| Checked | Name | Title |
|---|
| ☐ | SV-280094r1184607_rule | RHEL 10 must disable the debug-shell systemd service. |
| ☐ | SV-280931r1197213_rule | RHEL 10 must ensure cryptographic verification of vendor software packages. |
| ☐ | SV-280932r1197215_rule | RHEL 10 must check the GNU Privacy Guard (GPG) signature of software packages originating from external software repositories before installation. |
| ☐ | SV-280933r1197217_rule | RHEL 10 must check the GNU Privacy Guard (GPG) signature of locally installed software packages before installation. |
| ☐ | SV-280934r1165157_rule | RHEL 10 must have GNU Privacy Guard (GPG) signature verification enabled for all software repositories. |
| ☐ | SV-280935r1184775_rule | RHEL 10 must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information on local disk partitions that requires at-rest protection. |
| ☐ | SV-280936r1184726_rule | RHEL 10 must use a separate file system for the system audit data path. |
| ☐ | SV-280937r1184727_rule | RHEL 10 must use a separate file system for user home directories (such as "/home" or an equivalent). |
| ☐ | SV-280938r1184728_rule | RHEL 10 must use a separate file system for "/tmp". |
| ☐ | SV-280939r1184729_rule | RHEL 10 must use a separate file system for "/var". |
| ☐ | SV-280940r1184730_rule | RHEL 10 must use a separate file system for "/var/log". |
| ☐ | SV-280941r1184731_rule | RHEL 10 must use a separate file system for "/var/tmp". |
| ☐ | SV-280942r1165181_rule | RHEL 10 must remove all software components after updated versions have been installed. |
| ☐ | SV-280943r1165184_rule | RHEL 10 must not have the "nfs-utils" package installed. |
| ☐ | SV-280944r1184749_rule | RHEL 10 must not have the "telnet-server" package installed. |
| ☐ | SV-280945r1184750_rule | RHEL 10 must not have the "gssproxy" package installed. |
| ☐ | SV-280946r1184751_rule | RHEL 10 must not have the tuned package installed. |
| ☐ | SV-280947r1165196_rule | RHEL 10 must not have a Trivial File Transfer Protocol (TFTP) server package installed unless it is required by the mission, and if required, the TFTP daemon must be configured to operate in secure mode. |
| ☐ | SV-280948r1197218_rule | RHEL 10 must not have the unbound package installed. |
| ☐ | SV-280949r1195338_rule | RHEL 10 must not have the "tftp" package installed. |
| ☐ | SV-280950r1165205_rule | RHEL 10 must not have the "gdm" package installed. |
| ☐ | SV-280951r1184744_rule | RHEL 10 must not have a File Transfer Protocol (FTP) server package installed. |
| ☐ | SV-280952r1195340_rule | RHEL 10 must have the "subscription-manager" package installed. |
| ☐ | SV-280953r1195342_rule | RHEL 10 must have the "nss-tools" package installed. |
| ☐ | SV-280954r1195344_rule | RHEL 10 must have the "s-nail" package installed. |
| ☐ | SV-280955r1208792_rule | RHEL 10 must have the "firewalld" package installed. |
| ☐ | SV-280956r1165223_rule | RHEL 10 must have the "firewalld" service set to active. |
| ☐ | SV-280957r1165226_rule | RHEL 10 must employ a deny-all, allow-by-exception policy for allowing connections to other systems. |
| ☐ | SV-280958r1195348_rule | RHEL 10 must have the "chrony" package installed. |
| ☐ | SV-280959r1165232_rule | RHEL 10 must enable the chronyd service. |
| ☐ | SV-280960r1165235_rule | RHEL 10 must disable the chrony daemon from acting as a server. |
| ☐ | SV-280961r1165238_rule | RHEL 10 must disable network management of the chrony daemon. |
| ☐ | SV-280962r1195350_rule | RHEL 10 must have the USBGuard package installed. |
| ☐ | SV-280963r1165244_rule | RHEL 10 must have the USBGuard package enabled. |
| ☐ | SV-280964r1165247_rule | RHEL 10 must block unauthorized peripherals before establishing a connection. |
| ☐ | SV-280965r1165250_rule | RHEL 10 must enable audit logging for the USBGuard daemon. |
| ☐ | SV-280966r1195352_rule | RHEL 10 must have the "policycoreutils" package installed. |
| ☐ | SV-280967r1195354_rule | RHEL 10 must have the "policycoreutils-python-utils" package installed. |
| ☐ | SV-280968r1195356_rule | RHEL 10 must have the "sudo" package installed. |
| ☐ | SV-280969r1195358_rule | RHEL 10 must have the "fapolicy" module installed. |
| ☐ | SV-280970r1165265_rule | RHEL 10 must enable the "fapolicy" module. |
| ☐ | SV-280971r1184780_rule | RHEL 10 must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs. |
| ☐ | SV-280972r1195360_rule | RHEL 10 must have the "pcsc-lite" package installed. |
| ☐ | SV-280973r1208793_rule | RHEL 10 must have the "pcscd" socket set to active. |
| ☐ | SV-280974r1195362_rule | RHEL 10 must have the "pcsc-lite-ccid" package installed. |
| ☐ | SV-280975r1195364_rule | RHEL 10 must have the "opensc" package installed. |
| ☐ | SV-280976r1165283_rule | RHEL 10 must use the common access card (CAC) smart card driver. |
| ☐ | SV-280977r1195366_rule | RHEL 10 must have the Advanced Intrusion Detection Environment (AIDE) package installed. |
| ☐ | SV-280978r1165289_rule | RHEL 10 must use cryptographic mechanisms to protect the integrity of audit tools. |
| ☐ | SV-280979r1165292_rule | RHEL 10 must use a file integrity tool that is configured to use FIPS 140-3-approved cryptographic hashes for validating file contents and directories. |
| ☐ | SV-280980r1165295_rule | RHEL 10 must routinely check the baseline configuration for unauthorized changes and notify the system administrator when anomalies in the operation of any security functions are discovered. |
| ☐ | SV-280981r1165298_rule | RHEL 10 must be configured so that the file integrity tool verifies Access Control Lists (ACLs). |
| ☐ | SV-280982r1165301_rule | RHEL 10 must be configured so that the file integrity tool verifies extended attributes. |
| ☐ | SV-280983r1195368_rule | RHEL 10 must have the "rsyslog" package installed. |
| ☐ | SV-280984r1165307_rule | RHEL 10 must have the rsyslog service set to active. |
| ☐ | SV-280985r1197221_rule | RHEL 10 must be configured to forward audit records via Transmission Control Protocol (TCP) to a different system or media from the system being audited via rsyslog. |
| ☐ | SV-280986r1184782_rule | RHEL 10 must be configured so that the rsyslog daemon does not accept log messages from other servers unless the server is being used for log aggregation. |
| ☐ | SV-280987r1195371_rule | RHEL 10 must authenticate the remote logging server for off-loading audit logs via "rsyslog". |
| ☐ | SV-280988r1195374_rule | RHEL 10 must encrypt the transfer of audit records off-loaded onto a different system or media from the system being audited via rsyslog. |
| ☐ | SV-280989r1197222_rule | RHEL 10 must encrypt, via the gtls driver, the transfer of audit records off-loaded onto a different system or media from the system being audited via rsyslog. |
| ☐ | SV-280990r1165325_rule | RHEL 10 must monitor all remote access methods. |
| ☐ | SV-280991r1165328_rule | RHEL 10 must use cron logging. |
| ☐ | SV-280992r1195379_rule | RHEL 10 must have the packages required for encrypting off-loaded audit logs installed. |
| ☐ | SV-280993r1195381_rule | RHEL 10 must have the "audit" package installed. |
| ☐ | SV-280994r1165337_rule | RHEL 10 must enable the audit service. |
| ☐ | SV-280995r1195383_rule | RHEL 10 must have the "audispd-plugins" package installed. |
| ☐ | SV-280996r1195385_rule | RHEL 10 must have the "libreswan" package installed. |
| ☐ | SV-280997r1195387_rule | RHEL 10 must notify designated personnel if baseline configurations are changed in an unauthorized manner. |
| ☐ | SV-280998r1208794_rule | RHEL 10 must have mail aliases to notify the information system security officer (ISSO) and system administrator (SA) (at a minimum) of an audit processing failure. |
| ☐ | SV-280999r1165352_rule | RHEL 10 must be configured to prevent unrestricted mail relaying. |
| ☐ | SV-281000r1195389_rule | RHEL 10 must have the "cronie" package installed. |
| ☐ | SV-281001r1195391_rule | RHEL 10 must have a Secure Shell (SSH) server installed for all networked systems. |
| ☐ | SV-281002r1184641_rule | RHEL 10 must, for all networked systems, have and implement Secure Shell (SSH) to protect the confidentiality and integrity of transmitted and received information. |
| ☐ | SV-281003r1195393_rule | RHEL 10 must have the "openssh-clients" package installed. |
| ☐ | SV-281005r1195395_rule | RHEL 10 must have the "pkcs11-provider" package installed. |
| ☐ | SV-281006r1195397_rule | RHEL 10 must have the "gnutls-utils" package installed. |
| ☐ | SV-281007r1195399_rule | RHEL 10 must have the "crypto-policies" package installed. |
| ☐ | SV-281008r1195401_rule | RHEL 10 must implement a FIPS 140-3-compliant systemwide cryptographic policy. |
| ☐ | SV-281009r1184724_rule | RHEL 10 must enable FIPS mode. |
| ☐ | SV-281010r1184643_rule | RHEL 10 must be configured so that Secure Shell (SSH) clients use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. |
| ☐ | SV-281011r1184644_rule | RHEL 10 must be configured so that Secure Shell (SSH) servers use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections. |
| ☐ | SV-281012r1184645_rule | RHEL 10 must be configured so that Secure Shell (SSH) clients use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. |
| ☐ | SV-281013r1184646_rule | RHEL 10 must be configured so that Secure Shell (SSH) servers use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections. |
| ☐ | SV-281014r1165397_rule | RHEL 10 must use FIPS 140-3-approved cryptographic algorithms for IP tunnels. |
| ☐ | SV-281015r1184783_rule | RHEL 10 must implement DOD-approved encryption in the bind package. |
| ☐ | SV-281016r1165403_rule | RHEL 10 cryptographic policy must not be overridden. |
| ☐ | SV-281017r1165406_rule | RHEL 10 must be configured so that the "/etc/group" file is owned by root. |
| ☐ | SV-281018r1165409_rule | RHEL 10 must be configured so that the "/etc/group" file is group-owned by "root". |
| ☐ | SV-281019r1165412_rule | RHEL 10 must be configured so that the "/etc/group-" file is owned by "root". |
| ☐ | SV-281020r1165415_rule | RHEL 10 must be configured so that the "/etc/group-" file is group-owned by "root". |
| ☐ | SV-281021r1165418_rule | RHEL 10 must be configured so that the "/etc/gshadow" file is owned by "root". |
| ☐ | SV-281022r1165421_rule | RHEL 10 must be configured so that the "/etc/gshadow" file is group-owned by "root". |
| ☐ | SV-281023r1165424_rule | RHEL 10 must be configured so that the "/etc/gshadow-" file is owned by "root". |
| ☐ | SV-281024r1165427_rule | RHEL 10 must be configured so that the "/etc/gshadow-" file is group-owned by "root". |
| ☐ | SV-281025r1165430_rule | RHEL 10 must be configured so that the "/etc/passwd" file is owned by "root". |
| ☐ | SV-281026r1165433_rule | RHEL 10 must be configured so that the "/etc/passwd" file is group-owned by "root". |
| ☐ | SV-281027r1165436_rule | RHEL 10 must be configured so that the "/etc/passwd-" file is owned by "root". |
| ☐ | SV-281028r1165439_rule | RHEL 10 must be configured so that the "/etc/passwd-" file is group-owned by "root". |
| ☐ | SV-281029r1165442_rule | RHEL 10 must be configured so that the "/etc/shadow" file is owned by "root". |
| ☐ | SV-281030r1165445_rule | RHEL 10 must be configured so that the "/etc/shadow" file is group-owned by "root". |
| ☐ | SV-281031r1165448_rule | RHEL 10 must be configured so that the "/etc/shadow-" file is owned by "root". |
| ☐ | SV-281032r1165451_rule | RHEL 10 must be configured so that the "/etc/shadow-" file is group-owned by "root". |
| ☐ | SV-281033r1165454_rule | RHEL 10 must be configured so that the "/var/log" directory is owned by "root". |
| ☐ | SV-281034r1165457_rule | RHEL 10 must be configured so that the "/var/log" directory is group-owned by "root". |
| ☐ | SV-281035r1165460_rule | RHEL 10 must be configured so that the "/var/log/"messages file is owned by root. |
| ☐ | SV-281036r1165463_rule | RHEL 10 must be configured so that the "/var/log/messages" file is group-owned by "root". |
| ☐ | SV-281037r1165466_rule | RHEL 10 must be configured so that system commands are owned by "root". |
| ☐ | SV-281038r1184683_rule | RHEL 10 must be configured so that system commands are group-owned by root or a system account. |
| ☐ | SV-281039r1165472_rule | RHEL 10 must be configured so that library files are owned by "root". |
| ☐ | SV-281040r1184734_rule | RHEL 10 must be configured so that library files are group-owned by "root" or a system account. |
| ☐ | SV-281041r1165478_rule | RHEL 10 must be configured so that library directories are owned by "root". |
| ☐ | SV-281042r1184676_rule | RHEL 10 must be configured so that library directories are group-owned by "root" or a system account. |
| ☐ | SV-281043r1184617_rule | RHEL 10 must be configured so that cron configuration file directories are owned by root. |
| ☐ | SV-281044r1184618_rule | RHEL 10 must be configured so that cron configuration files directories are group-owned by root. |
| ☐ | SV-281045r1165490_rule | RHEL 10 must be configured so that world-writable directories are owned by root, sys, bin, or an application user. |
| ☐ | SV-281046r1165493_rule | RHEL 10 must be configured so that all system device files are correctly labeled to prevent unauthorized modification. |
| ☐ | SV-281047r1184647_rule | RHEL 10 must be configured so that the Secure Shell (SSH) server configuration file is group-owned by "root". |
| ☐ | SV-281048r1184648_rule | RHEL 10 must be configured so that the Secure Shell (SSH) server configuration file is owned by "root". |
| ☐ | SV-281049r1197223_rule | RHEL 10 must ensure that all local interactive user home directories are group-owned by the home directory owner's primary group. |
| ☐ | SV-281050r1184685_rule | RHEL 10 must enforce group ownership of audit logs by "root" or by a restricted logging group to prevent unauthorized read access. |
| ☐ | SV-281051r1165508_rule | RHEL 10 must enforce "root" ownership of the audit log directory to prevent unauthorized read access. |
| ☐ | SV-281052r1165511_rule | RHEL 10 must enforce "root" ownership of audit logs to prevent unauthorized access. |
| ☐ | SV-281053r1165514_rule | RHEL 10 must enforce group ownership by "root" or a restricted logging group for audit log files to prevent unauthorized access. |
| ☐ | SV-281054r1197224_rule | RHEL 10 must set mode "0600" or less permissive for the audit logs file to prevent unauthorized access to the audit log. |
| ☐ | SV-281055r1165520_rule | RHEL 10 must enforce the audit log directory to have a mode of "0750" or less permissive to prevent unauthorized read access. |
| ☐ | SV-281056r1165523_rule | RHEL 10 must enforce root ownership of the "/etc/audit/" directory. |
| ☐ | SV-281057r1165526_rule | RHEL 10 must enforce root group ownership of the "/etc/audit/" directory. |
| ☐ | SV-281058r1165529_rule | RHEL 10 must enforce mode "755" or less permissive for system commands. |
| ☐ | SV-281059r1165532_rule | RHEL 10 must enforce mode "755" or less permissive on library directories. |
| ☐ | SV-281060r1165535_rule | RHEL 10 must enforce mode "755" or less permissive for library files. |
| ☐ | SV-281061r1165538_rule | RHEL 10 must enforce mode "0755" or less permissive for the "/var/log" directory. |
| ☐ | SV-281062r1165541_rule | RHEL 10 must enforce mode "0640" or less permissive for the "/var/log/messages" file. |
| ☐ | SV-281063r1195403_rule | RHEL 10 must be configured to prohibit modification of permissions for cron configuration files and directories from the operating system defaults. |
| ☐ | SV-281064r1165547_rule | RHEL 10 must enforce mode "0740" or less permissive for local initialization files. |
| ☐ | SV-281065r1165550_rule | RHEL 10 must enforce mode "0750" or less permissive for local interactive user home directories. |
| ☐ | SV-281066r1165553_rule | RHEL 10 must enforce mode "0644" or less permissive for the "/etc/group" file to prevent unauthorized access. |
| ☐ | SV-281067r1165556_rule | RHEL 10 must enforce mode "0644" or less permissive for the "/etc/group-" file to prevent unauthorized access. |
| ☐ | SV-281068r1165559_rule | RHEL 10 must enforce mode "0000" or less permissive for the "/etc/gshadow" file to prevent unauthorized access. |
| ☐ | SV-281069r1165562_rule | RHEL 10 must enforce mode "0000" or less permissive for the "/etc/gshadow-" file to prevent unauthorized access. |
| ☐ | SV-281070r1165565_rule | RHEL 10 must enforce mode "0644" or less permissive for the "/etc/passwd" file to prevent unauthorized access. |
| ☐ | SV-281071r1165568_rule | RHEL 10 must enforce mode "0644" or less permissive for "/etc/passwd-" file to prevent unauthorized access. |
| ☐ | SV-281072r1165571_rule | RHEL 10 must enforce mode "0000" or less permissive for "/etc/shadow-" file to prevent unauthorized access. |
| ☐ | SV-281073r1165574_rule | RHEL 10 must be configured so that a sticky bit is set on all public directories. |
| ☐ | SV-281074r1165577_rule | RHEL 10 must be configured so that all local files and directories have a valid group owner. |
| ☐ | SV-281075r1165580_rule | RHEL 10 must be configured so that all local files and directories must have a valid owner. |
| ☐ | SV-281076r1165583_rule | RHEL 10 must enforce mode "0000" for "/etc/shadow" to prevent unauthorized access. |
| ☐ | SV-281077r1165586_rule | RHEL 10 must be configured so that audit tools are owned by "root". |
| ☐ | SV-281078r1165589_rule | RHEL 10 must be configured so that audit tools are group-owned by "root". |
| ☐ | SV-281079r1165592_rule | RHEL 10 must set the umask value to "077" for all local interactive user accounts. |
| ☐ | SV-281080r1184687_rule | RHEL 10 must define default permissions for the bash shell. |
| ☐ | SV-281081r1184682_rule | RHEL 10 must define default permissions for the c shell. |
| ☐ | SV-281082r1195406_rule | RHEL 10 must define default permissions for all authenticated users in such a way that the user can read and modify only their own files. |
| ☐ | SV-281083r1184689_rule | RHEL 10 must define default permissions for the system default profile. |
| ☐ | SV-281084r1165607_rule | RHEL 10 must enforce that all local initialization files configured by systemd-tmpfiles have mode "0600" or less permissive. |
| ☐ | SV-281085r1195409_rule | RHEL 10 must enforce mode "0600" or less permissive for Secure Shell (SSH) private host key files. |
| ☐ | SV-281086r1165613_rule | RHEL 10 must enforce "root" group ownership of the "/boot/grub2/grub.cfg" file. |
| ☐ | SV-281087r1165616_rule | RHEL 10 must enforce "root" ownership of the "/boot/grub2/grub.cfg" file. |
| ☐ | SV-281088r1165619_rule | RHEL 10 must prevent device files from being interpreted on file systems that contain user home directories. |
| ☐ | SV-281089r1165622_rule | RHEL 10 must prevent files with the "setuid" and "setgid" bit set from being executed on file systems that contain user home directories. |
| ☐ | SV-281090r1165625_rule | RHEL 10 must prevent code from being executed on file systems that contain user home directories. |
| ☐ | SV-281091r1165628_rule | RHEL 10 must mount "/var/log/audit" with the "nodev" option. |
| ☐ | SV-281092r1165631_rule | RHEL 10 must mount "/var/log/audit" with the "noexec" option. |
| ☐ | SV-281093r1165634_rule | RHEL 10 must mount "/var/log/audit" with the "nosuid" option. |
| ☐ | SV-281094r1165637_rule | RHEL 10 must enforce a mode of "0755" or less permissive for audit tools. |
| ☐ | SV-281095r1184678_rule | RHEL 10 must prohibit local initialization files from executing world-writable programs. |
| ☐ | SV-281096r1165643_rule | RHEL 10 must enable the systemd-journald service. |
| ☐ | SV-281097r1165646_rule | RHEL 10 must enable auditing of processes that start prior to the audit daemon. |
| ☐ | SV-281098r1165649_rule | RHEL 10 must audit local events. |
| ☐ | SV-281099r1165652_rule | RHEL 10 must write audit records to disk. |
| ☐ | SV-281100r1165655_rule | RHEL 10 must log username information when unsuccessful login attempts occur. |
| ☐ | SV-281101r1195411_rule | RHEL 10 must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited. |
| ☐ | SV-281102r1195414_rule | RHEL 10 must allocate an "audit_backlog_limit" of sufficient size to capture processes that start prior to the audit daemon. |
| ☐ | SV-281103r1166261_rule | RHEL 10 must take appropriate action when a critical audit processing failure occurs. |
| ☐ | SV-281104r1208795_rule | RHEL 10 must take action when allocated audit record storage volume reaches 75 percent of the audit record storage capacity. |
| ☐ | SV-281105r1166267_rule | RHEL 10 must label all off-loaded audit logs before sending them to the central log server. |
| ☐ | SV-281106r1166270_rule | RHEL 10 must allocate audit record storage capacity to store at least one week's worth of audit records. |
| ☐ | SV-281107r1166273_rule | RHEL 10 must take action when allocated audit record storage volume reaches 95 percent of the audit record storage capacity. |
| ☐ | SV-281108r1166276_rule | RHEL 10 must take action when allocated audit record storage volume reaches 95 percent of the repository maximum audit record storage capacity. |
| ☐ | SV-281109r1184691_rule | RHEL 10 must take appropriate action when the internal event queue is full. |
| ☐ | SV-281110r1166282_rule | RHEL 10 must produce audit records containing information to establish the identity of any individual or process associated with the event. |
| ☐ | SV-281111r1166285_rule | RHEL 10 must periodically flush audit records to disk to ensure that audit records are not lost. |
| ☐ | SV-281113r1184746_rule | RHEL 10 must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume 75 percent utilization. |
| ☐ | SV-281114r1166294_rule | RHEL 10 must notify the system administrator (SA) and/or information system security officer (ISSO) (at a minimum) of an audit processing failure. |
| ☐ | SV-281115r1184650_rule | RHEL 10 must log Secure Shell (SSH) connection attempts and failures to the server. |
| ☐ | SV-281116r1166300_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "execve" system call. |
| ☐ | SV-281117r1184680_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "setxattr", "fsetxattr", "lsetxattr", "removexattr", "fremovexattr", and "lremovexattr" system calls. |
| ☐ | SV-281118r1166306_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of "umount" system calls. |
| ☐ | SV-281119r1166309_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "chacl" command. |
| ☐ | SV-281120r1166312_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "setfacl" command. |
| ☐ | SV-281121r1166315_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "chcon" command. |
| ☐ | SV-281122r1166318_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "semanage" command. |
| ☐ | SV-281123r1166321_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "setfiles" command. |
| ☐ | SV-281124r1166324_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "setsebool" command. |
| ☐ | SV-281125r1197225_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "truncate", "ftruncate", "creat", "open", "openat", and "open_by_handle_at" system calls. |
| ☐ | SV-281126r1166330_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "delete_module" system call. |
| ☐ | SV-281127r1208796_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "init_module" and "finit_module" system calls. |
| ☐ | SV-281128r1166336_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "chage" command. |
| ☐ | SV-281129r1166339_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "chsh" command. |
| ☐ | SV-281130r1166342_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "crontab" command. |
| ☐ | SV-281131r1166345_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "gpasswd" command. |
| ☐ | SV-281132r1166348_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "kmod" command. |
| ☐ | SV-281133r1166351_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "newgrp" command. |
| ☐ | SV-281134r1166354_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "pam_timestamp_check" command. |
| ☐ | SV-281135r1184693_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "passwd" command. |
| ☐ | SV-281136r1166360_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "postdrop" command. |
| ☐ | SV-281137r1197226_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "postqueue" command. |
| ☐ | SV-281138r1197227_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the ssh-agent command. |
| ☐ | SV-281139r1197228_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "ssh-keysign" command. |
| ☐ | SV-281140r1197229_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "su" command. |
| ☐ | SV-281141r1197230_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "sudo" command. |
| ☐ | SV-281142r1197231_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "sudoedit" command. |
| ☐ | SV-281143r1197232_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "unix_chkpwd" command. |
| ☐ | SV-281144r1166384_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "unix_update" command. |
| ☐ | SV-281145r1197233_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "userhelper" command. |
| ☐ | SV-281146r1197235_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "usermod" command. |
| ☐ | SV-281147r1166393_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "mount" command. |
| ☐ | SV-281148r1166396_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "init" command. |
| ☐ | SV-281149r1166399_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "poweroff" command. |
| ☐ | SV-281150r1166402_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "reboot" command. |
| ☐ | SV-281151r1166405_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the shutdown command. |
| ☐ | SV-281152r1166408_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "umount" system call. |
| ☐ | SV-281153r1166411_rule | RHEL 10 must generate audit records for successful and unsuccessful uses of the "umount2" system call. |
| ☐ | SV-281154r1166414_rule | RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/sudoers". |
| ☐ | SV-281155r1197236_rule | RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect the "/etc/sudoers.d/" directory. |
| ☐ | SV-281156r1166420_rule | RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/group". |
| ☐ | SV-281157r1166423_rule | RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/gshadow". |
| ☐ | SV-281158r1166426_rule | RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/opasswd". |
| ☐ | SV-281159r1166429_rule | RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/passwd". |
| ☐ | SV-281160r1184695_rule | RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/shadow". |
| ☐ | SV-281161r1166435_rule | RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/var/log/faillock". |
| ☐ | SV-281162r1166438_rule | RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/var/log/lastlog". |
| ☐ | SV-281163r1166441_rule | RHEL 10 must generate audit records for all uses of the "chmod", "fchmod", "fchmodat", and "fchmodat2" syscalls. |
| ☐ | SV-281164r1166444_rule | RHEL 10 must generate audit records for all uses of the "chown", "fchown", "fchownat", and "lchown" syscalls. |
| ☐ | SV-281165r1166447_rule | RHEL 10 must generate audit records for all uses of the "rename", "unlink", "rmdir", "renameat", "renameat2", and "unlinkat" system calls. |
| ☐ | SV-281166r1166450_rule | RHEL 10 must require a boot loader superuser password. |
| ☐ | SV-281167r1166453_rule | RHEL 10 must require a unique superusers name upon booting into single-user and maintenance modes. |
| ☐ | SV-281168r1195416_rule | RHEL 10 must not assign an interactive login shell for system accounts. |
| ☐ | SV-281169r1166459_rule | RHEL 10 must, for new users or password changes, have a 60-day maximum password lifetime restriction for user account passwords in "/etc/login.defs". |
| ☐ | SV-281170r1184651_rule | RHEL 10 must, for user account passwords, have a 60-day maximum password lifetime restriction. |
| ☐ | SV-281171r1166465_rule | RHEL 10 must assign a home directory for local interactive user accounts upon creation. |
| ☐ | SV-281172r1166468_rule | RHEL 10 must not allow duplicate user IDs (UIDs) to exist for interactive users. |
| ☐ | SV-281173r1166471_rule | RHEL 10 must automatically expire temporary accounts within 72 hours. |
| ☐ | SV-281174r1166474_rule | RHEL 10 must assign a primary group to all interactive users. |
| ☐ | SV-281175r1197238_rule | RHEL 10 must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity. |
| ☐ | SV-281176r1166480_rule | RHEL 10 must be configured so that all local interactive user initialization file executable search path statements do not contain statements that will reference a working directory other than user home directories. |
| ☐ | SV-281177r1184748_rule | RHEL 10 must assign a home directory to all local interactive users in the "/etc/passwd" file. |
| ☐ | SV-281178r1195418_rule | RHEL 10 must ensure that all local interactive user home directories defined in the "/etc/passwd" file must exist. |
| ☐ | SV-281179r1166489_rule | RHEL 10 must enforce a delay of at least four seconds between login prompts following a failed login attempt. |
| ☐ | SV-281180r1166492_rule | RHEL 10 must enforce a 24-hours minimum password lifetime restriction for passwords for new users or password changes in "/etc/login.defs". |
| ☐ | SV-281181r1195421_rule | RHEL 10 must enforce that passwords be created with a minimum of 15 characters. |
| ☐ | SV-281182r1195424_rule | RHEL 10 must enforce password complexity by requiring at least one special character to be used. |
| ☐ | SV-281183r1195427_rule | RHEL 10 must enforce password complexity by requiring that at least one lowercase character be used. |
| ☐ | SV-281184r1197239_rule | RHEL 10 must enforce password complexity by requiring that at least one uppercase character be used. |
| ☐ | SV-281185r1195433_rule | RHEL 10 must require the change of at least eight characters when passwords are changed. |
| ☐ | SV-281186r1184622_rule | RHEL 10 must enforce that passwords have a 24 hours/1 day minimum lifetime restriction in "/etc/shadow". |
| ☐ | SV-281187r1195436_rule | RHEL 10 must require the maximum number of repeating characters of the same character class to be limited to four when passwords are changed. |
| ☐ | SV-281188r1195439_rule | RHEL 10 must require that the maximum number of repeating characters be limited to three when passwords are changed. |
| ☐ | SV-281189r1195442_rule | RHEL 10 must require the change of at least four character classes when passwords are changed. |
| ☐ | SV-281190r1195445_rule | RHEL 10 must enforce password complexity by requiring that at least one numeric character be used. |
| ☐ | SV-281191r1195448_rule | RHEL 10 must prevent the use of dictionary words for passwords. |
| ☐ | SV-281192r1166528_rule | RHEL 10 must allow only the root account to have unrestricted access to the system. |
| ☐ | SV-281193r1166531_rule | RHEL 10 must enforce password complexity rules for the "root" account. |
| ☐ | SV-281194r1166534_rule | RHEL 10 must automatically lock an account when three unsuccessful login attempts occur. |
| ☐ | SV-281195r1166537_rule | RHEL 10 must automatically lock the root account until the root account is released by an administrator when three unsuccessful login attempts occur during a 15-minute time period. |
| ☐ | SV-281196r1166540_rule | RHEL 10 must automatically lock an account when three unsuccessful login attempts occur during a 15-minute time period. |
| ☐ | SV-281197r1166543_rule | RHEL 10 must maintain an account lock until the locked account is released by an administrator. |
| ☐ | SV-281198r1166546_rule | RHEL 10 must ensure account lockouts persist. |
| ☐ | SV-281199r1166549_rule | RHEL 10 must not have unauthorized accounts. |
| ☐ | SV-281200r1166552_rule | RHEL 10 must not allow blank or null passwords. |
| ☐ | SV-281201r1166555_rule | RHEL 10 must not have accounts configured with blank or null passwords. |
| ☐ | SV-281202r1166558_rule | RHEL 10 must have a unique group ID (GID) for each group in "/etc/group". |
| ☐ | SV-281203r1166561_rule | RHEL 10 must limit the number of concurrent sessions to 10 for all accounts and/or account types. |
| ☐ | SV-281204r1197240_rule | RHEL 10 must ensure the password complexity module in the system-auth file is configured for three or fewer retries. |
| ☐ | SV-281205r1166567_rule | RHEL 10 must restrict the use of the "su" command. |
| ☐ | SV-281206r1166570_rule | RHEL 10 must be configured to not bypass password requirements for privilege escalation. |
| ☐ | SV-281207r1166573_rule | RHEL 10 must restrict privilege elevation to authorized personnel. |
| ☐ | SV-281208r1166576_rule | RHEL 10 must require users to reauthenticate for privilege escalation. |
| ☐ | SV-281209r1166579_rule | RHEL 10 must require reauthentication when using the "sudo" command. |
| ☐ | SV-281210r1166582_rule | RHEL 10 must use the invoking user's password for privilege escalation when using "sudo". |
| ☐ | SV-281211r1166585_rule | RHEL 10 must require users to provide a password for privilege escalation. |
| ☐ | SV-281212r1166588_rule | RHEL 10 must configure the use of the pam_faillock.so module in the "/etc/pam.d/system-auth" file. |
| ☐ | SV-281213r1166591_rule | RHEL 10 must configure the use of the pam_faillock.so module in the "/etc/pam.d/password-auth" file. |
| ☐ | SV-281214r1166594_rule | RHEL 10 must ensure the password complexity module is enabled in the "password-auth" file. |
| ☐ | SV-281215r1166597_rule | RHEL 10 must ensure the password complexity module is enabled in the "system-auth" file. |
| ☐ | SV-281216r1166600_rule | RHEL 10 must enable the Pluggable Authentication Module (PAM) interface for SSHD. |
| ☐ | SV-281217r1195450_rule | RHEL 10 must ensure that the pam_unix.so module is configured in the password-auth file to use a FIPS 140-3-approved cryptographic hashing algorithm for system authentication. |
| ☐ | SV-281218r1166606_rule | RHEL 10 must be configured to use a sufficient number of hashing rounds for the shadow password suite. |
| ☐ | SV-281219r1166609_rule | RHEL 10 must be configured to use a FIPS 140-3-approved cryptographic hashing algorithm for system authentication by ensuring that the pam_unix.so module is configured in the "system-auth" file. |
| ☐ | SV-281220r1166612_rule | RHEL 10 must be configured so that password-auth uses a sufficient number of hashing rounds. |
| ☐ | SV-281221r1208797_rule | RHEL 10 must employ FIPS 140-3-approved cryptographic hashing algorithms for all stored passwords. |
| ☐ | SV-281222r1184626_rule | RHEL 10 must be configured to use the shadow file to store only encrypted representations of passwords. |
| ☐ | SV-281223r1208798_rule | RHEL 10 must be configured so that user and group account administration utilities are configured to store only encrypted representations of passwords. |
| ☐ | SV-281224r1184753_rule | RHEL 10 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a Secure Shell (SSH) login. |
| ☐ | SV-281225r1166627_rule | RHEL 10 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a graphical user login. |
| ☐ | SV-281226r1166630_rule | RHEL 10 must prevent a user from overriding the banner-message-enable setting for the graphical user interface. |
| ☐ | SV-281227r1184627_rule | RHEL 10 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a command line user login. |
| ☐ | SV-281228r1166636_rule | RHEL 10 must prevent special devices on file systems that are imported via Network File System (NFS). |
| ☐ | SV-281229r1166639_rule | RHEL 10 must prevent code from being executed on file systems that are imported via Network File System (NFS). |
| ☐ | SV-281230r1166642_rule | RHEL 10 must prevent files with the "setuid" and "setgid" bit set from being executed on file systems that are imported via Network File System (NFS). |
| ☐ | SV-281231r1166645_rule | RHEL 10 must be configured so that the Network File System (NFS) is configured to use RPCSEC_GSS. |
| ☐ | SV-281232r1166648_rule | RHEL 10 must mount "/boot" with the "nodev" option. |
| ☐ | SV-281233r1166651_rule | RHEL 10 must prevent files with the "setuid" and "setgid" bit set from being executed on the "/boot" directory. |
| ☐ | SV-281234r1166654_rule | RHEL 10 must prevent files with the "setuid" and "setgid" bit set from being executed on the "/boot/efi" directory. |
| ☐ | SV-281235r1166657_rule | RHEL 10 must mount "/dev/shm" with the "nodev" option. |
| ☐ | SV-281236r1166660_rule | RHEL 10 must mount "/dev/shm" with the "noexec" option. |
| ☐ | SV-281237r1166663_rule | RHEL 10 must mount "/dev/shm" with the "nosuid" option. |
| ☐ | SV-281238r1166666_rule | RHEL 10 must mount "/tmp" with the "nodev" option. |
| ☐ | SV-281239r1166669_rule | RHEL 10 must mount "/tmp" with the "noexec" option. |
| ☐ | SV-281240r1166672_rule | RHEL 10 must mount "/tmp" with the "nosuid" option. |
| ☐ | SV-281241r1166675_rule | RHEL 10 must mount "/var" with the "nodev" option. |
| ☐ | SV-281242r1166678_rule | RHEL 10 must mount "/var/log" with the "nodev" option. |
| ☐ | SV-281243r1166681_rule | RHEL 10 must mount "/var/log" with the "noexec" option. |
| ☐ | SV-281244r1166684_rule | RHEL 10 must mount "/var/log" with the "nosuid" option. |
| ☐ | SV-281245r1166687_rule | RHEL 10 must mount "/var/tmp" with the "nodev" option. |
| ☐ | SV-281246r1166690_rule | RHEL 10 must mount "/var/tmp" with the "noexec" option. |
| ☐ | SV-281247r1166693_rule | RHEL 10 must mount "/var/tmp" with the "nosuid" option. |
| ☐ | SV-281248r1166696_rule | RHEL 10 must prevent special devices on nonroot local partitions. |
| ☐ | SV-281249r1197242_rule | RHEL 10 must enable the SELinux targeted policy. |
| ☐ | SV-281250r1184704_rule | RHEL 10 must elevate the SELinux context when an administrator calls the sudo command. |
| ☐ | SV-281251r1166705_rule | RHEL 10 must use a Linux Security Module configured to enforce limits on system services. |
| ☐ | SV-281252r1166708_rule | RHEL 10 must configure SELinux context type to allow the use of a nondefault faillock tally directory. |
| ☐ | SV-281253r1184654_rule | RHEL 10 must be configured so that Secure Shell (SSH) public host key files have mode "0644" or less permissive. |
| ☐ | SV-281254r1184754_rule | RHEL 10 must be configured so that the Secure Shell (SSH) daemon does not allow Generic Security Service Application Program Interface (GSSAPI) authentication. |
| ☐ | SV-281255r1184755_rule | RHEL 10 must be configured so that the Secure Shell (SSH) daemon does not allow Kerberos authentication. |
| ☐ | SV-281256r1184756_rule | RHEL 10 must be configured so that the Secure Shell (SSH) daemon does not allow rhosts authentication. |
| ☐ | SV-281257r1184757_rule | RHEL 10 must be configured so that the Secure Shell (SSH) daemon does not allow known hosts authentication. |
| ☐ | SV-281258r1184758_rule | RHEL 10 must be configured so that the Secure Shell (SSH) daemon disables remote X connections for interactive users. |
| ☐ | SV-281259r1184759_rule | RHEL 10 must be configured so that the Secure Shell (SSH) daemon performs strict mode checking of home directory configuration files. |
| ☐ | SV-281260r1184760_rule | RHEL 10 must be configured so that the Secure Shell (SSH) daemon displays the date and time of the last successful account login upon an SSH login. |
| ☐ | SV-281261r1184761_rule | RHEL 10 must be configured so that the Secure Shell (SSH) daemon prevents remote hosts from connecting to the proxy display. |
| ☐ | SV-281262r1184762_rule | RHEL 10 must be configured so that Secure Shell (SSH) server configuration files' permissions are not modified. |
| ☐ | SV-281263r1184763_rule | RHEL 10 must be configured so that SSHD accepts public key authentication. |
| ☐ | SV-281264r1184764_rule | RHEL 10 must be configured so that SSHD does not allow blank passwords. |
| ☐ | SV-281265r1184765_rule | RHEL 10 must not permit direct logins to the root account using remote access via Secure Shell (SSH). |
| ☐ | SV-281266r1184766_rule | RHEL 10 must not allow a noncertificate trusted host Secure Shell (SSH) login to the system. |
| ☐ | SV-281267r1184767_rule | RHEL 10 must not allow users to override Secure Shell (SSH) environment variables. |
| ☐ | SV-281268r1184768_rule | RHEL 10 must force a frequent session key renegotiation for Secure Shell (SSH) connections to the server. |
| ☐ | SV-281269r1184769_rule | RHEL 10 must be configured so that all network connections associated with Secure Shell (SSH) traffic terminate after becoming unresponsive. |
| ☐ | SV-281270r1166762_rule | RHEL 10 must forward mail from postmaster to the root account using a postfix alias. |
| ☐ | SV-281271r1197244_rule | RHEL 10 must not have a "shosts.equiv" file on the system. |
| ☐ | SV-281272r1166768_rule | RHEL 10 must not have any ".shosts" files on the system. |
| ☐ | SV-281273r1184699_rule | RHEL 10 must prevent a user from overriding the disabling of the graphical user interface automount function. |
| ☐ | SV-281274r1197245_rule | RHEL 10 must prevent a user from overriding the disabling of the graphical user interface autorun function. |
| ☐ | SV-281275r1166777_rule | RHEL 10 must not allow unattended or automatic login via the graphical user interface. |
| ☐ | SV-281276r1166780_rule | RHEL 10 must prevent a user from overriding the disabling of the graphical user smart card removal action. |
| ☐ | SV-281277r1166783_rule | RHEL 10 must prevent a user from overriding the screensaver lock-enabled setting for the graphical user interface. |
| ☐ | SV-281278r1208799_rule | RHEL 10 must automatically lock graphical user sessions after 10 minutes of inactivity. |
| ☐ | SV-281279r1166789_rule | RHEL 10 must prevent a user from overriding the session idle-delay setting for the graphical user interface. |
| ☐ | SV-281280r1166792_rule | RHEL 10 must initiate a session lock for graphical user interfaces when the screensaver is activated. |
| ☐ | SV-281281r1166795_rule | RHEL 10 must prevent a user from overriding the session lock-delay setting for the graphical user interface. |
| ☐ | SV-281282r1166798_rule | RHEL 10 must conceal, via the session lock, information previously visible on the display with a publicly viewable image. |
| ☐ | SV-281283r1166801_rule | RHEL 10 must ensure effective dconf policy matches the policy keyfiles. |
| ☐ | SV-281284r1197247_rule | RHEL 10 must prevent a user from overriding the disable-restart-buttons setting for the graphical user interface. |
| ☐ | SV-281285r1197249_rule | RHEL 10 must prevent a user from overriding the Ctrl-Alt-Del sequence settings for the graphical user interface. |
| ☐ | SV-281286r1166810_rule | RHEL 10 must disable the ability of a user to accidentally press Ctrl-Alt-Del and cause a system to shut down or reboot. |
| ☐ | SV-281287r1166813_rule | RHEL 10 must disable the user list at login for graphical user interfaces. |
| ☐ | SV-281288r1166816_rule | RHEL 10 must be configured to disable USB mass storage. |
| ☐ | SV-281289r1166819_rule | RHEL 10 must disable Bluetooth. |
| ☐ | SV-281290r1166822_rule | RHEL 10 must disable wireless network adapters. |
| ☐ | SV-281291r1166825_rule | RHEL 10 must disable the graphical user interface automounter unless required. |
| ☐ | SV-281292r1166828_rule | RHEL 10 must disable the graphical user interface autorunner unless required. |
| ☐ | SV-281293r1166831_rule | RHEL 10 must implement nonexecutable data to protect its memory from unauthorized code execution. |
| ☐ | SV-281295r1208800_rule | RHEL 10 must automatically exit interactive command shell user sessions after 15 minutes of inactivity. |
| ☐ | SV-281296r1184670_rule | RHEL 10 must be configured with a timeout interval for the Secure Shell (SSH) daemon. |
| ☐ | SV-281297r1166843_rule | RHEL 10 must not default to the graphical display manager unless approved. |
| ☐ | SV-281298r1166846_rule | RHEL 10 must disable the systemd Ctrl-Alt-Delete burst key sequence. |
| ☐ | SV-281299r1166849_rule | RHEL 10 must disable the x86 Ctrl-Alt-Delete key sequence. |
| ☐ | SV-281300r1167050_rule | RHEL 10 must disable the ability of systemd to spawn an interactive boot process. |
| ☐ | SV-281301r1184700_rule | RHEL 10 must disable virtual system calls. |
| ☐ | SV-281302r1167056_rule | RHEL 10 must clear the page allocator to prevent use-after-free attacks. |
| ☐ | SV-281303r1167059_rule | RHEL 10 must clear memory when it is freed to prevent use-after-free attacks. |
| ☐ | SV-281304r1167062_rule | RHEL 10 must enable mitigations against processor-based vulnerabilities. |
| ☐ | SV-281305r1167065_rule | RHEL 10 must restrict access to the kernel message buffer. |
| ☐ | SV-281306r1167068_rule | RHEL 10 must prevent kernel profiling by nonprivileged users. |
| ☐ | SV-281307r1184629_rule | RHEL 10 must prevent the loading of a new kernel for later execution. |
| ☐ | SV-281308r1167074_rule | RHEL 10 must restrict exposed kernel pointer address access. |
| ☐ | SV-281309r1184631_rule | RHEL 10 must enable kernel parameters to enforce discretionary access control (DAC) on hardlinks. |
| ☐ | SV-281310r1167080_rule | RHEL 10 must enable kernel parameters to enforce discretionary access control (DAC) on symlinks. |
| ☐ | SV-281311r1167083_rule | RHEL 10 must disable the "kernel.core_pattern". |
| ☐ | SV-281312r1167086_rule | RHEL 10 must be configured to disable the Controller Area Network (CAN) kernel module. |
| ☐ | SV-281313r1184770_rule | RHEL 10 must disable the Stream Control Transmission Protocol (SCTP) kernel module. |
| ☐ | SV-281314r1184771_rule | RHEL 10 must disable the Transparent Inter Process Communication (TIPC) kernel module. |
| ☐ | SV-281315r1208802_rule | RHEL 10 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution. |
| ☐ | SV-281316r1167098_rule | RHEL 10 must restrict usage of ptrace to descendant processes. |
| ☐ | SV-281317r1167101_rule | RHEL 10 must disable core dump backtraces. |
| ☐ | SV-281318r1167104_rule | RHEL 10 must disable storing core dumps. |
| ☐ | SV-281319r1184633_rule | RHEL 10 must disable core dumps for all users. |
| ☐ | SV-281320r1184635_rule | RHEL 10 must disable acquiring, saving, and processing core dumps. |
| ☐ | SV-281321r1167113_rule | RHEL 10 must implement nonexecutable data to protect its memory from unauthorized code execution. |
| ☐ | SV-281322r1167116_rule | RHEL 10 must disable the kdump service. |
| ☐ | SV-281323r1167119_rule | RHEL 10 must disable file system automount function unless required. |
| ☐ | SV-281324r1167122_rule | RHEL 10 must enable certificate-based smart card authentication. |
| ☐ | SV-281325r1184772_rule | RHEL 10 must implement certificate status checking for multifactor authentication. |
| ☐ | SV-281326r1184637_rule | RHEL 10 must, for PKI-based authentication, enforce authorized access to the corresponding private key. |
| ☐ | SV-281327r1167131_rule | RHEL 10 must require authentication to access emergency mode. |
| ☐ | SV-281328r1167134_rule | RHEL 10 must require authentication to access single-user mode. |
| ☐ | SV-281329r1195452_rule | RHEL 10 must, for PKI-based authentication, validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor. |
| ☐ | SV-281330r1167140_rule | RHEL 10 must map the authenticated identity to the user or group account for public key infrastructure (PKI)-based authentication. |
| ☐ | SV-281331r1167143_rule | RHEL 10 must prohibit the use of cached authenticators after one day. |
| ☐ | SV-281332r1167146_rule | RHEL 10 must control remote access methods. |
| ☐ | SV-281333r1167149_rule | RHEL 10 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments. |
| ☐ | SV-281334r1167152_rule | RHEL 10 must enforce that network interfaces not be in promiscuous mode. |
| ☐ | SV-281335r1167155_rule | RHEL 10 must disable access to the network bpf system call from nonprivileged processes. |
| ☐ | SV-281336r1167158_rule | RHEL 10 must securely compare internal information system clocks at least every 24 hours. |
| ☐ | SV-281337r1167161_rule | RHEL 10 must enable hardening for the Berkeley Packet Filter (BPF) just-in-time compiler. |
| ☐ | SV-281338r1167164_rule | RHEL 10 must have at least two name servers configured for systems using Domain Name Server (DNS) resolution. |
| ☐ | SV-281339r1167167_rule | RHEL 10 must not have unauthorized IP tunnels configured. |
| ☐ | SV-281340r1167170_rule | RHEL 10 must be configured to use Transmission Control Protocol (TCP) syncookies. |
| ☐ | SV-281341r1167173_rule | RHEL 10 must ignore Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages. |
| ☐ | SV-281342r1167176_rule | RHEL 10 must not forward Internet Protocol version 4 (IPv4) source-routed packets. |
| ☐ | SV-281343r1167179_rule | RHEL 10 must log Internet Protocol version 4 (IPv4) packets with impossible addresses. |
| ☐ | SV-281344r1167182_rule | RHEL 10 must log Internet Protocol version 4 (IPv4) packets with impossible addresses by default. |
| ☐ | SV-281345r1167185_rule | RHEL 10 must use reverse path filtering on all Internet Protocol version 4 (IPv4) interfaces. |
| ☐ | SV-281346r1197251_rule | RHEL 10 must prevent Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages from being accepted. |
| ☐ | SV-281347r1167191_rule | RHEL 10 must not forward Internet Protocol version 4 (IPv4) source-routed packets by default. |
| ☐ | SV-281348r1167194_rule | RHEL 10 must use a reverse-path filter for Internet Protocol version 4 (IPv4) network traffic when possible by default. |
| ☐ | SV-281349r1167197_rule | RHEL 10 must not respond to Internet Control Message Protocol (ICMP) echoes sent to a broadcast address. |
| ☐ | SV-281350r1167200_rule | RHEL 10 must limit the number of bogus Internet Control Message Protocol (ICMP) response errors logs. |
| ☐ | SV-281351r1184698_rule | RHEL 10 must not send Internet Control Message Protocol (ICMP) redirects. |
| ☐ | SV-281352r1184706_rule | RHEL 10 must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default. |
| ☐ | SV-281353r1167209_rule | RHEL 10 must not enable Internet Protocol version 4 (IPv4) packet forwarding unless the system is a router. |
| ☐ | SV-281354r1167212_rule | RHEL 10 must not accept router advertisements on all Internet Protocol version 6 (IPv6) interfaces. |
| ☐ | SV-281355r1167215_rule | RHEL 10 must ignore IPv6 Internet Control Message Protocol (ICMP) redirect messages. |
| ☐ | SV-281356r1167218_rule | RHEL 10 must not forward Internet Protocol version 6 (IPv6) source-routed packets. |
| ☐ | SV-281357r1167221_rule | RHEL 10 must not enable Internet Protocol version 6 (IPv6) packet forwarding unless the system is a router. |
| ☐ | SV-281358r1167224_rule | RHEL 10 must not accept router advertisements on all Internet Protocol version 6 (IPv6) interfaces by default. |
| ☐ | SV-281359r1167227_rule | RHEL 10 must prevent Internet Protocol version 6 (IPv6) Internet Control Message Protocol (ICMP) redirect messages from being accepted. |
| ☐ | SV-281360r1167230_rule | RHEL 10 must not forward Internet Protocol version 6 (IPv6) source-routed packets by default. |
| ☐ | SV-281361r1167233_rule | RHEL 10 must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring that rate-limiting measures on impacted network interfaces are implemented. |
| ☐ | SV-281362r1167236_rule | RHEL 10 must configure a DNS processing mode in Network Manager to avoid conflicts with other Domain Name Server (DNS) managers and to not leak DNS queries to untrusted networks. |
| ☐ | SV-281363r1195454_rule | RHEL 10 must be configured to operate in secure mode if the Trivial File Transfer Protocol (TFTP) server service is required. |
| ☐ | SV-281364r1167242_rule | RHEL 10 must enforce mode "0640" or less for the "/etc/audit/auditd.conf" file to prevent unauthorized access. |
| ☐ | SV-281365r1167245_rule | RHEL 10 must prevent unauthorized changes to the audit system. |
| ☐ | SV-282965r1197252_rule | RHEL 10 must be a vendor-supported release. |