| Checked | Name | Title |
|---|
| ☐ | SV-282352r1200036_rule | TOSS 5 must automatically expire temporary accounts within 72 hours. |
| ☐ | SV-282353r1200039_rule | TOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers. |
| ☐ | SV-282354r1201500_rule | TOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory. |
| ☐ | SV-282355r1200045_rule | TOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group. |
| ☐ | SV-282356r1200048_rule | TOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow. |
| ☐ | SV-282357r1200051_rule | TOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd. |
| ☐ | SV-282358r1200054_rule | TOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd. |
| ☐ | SV-282359r1200057_rule | TOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow. |
| ☐ | SV-282360r1200060_rule | TOSS 5 must automatically lock an account when three unsuccessful login attempts occur. |
| ☐ | SV-282361r1200063_rule | TOSS 5 must automatically lock an account when three unsuccessful login attempts occur during a 15-minute time period. |
| ☐ | SV-282362r1200066_rule | TOSS 5 must ensure account lockouts persist. |
| ☐ | SV-282363r1200069_rule | TOSS 5 must log username information when unsuccessful login attempts occur. |
| ☐ | SV-282364r1200072_rule | TOSS 5 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file. |
| ☐ | SV-282365r1200075_rule | TOSS 5 must configure the use of the pam_faillock.so module in the /etc/pam.d/password-auth file. |
| ☐ | SV-282366r1200078_rule | TOSS 5 must display the Standard Mandatory DOD or other applicable U.S. Government Notice and Consent Banner before granting local or remote access to the system via a command line user login. |
| ☐ | SV-282367r1201610_rule | TOSS 5 must display the Standard Mandatory DOD or other applicable U.S. Government agency Notice and Consent Banner before granting local or remote access to the system via a SSH login. |
| ☐ | SV-282368r1200084_rule | TOSS 5 must display the Standard Mandatory DOD or other applicable U.S. Government agency Notice and Consent Banner before granting local or remote access to the system via a graphical user login. |
| ☐ | SV-282369r1200087_rule | TOSS 5 must prevent a user from overriding the banner-message-enable setting for the graphical user interface. |
| ☐ | SV-282371r1200093_rule | TOSS 5 must limit the number of concurrent sessions to 256 for all accounts and/or account types. |
| ☐ | SV-282372r1201380_rule | TOSS 5 must directly initiate a session lock for all connection types when the smart card is removed. |
| ☐ | SV-282373r1200099_rule | TOSS 5 must prevent a user from overriding the disabling of the graphical user smart card removal action. |
| ☐ | SV-282374r1201498_rule | TOSS 5 must enable a user session lock until that user reestablishes access using established identification and authentication procedures for graphical user sessions. |
| ☐ | SV-282375r1200105_rule | TOSS 5 must prevent a user from overriding the screensaver lock-enabled setting for the graphical user interface. |
| ☐ | SV-282376r1200108_rule | TOSS 5 must have the tmux package installed. |
| ☐ | SV-282377r1200111_rule | TOSS 5 must automatically lock graphical user sessions after 10 minutes of inactivity. |
| ☐ | SV-282378r1200114_rule | TOSS 5 must prevent a user from overriding the session idle-delay setting for the graphical user interface. |
| ☐ | SV-282379r1200117_rule | TOSS 5 must initiate a session lock for graphical user interfaces when the screensaver is activated. |
| ☐ | SV-282380r1200120_rule | TOSS 5 must prevent a user from overriding the session lock-delay setting for the graphical user interface. |
| ☐ | SV-282381r1200123_rule | TOSS 5 must automatically exit interactive command shell user sessions after 15 minutes of inactivity. |
| ☐ | SV-282382r1200126_rule | TOSS 5 must conceal via the session lock information previously visible on the display with a publicly viewable image. |
| ☐ | SV-282383r1200129_rule | TOSS 5 must log SSH connection attempts and failures to the server. |
| ☐ | SV-282384r1200132_rule | All TOSS 5 remote access methods must be monitored. |
| ☐ | SV-282385r1200135_rule | TOSS 5 must force a frequent session key renegotiation for SSH connections to the server. |
| ☐ | SV-282386r1200138_rule | TOSS 5 IP tunnels must use FIPS 140-3-approved cryptographic algorithms. |
| ☐ | SV-282387r1200141_rule | TOSS 5 must enable auditing of processes that start prior to the audit daemon. |
| ☐ | SV-282388r1201627_rule | TOSS 5 must audit all uses of the chmod, fchmod, and fchmodat system calls. |
| ☐ | SV-282389r1201629_rule | TOSS 5 must audit all uses of the chown, fchown, fchownat, and lchown system calls. |
| ☐ | SV-282390r1201503_rule | TOSS 5 must audit all uses of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls. |
| ☐ | SV-282391r1201505_rule | TOSS 5 must audit all uses of umount system calls. |
| ☐ | SV-282392r1201507_rule | TOSS 5 must audit all uses of the chacl command. |
| ☐ | SV-282393r1201509_rule | TOSS 5 must audit all uses of the setfacl command. |
| ☐ | SV-282394r1201511_rule | TOSS 5 must audit all uses of the chcon command. |
| ☐ | SV-282395r1201513_rule | TOSS 5 must audit all uses of the semanage command. |
| ☐ | SV-282396r1201515_rule | TOSS 5 must audit all uses of the setfiles command. |
| ☐ | SV-282397r1201517_rule | TOSS 5 must audit all uses of the setsebool command. |
| ☐ | SV-282398r1201519_rule | TOSS 5 must audit all uses of the rename, unlink, rmdir, renameat, and unlinkat system calls. |
| ☐ | SV-282399r1201521_rule | TOSS 5 must audit all uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls. |
| ☐ | SV-282400r1201523_rule | TOSS 5 must audit all uses of the delete_module system call. |
| ☐ | SV-282401r1201525_rule | TOSS 5 must audit all uses of the init_module and finit_module system calls. |
| ☐ | SV-282402r1201527_rule | TOSS 5 must audit all uses of the chage command. |
| ☐ | SV-282403r1201529_rule | TOSS 5 must audit all uses of the chsh command. |
| ☐ | SV-282404r1201531_rule | TOSS 5 must audit all uses of the crontab command. |
| ☐ | SV-282405r1201533_rule | TOSS 5 must audit all uses of the gpasswd command. |
| ☐ | SV-282406r1201535_rule | TOSS 5 must audit all uses of the kmod command. |
| ☐ | SV-282407r1201537_rule | TOSS 5 must audit all uses of the newgrp command. |
| ☐ | SV-282408r1201539_rule | TOSS 5 must audit all uses of the pam_timestamp_check command. |
| ☐ | SV-282409r1201541_rule | TOSS 5 must audit all uses of the passwd command. |
| ☐ | SV-282410r1201543_rule | TOSS 5 must audit all uses of the postdrop command. |
| ☐ | SV-282411r1201545_rule | TOSS 5 must audit all uses of the postqueue command. |
| ☐ | SV-282412r1201547_rule | TOSS 5 must audit all uses of the ssh-agent command. |
| ☐ | SV-282413r1201549_rule | TOSS 5 must audit all uses of the ssh-keysign command. |
| ☐ | SV-282414r1201551_rule | TOSS 5 must audit all uses of the su command. |
| ☐ | SV-282415r1201553_rule | TOSS 5 must audit all uses of the sudo command. |
| ☐ | SV-282416r1201555_rule | TOSS 5 must audit all uses of the sudoedit command. |
| ☐ | SV-282417r1201557_rule | TOSS 5 must audit all uses of the unix_chkpwd command. |
| ☐ | SV-282418r1201559_rule | TOSS 5 must audit all uses of the unix_update command. |
| ☐ | SV-282419r1201561_rule | TOSS 5 must audit all uses of the userhelper command. |
| ☐ | SV-282420r1201563_rule | TOSS 5 must audit all uses of the usermod command. |
| ☐ | SV-282421r1201565_rule | TOSS 5 must audit all uses of the mount command. |
| ☐ | SV-282422r1201567_rule | Successful/unsuccessful uses of the umount system call in TOSS 5 must generate an audit record. |
| ☐ | SV-282423r1201569_rule | Successful/unsuccessful uses of the umount2 system call in TOSS 5 must generate an audit record. |
| ☐ | SV-282424r1201571_rule | TOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/lastlog. |
| ☐ | SV-282425r1201625_rule | TOSS 5 must label all offloaded audit logs before sending them to the central log server. |
| ☐ | SV-282426r1200258_rule | TOSS 5 must forward mail from postmaster to the root account using a postfix alias. |
| ☐ | SV-282427r1200261_rule | TOSS 5 system administrators (SAs) and/or information system security officer (ISSOs) (at a minimum) must be alerted of an audit processing failure event. |
| ☐ | SV-282428r1200264_rule | TOSS 5 must have mail aliases to notify the information system security officer (ISSO) and system administrator (SA) (at a minimum) in the event of an audit processing failure. |
| ☐ | SV-282429r1200267_rule | TOSS 5 must take appropriate action when a critical audit processing failure occurs. |
| ☐ | SV-282430r1200270_rule | TOSS 5 must periodically flush audit records to disk to prevent the loss of audit records. |
| ☐ | SV-282431r1200273_rule | TOSS 5 audit logs must be group-owned by root or by a restricted logging group to prevent unauthorized read access. |
| ☐ | SV-282432r1200276_rule | TOSS 5 audit log directory must be owned by root to prevent unauthorized read access. |
| ☐ | SV-282433r1200279_rule | TOSS 5 audit logs file must have mode 0600 or less permissive to prevent unauthorized access to the audit log. |
| ☐ | SV-282434r1200282_rule | TOSS 5 audit system must protect login user identifiers (UIDs) from unauthorized change. |
| ☐ | SV-282435r1200285_rule | TOSS 5 audit system must protect auditing rules from unauthorized change. |
| ☐ | SV-282436r1200288_rule | TOSS 5 must enable Linux audit logging for the USBGuard daemon. |
| ☐ | SV-282437r1200291_rule | TOSS 5 audit package must be installed. |
| ☐ | SV-282438r1200294_rule | TOSS 5 audit service must be enabled. |
| ☐ | SV-282439r1200297_rule | The TOSS 5 audit system must audit local events. |
| ☐ | SV-282440r1200300_rule | TOSS 5 must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited. |
| ☐ | SV-282441r1200303_rule | TOSS 5 /etc/audit/auditd.conf file must have 0640 or less permissive to prevent unauthorized access. |
| ☐ | SV-282442r1200306_rule | TOSS 5, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor. |
| ☐ | SV-282443r1200309_rule | TOSS 5, for public key infrastructure (PKI)-based authentication, must enforce authorized access to the corresponding private key. |
| ☐ | SV-282444r1200312_rule | TOSS 5 must map the authenticated identity to the user or group account for PKI-based authentication. |
| ☐ | SV-282445r1200315_rule | TOSS 5 must ensure the password complexity module in the system-auth file is configured for three retries or less. |
| ☐ | SV-282446r1200318_rule | TOSS 5 must ensure the password complexity module is enabled in the password-auth file. |
| ☐ | SV-282447r1200321_rule | TOSS 5 must enforce password complexity by requiring at least one uppercase character. |
| ☐ | SV-282448r1200324_rule | TOSS 5 must enforce password complexity by requiring that at least one lowercase character be used. |
| ☐ | SV-282449r1200327_rule | TOSS 5 must enforce password complexity by requiring that at least one numeric character be used. |
| ☐ | SV-282450r1200330_rule | TOSS 5 must enforce password complexity rules for the root account. |
| ☐ | SV-282451r1200333_rule | TOSS 5 must require users to change at least eight characters when changing passwords. |
| ☐ | SV-282452r1200336_rule | TOSS 5 must limit the maximum number of repeating characters of the same character class to four when passwords are changed. |
| ☐ | SV-282453r1200339_rule | TOSS 5 must limit the maximum number of repeating characters to three when passwords are changed. |
| ☐ | SV-282454r1200342_rule | TOSS 5 must require the change of at least four character classes when passwords are changed. |
| ☐ | SV-282455r1201382_rule | TOSS 5 password-auth must be configured to use a sufficient number of hashing rounds. |
| ☐ | SV-282456r1201574_rule | TOSS 5 system-auth must be configured to use a sufficient number of hashing rounds. |
| ☐ | SV-282457r1200351_rule | TOSS 5 must be configured so that user and group account administration utilities are configured to store only encrypted representations of passwords. |
| ☐ | SV-282458r1200354_rule | TOSS 5 must be configured to use the shadow file to store only encrypted representations of passwords. |
| ☐ | SV-282459r1200357_rule | TOSS 5 shadow password suite must be configured to use a sufficient number of hashing rounds. |
| ☐ | SV-282460r1200360_rule | TOSS 5 must employ FIPS 140-3-approved cryptographic hashing algorithms for all stored passwords. |
| ☐ | SV-282461r1200363_rule | The TOSS 5 pam_unix.so module must be configured in the password-auth file to use a FIPS 140-3-approved cryptographic hashing algorithm for system authentication. |
| ☐ | SV-282462r1200366_rule | TOSS 5 must not have the rsh-server package installed. |
| ☐ | SV-282463r1200369_rule | TOSS 5 passwords for new users or password changes must have a 24 hours minimum password lifetime restriction in /etc/login.defs. |
| ☐ | SV-282464r1200372_rule | TOSS 5 passwords must have a 24 hours minimum password lifetime restriction in /etc/shadow. |
| ☐ | SV-282465r1200375_rule | TOSS 5 user account passwords for new users or password changes must have a 60-day maximum password lifetime restriction in /etc/login.defs. |
| ☐ | SV-282466r1200378_rule | TOSS 5 user account passwords must have a 60-day maximum password lifetime restriction. |
| ☐ | SV-282467r1200381_rule | TOSS 5 passwords must be created with a minimum of 15 characters. |
| ☐ | SV-282468r1200384_rule | TOSS 5 passwords, for new users, must have a minimum of 15 characters. |
| ☐ | SV-282470r1201601_rule | TOSS 5 must require a unique superuser name upon booting into single-user and maintenance modes. |
| ☐ | SV-282471r1200393_rule | TOSS 5 must require authentication to access emergency mode. |
| ☐ | SV-282472r1200396_rule | TOSS 5 must require authentication to access single-user mode. |
| ☐ | SV-282473r1200399_rule | TOSS 5 must enable mitigations against processor-based vulnerabilities. |
| ☐ | SV-282474r1200402_rule | TOSS 5 must be configured to disable the Asynchronous Transfer Mode (ATM) kernel module. |
| ☐ | SV-282475r1200405_rule | TOSS 5 must be configured to disable the Controller Area Network (CAN) kernel module. |
| ☐ | SV-282476r1200408_rule | TOSS 5 must be configured to disable the FireWire kernel module. |
| ☐ | SV-282477r1200411_rule | TOSS 5 must disable the Stream Control Transmission Protocol (SCTP) kernel module. |
| ☐ | SV-282478r1200414_rule | TOSS 5 must disable the Transparent Inter Process Communication (TIPC) kernel module. |
| ☐ | SV-282479r1200417_rule | TOSS 5 must not have the ypserv package installed. |
| ☐ | SV-282480r1200420_rule | TOSS 5 must not have the rsh-server package installed. |
| ☐ | SV-282481r1200423_rule | TOSS 5 must not have the telnet-server package installed. |
| ☐ | SV-282482r1200426_rule | TOSS 5 must not have the iprutils package installed. |
| ☐ | SV-282483r1200429_rule | TOSS 5 must disable mounting of cramfs. |
| ☐ | SV-282484r1201332_rule | TOSS 5 must disable network management of the chrony daemon. |
| ☐ | SV-282485r1200435_rule | TOSS 5 must have the firewalld package installed. |
| ☐ | SV-282486r1200438_rule | The firewalld service on TOSS 5 must be active. |
| ☐ | SV-282487r1200441_rule | TOSS 5 must control remote access methods. |
| ☐ | SV-282488r1200444_rule | TOSS 5 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments. |
| ☐ | SV-282489r1200447_rule | TOSS 5 duplicate User IDs (UIDs) must not exist for interactive users. |
| ☐ | SV-282490r1200450_rule | All TOSS 5 interactive users must have a primary group that exists. |
| ☐ | SV-282491r1200453_rule | TOSS 5 groups must have unique Group ID (GID). |
| ☐ | SV-282492r1200456_rule | TOSS 5 must have the openssl-pkcs11 package installed. |
| ☐ | SV-282493r1200459_rule | TOSS 5 SSHD must not allow blank or null passwords. |
| ☐ | SV-282494r1200462_rule | TOSS 5 must not permit direct logins to the root account using remote access via SSH. |
| ☐ | SV-282497r1200471_rule | TOSS 5 file system automount function must be disabled unless required. |
| ☐ | SV-282498r1200474_rule | TOSS 5 must disable the graphical user interface automount function unless required. |
| ☐ | SV-282499r1200477_rule | TOSS 5 must prevent a user from overriding the disabling of the graphical user interface automount function. |
| ☐ | SV-282500r1200480_rule | TOSS 5 must prevent a user from overriding the disabling of the graphical user interface autorun function. |
| ☐ | SV-282501r1200483_rule | TOSS 5 must be configured to disable USB mass storage. |
| ☐ | SV-282502r1200486_rule | TOSS 5 must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity. |
| ☐ | SV-282503r1200489_rule | TOSS 5 must use mechanisms meeting the requirements of applicable federal laws, executive orders, directives, policies, regulations, standards, and guidance for authentication to a cryptographic module. |
| ☐ | SV-282504r1200492_rule | TOSS 5 must enable the Pluggable Authentication Module (PAM) interface for SSHD. |
| ☐ | SV-282505r1200495_rule | TOSS 5 must restrict access to the kernel message buffer. |
| ☐ | SV-282506r1200498_rule | TOSS 5 must prevent kernel profiling by nonprivileged users. |
| ☐ | SV-282507r1200501_rule | TOSS 5 must restrict exposed kernel pointer addresses access. |
| ☐ | SV-282508r1200504_rule | TOSS 5 must disable access to network bpf system call from nonprivileged processes. |
| ☐ | SV-282509r1200507_rule | TOSS 5 must restrict usage of ptrace to descendant processes. |
| ☐ | SV-282510r1201302_rule | TOSS 5 must use a Linux Security Module configured to enforce limits on system services. |
| ☐ | SV-282511r1200513_rule | A sticky bit must be set on all TOSS 5 public directories. |
| ☐ | SV-282512r1201342_rule | TOSS 5 must be configured to use TCP syncookies. |
| ☐ | SV-282514r1201603_rule | TOSS 5 local disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at rest protection. |
| ☐ | SV-282516r1200528_rule | TOSS 5 /var/log directory must have mode 0755 or less permissive. |
| ☐ | SV-282517r1200531_rule | TOSS 5 /var/log/messages file must have mode 0640 or less permissive. |
| ☐ | SV-282518r1200534_rule | TOSS 5 /var/log directory must be owned by root. |
| ☐ | SV-282519r1200537_rule | TOSS 5 /var/log directory must be group-owned by root. |
| ☐ | SV-282520r1200540_rule | TOSS 5 /var/log/messages file must be owned by root. |
| ☐ | SV-282521r1200543_rule | TOSS 5 /var/log/messages file must be group-owned by root. |
| ☐ | SV-282522r1200546_rule | TOSS 5 SSH daemon must be configured to use systemwide crypto policies. |
| ☐ | SV-282523r1200549_rule | TOSS 5 must implement DOD or other applicable U.S. Government agency-approved encryption ciphers to protect the confidentiality of SSH client connections. |
| ☐ | SV-282524r1201364_rule | TOSS 5 must implement DOD or other applicable U.S. Government agency-approved encryption ciphers to protect the confidentiality of SSH server connections. |
| ☐ | SV-282525r1201367_rule | The TOSS 5 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms. |
| ☐ | SV-282526r1201501_rule | TOSS 5 must implement DOD or other applicable U.S. Government agency-approved TLS encryption in the GnuTLS package. |
| ☐ | SV-282527r1200561_rule | TOSS 5 must implement DOD or other applicable U.S. Government agency -approved encryption in the OpenSSL package. |
| ☐ | SV-282528r1201630_rule | TOSS 5 must implement DOD or other applicable U.S. Government agency-approved TLS encryption in the OpenSSL package. |
| ☐ | SV-282529r1200567_rule | TOSS 5 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon. |
| ☐ | SV-282530r1200570_rule | TOSS 5 must produce audit records containing information to establish the identity of any individual or process associated with the event. |
| ☐ | SV-282531r1201577_rule | TOSS 5 audit tools must have a mode of 0755 or less permissive. |
| ☐ | SV-282532r1200576_rule | TOSS 5 audit tools must be owned by root. |
| ☐ | SV-282533r1201328_rule | TOSS 5 audit tools must be group-owned by root. |
| ☐ | SV-282534r1200582_rule | TOSS 5 must use cryptographic mechanisms to protect the integrity of audit tools. |
| ☐ | SV-282535r1200585_rule | TOSS 5 system commands must have mode 755 or less permissive. |
| ☐ | SV-282536r1201579_rule | TOSS 5 library directories must have mode 755 or less permissive. |
| ☐ | SV-282537r1201581_rule | TOSS 5 library files must have mode 755 or less permissive. |
| ☐ | SV-282538r1200594_rule | TOSS 5 system commands must be owned by root. |
| ☐ | SV-282539r1200597_rule | TOSS 5 system commands must be group-owned by root or a system account. |
| ☐ | SV-282540r1201318_rule | TOSS 5 library files must be owned by root. |
| ☐ | SV-282541r1201321_rule | TOSS 5 library files must be group-owned by root or a system account. |
| ☐ | SV-282542r1201324_rule | TOSS 5 library directories must be owned by root. |
| ☐ | SV-282543r1201327_rule | TOSS 5 library directories must be group-owned by root or a system account. |
| ☐ | SV-282544r1200612_rule | TOSS 5 must enforce password complexity by requiring at least one special character. |
| ☐ | SV-282545r1200615_rule | The TOSS 5 systemd-journald service must be enabled. |
| ☐ | SV-282549r1200627_rule | TOSS 5 must securely compare internal information system clocks at least every 24 hours. |
| ☐ | SV-282553r1200639_rule | TOSS 5 must enable kernel parameters to enforce discretionary access control on hardlinks. |
| ☐ | SV-282554r1201608_rule | TOSS 5 must enable kernel parameters to enforce discretionary access control (DAC) on symlinks. |
| ☐ | SV-282557r1200651_rule | The systemd Ctrl-Alt-Delete burst key sequence in TOSS 5 must be disabled. |
| ☐ | SV-282558r1200654_rule | The x86 Ctrl-Alt-Delete key sequence must be disabled on TOSS 5. |
| ☐ | SV-282559r1200657_rule | The TOSS 5 debug-shell systemd service must be disabled. |
| ☐ | SV-282560r1200660_rule | TOSS 5 must have the sudo package installed. |
| ☐ | SV-282561r1200663_rule | TOSS 5 must audit uses of the execve system call. |
| ☐ | SV-282562r1201623_rule | TOSS 5 must allocate audit record storage capacity to store at least one week's worth of audit records. |
| ☐ | SV-282563r1200669_rule | TOSS 5 must be configured to off-load audit records onto a different system from the system being audited via syslog. |
| ☐ | SV-282564r1201619_rule | TOSS 5 must authenticate the remote logging server for off-loading audit logs via rsyslog. |
| ☐ | SV-282565r1201620_rule | TOSS 5 must encrypt the transfer of audit records off-loaded onto a different system or media from the system being audited via rsyslog. |
| ☐ | SV-282566r1200678_rule | TOSS 5 must encrypt, via the gtls driver, the transfer of audit records off-loaded onto a different system or media from the system being audited via rsyslog. |
| ☐ | SV-282567r1200681_rule | TOSS 5 must take appropriate action when the internal event queue is full. |
| ☐ | SV-282568r1200684_rule | TOSS 5 audispd-plugins package must be installed. |
| ☐ | SV-282569r1200687_rule | TOSS 5 must act when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity. |
| ☐ | SV-282570r1200690_rule | TOSS 5 must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume 75 percent utilization. |
| ☐ | SV-282571r1200693_rule | TOSS 5 must act when allocated audit record storage volume reaches 95 percent of the audit record storage capacity. |
| ☐ | SV-282572r1200696_rule | TOSS 5 must act when allocated audit record storage volume reaches 95 percent of the repository maximum audit record storage capacity. |
| ☐ | SV-282574r1200702_rule | TOSS 5 must have the chrony package installed. |
| ☐ | SV-282575r1200705_rule | TOSS 5 chronyd service must be enabled. |
| ☐ | SV-282578r1200714_rule | TOSS 5 must have the s-nail package installed. |
| ☐ | SV-282579r1201582_rule | TOSS 5 must have the Advanced Intrusion Detection Environment (AIDE) package installed. |
| ☐ | SV-282580r1201642_rule | TOSS 5 must routinely check the baseline configuration for unauthorized changes and notify the system administrator (SA) when anomalies in the operation of any security functions are discovered. |
| ☐ | SV-282581r1200723_rule | TOSS 5 SSH daemon must not allow Kerberos authentication. |
| ☐ | SV-282582r1200726_rule | TOSS 5 must ensure cryptographic verification of vendor software packages. |
| ☐ | SV-282583r1200729_rule | TOSS 5 must check the GPG signature of software packages originating from external software repositories before installation. |
| ☐ | SV-282584r1200732_rule | TOSS 5 must check the GPG signature of locally installed software packages before installation. |
| ☐ | SV-282585r1200735_rule | TOSS 5 must have GPG signature verification enabled for all software repositories. |
| ☐ | SV-282586r1200738_rule | TOSS 5 subscription-manager package must be installed. |
| ☐ | SV-282587r1200741_rule | TOSS 5 must mount /var/tmp with the nosuid option. |
| ☐ | SV-282588r1200744_rule | TOSS 5 must disable the graphical user interface autorun function unless required. |
| ☐ | SV-282589r1200747_rule | TOSS 5 fapolicy module must be installed. |
| ☐ | SV-282590r1200750_rule | TOSS 5 must use the invoking user's password for privilege escalation when using sudo. |
| ☐ | SV-282591r1200753_rule | TOSS 5 must have the pcsc-lite package installed. |
| ☐ | SV-282592r1200756_rule | TOSS 5 must have the opensc package installed. |
| ☐ | SV-282593r1200759_rule | TOSS 5 must have the USBGuard package installed. |
| ☐ | SV-282594r1200762_rule | TOSS 5 must have the USBGuard package enabled. |
| ☐ | SV-282595r1200765_rule | TOSS 5 must block unauthorized peripherals before establishing a connection. |
| ☐ | SV-282597r1200771_rule | TOSS 5 must prohibit the use of cached authenticators after one day. |
| ☐ | SV-282598r1200774_rule | TOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/faillock. |
| ☐ | SV-282599r1201494_rule | TOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/tallylog. |
| ☐ | SV-282601r1200783_rule | TOSS 5 must have the crypto-policies package installed. |
| ☐ | SV-282602r1200786_rule | TOSS 5 crypto policy must not be overridden. |
| ☐ | SV-282603r1200789_rule | TOSS 5 must implement a systemwide encryption policy. |
| ☐ | SV-282605r1200795_rule | TOSS 5 must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring rate-limiting measures on impacted network interfaces are implemented. |
| ☐ | SV-282606r1201360_rule | All TOSS 5 networked systems must have SSH installed. |
| ☐ | SV-282607r1200801_rule | All TOSS 5 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission. |
| ☐ | SV-282608r1200804_rule | TOSS 5 must implement DOD or other applicable U.S. Government agency-approved encryption in the bind package. |
| ☐ | SV-282610r1200810_rule | TOSS 5 must implement nonexecutable data to protect its memory from unauthorized code execution. |
| ☐ | SV-282611r1200813_rule | TOSS 5 must remove all software components after updated versions have been installed. |
| ☐ | SV-282613r1201304_rule | TOSS 5 must enable the "SELinux" targeted policy. |
| ☐ | SV-282615r1201495_rule | TOSS 5 crypto policy files must match files shipped with the operating system. |
| ☐ | SV-282616r1200828_rule | TOSS 5 must have the rsyslog package installed. |
| ☐ | SV-282617r1201621_rule | TOSS 5 must be configured to forward audit records via TCP to a different system or media from the system being audited via rsyslog. |
| ☐ | SV-282618r1200834_rule | TOSS 5 must prevent the use of dictionary words for passwords. |
| ☐ | SV-282619r1200837_rule | TOSS 5 must enforce a delay of at least four seconds between logon prompts following a failed logon attempt. |
| ☐ | SV-282620r1200840_rule | TOSS 5 must disable virtual system calls. |
| ☐ | SV-282621r1200843_rule | TOSS 5 must clear the page allocator to prevent use-after-free attacks. |
| ☐ | SV-282622r1201309_rule | TOSS 5 must disable the kernel.core_pattern. |
| ☐ | SV-282623r1201600_rule | TOSS 5 must be a vendor-supported release. |
| ☐ | SV-282624r1200852_rule | TOSS 5 vendor packaged system security patches and updates must be installed and up to date. |
| ☐ | SV-282625r1200855_rule | The graphical display manager must not be the default target on TOSS 5 unless approved. |
| ☐ | SV-282626r1200858_rule | TOSS 5 must enable the hardware random number generator entropy gatherer service. |
| ☐ | SV-282627r1200861_rule | TOSS 5 must disable the ability of systemd to spawn an interactive boot process. |
| ☐ | SV-282628r1200864_rule | The TOSS 5 /boot/grub2/grub.cfg file must be group owned by root. |
| ☐ | SV-282629r1200867_rule | The TOSS 5 /boot/grub2/grub.cfg file must be owned by root. |
| ☐ | SV-282630r1200870_rule | TOSS 5 must prevent loading a new kernel for later execution. |
| ☐ | SV-282631r1200873_rule | TOSS 5 must disable core dump backtraces. |
| ☐ | SV-282632r1200876_rule | TOSS 5 must disable storing core dumps. |
| ☐ | SV-282633r1200879_rule | TOSS 5 must disable acquiring, saving, and processing core dumps. |
| ☐ | SV-282634r1200882_rule | TOSS 5 must not have the sendmail package installed. |
| ☐ | SV-282635r1201602_rule | TOSS 5 must not have the quagga package installed. |
| ☐ | SV-282636r1201310_rule | TOSS 5 must have the gnutls-utils package installed. |
| ☐ | SV-282637r1200891_rule | TOSS 5 must have the nss-tools package installed. |
| ☐ | SV-282638r1200894_rule | TOSS 5 must have the rng-tools package installed. |
| ☐ | SV-282639r1200897_rule | TOSS 5 must be configured so that the Network File System (NFS) is configured to use RPCSEC_GSS. |
| ☐ | SV-282640r1200900_rule | TOSS 5 must prevent special devices on file systems that are imported via Network File System (NFS). |
| ☐ | SV-282641r1200903_rule | TOSS 5 cron configuration directories must have a mode of 0700 or less permissive. |
| ☐ | SV-282642r1200906_rule | All TOSS 5 local initialization files must have mode 0740 or less permissive. |
| ☐ | SV-282643r1200909_rule | All TOSS 5 local interactive user home directories must have mode 0770 or less permissive. |
| ☐ | SV-282644r1200912_rule | The TOSS 5 /etc/group file must have mode 0644 or less permissive to prevent unauthorized access. |
| ☐ | SV-282645r1200915_rule | The TOSS 5 /etc/group- file must have mode 0644 or less permissive to prevent unauthorized access. |
| ☐ | SV-282646r1200918_rule | The TOSS 5 /etc/gshadow file must have mode 0000 or less permissive to prevent unauthorized access. |
| ☐ | SV-282647r1200921_rule | The TOSS 5 /etc/gshadow- file must have mode 0000 or less permissive to prevent unauthorized access. |
| ☐ | SV-282648r1201583_rule | The TOSS 5 /etc/passwd file must have mode 0644 or less permissive to prevent unauthorized access. |
| ☐ | SV-282649r1200927_rule | The TOSS 5 /etc/passwd- file must have mode 0644 or less permissive to prevent unauthorized access. |
| ☐ | SV-282650r1200930_rule | The TOSS 5 /etc/shadow- file must have mode 0000 or less permissive to prevent unauthorized access. |
| ☐ | SV-282651r1200933_rule | The TOSS 5 /etc/group file must be owned by root. |
| ☐ | SV-282652r1200936_rule | The TOSS 5 /etc/group file must be group-owned by root. |
| ☐ | SV-282653r1200939_rule | The TOSS 5 /etc/group- file must be owned by root. |
| ☐ | SV-282654r1200942_rule | The TOSS 5 /etc/group- file must be group-owned by root. |
| ☐ | SV-282655r1200945_rule | The TOSS 5 /etc/gshadow file must be owned by root. |
| ☐ | SV-282656r1200948_rule | The TOSS 5 /etc/gshadow file must be group-owned by root. |
| ☐ | SV-282657r1200951_rule | The TOSS 5 /etc/gshadow- file must be owned by root. |
| ☐ | SV-282658r1200954_rule | The TOSS 5 /etc/gshadow- file must be group-owned by root. |
| ☐ | SV-282659r1200957_rule | The TOSS 5 /etc/passwd file must be owned by root. |
| ☐ | SV-282660r1200960_rule | The TOSS 5 /etc/passwd file must be group-owned by root. |
| ☐ | SV-282661r1200963_rule | The TOSS 5 /etc/passwd- file must be owned by root. |
| ☐ | SV-282662r1200966_rule | The TOSS 5 /etc/passwd- file must be group-owned by root. |
| ☐ | SV-282663r1200969_rule | The TOSS 5 /etc/shadow file must be owned by root. |
| ☐ | SV-282664r1200972_rule | The TOSS 5 /etc/shadow file must be group-owned by root. |
| ☐ | SV-282665r1200975_rule | The TOSS 5 /etc/shadow- file must be owned by root. |
| ☐ | SV-282666r1200978_rule | The TOSS 5 /etc/shadow- file must be group-owned by root. |
| ☐ | SV-282667r1200981_rule | The TOSS 5 cron configuration files directory must be owned by root. |
| ☐ | SV-282668r1200984_rule | The TOSS 5 cron configuration files directory must be group-owned by root. |
| ☐ | SV-282669r1200987_rule | All TOSS 5 world-writable directories must be owned by root, sys, bin, or an application user. |
| ☐ | SV-282670r1200990_rule | All TOSS 5 local files and directories must have a valid group owner. |
| ☐ | SV-282671r1200993_rule | All TOSS 5 local files and directories must have a valid owner. |
| ☐ | SV-282672r1200996_rule | TOSS 5 must be configured so that all system device files are correctly labeled to prevent unauthorized modification. |
| ☐ | SV-282673r1201585_rule | TOSS 5 /etc/crontab file must have mode 0600. |
| ☐ | SV-282674r1201002_rule | The TOSS 5 /etc/shadow file must have mode 0000 to prevent unauthorized access. |
| ☐ | SV-282675r1201005_rule | A TOSS 5 firewall must employ a deny-all, allow-by-exception policy for allowing connections to other systems. |
| ☐ | SV-282676r1201008_rule | TOSS 5 network interfaces must not be in promiscuous mode. |
| ☐ | SV-282677r1201330_rule | TOSS 5 must enable hardening for the Berkeley Packet Filter (BPF) just-in-time (JIT) compiler. |
| ☐ | SV-282678r1201587_rule | TOSS 5 systems using DNS resolution must have at least two name servers configured. |
| ☐ | SV-282679r1201334_rule | TOSS 5 must configure a DNS processing mode set in Network Manager. |
| ☐ | SV-282680r1201020_rule | TOSS 5 must not have unauthorized IP tunnels configured. |
| ☐ | SV-282681r1201023_rule | TOSS 5 must be configured to prevent unrestricted mail relaying. |
| ☐ | SV-282682r1201337_rule | If the Trivial File Transfer Protocol (TFTP) server is required, TOSS 5 TFTP daemon must be configured to operate in secure mode. |
| ☐ | SV-282683r1201340_rule | The TOSS 5 libreswan package must be installed. |
| ☐ | SV-282684r1201032_rule | There must be no .shosts files on TOSS 5. |
| ☐ | SV-282685r1201035_rule | TOSS 5 must ignore Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages. |
| ☐ | SV-282686r1201038_rule | TOSS 5 must not forward Internet Protocol version 4 (IPv4) source-routed packets. |
| ☐ | SV-282687r1201041_rule | TOSS 5 must log IPv4 packets with impossible addresses. |
| ☐ | SV-282688r1201044_rule | TOSS 5 must log IPv4 packets with impossible addresses by default. |
| ☐ | SV-282689r1201344_rule | TOSS 5 must use reverse path filtering on all IPv4 interfaces. |
| ☐ | SV-282690r1201050_rule | TOSS 5 must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted. |
| ☐ | SV-282691r1201053_rule | TOSS 5 must not forward IPv4 source-routed packets by default. |
| ☐ | SV-282692r1201056_rule | TOSS 5 must use a reverse-path filter for IPv4 network traffic when possible by default. |
| ☐ | SV-282693r1201059_rule | TOSS 5 must not respond to Internet Control Message Protocol (ICMP) echoes sent to a broadcast address. |
| ☐ | SV-282694r1201062_rule | TOSS 5 must limit the number of bogus Internet Control Message Protocol (ICMP) response errors logs. |
| ☐ | SV-282695r1201065_rule | TOSS 5 must not send Internet Control Message Protocol (ICMP) redirects. |
| ☐ | SV-282696r1201346_rule | TOSS 5 must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default. |
| ☐ | SV-282697r1201349_rule | TOSS 5 must not enable Internet Protocol version 4 (IPv4) packet forwarding unless the system is a router. |
| ☐ | SV-282698r1201350_rule | TOSS 5 must not accept router advertisements on all Internet Protocol version 6 (IPv6) interfaces. |
| ☐ | SV-282699r1201351_rule | TOSS 5 must ignore Internet Protocol version 6 (IPv6) Internet Control Message Protocol (ICMP) redirect messages. |
| ☐ | SV-282700r1201352_rule | TOSS 5 must not forward Internet Protocol version 6 (IPv6) source-routed packets. |
| ☐ | SV-282701r1201355_rule | TOSS 5 must not enable Internet Protocol version 6 (IPv6) packet forwarding unless the system is a router. |
| ☐ | SV-282702r1201356_rule | TOSS 5 must not accept router advertisements on all Internet Protocol version 6 (IPv6) interfaces by default. |
| ☐ | SV-282703r1201358_rule | TOSS 5 must prevent Internet Protocol version 6 (IPv6) Internet Control Message Protocol (ICMP) redirect messages from being accepted. |
| ☐ | SV-282704r1201359_rule | TOSS 5 must not forward Internet Protocol version 6 (IPv6) source-routed packets by default. |
| ☐ | SV-282705r1201362_rule | TOSS 5 must have the openssh-clients package installed. |
| ☐ | SV-282706r1201098_rule | The TOSS 5 SSH server configuration file must be group-owned by root. |
| ☐ | SV-282707r1201101_rule | The TOSS 5 SSH server configuration file must be owned by root. |
| ☐ | SV-282708r1201104_rule | The TOSS 5 SSH server configuration file must have mode 0600 or less permissive. |
| ☐ | SV-282709r1201369_rule | TOSS 5 SSH private host key files must have mode 0640 or less permissive. |
| ☐ | SV-282710r1201371_rule | TOSS 5 SSH public host key files must have mode 0644 or less permissive. |
| ☐ | SV-282711r1201373_rule | The TOSS 5 SSH daemon must not allow rhosts authentication. |
| ☐ | SV-282712r1201589_rule | The TOSS 5 SSH daemon must not allow known hosts authentication. |
| ☐ | SV-282713r1201377_rule | The TOSS 5 SSH daemon must perform strict mode checking of home directory configuration files. |
| ☐ | SV-282714r1201379_rule | The TOSS 5 SSH daemon must display the date and time of the last successful account logon upon an SSH logon. |
| ☐ | SV-282715r1201125_rule | The TOSS 5 effective dconf policy must match the policy keyfiles. |
| ☐ | SV-282716r1201128_rule | TOSS 5 must disable the ability of a user to restart the system from the login screen. |
| ☐ | SV-282717r1201644_rule | TOSS 5 must prevent a user from overriding the disable-restart-buttons setting for the graphical user interface. |
| ☐ | SV-282718r1201134_rule | TOSS 5 must disable the ability of a user to accidentally press Ctrl-Alt-Del and cause a system to shut down or reboot. |
| ☐ | SV-282719r1201137_rule | TOSS 5 must prevent a user from overriding the Ctrl-Alt-Del sequence settings for the graphical user interface. |
| ☐ | SV-282720r1201591_rule | TOSS 5 must disable the user list at logon for graphical user interfaces. |
| ☐ | SV-282721r1201143_rule | All TOSS 5 local interactive user accounts must be assigned a home directory upon creation. |
| ☐ | SV-282722r1201146_rule | TOSS 5 must set the umask value to 077 for all local interactive user accounts. |
| ☐ | SV-282723r1201149_rule | TOSS 5 system accounts must not have an interactive login shell. |
| ☐ | SV-282724r1201152_rule | Executable search paths within the initialization files of all local interactive TOSS 5 users must only contain paths that resolve to the system default or the users home directory. |
| ☐ | SV-282725r1201593_rule | All TOSS 5 local interactive users must have a home directory assigned in the /etc/passwd file. |
| ☐ | SV-282726r1201158_rule | All TOSS 5 local interactive user home directories defined in the /etc/passwd file must exist. |
| ☐ | SV-282727r1201161_rule | All TOSS 5 local interactive user home directories must be group-owned by the home directory owner's primary group. |
| ☐ | SV-282728r1201164_rule | TOSS 5 must not have unauthorized accounts. |
| ☐ | SV-282729r1201167_rule | The root account must be the only account with unrestricted access to TOSS 5 system. |
| ☐ | SV-282730r1201170_rule | Local TOSS 5 initialization files must not execute world-writable programs. |
| ☐ | SV-282731r1201173_rule | TOSS 5 must display the date and time of the last successful account logon upon user logon. |
| ☐ | SV-282732r1201176_rule | TOSS 5 must have policycoreutils package installed. |
| ☐ | SV-282733r1201179_rule | TOSS 5 policycoreutils-python-utils package must be installed. |
| ☐ | SV-282734r1201182_rule | TOSS 5 must require reauthentication when using the sudo command. |
| ☐ | SV-282735r1201185_rule | TOSS 5 must require users to reauthenticate for privilege escalation. |
| ☐ | SV-282736r1201188_rule | TOSS 5 must restrict privilege elevation to authorized personnel. |
| ☐ | SV-282737r1201191_rule | TOSS 5 must not allow blank or null passwords. |
| ☐ | SV-282738r1201194_rule | TOSS 5 must ensure the password complexity module is enabled in the system-auth file. |
| ☐ | SV-282739r1201595_rule | TOSS 5 must require users to provide a password for privilege escalation. |
| ☐ | SV-282740r1201200_rule | TOSS 5 must not be configured to bypass password requirements for privilege escalation. |
| ☐ | SV-282741r1201203_rule | TOSS 5 must not have accounts configured with blank or null passwords. |
| ☐ | SV-282742r1201206_rule | TOSS 5 must use a file integrity tool that is configured to use FIPS 140-3-approved cryptographic hashes for validating file contents and directories. |
| ☐ | SV-282743r1201209_rule | TOSS 5 must be configured so that the file integrity tool verifies Access Control Lists (ACLs). |
| ☐ | SV-282744r1201212_rule | TOSS 5 must be configured so the file integrity tool verifies extended attributes. |
| ☐ | SV-282745r1201645_rule | TOSS 5 must have the packages required for encrypting off-loaded audit logs installed. |
| ☐ | SV-282746r1201218_rule | The rsyslog service on TOSS 5 must be active. |
| ☐ | SV-282747r1201386_rule | TOSS 5 must be configured so the rsyslog daemon does not accept log messages from other servers unless the server is being used for log aggregation. |
| ☐ | SV-282748r1201388_rule | TOSS 5 must use cron logging. |
| ☐ | SV-282749r1201227_rule | The TOSS 5 audit system must take appropriate action when an error writing to the audit storage volume occurs. |
| ☐ | SV-282750r1201230_rule | The TOSS 5 audit system must take appropriate action when the audit storage volume is full. |
| ☐ | SV-282751r1201233_rule | The TOSS 5 audit system must take appropriate action when the audit files have reached maximum size. |
| ☐ | SV-282752r1201236_rule | TOSS 5 must write audit records to disk. |
| ☐ | SV-282753r1201612_rule | TOSS 5 must define default permissions for the bash shell. |
| ☐ | SV-282754r1201614_rule | TOSS 5 must define default permissions for the c shell. |
| ☐ | SV-282755r1201616_rule | TOSS 5 must define default permissions for all authenticated users in such a way that the user can only read and modify their own files. |
| ☐ | SV-282756r1201618_rule | TOSS 5 must define default permissions for the system default profile. |
| ☐ | SV-282757r1201251_rule | TOSS 5 must not allow an unattended or automatic logon to the system. |
| ☐ | SV-282758r1201254_rule | TOSS 5 must not allow users to override SSH environment variables. |
| ☐ | SV-282759r1201257_rule | TOSS 5 must not allow unattended or automatic logon via the graphical user interface. |
| ☐ | SV-282760r1201260_rule | All TOSS local interactive user home directories must have mode 0770 or less permissive. |
| ☐ | SV-282764r1201597_rule | TOSS 5 must, for password-based authentication, verify when users create or update passwords the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a). |
| ☐ | SV-282768r1201307_rule | TOSS 5 must accept only external credentials that are NIST compliant. |
| ☐ | SV-282770r1201607_rule | TOSS 5 must include only approved trust anchors in trust stores or certificate stores managed by the organization. |
| ☐ | SV-282771r1201293_rule | TOSS 5 must provide protected storage for cryptographic keys with organization-defined safeguards and/or hardware protected key store. |
| ☐ | SV-282772r1201296_rule | TOSS 5 must securely compare internal information system clocks at least every 24 hours. |