| Checked | Name | Title |
|---|
| ☐ | SV-230221r1017040_rule | RHEL 8 must be a vendor-supported release. |
| ☐ | SV-230222r1184233_rule | RHEL 8 vendor packaged system security patches and updates must be installed and up to date. |
| ☐ | SV-230223r1155356_rule | RHEL 8 must implement a FIPS 140-3-compliant systemwide cryptographic policy. |
| ☐ | SV-230224r1044787_rule | All RHEL 8 local disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at rest protection. |
| ☐ | SV-230225r1184236_rule | RHEL 8 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a ssh logon. |
| ☐ | SV-230226r1069298_rule | RHEL 8 must display the Standard Mandatory DoD Notice and Consent Banner before granting local or remote access to the system via a graphical user logon. |
| ☐ | SV-230227r1017046_rule | RHEL 8 must display the Standard Mandatory DoD Notice and Consent Banner before granting local or remote access to the system via a command line user logon. |
| ☐ | SV-230228r1069299_rule | All RHEL 8 remote access methods must be monitored. |
| ☐ | SV-230229r1017048_rule | RHEL 8, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor. |
| ☐ | SV-230230r1069287_rule | RHEL 8, for certificate-based authentication, must enforce authorized access to the corresponding private key. |
| ☐ | SV-230231r1017050_rule | RHEL 8 must encrypt all stored passwords with a FIPS 140-2 approved cryptographic hashing algorithm. |
| ☐ | SV-230232r1208739_rule | RHEL 8 must employ FIPS 140-3-approved cryptographic hashing algorithms for all stored passwords. |
| ☐ | SV-230233r1044790_rule | The RHEL 8 shadow password suite must be configured to use a sufficient number of hashing rounds. |
| ☐ | SV-230234r1137691_rule | RHEL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must require authentication upon booting into single-user mode and maintenance. |
| ☐ | SV-230235r1137691_rule | RHEL 8 operating systems booted with a BIOS must require authentication upon booting into single-user and maintenance modes. |
| ☐ | SV-230236r1137691_rule | RHEL 8 operating systems must require authentication upon booting into rescue mode. |
| ☐ | SV-230237r1017056_rule | The RHEL 8 pam_unix.so module must be configured in the password-auth file to use a FIPS 140-2 approved cryptographic hashing algorithm for system authentication. |
| ☐ | SV-230238r1017057_rule | RHEL 8 must prevent system daemons from using Kerberos for authentication. |
| ☐ | SV-230239r1017058_rule | The krb5-workstation package must not be installed on RHEL 8. |
| ☐ | SV-230240r1017059_rule | RHEL 8 must use a Linux Security Module configured to enforce limits on system services. |
| ☐ | SV-230241r1017060_rule | RHEL 8 must have policycoreutils package installed. |
| ☐ | SV-230243r1137695_rule | A sticky bit must be set on all RHEL 8 public directories to prevent unauthorized and unintended information transferred via shared system resources. |
| ☐ | SV-230244r1069300_rule | RHEL 8 must be configured so that all network connections associated with SSH traffic terminate after becoming unresponsive. |
| ☐ | SV-230245r1017063_rule | The RHEL 8 /var/log/messages file must have mode 0640 or less permissive. |
| ☐ | SV-230246r1017064_rule | The RHEL 8 /var/log/messages file must be owned by root. |
| ☐ | SV-230247r1017065_rule | The RHEL 8 /var/log/messages file must be group-owned by root. |
| ☐ | SV-230248r1069291_rule | The RHEL 8 /var/log directory must have mode 0755 or less permissive. |
| ☐ | SV-230249r1017067_rule | The RHEL 8 /var/log directory must be owned by root. |
| ☐ | SV-230250r1017068_rule | The RHEL 8 /var/log directory must be group-owned by root. |
| ☐ | SV-230251r1184240_rule | The RHEL 8 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections. |
| ☐ | SV-230252r1184241_rule | The RHEL 8 SSH server must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections. |
| ☐ | SV-230253r1044799_rule | RHEL 8 must ensure the SSH server uses strong entropy. |
| ☐ | SV-230257r1017077_rule | RHEL 8 system commands must have mode 755 or less permissive. |
| ☐ | SV-230258r1017078_rule | RHEL 8 system commands must be owned by root. |
| ☐ | SV-230259r1017079_rule | RHEL 8 system commands must be group-owned by root or a system account. |
| ☐ | SV-230260r1101888_rule | RHEL 8 library files must have mode 755 or less permissive. |
| ☐ | SV-230261r1101891_rule | RHEL 8 library files must be owned by root. |
| ☐ | SV-230262r1155384_rule | RHEL 8 library files must be group-owned by root. |
| ☐ | SV-230263r1017083_rule | The RHEL 8 file integrity tool must notify the system administrator when changes to the baseline configuration or anomalies in the operation of any security functions are discovered within an organizationally defined frequency. |
| ☐ | SV-230264r1017377_rule | RHEL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components from a repository without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization. |
| ☐ | SV-230265r1208742_rule | RHEL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components of local packages without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization. |
| ☐ | SV-230266r1184246_rule | RHEL 8 must prevent the loading of a new kernel for later execution. |
| ☐ | SV-230267r1184249_rule | RHEL 8 must enable kernel parameters to enforce discretionary access control on symlinks. |
| ☐ | SV-230268r1184252_rule | RHEL 8 must enable kernel parameters to enforce discretionary access control on hardlinks. |
| ☐ | SV-230269r1184255_rule | RHEL 8 must restrict access to the kernel message buffer. |
| ☐ | SV-230270r1184258_rule | RHEL 8 must prevent kernel profiling by unprivileged users. |
| ☐ | SV-230271r1101896_rule | RHEL 8 must require users to provide a password for privilege escalation. |
| ☐ | SV-230272r1101898_rule | RHEL 8 must require users to reauthenticate for privilege escalation. |
| ☐ | SV-230273r1017381_rule | RHEL 8 must have the packages required for multifactor authentication installed. |
| ☐ | SV-230274r1017089_rule | RHEL 8 must implement certificate status checking for multifactor authentication. |
| ☐ | SV-230275r958816_rule | RHEL 8 must accept Personal Identity Verification (PIV) credentials. |
| ☐ | SV-230276r958928_rule | RHEL 8 must implement non-executable data to protect its memory from unauthorized code execution. |
| ☐ | SV-230277r1017090_rule | RHEL 8 must clear the page allocator to prevent use-after-free attacks. |
| ☐ | SV-230278r1017091_rule | RHEL 8 must disable virtual syscalls. |
| ☐ | SV-230279r1069286_rule | RHEL 8 must clear memory when it is freed to prevent use-after-free attacks. |
| ☐ | SV-230280r1208745_rule | RHEL 8 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution. |
| ☐ | SV-230281r958936_rule | YUM must remove all software components after updated versions have been installed on RHEL 8. |
| ☐ | SV-230282r958944_rule | RHEL 8 must enable the SELinux targeted policy. |
| ☐ | SV-230283r1017094_rule | There must be no shosts.equiv files on the RHEL 8 operating system. |
| ☐ | SV-230284r1017095_rule | There must be no .shosts files on the RHEL 8 operating system. |
| ☐ | SV-230285r1017096_rule | RHEL 8 must enable the hardware random number generator entropy gatherer service. |
| ☐ | SV-230286r1017097_rule | The RHEL 8 SSH public host key files must have mode 0644 or less permissive. |
| ☐ | SV-230287r1208746_rule | The RHEL 8 SSH private host key files must have mode 0600 or less permissive. |
| ☐ | SV-230288r1069301_rule | The RHEL 8 SSH daemon must perform strict mode checking of home directory configuration files. |
| ☐ | SV-230290r1069302_rule | The RHEL 8 SSH daemon must not allow authentication using known host’s authentication. |
| ☐ | SV-230291r1069303_rule | The RHEL 8 SSH daemon must not allow Kerberos authentication, except to fulfill documented and validated mission requirements. |
| ☐ | SV-230292r1017103_rule | RHEL 8 must use a separate file system for /var. |
| ☐ | SV-230293r1017104_rule | RHEL 8 must use a separate file system for /var/log. |
| ☐ | SV-230294r1017105_rule | RHEL 8 must use a separate file system for the system audit data path. |
| ☐ | SV-230295r1017106_rule | A separate RHEL 8 filesystem must be used for the /tmp directory. |
| ☐ | SV-230296r1069322_rule | RHEL 8 must not permit direct logons to the root account using remote access via SSH. |
| ☐ | SV-230298r1017108_rule | The rsyslog service must be running in RHEL 8. |
| ☐ | SV-230299r1017109_rule | RHEL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories. |
| ☐ | SV-230300r1017110_rule | RHEL 8 must prevent files with the setuid and setgid bit set from being executed on the /boot directory. |
| ☐ | SV-230301r1184262_rule | RHEL 8 must prevent special devices on non-root local partitions. |
| ☐ | SV-230302r1017112_rule | RHEL 8 must prevent code from being executed on file systems that contain user home directories. |
| ☐ | SV-230303r1017113_rule | RHEL 8 must prevent special devices on file systems that are used with removable media. |
| ☐ | SV-230304r1017114_rule | RHEL 8 must prevent code from being executed on file systems that are used with removable media. |
| ☐ | SV-230305r1017115_rule | RHEL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that are used with removable media. |
| ☐ | SV-230306r1155386_rule | RHEL 8 must prevent code from being executed on file systems that are imported via Network File System (NFS). |
| ☐ | SV-230307r1155388_rule | RHEL 8 must prevent special devices on file systems that are imported via Network File System (NFS). |
| ☐ | SV-230308r1155390_rule | RHEL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that are imported via Network File System (NFS). |
| ☐ | SV-230310r1155383_rule | RHEL 8 must disable kernel dumps unless needed. |
| ☐ | SV-230311r1155408_rule | RHEL 8 must disable the kernel.core_pattern. |
| ☐ | SV-230312r1134877_rule | RHEL 8 must disable acquiring, saving, and processing core dumps. |
| ☐ | SV-230313r1155379_rule | RHEL 8 must disable core dumps for all users. |
| ☐ | SV-230314r1134881_rule | RHEL 8 must disable storing core dumps. |
| ☐ | SV-230315r1134883_rule | RHEL 8 must disable core dump backtraces. |
| ☐ | SV-230316r1044801_rule | For RHEL 8 systems using Domain Name Servers (DNS) resolution, at least two name servers must be configured. |
| ☐ | SV-230317r1069320_rule | Executable search paths within the initialization files of all local interactive RHEL 8 users must only contain paths that resolve to the system default or the users home directory. |
| ☐ | SV-230318r1155352_rule | All RHEL 8 world-writable directories must be owned by root, sys, bin, or an application user. |
| ☐ | SV-230319r1017130_rule | All RHEL 8 world-writable directories must be group-owned by root, sys, bin, or an application group. |
| ☐ | SV-230320r1017131_rule | All RHEL 8 local interactive users must have a home directory assigned in the /etc/passwd file. |
| ☐ | SV-230321r1017132_rule | All RHEL 8 local interactive user home directories must have mode 0750 or less permissive. |
| ☐ | SV-230322r1017133_rule | All RHEL 8 local interactive user home directories must be group-owned by the home directory owner’s primary group. |
| ☐ | SV-230323r1017134_rule | All RHEL 8 local interactive user home directories defined in the /etc/passwd file must exist. |
| ☐ | SV-230324r1017135_rule | All RHEL 8 local interactive user accounts must be assigned a home directory upon creation. |
| ☐ | SV-230325r1017136_rule | All RHEL 8 local initialization files must have mode 0740 or less permissive. |
| ☐ | SV-230326r1069284_rule | All RHEL 8 local files and directories must have a valid owner. |
| ☐ | SV-230327r1069285_rule | All RHEL 8 local files and directories must have a valid group owner. |
| ☐ | SV-230328r1155410_rule | A separate RHEL 8 filesystem must be used for user home directories (such as /home or an equivalent). |
| ☐ | SV-230329r1017140_rule | Unattended or automatic logon via the RHEL 8 graphical user interface must not be allowed. |
| ☐ | SV-230330r1069305_rule | RHEL 8 must not allow users to override SSH environment variables. |
| ☐ | SV-230332r1184264_rule | RHEL 8 must automatically lock an account when three unsuccessful logon attempts occur. |
| ☐ | SV-230333r1017145_rule | RHEL 8 must automatically lock an account when three unsuccessful logon attempts occur. |
| ☐ | SV-230334r1184266_rule | RHEL 8 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period. |
| ☐ | SV-230335r1017147_rule | RHEL 8 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period. |
| ☐ | SV-230336r1184268_rule | RHEL 8 must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period. |
| ☐ | SV-230337r1134885_rule | RHEL 8 must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period. |
| ☐ | SV-230338r1184270_rule | RHEL 8 must ensure account lockouts persist. |
| ☐ | SV-230339r1017151_rule | RHEL 8 must ensure account lockouts persist. |
| ☐ | SV-230340r1184272_rule | RHEL 8 must prevent system messages from being presented when three unsuccessful logon attempts occur. |
| ☐ | SV-230341r1017153_rule | RHEL 8 must prevent system messages from being presented when three unsuccessful logon attempts occur. |
| ☐ | SV-230342r1184274_rule | RHEL 8 must log user name information when unsuccessful logon attempts occur. |
| ☐ | SV-230343r1017155_rule | RHEL 8 must log user name information when unsuccessful logon attempts occur. |
| ☐ | SV-230344r1184276_rule | RHEL 8 must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period. |
| ☐ | SV-230345r1017157_rule | RHEL 8 must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period. |
| ☐ | SV-230346r1069306_rule | RHEL 8 must limit the number of concurrent sessions to ten for all accounts and/or account types. |
| ☐ | SV-230347r1017160_rule | RHEL 8 must enable a user session lock until that user re-establishes access using established identification and authentication procedures for graphical user sessions. |
| ☐ | SV-230351r1017164_rule | RHEL 8 must be able to initiate directly a session lock for all connection types using smartcard when the smartcard is removed. |
| ☐ | SV-230352r1208749_rule | RHEL 8 must automatically lock graphical user sessions after 10 minutes of inactivity. |
| ☐ | SV-230354r1069323_rule | RHEL 8 must prevent a user from overriding the session lock-delay setting for the graphical user interface. |
| ☐ | SV-230355r1017168_rule | RHEL 8 must map the authenticated identity to the user or group account for PKI-based authentication. |
| ☐ | SV-230356r982195_rule | RHEL 8 must ensure the password complexity module is enabled in the password-auth file. |
| ☐ | SV-230357r1017169_rule | RHEL 8 must enforce password complexity by requiring that at least one uppercase character be used. |
| ☐ | SV-230358r1017170_rule | RHEL 8 must enforce password complexity by requiring that at least one lower-case character be used. |
| ☐ | SV-230359r1017171_rule | RHEL 8 must enforce password complexity by requiring that at least one numeric character be used. |
| ☐ | SV-230360r1017172_rule | RHEL 8 must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed. |
| ☐ | SV-230361r1017173_rule | RHEL 8 must require the maximum number of repeating characters be limited to three when passwords are changed. |
| ☐ | SV-230362r1017174_rule | RHEL 8 must require the change of at least four character classes when passwords are changed. |
| ☐ | SV-230363r1017175_rule | RHEL 8 must require the change of at least 8 characters when passwords are changed. |
| ☐ | SV-230364r1017176_rule | RHEL 8 passwords must have a 24 hours/1 day minimum password lifetime restriction in /etc/shadow. |
| ☐ | SV-230365r1017177_rule | RHEL 8 passwords for new users or password changes must have a 24 hours/1 day minimum password lifetime restriction in /etc/login.defs. |
| ☐ | SV-230366r1038967_rule | RHEL 8 user account passwords must have a 60-day maximum password lifetime restriction. |
| ☐ | SV-230367r1038967_rule | RHEL 8 user account passwords must be configured so that existing passwords are restricted to a 60-day maximum lifetime. |
| ☐ | SV-230369r1017181_rule | RHEL 8 passwords must have a minimum of 15 characters. |
| ☐ | SV-230370r1017182_rule | RHEL 8 passwords for new users must have a minimum of 15 characters. |
| ☐ | SV-230371r1017183_rule | RHEL 8 duplicate User IDs (UIDs) must not exist for interactive users. |
| ☐ | SV-230372r1017184_rule | RHEL 8 must implement smart card logon for multifactor authentication for access to interactive accounts. |
| ☐ | SV-230373r1017185_rule | RHEL 8 account identifiers (individuals, groups, roles, and devices) must be disabled after 35 days of inactivity. |
| ☐ | SV-230374r1069293_rule | RHEL 8 must automatically expire temporary accounts within 72 hours. |
| ☐ | SV-230375r1017187_rule | All RHEL 8 passwords must contain at least one special character. |
| ☐ | SV-230376r1069307_rule | RHEL 8 must prohibit the use of cached authentications after one day. |
| ☐ | SV-230377r1017188_rule | RHEL 8 must prevent the use of dictionary words for passwords. |
| ☐ | SV-230378r1017189_rule | RHEL 8 must enforce a delay of at least four seconds between logon prompts following a failed logon attempt. |
| ☐ | SV-230379r1017190_rule | RHEL 8 must not have unnecessary accounts. |
| ☐ | SV-230380r1069308_rule | RHEL 8 must not allow accounts configured with blank or null passwords. |
| ☐ | SV-230382r1069309_rule | RHEL 8 must display the date and time of the last successful account logon upon an SSH logon. |
| ☐ | SV-230383r1017192_rule | RHEL 8 must define default permissions for all authenticated users in such a way that the user can only read and modify their own files. |
| ☐ | SV-230384r1017193_rule | RHEL 8 must set the umask value to 077 for all local interactive user accounts. |
| ☐ | SV-230385r1017194_rule | RHEL 8 must define default permissions for logon and non-logon shells. |
| ☐ | SV-230386r958730_rule | The RHEL 8 audit system must be configured to audit the execution of privileged functions and prevent all software from executing at higher privilege levels than users executing the software. |
| ☐ | SV-230387r1017195_rule | Cron logging must be implemented in RHEL 8. |
| ☐ | SV-230388r1017196_rule | The RHEL 8 System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) must be alerted of an audit processing failure event. |
| ☐ | SV-230389r1017197_rule | The RHEL 8 Information System Security Officer (ISSO) and System Administrator (SA) (at a minimum) must have mail aliases to be notified of an audit processing failure. |
| ☐ | SV-230390r1038966_rule | The RHEL 8 System must take appropriate action when an audit processing failure occurs. |
| ☐ | SV-230392r1038966_rule | The RHEL 8 audit system must take appropriate action when the audit storage volume is full. |
| ☐ | SV-230393r1017200_rule | The RHEL 8 audit system must audit local events. |
| ☐ | SV-230394r958754_rule | RHEL 8 must label all off-loaded audit logs before sending them to the central log server. |
| ☐ | SV-230395r1017201_rule | RHEL 8 must resolve audit information before writing to disk. |
| ☐ | SV-230396r1017202_rule | RHEL 8 audit logs must have a mode of 0600 or less permissive to prevent unauthorized read access. |
| ☐ | SV-230397r1017203_rule | RHEL 8 audit logs must be owned by root to prevent unauthorized read access. |
| ☐ | SV-230398r1017204_rule | RHEL 8 audit logs must be group-owned by root to prevent unauthorized read access. |
| ☐ | SV-230399r1017205_rule | RHEL 8 audit log directory must be owned by root to prevent unauthorized read access. |
| ☐ | SV-230400r1017206_rule | RHEL 8 audit log directory must be group-owned by root to prevent unauthorized read access. |
| ☐ | SV-230401r1017207_rule | RHEL 8 audit log directory must have a mode of 0700 or less permissive to prevent unauthorized read access. |
| ☐ | SV-230402r1017208_rule | RHEL 8 audit system must protect auditing rules from unauthorized change. |
| ☐ | SV-230403r1017209_rule | RHEL 8 audit system must protect logon UIDs from unauthorized change. |
| ☐ | SV-230404r1017210_rule | RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow. |
| ☐ | SV-230405r1017211_rule | RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd. |
| ☐ | SV-230406r1017212_rule | RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd. |
| ☐ | SV-230407r1017213_rule | RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow. |
| ☐ | SV-230408r1017214_rule | RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group. |
| ☐ | SV-230409r1017215_rule | RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers. |
| ☐ | SV-230410r1017216_rule | RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/. |
| ☐ | SV-230411r1017217_rule | The RHEL 8 audit package must be installed. |
| ☐ | SV-230412r1017218_rule | Successful/unsuccessful uses of the su command in RHEL 8 must generate an audit record. |
| ☐ | SV-230413r1017219_rule | The RHEL 8 audit system must be configured to audit any usage of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls. |
| ☐ | SV-230418r1017220_rule | Successful/unsuccessful uses of the chage command in RHEL 8 must generate an audit record. |
| ☐ | SV-230419r1017221_rule | Successful/unsuccessful uses of the chcon command in RHEL 8 must generate an audit record. |
| ☐ | SV-230421r1017222_rule | Successful/unsuccessful uses of the ssh-agent in RHEL 8 must generate an audit record. |
| ☐ | SV-230422r1017223_rule | Successful/unsuccessful uses of the passwd command in RHEL 8 must generate an audit record. |
| ☐ | SV-230423r1017224_rule | Successful/unsuccessful uses of the mount command in RHEL 8 must generate an audit record. |
| ☐ | SV-230424r1017225_rule | Successful/unsuccessful uses of the umount command in RHEL 8 must generate an audit record. |
| ☐ | SV-230425r1017226_rule | Successful/unsuccessful uses of the mount syscall in RHEL 8 must generate an audit record. |
| ☐ | SV-230426r1017227_rule | Successful/unsuccessful uses of the unix_update in RHEL 8 must generate an audit record. |
| ☐ | SV-230427r1017228_rule | Successful/unsuccessful uses of postdrop in RHEL 8 must generate an audit record. |
| ☐ | SV-230428r1017229_rule | Successful/unsuccessful uses of postqueue in RHEL 8 must generate an audit record. |
| ☐ | SV-230429r1017230_rule | Successful/unsuccessful uses of semanage in RHEL 8 must generate an audit record. |
| ☐ | SV-230430r1017231_rule | Successful/unsuccessful uses of setfiles in RHEL 8 must generate an audit record. |
| ☐ | SV-230431r1017232_rule | Successful/unsuccessful uses of userhelper in RHEL 8 must generate an audit record. |
| ☐ | SV-230432r1017233_rule | Successful/unsuccessful uses of setsebool in RHEL 8 must generate an audit record. |
| ☐ | SV-230433r1017234_rule | Successful/unsuccessful uses of unix_chkpwd in RHEL 8 must generate an audit record. |
| ☐ | SV-230434r1017235_rule | Successful/unsuccessful uses of the ssh-keysign in RHEL 8 must generate an audit record. |
| ☐ | SV-230435r1017236_rule | Successful/unsuccessful uses of the setfacl command in RHEL 8 must generate an audit record. |
| ☐ | SV-230436r1017237_rule | Successful/unsuccessful uses of the pam_timestamp_check command in RHEL 8 must generate an audit record. |
| ☐ | SV-230437r1017238_rule | Successful/unsuccessful uses of the newgrp command in RHEL 8 must generate an audit record. |
| ☐ | SV-230438r1017241_rule | Successful/unsuccessful uses of the init_module and finit_module system calls in RHEL 8 must generate an audit record. |
| ☐ | SV-230439r1017243_rule | Successful/unsuccessful uses of the rename, unlink, rmdir, renameat, and unlinkat system calls in RHEL 8 must generate an audit record. |
| ☐ | SV-230444r1017244_rule | Successful/unsuccessful uses of the gpasswd command in RHEL 8 must generate an audit record. |
| ☐ | SV-230446r1017245_rule | Successful/unsuccessful uses of the delete_module command in RHEL 8 must generate an audit record. |
| ☐ | SV-230447r1017246_rule | Successful/unsuccessful uses of the crontab command in RHEL 8 must generate an audit record. |
| ☐ | SV-230448r1017247_rule | Successful/unsuccessful uses of the chsh command in RHEL 8 must generate an audit record. |
| ☐ | SV-230449r1017249_rule | Successful/unsuccessful uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls in RHEL 8 must generate an audit record. |
| ☐ | SV-230455r1017251_rule | Successful/unsuccessful uses of the chown, fchown, fchownat, and lchown system calls in RHEL 8 must generate an audit record. |
| ☐ | SV-230456r1017253_rule | Successful/unsuccessful uses of the chmod, fchmod, and fchmodat system calls in RHEL 8 must generate an audit record. |
| ☐ | SV-230462r1017254_rule | Successful/unsuccessful uses of the sudo command in RHEL 8 must generate an audit record. |
| ☐ | SV-230463r1017255_rule | Successful/unsuccessful uses of the usermod command in RHEL 8 must generate an audit record. |
| ☐ | SV-230464r1017256_rule | Successful/unsuccessful uses of the chacl command in RHEL 8 must generate an audit record. |
| ☐ | SV-230465r1017257_rule | Successful/unsuccessful uses of the kmod command in RHEL 8 must generate an audit record. |
| ☐ | SV-230466r1017258_rule | Successful/unsuccessful modifications to the faillock log file in RHEL 8 must generate an audit record. |
| ☐ | SV-230467r1017259_rule | Successful/unsuccessful modifications to the lastlog file in RHEL 8 must generate an audit record. |
| ☐ | SV-230468r1017260_rule | RHEL 8 must enable auditing of processes that start prior to the audit daemon. |
| ☐ | SV-230469r958752_rule | RHEL 8 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon. |
| ☐ | SV-230470r1017261_rule | RHEL 8 must enable Linux audit logging for the USBGuard daemon. |
| ☐ | SV-230471r1208750_rule | RHEL 8 must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited. |
| ☐ | SV-230472r1017263_rule | RHEL 8 audit tools must have a mode of 0755 or less permissive. |
| ☐ | SV-230473r1017264_rule | RHEL 8 audit tools must be owned by root. |
| ☐ | SV-230474r1017265_rule | RHEL 8 audit tools must be group-owned by root. |
| ☐ | SV-230475r1017266_rule | RHEL 8 must use cryptographic mechanisms to protect the integrity of audit tools. |
| ☐ | SV-230476r958752_rule | RHEL 8 must allocate audit record storage capacity to store at least one week of audit records, when audit records are not immediately sent to a central audit record storage facility. |
| ☐ | SV-230477r1017267_rule | RHEL 8 must have the packages required for offloading audit logs installed. |
| ☐ | SV-230478r1017268_rule | RHEL 8 must have the packages required for encrypting offloaded audit logs installed. |
| ☐ | SV-230479r958754_rule | The RHEL 8 audit records must be off-loaded onto a different system or storage media from the system being audited. |
| ☐ | SV-230480r958754_rule | RHEL 8 must take appropriate action when the internal event queue is full. |
| ☐ | SV-230481r958754_rule | RHEL 8 must encrypt the transfer of audit records off-loaded onto a different system or media from the system being audited. |
| ☐ | SV-230482r1069330_rule | RHEL 8 must authenticate the remote logging server for off-loading audit logs. |
| ☐ | SV-230483r971542_rule | RHEL 8 must take action when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity. |
| ☐ | SV-230484r1038944_rule | RHEL 8 must securely compare internal information system clocks at least every 24 hours with a server synchronized to an authoritative time source, such as the United States Naval Observatory (USNO) time servers, or a time server designated for the appropriate DoD network (NIPRNet/SIPRNet), and/or the Global Positioning System (GPS). |
| ☐ | SV-230485r1017269_rule | RHEL 8 must disable the chrony daemon from acting as a server. |
| ☐ | SV-230486r1017270_rule | RHEL 8 must disable network management of the chrony daemon. |
| ☐ | SV-230487r1017271_rule | RHEL 8 must not have the telnet-server package installed. |
| ☐ | SV-230488r1017272_rule | RHEL 8 must not have any automated bug reporting tools installed. |
| ☐ | SV-230489r1017273_rule | RHEL 8 must not have the sendmail package installed. |
| ☐ | SV-230491r1017274_rule | RHEL 8 must enable mitigations against processor-based vulnerabilities. |
| ☐ | SV-230492r1184277_rule | RHEL 8 must not install packages from the Extra Packages for Enterprise Linux (EPEL) repository. |
| ☐ | SV-230493r1184280_rule | RHEL 8 must cover or disable the built-in or attached camera when not in use. |
| ☐ | SV-230494r1069310_rule | RHEL 8 must disable the asynchronous transfer mode (ATM) protocol. |
| ☐ | SV-230495r1069311_rule | RHEL 8 must disable the controller area network (CAN) protocol. |
| ☐ | SV-230496r1069312_rule | RHEL 8 must disable the stream control transmission protocol (SCTP). |
| ☐ | SV-230497r1069313_rule | RHEL 8 must disable the transparent inter-process communication (TIPC) protocol. |
| ☐ | SV-230498r1069314_rule | RHEL 8 must disable mounting of cramfs. |
| ☐ | SV-230499r1069315_rule | RHEL 8 must disable IEEE 1394 (FireWire) Support. |
| ☐ | SV-230500r1101900_rule | RHEL 8 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments. |
| ☐ | SV-230502r1155393_rule | The RHEL 8 file system automounter must be disabled. |
| ☐ | SV-230503r1069316_rule | RHEL 8 must be configured to disable USB mass storage. |
| ☐ | SV-230504r958672_rule | A RHEL 8 firewall must employ a deny-all, allow-by-exception policy for allowing connections to other systems. |
| ☐ | SV-230505r958672_rule | A firewall must be installed on RHEL 8. |
| ☐ | SV-230506r1017286_rule | RHEL 8 wireless network adapters must be disabled. |
| ☐ | SV-230507r1017287_rule | RHEL 8 Bluetooth must be disabled. |
| ☐ | SV-230508r958804_rule | RHEL 8 must mount /dev/shm with the nodev option. |
| ☐ | SV-230509r958804_rule | RHEL 8 must mount /dev/shm with the nosuid option. |
| ☐ | SV-230510r958804_rule | RHEL 8 must mount /dev/shm with the noexec option. |
| ☐ | SV-230511r958804_rule | RHEL 8 must mount /tmp with the nodev option. |
| ☐ | SV-230512r958804_rule | RHEL 8 must mount /tmp with the nosuid option. |
| ☐ | SV-230513r958804_rule | RHEL 8 must mount /tmp with the noexec option. |
| ☐ | SV-230514r958804_rule | RHEL 8 must mount /var/log with the nodev option. |
| ☐ | SV-230515r958804_rule | RHEL 8 must mount /var/log with the nosuid option. |
| ☐ | SV-230516r958804_rule | RHEL 8 must mount /var/log with the noexec option. |
| ☐ | SV-230517r958804_rule | RHEL 8 must mount /var/log/audit with the nodev option. |
| ☐ | SV-230518r958804_rule | RHEL 8 must mount /var/log/audit with the nosuid option. |
| ☐ | SV-230519r958804_rule | RHEL 8 must mount /var/log/audit with the noexec option. |
| ☐ | SV-230520r958804_rule | RHEL 8 must mount /var/tmp with the nodev option. |
| ☐ | SV-230521r958804_rule | RHEL 8 must mount /var/tmp with the nosuid option. |
| ☐ | SV-230522r958804_rule | RHEL 8 must mount /var/tmp with the noexec option. |
| ☐ | SV-230523r958804_rule | The RHEL 8 fapolicy module must be installed. |
| ☐ | SV-230524r1155418_rule | RHEL 8 must block unauthorized peripherals before establishing a connection. |
| ☐ | SV-230525r958902_rule | A firewall must be able to protect against or limit the effects of Denial of Service (DoS) attacks by ensuring RHEL 8 can implement rate-limiting measures on impacted network interfaces. |
| ☐ | SV-230526r958908_rule | All RHEL 8 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission. |
| ☐ | SV-230527r1017288_rule | RHEL 8 must force a frequent session key renegotiation for SSH connections to the server. |
| ☐ | SV-230529r1017289_rule | The x86 Ctrl-Alt-Delete key sequence must be disabled on RHEL 8. |
| ☐ | SV-230530r1069317_rule | The x86 Ctrl-Alt-Delete key sequence in RHEL 8 must be disabled if a graphical user interface is installed. |
| ☐ | SV-230531r1208754_rule | The systemd Ctrl-Alt-Delete burst key sequence in RHEL 8 must be disabled. |
| ☐ | SV-230532r1017294_rule | The debug-shell systemd service must be disabled on RHEL 8. |
| ☐ | SV-230533r1017295_rule | The Trivial File Transfer Protocol (TFTP) server package must not be installed if not required for RHEL 8 operational support. |
| ☐ | SV-230534r1017296_rule | The root account must be the only account having unrestricted access to the RHEL 8 system. |
| ☐ | SV-230535r1017297_rule | RHEL 8 must prevent IPv6 Internet Control Message Protocol (ICMP) redirect messages from being accepted. |
| ☐ | SV-230536r1208868_rule | RHEL 8 must not allow IPv4 ICMP redirect messages. |
| ☐ | SV-230537r1017299_rule | RHEL 8 must not respond to Internet Control Message Protocol (ICMP) echoes sent to a broadcast address. |
| ☐ | SV-230538r1017300_rule | RHEL 8 must not forward IPv6 source-routed packets. |
| ☐ | SV-230539r1017301_rule | RHEL 8 must not forward IPv6 source-routed packets by default. |
| ☐ | SV-230540r1017302_rule | RHEL 8 must not enable IPv6 packet forwarding unless the system is a router. |
| ☐ | SV-230541r1017303_rule | RHEL 8 must not accept router advertisements on all IPv6 interfaces. |
| ☐ | SV-230542r1017304_rule | RHEL 8 must not accept router advertisements on all IPv6 interfaces by default. |
| ☐ | SV-230543r1017305_rule | RHEL 8 must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default. |
| ☐ | SV-230544r1017306_rule | RHEL 8 must ignore IPv6 Internet Control Message Protocol (ICMP) redirect messages. |
| ☐ | SV-230545r1017307_rule | RHEL 8 must disable access to network bpf syscall from unprivileged processes. |
| ☐ | SV-230546r1155413_rule | RHEL 8 must restrict usage of ptrace to descendant processes. |
| ☐ | SV-230547r1184283_rule | RHEL 8 must restrict exposed kernel pointer addresses access. |
| ☐ | SV-230548r1017310_rule | RHEL 8 must disable the use of user namespaces. |
| ☐ | SV-230549r1208761_rule | RHEL 8 must use reverse path filtering on all IPv4 interfaces. |
| ☐ | SV-230550r1017312_rule | RHEL 8 must be configured to prevent unrestricted mail relaying. |
| ☐ | SV-230551r1017313_rule | The RHEL 8 file integrity tool must be configured to verify extended attributes. |
| ☐ | SV-230552r1101902_rule | The RHEL 8 file integrity tool must be configured to verify Access Control Lists (ACLs). |
| ☐ | SV-230553r1017315_rule | The graphical display manager must not be installed on RHEL 8 unless approved. |
| ☐ | SV-230554r1017316_rule | RHEL 8 network interfaces must not be in promiscuous mode. |
| ☐ | SV-230555r1017317_rule | RHEL 8 remote X connections for interactive users must be disabled unless to fulfill documented and validated mission requirements. |
| ☐ | SV-230556r1017318_rule | The RHEL 8 SSH daemon must prevent remote hosts from connecting to the proxy display. |
| ☐ | SV-230557r1088855_rule | If the Trivial File Transfer Protocol (TFTP) server is required, the RHEL 8 TFTP daemon must be configured to operate in secure mode. |
| ☐ | SV-230558r1017320_rule | A File Transfer Protocol (FTP) server package must not be installed unless mission essential on RHEL 8. |
| ☐ | SV-230559r1155398_rule | The gssproxy package must not be installed unless mission essential on RHEL 8. |
| ☐ | SV-230560r1017321_rule | The iprutils package must not be installed unless mission essential on RHEL 8. |
| ☐ | SV-230561r1017322_rule | The tuned package must not be installed unless mission essential on RHEL 8. |
| ☐ | SV-237640r1017323_rule | The krb5-server package must not be installed on RHEL 8. |
| ☐ | SV-237641r1101904_rule | RHEL 8 must restrict privilege elevation to authorized personnel. |
| ☐ | SV-237642r991589_rule | RHEL 8 must use the invoking user's password for privilege escalation when using "sudo". |
| ☐ | SV-237643r1050789_rule | RHEL 8 must require re-authentication when using the "sudo" command. |
| ☐ | SV-244519r1017326_rule | RHEL 8 must display a banner before granting local or remote access to the system via a graphical user logon. |
| ☐ | SV-244521r1137691_rule | RHEL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must require a unique superusers name upon booting into single-user mode and maintenance. |
| ☐ | SV-244522r1137691_rule | RHEL 8 operating systems booted with a BIOS must require a unique superusers name upon booting into single-user and maintenance modes. |
| ☐ | SV-244523r1137691_rule | RHEL 8 operating systems must require authentication upon booting into emergency mode. |
| ☐ | SV-244524r1017330_rule | The RHEL 8 pam_unix.so module must be configured in the system-auth file to use a FIPS 140-2 approved cryptographic hashing algorithm for system authentication. |
| ☐ | SV-244525r1017331_rule | RHEL 8 must be configured so that all network connections associated with SSH traffic are terminated after 10 minutes of becoming unresponsive. |
| ☐ | SV-244527r1017333_rule | RHEL 8 must have the packages required to use the hardware random number generator entropy gatherer service. |
| ☐ | SV-244528r1017335_rule | The RHEL 8 SSH daemon must not allow GSSAPI authentication, except to fulfill documented and validated mission requirements. |
| ☐ | SV-244529r1017336_rule | RHEL 8 must use a separate file system for /var/tmp. |
| ☐ | SV-244530r1184260_rule | RHEL 8 must prevent files with the setuid and setgid bit set from being executed on the /boot/efi directory. |
| ☐ | SV-244531r1017338_rule | All RHEL 8 local interactive user home directory files must have mode 0750 or less permissive. |
| ☐ | SV-244532r1101906_rule | RHEL 8 must be configured so that all files and directories contained in local interactive user home directories are group-owned by a group of which the home directory owner is a member. |
| ☐ | SV-244533r1069318_rule | RHEL 8 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file. |
| ☐ | SV-244534r1069319_rule | RHEL 8 must configure the use of the pam_faillock.so module in the /etc/pam.d/password-auth file. |
| ☐ | SV-244535r1017342_rule | RHEL 8 must initiate a session lock for graphical user interfaces when the screensaver is activated. |
| ☐ | SV-244536r1017343_rule | RHEL 8 must disable the user list at logon for graphical user interfaces. |
| ☐ | SV-244538r1069324_rule | RHEL 8 must prevent a user from overriding the session idle-delay setting for the graphical user interface. |
| ☐ | SV-244539r1069325_rule | RHEL 8 must prevent a user from overriding the screensaver lock-enabled setting for the graphical user interface. |
| ☐ | SV-244541r1017347_rule | RHEL 8 must not allow blank or null passwords in the password-auth file. |
| ☐ | SV-244542r1017348_rule | RHEL 8 audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events. |
| ☐ | SV-244543r971542_rule | RHEL 8 must notify the System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) when allocated audit record storage volume 75 percent utilization. |
| ☐ | SV-244544r958672_rule | A firewall must be active on RHEL 8. |
| ☐ | SV-244545r958804_rule | The RHEL 8 fapolicy module must be enabled. |
| ☐ | SV-244546r1208752_rule | The RHEL 8 fapolicy module must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs. |
| ☐ | SV-244547r1014811_rule | RHEL 8 must have the USBGuard installed. |
| ☐ | SV-244548r1014815_rule | RHEL 8 must enable the USBGuard. |
| ☐ | SV-244549r958908_rule | All RHEL 8 networked systems must have SSH installed. |
| ☐ | SV-244550r1017350_rule | RHEL 8 must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted. |
| ☐ | SV-244551r1017351_rule | RHEL 8 must not forward IPv4 source-routed packets. |
| ☐ | SV-244552r1017352_rule | RHEL 8 must not forward IPv4 source-routed packets by default. |
| ☐ | SV-244553r1017353_rule | RHEL 8 must ignore IPv4 Internet Control Message Protocol (ICMP) redirect messages. |
| ☐ | SV-244554r1210517_rule | RHEL 8 must enable hardening for the Berkeley Packet Filter Just-in-time compiler. |
| ☐ | SV-250315r1017356_rule | RHEL 8 systems, versions 8.2 and above, must configure SELinux context type to allow the use of a non-default faillock tally directory. |
| ☐ | SV-250316r1017357_rule | RHEL 8 systems below version 8.2 must configure SELinux context type to allow the use of a non-default faillock tally directory. |
| ☐ | SV-250317r1017358_rule | RHEL 8 must not enable IPv4 packet forwarding unless the system is a router. |
| ☐ | SV-251706r1017359_rule | The RHEL 8 operating system must not have accounts configured with blank or null passwords. |
| ☐ | SV-251707r1017360_rule | RHEL 8 library directories must have mode 755 or less permissive. |
| ☐ | SV-251708r1017362_rule | RHEL 8 library directories must be owned by root. |
| ☐ | SV-251709r1017364_rule | RHEL 8 library directories must be group-owned by root or a system account. |
| ☐ | SV-251710r958944_rule | The RHEL 8 operating system must use a file integrity tool to verify correct operation of all security functions. |
| ☐ | SV-251711r1017365_rule | RHEL 8 must specify the default "include" directory for the /etc/sudoers file. |
| ☐ | SV-251712r1050789_rule | The RHEL 8 operating system must not be configured to bypass password requirements for privilege escalation. |
| ☐ | SV-251713r1017366_rule | RHEL 8 must ensure the password complexity module is enabled in the system-auth file. |
| ☐ | SV-251716r1069329_rule | RHEL 8 systems, version 8.4 and above, must ensure the password complexity module is configured for three retries or less. |
| ☐ | SV-251718r1017371_rule | The graphical display manager must not be the default target on RHEL 8 unless approved. |
| ☐ | SV-254520r1069331_rule | RHEL 8 must prevent nonprivileged users from executing privileged functions, including disabling, circumventing, or altering implemented security safeguards/countermeasures. |
| ☐ | SV-256973r1017373_rule | RHEL 8 must ensure cryptographic verification of vendor software packages. |
| ☐ | SV-256974r1069321_rule | RHEL 8 must be configured to allow sending email notifications of unauthorized configuration changes to designated personnel. |
| ☐ | SV-257258r1069328_rule | RHEL 8.7 and higher must terminate idle user sessions. |
| ☐ | SV-268322r1017568_rule | RHEL 8 must not allow blank or null passwords in the system-auth file. |
| ☐ | SV-272482r1208740_rule | The RHEL 8 SSH client must be configured to use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. |
| ☐ | SV-272483r1184243_rule | The RHEL 8 SSH client must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. |
| ☐ | SV-272484r1134875_rule | RHEL 8 must elevate the SELinux context when an administrator calls the sudo command. |
| ☐ | SV-274877r1155381_rule | RHEL 8 must audit any script or executable called by cron as root or by any privileged user. |
| ☐ | SV-279929r1156340_rule | RHEL 8 must automatically exit interactive command shell user sessions after 10 minutes of inactivity. |
| ☐ | SV-279930r1184239_rule | RHEL 8 IP tunnels must use FIPS 140-3-approved cryptographic algorithms. |
| ☐ | SV-279931r1184237_rule | RHEL 8 must implement DOD-approved encryption in the bind package. |
| ☐ | SV-279932r1156349_rule | RHEL 8 cryptographic policy must not be overridden. |
| ☐ | SV-279933r1156352_rule | RHEL 8 must have the crypto-policies package installed. |
| ☐ | SV-284947r1210519_rule | RHEL 8 must use a reverse-path filter for IPv4 network traffic, when possible, by default. |
| ☐ | SV-284948r1208757_rule | RHEL 8 must log IPv4 packets with impossible addresses. |
| ☐ | SV-284949r1208759_rule | RHEL 8 must log IPv4 packets with impossible addresses by default. |