281104r1208795_ruleRHEL 10 must take action when allocated audit record storage volume reaches 75 percent of the audit record storage capacity.
SV-281105r1166267_ruleRHEL 10 must label all off-loaded audit logs before sending them to the central log server.
SV-281106r1166270_ruleRHEL 10 must allocate audit record storage capacity to store at least one week's worth of audit records.
SV-281107r1166273_ruleRHEL 10 must take action when allocated audit record storage volume reaches 95 percent of the audit record storage capacity.
SV-281108r1166276_ruleRHEL 10 must take action when allocated audit record storage volume reaches 95 percent of the repository maximum audit record storage capacity.
SV-281109r1184691_ruleRHEL 10 must take appropriate action when the internal event queue is full.
SV-281110r1166282_ruleRHEL 10 must produce audit records containing information to establish the identity of any individual or process associated with the event.
SV-281111r1166285_ruleRHEL 10 must periodically flush audit records to disk to ensure that audit records are not lost.
SV-281113r1184746_ruleRHEL 10 must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume 75 percent utilization.
SV-281114r1166294_ruleRHEL 10 must notify the system administrator (SA) and/or information system security officer (ISSO) (at a minimum) of an audit processing failure.
SV-281115r1184650_ruleRHEL 10 must log Secure Shell (SSH) connection attempts and failures to the server.
SV-281116r1166300_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "execve" system call.
SV-281117r1184680_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "setxattr", "fsetxattr", "lsetxattr", "removexattr", "fremovexattr", and "lremovexattr" system calls.
SV-281118r1166306_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of "umount" system calls.
SV-281119r1166309_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "chacl" command.
SV-281120r1166312_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "setfacl" command.
SV-281121r1166315_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "chcon" command.
SV-281122r1166318_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "semanage" command.
SV-281123r1166321_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "setfiles" command.
SV-281124r1166324_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "setsebool" command.
SV-281125r1197225_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "truncate", "ftruncate", "creat", "open", "openat", and "open_by_handle_at" system calls.
SV-281126r1166330_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "delete_module" system call.
SV-281127r1208796_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "init_module" and "finit_module" system calls.
SV-281128r1166336_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "chage" command.
SV-281129r1166339_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "chsh" command.
SV-281130r1166342_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "crontab" command.
SV-281131r1166345_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "gpasswd" command.
SV-281132r1166348_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "kmod" command.
SV-281133r1166351_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "newgrp" command.
SV-281134r1166354_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "pam_timestamp_check" command.
SV-281135r1184693_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "passwd" command.
SV-281136r1166360_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "postdrop" command.
SV-281137r1197226_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "postqueue" command.
SV-281138r1197227_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the ssh-agent command.
SV-281139r1197228_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "ssh-keysign" command.
SV-281140r1197229_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "su" command.
SV-281141r1197230_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "sudo" command.
SV-281142r1197231_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "sudoedit" command.
SV-281143r1197232_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "unix_chkpwd" command.
SV-281144r1166384_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "unix_update" command.
SV-281145r1197233_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "userhelper" command.
SV-281146r1197235_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "usermod" command.
SV-281147r1166393_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "mount" command.
SV-281148r1166396_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "init" command.
SV-281149r1166399_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "poweroff" command.
SV-281150r1166402_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "reboot" command.
SV-281151r1166405_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the shutdown command.
SV-281152r1166408_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "umount" system call.
SV-281153r1166411_ruleRHEL 10 must generate audit records for successful and unsuccessful uses of the "umount2" system call.
SV-281154r1166414_ruleRHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/sudoers".
SV-281155r1197236_ruleRHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect the "/etc/sudoers.d/" directory.
SV-281156r1166420_ruleRHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/group".
SV-281157r1166423_ruleRHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/gshadow".
SV-281158r1166426_ruleRHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/opasswd".
SV-281159r1166429_ruleRHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/passwd".
SV-281160r1184695_ruleRHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/shadow".
SV-281161r1166435_ruleRHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/var/log/faillock".
SV-281162r1166438_ruleRHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/var/log/lastlog".
SV-281163r1166441_ruleRHEL 10 must generate audit records for all uses of the "chmod", "fchmod", "fchmodat", and "fchmodat2" syscalls.
SV-281164r1166444_ruleRHEL 10 must generate audit records for all uses of the "chown", "fchown", "fchownat", and "lchown" syscalls.
SV-281165r1166447_ruleRHEL 10 must generate audit records for all uses of the "rename", "unlink", "rmdir", "renameat", "renameat2", and "unlinkat" system calls.
SV-281166r1166450_ruleRHEL 10 must require a boot loader superuser password.
SV-281167r1166453_ruleRHEL 10 must require a unique superusers name upon booting into single-user and maintenance modes.
SV-281168r1195416_ruleRHEL 10 must not assign an interactive login shell for system accounts.
SV-281169r1166459_ruleRHEL 10 must, for new users or password changes, have a 60-day maximum password lifetime restriction for user account passwords in "/etc/login.defs".
SV-281170r1184651_ruleRHEL 10 must, for user account passwords, have a 60-day maximum password lifetime restriction.
SV-281171r1166465_ruleRHEL 10 must assign a home directory for local interactive user accounts upon creation.
SV-281172r1166468_ruleRHEL 10 must not allow duplicate user IDs (UIDs) to exist for interactive users.
SV-281173r1166471_ruleRHEL 10 must automatically expire temporary accounts within 72 hours.
SV-281174r1166474_ruleRHEL 10 must assign a primary group to all interactive users.
SV-281175r1197238_ruleRHEL 10 must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.
SV-281176r1166480_ruleRHEL 10 must be configured so that all local interactive user initialization file executable search path statements do not contain statements that will reference a working directory other than user home directories.
SV-281177r1184748_ruleRHEL 10 must assign a home directory to all local interactive users in the "/etc/passwd" file.
SV-281178r1195418_ruleRHEL 10 must ensure that all local interactive user home directories defined in the "/etc/passwd" file must exist.
SV-281179r1166489_ruleRHEL 10 must enforce a delay of at least four seconds between login prompts following a failed login attempt.
SV-281180r1166492_ruleRHEL 10 must enforce a 24-hours minimum password lifetime restriction for passwords for new users or password changes in "/etc/login.defs".
SV-281181r1195421_ruleRHEL 10 must enforce that passwords be created with a minimum of 15 characters.
SV-281182r1195424_ruleRHEL 10 must enforce password complexity by requiring at least one special character to be used.
SV-281183r1195427_ruleRHEL 10 must enforce password complexity by requiring that at least one lowercase character be used.
SV-281184r1197239_ruleRHEL 10 must enforce password complexity by requiring that at least one uppercase character be used.
SV-281185r1195433_ruleRHEL 10 must require the change of at least eight characters when passwords are changed.
SV-281186r1184622_ruleRHEL 10 must enforce that passwords have a 24 hours/1 day minimum lifetime restriction in "/etc/shadow".
SV-281187r1195436_ruleRHEL 10 must require the maximum number of repeating characters of the same character class to be limited to four when passwords are changed.
SV-281188r1195439_ruleRHEL 10 must require that the maximum number of repeating characters be limited to three when passwords are changed.
SV-281189r1195442_ruleRHEL 10 must require the change of at least four character classes when passwords are changed.
SV-281190r1195445_ruleRHEL 10 must enforce password complexity by requiring that at least one numeric character be used.
SV-281191r1195448_ruleRHEL 10 must prevent the use of dictionary words for passwords.
SV-281192r1166528_ruleRHEL 10 must allow only the root account to have unrestricted access to the system.
SV-281193r1166531_ruleRHEL 10 must enforce password complexity rules for the "root" account.
SV-281194r1166534_ruleRHEL 10 must automatically lock an account when three unsuccessful login attempts occur.
SV-281195r1166537_ruleRHEL 10 must automatically lock the root account until the root account is released by an administrator when three unsuccessful login attempts occur during a 15-minute time period.
SV-281196r1166540_ruleRHEL 10 must automatically lock an account when three unsuccessful login attempts occur during a 15-minute time period.
SV-281197r1166543_ruleRHEL 10 must maintain an account lock until the locked account is released by an administrator.
SV-281198r1166546_ruleRHEL 10 must ensure account lockouts persist.
SV-281199r1166549_ruleRHEL 10 must not have unauthorized accounts.
SV-281200r1166552_ruleRHEL 10 must not allow blank or null passwords.
SV-281201r1166555_ruleRHEL 10 must not have accounts configured with blank or null passwords.
SV-281202r1166558_ruleRHEL 10 must have a unique group ID (GID) for each group in "/etc/group".
SV-281203r1166561_ruleRHEL 10 must limit the number of concurrent sessions to 10 for all accounts and/or account types.
SV-281204r1197240_ruleRHEL 10 must ensure the password complexity module in the system-auth file is configured for three or fewer retries.
SV-281205r1166567_ruleRHEL 10 must restrict the use of the "su" command.
SV-281206r1166570_ruleRHEL 10 must be configured to not bypass password requirements for privilege escalation.
SV-281207r1166573_ruleRHEL 10 must restrict privilege elevation to authorized personnel.
SV-281208r1166576_ruleRHEL 10 must require users to reauthenticate for privilege escalation.
SV-281209r1166579_ruleRHEL 10 must require reauthentication when using the "sudo" command.
SV-281210r1166582_ruleRHEL 10 must use the invoking user's password for privilege escalation when using "sudo".
SV-281211r1166585_ruleRHEL 10 must require users to provide a password for privilege escalation.
SV-281212r1166588_ruleRHEL 10 must configure the use of the pam_faillock.so module in the "/etc/pam.d/system-auth" file.
SV-281213r1166591_ruleRHEL 10 must configure the use of the pam_faillock.so module in the "/etc/pam.d/password-auth" file.
SV-281214r1166594_ruleRHEL 10 must ensure the password complexity module is enabled in the "password-auth" file.
SV-281215r1166597_ruleRHEL 10 must ensure the password complexity module is enabled in the "system-auth" file.
SV-281216r1166600_ruleRHEL 10 must enable the Pluggable Authentication Module (PAM) interface for SSHD.
SV-281217r1195450_ruleRHEL 10 must ensure that the pam_unix.so module is configured in the password-auth file to use a FIPS 140-3-approved cryptographic hashing algorithm for system authentication.
SV-281218r1166606_ruleRHEL 10 must be configured to use a sufficient number of hashing rounds for the shadow password suite.
SV-281219r1166609_ruleRHEL 10 must be configured to use a FIPS 140-3-approved cryptographic hashing algorithm for system authentication by ensuring that the pam_unix.so module is configured in the "system-auth" file.
SV-281220r1166612_ruleRHEL 10 must be configured so that password-auth uses a sufficient number of hashing rounds.
SV-281221r1208797_ruleRHEL 10 must employ FIPS 140-3-approved cryptographic hashing algorithms for all stored passwords.
SV-281222r1184626_ruleRHEL 10 must be configured to use the shadow file to store only encrypted representations of passwords.
SV-281223r1208798_ruleRHEL 10 must be configured so that user and group account administration utilities are configured to store only encrypted representations of passwords.
SV-281224r1184753_ruleRHEL 10 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a Secure Shell (SSH) login.
SV-281225r1166627_ruleRHEL 10 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a graphical user login.
SV-281226r1166630_ruleRHEL 10 must prevent a user from overriding the banner-message-enable setting for the graphical user interface.
SV-281227r1184627_ruleRHEL 10 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a command line user login.
SV-281228r1166636_ruleRHEL 10 must prevent special devices on file systems that are imported via Network File System (NFS).
SV-281229r1166639_ruleRHEL 10 must prevent code from being executed on file systems that are imported via Network File System (NFS).
SV-281230r1166642_ruleRHEL 10 must prevent files with the "setuid" and "setgid" bit set from being executed on file systems that are imported via Network File System (NFS).
SV-281231r1166645_ruleRHEL 10 must be configured so that the Network File System (NFS) is configured to use RPCSEC_GSS.
SV-281232r1166648_ruleRHEL 10 must mount "/boot" with the "nodev" option.
SV-281233r1166651_ruleRHEL 10 must prevent files with the "setuid" and "setgid" bit set from being executed on the "/boot" directory.
SV-281234r1166654_ruleRHEL 10 must prevent files with the "setuid" and "setgid" bit set from being executed on the "/boot/efi" directory.
SV-281235r1166657_ruleRHEL 10 must mount "/dev/shm" with the "nodev" option.
SV-281236r1166660_ruleRHEL 10 must mount "/dev/shm" with the "noexec" option.
SV-281237r1166663_ruleRHEL 10 must mount "/dev/shm" with the "nosuid" option.
SV-281238r1166666_ruleRHEL 10 must mount "/tmp" with the "nodev" option.
SV-281239r1166669_ruleRHEL 10 must mount "/tmp" with the "noexec" option.
SV-281240r1166672_ruleRHEL 10 must mount "/tmp" with the "nosuid" option.
SV-281241r1166675_ruleRHEL 10 must mount "/var" with the "nodev" option.
SV-281242r1166678_ruleRHEL 10 must mount "/var/log" with the "nodev" option.
SV-281243r1166681_ruleRHEL 10 must mount "/var/log" with the "noexec" option.
SV-281244r1166684_ruleRHEL 10 must mount "/var/log" with the "nosuid" option.
SV-281245r1166687_ruleRHEL 10 must mount "/var/tmp" with the "nodev" option.
SV-281246r1166690_ruleRHEL 10 must mount "/var/tmp" with the "noexec" option.
SV-281247r1166693_ruleRHEL 10 must mount "/var/tmp" with the "nosuid" option.
SV-281248r1166696_ruleRHEL 10 must prevent special devices on nonroot local partitions.
SV-281249r1197242_ruleRHEL 10 must enable the SELinux targeted policy.
SV-281250r1184704_ruleRHEL 10 must elevate the SELinux context when an administrator calls the sudo command.
SV-281251r1166705_ruleRHEL 10 must use a Linux Security Module configured to enforce limits on system services.
SV-281252r1166708_ruleRHEL 10 must configure SELinux context type to allow the use of a nondefault faillock tally directory.
SV-281253r1184654_ruleRHEL 10 must be configured so that Secure Shell (SSH) public host key files have mode "0644" or less permissive.
SV-281254r1184754_ruleRHEL 10 must be configured so that the Secure Shell (SSH) daemon does not allow Generic Security Service Application Program Interface (GSSAPI) authentication.
SV-281255r1184755_ruleRHEL 10 must be configured so that the Secure Shell (SSH) daemon does not allow Kerberos authentication.
SV-281256r1184756_ruleRHEL 10 must be configured so that the Secure Shell (SSH) daemon does not allow rhosts authentication.
SV-281257r1184757_ruleRHEL 10 must be configured so that the Secure Shell (SSH) daemon does not allow known hosts authentication.
SV-281258r1184758_ruleRHEL 10 must be configured so that the Secure Shell (SSH) daemon disables remote X connections for interactive users.
SV-281259r1184759_ruleRHEL 10 must be configured so that the Secure Shell (SSH) daemon performs strict mode checking of home directory configuration files.
SV-281260r1184760_ruleRHEL 10 must be configured so that the Secure Shell (SSH) daemon displays the date and time of the last successful account login upon an SSH login.
SV-281261r1184761_ruleRHEL 10 must be configured so that the Secure Shell (SSH) daemon prevents remote hosts from connecting to the proxy display.
SV-281262r1184762_ruleRHEL 10 must be configured so that Secure Shell (SSH) server configuration files' permissions are not modified.
SV-281263r1184763_ruleRHEL 10 must be configured so that SSHD accepts public key authentication.
SV-281264r1184764_ruleRHEL 10 must be configured so that SSHD does not allow blank passwords.
SV-281265r1184765_ruleRHEL 10 must not permit direct logins to the root account using remote access via Secure Shell (SSH).
SV-281266r1184766_ruleRHEL 10 must not allow a noncertificate trusted host Secure Shell (SSH) login to the system.
SV-281267r1184767_ruleRHEL 10 must not allow users to override Secure Shell (SSH) environment variables.
SV-281268r1184768_ruleRHEL 10 must force a frequent session key renegotiation for Secure Shell (SSH) connections to the server.
SV-281269r1184769_ruleRHEL 10 must be configured so that all network connections associated with Secure Shell (SSH) traffic terminate after becoming unresponsive.
SV-281270r1166762_ruleRHEL 10 must forward mail from postmaster to the root account using a postfix alias.
SV-281271r1197244_ruleRHEL 10 must not have a "shosts.equiv" file on the system.
SV-281272r1166768_ruleRHEL 10 must not have any ".shosts" files on the system.
SV-281273r1184699_ruleRHEL 10 must prevent a user from overriding the disabling of the graphical user interface automount function.
SV-281274r1197245_ruleRHEL 10 must prevent a user from overriding the disabling of the graphical user interface autorun function.
SV-281275r1166777_ruleRHEL 10 must not allow unattended or automatic login via the graphical user interface.
SV-281276r1166780_ruleRHEL 10 must prevent a user from overriding the disabling of the graphical user smart card removal action.
SV-281277r1166783_ruleRHEL 10 must prevent a user from overriding the screensaver lock-enabled setting for the graphical user interface.
SV-281278r1208799_ruleRHEL 10 must automatically lock graphical user sessions after 10 minutes of inactivity.
SV-281279r1166789_ruleRHEL 10 must prevent a user from overriding the session idle-delay setting for the graphical user interface.
SV-281280r1166792_ruleRHEL 10 must initiate a session lock for graphical user interfaces when the screensaver is activated.
SV-281281r1166795_ruleRHEL 10 must prevent a user from overriding the session lock-delay setting for the graphical user interface.
SV-281282r1166798_ruleRHEL 10 must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
SV-281283r1166801_ruleRHEL 10 must ensure effective dconf policy matches the policy keyfiles.
SV-281284r1197247_ruleRHEL 10 must prevent a user from overriding the disable-restart-buttons setting for the graphical user interface.
SV-281285r1197249_ruleRHEL 10 must prevent a user from overriding the Ctrl-Alt-Del sequence settings for the graphical user interface.
SV-281286r1166810_ruleRHEL 10 must disable the ability of a user to accidentally press Ctrl-Alt-Del and cause a system to shut down or reboot.
SV-281287r1166813_ruleRHEL 10 must disable the user list at login for graphical user interfaces.
SV-281288r1166816_ruleRHEL 10 must be configured to disable USB mass storage.
SV-281289r1166819_ruleRHEL 10 must disable Bluetooth.
SV-281290r1166822_ruleRHEL 10 must disable wireless network adapters.
SV-281291r1166825_ruleRHEL 10 must disable the graphical user interface automounter unless required.
SV-281292r1166828_ruleRHEL 10 must disable the graphical user interface autorunner unless required.
SV-281293r1166831_ruleRHEL 10 must implement nonexecutable data to protect its memory from unauthorized code execution.
SV-281295r1208800_ruleRHEL 10 must automatically exit interactive command shell user sessions after 15 minutes of inactivity.
SV-281296r1184670_ruleRHEL 10 must be configured with a timeout interval for the Secure Shell (SSH) daemon.
SV-281297r1166843_ruleRHEL 10 must not default to the graphical display manager unless approved.
SV-281298r1166846_ruleRHEL 10 must disable the systemd Ctrl-Alt-Delete burst key sequence.
SV-281299r1166849_ruleRHEL 10 must disable the x86 Ctrl-Alt-Delete key sequence.
SV-281300r1167050_ruleRHEL 10 must disable the ability of systemd to spawn an interactive boot process.
SV-281301r1184700_ruleRHEL 10 must disable virtual system calls.
SV-281302r1167056_ruleRHEL 10 must clear the page allocator to prevent use-after-free attacks.
SV-281303r1167059_ruleRHEL 10 must clear memory when it is freed to prevent use-after-free attacks.
SV-281304r1167062_ruleRHEL 10 must enable mitigations against processor-based vulnerabilities.
SV-281305r1167065_ruleRHEL 10 must restrict access to the kernel message buffer.
SV-281306r1167068_ruleRHEL 10 must prevent kernel profiling by nonprivileged users.
SV-281307r1184629_ruleRHEL 10 must prevent the loading of a new kernel for later execution.
SV-281308r1167074_ruleRHEL 10 must restrict exposed kernel pointer address access.
SV-281309r1184631_ruleRHEL 10 must enable kernel parameters to enforce discretionary access control (DAC) on hardlinks.
SV-281310r1167080_ruleRHEL 10 must enable kernel parameters to enforce discretionary access control (DAC) on symlinks.
SV-281311r1167083_ruleRHEL 10 must disable the "kernel.core_pattern".
SV-281312r1167086_ruleRHEL 10 must be configured to disable the Controller Area Network (CAN) kernel module.
SV-281313r1184770_ruleRHEL 10 must disable the Stream Control Transmission Protocol (SCTP) kernel module.
SV-281314r1184771_ruleRHEL 10 must disable the Transparent Inter Process Communication (TIPC) kernel module.
SV-281315r1208802_ruleRHEL 10 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution.
SV-281316r1167098_ruleRHEL 10 must restrict usage of ptrace to descendant processes.
SV-281317r1167101_ruleRHEL 10 must disable core dump backtraces.
SV-281318r1167104_ruleRHEL 10 must disable storing core dumps.
SV-281319r1184633_ruleRHEL 10 must disable core dumps for all users.
SV-281320r1184635_ruleRHEL 10 must disable acquiring, saving, and processing core dumps.
SV-281321r1167113_ruleRHEL 10 must implement nonexecutable data to protect its memory from unauthorized code execution.
SV-281322r1167116_ruleRHEL 10 must disable the kdump service.
SV-281323r1167119_ruleRHEL 10 must disable file system automount function unless required.
SV-281324r1167122_ruleRHEL 10 must enable certificate-based smart card authentication.
SV-281325r1184772_ruleRHEL 10 must implement certificate status checking for multifactor authentication.
SV-281326r1184637_ruleRHEL 10 must, for PKI-based authentication, enforce authorized access to the corresponding private key.
SV-281327r1167131_ruleRHEL 10 must require authentication to access emergency mode.
SV-281328r1167134_ruleRHEL 10 must require authentication to access single-user mode.
SV-281329r1195452_ruleRHEL 10 must, for PKI-based authentication, validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
SV-281330r1167140_ruleRHEL 10 must map the authenticated identity to the user or group account for public key infrastructure (PKI)-based authentication.
SV-281331r1167143_ruleRHEL 10 must prohibit the use of cached authenticators after one day.
SV-281332r1167146_ruleRHEL 10 must control remote access methods.
SV-281333r1167149_ruleRHEL 10 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.
SV-281334r1167152_ruleRHEL 10 must enforce that network interfaces not be in promiscuous mode.
SV-281335r1167155_ruleRHEL 10 must disable access to the network bpf system call from nonprivileged processes.
SV-281336r1167158_ruleRHEL 10 must securely compare internal information system clocks at least every 24 hours.
SV-281337r1167161_ruleRHEL 10 must enable hardening for the Berkeley Packet Filter (BPF) just-in-time compiler.
SV-281338r1167164_ruleRHEL 10 must have at least two name servers configured for systems using Domain Name Server (DNS) resolution.
SV-281339r1167167_ruleRHEL 10 must not have unauthorized IP tunnels configured.
SV-281340r1167170_ruleRHEL 10 must be configured to use Transmission Control Protocol (TCP) syncookies.
SV-281341r1167173_ruleRHEL 10 must ignore Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages.
SV-281342r1167176_ruleRHEL 10 must not forward Internet Protocol version 4 (IPv4) source-routed packets.
SV-281343r1167179_ruleRHEL 10 must log Internet Protocol version 4 (IPv4) packets with impossible addresses.
SV-281344r1167182_ruleRHEL 10 must log Internet Protocol version 4 (IPv4) packets with impossible addresses by default.
SV-281345r1167185_ruleRHEL 10 must use reverse path filtering on all Internet Protocol version 4 (IPv4) interfaces.
SV-281346r1197251_ruleRHEL 10 must prevent Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages from being accepted.
SV-281347r1167191_ruleRHEL 10 must not forward Internet Protocol version 4 (IPv4) source-routed packets by default.
SV-281348r1167194_ruleRHEL 10 must use a reverse-path filter for Internet Protocol version 4 (IPv4) network traffic when possible by default.
SV-281349r1167197_ruleRHEL 10 must not respond to Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.
SV-281350r1167200_ruleRHEL 10 must limit the number of bogus Internet Control Message Protocol (ICMP) response errors logs.
SV-281351r1184698_ruleRHEL 10 must not send Internet Control Message Protocol (ICMP) redirects.
SV-281352r1184706_ruleRHEL 10 must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default.
SV-281353r1167209_ruleRHEL 10 must not enable Internet Protocol version 4 (IPv4) packet forwarding unless the system is a router.
SV-281354r1167212_ruleRHEL 10 must not accept router advertisements on all Internet Protocol version 6 (IPv6) interfaces.
SV-281355r1167215_ruleRHEL 10 must ignore IPv6 Internet Control Message Protocol (ICMP) redirect messages.
SV-281356r1167218_ruleRHEL 10 must not forward Internet Protocol version 6 (IPv6) source-routed packets.
SV-281357r1167221_ruleRHEL 10 must not enable Internet Protocol version 6 (IPv6) packet forwarding unless the system is a router.
SV-281358r1167224_ruleRHEL 10 must not accept router advertisements on all Internet Protocol version 6 (IPv6) interfaces by default.
SV-281359r1167227_ruleRHEL 10 must prevent Internet Protocol version 6 (IPv6) Internet Control Message Protocol (ICMP) redirect messages from being accepted.
SV-281360r1167230_ruleRHEL 10 must not forward Internet Protocol version 6 (IPv6) source-routed packets by default.
SV-281361r1167233_ruleRHEL 10 must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring that rate-limiting measures on impacted network interfaces are implemented.
SV-281362r1167236_ruleRHEL 10 must configure a DNS processing mode in Network Manager to avoid conflicts with other Domain Name Server (DNS) managers and to not leak DNS queries to untrusted networks.
SV-281363r1195454_ruleRHEL 10 must be configured to operate in secure mode if the Trivial File Transfer Protocol (TFTP) server service is required.
SV-281364r1167242_ruleRHEL 10 must enforce mode "0640" or less for the "/etc/audit/auditd.conf" file to prevent unauthorized access.
SV-281365r1167245_ruleRHEL 10 must prevent unauthorized changes to the audit system.
SV-282965r1197252_ruleRHEL 10 must be a vendor-supported release.