{
    "control": "AC-3",
    "title": "Access Enforcement",
    "ccis": [
        {
            "cci": "CCI-000021",
            "definition": "Enforce dual authorization for organization-defined privileged commands and/or other organization-defined actions."
        },
        {
            "cci": "CCI-000024",
            "definition": "Prevent access to organization-defined security-relevant information except during secure, non-operable system states."
        },
        {
            "cci": "CCI-000213",
            "definition": "Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies."
        },
        {
            "cci": "CCI-001408",
            "definition": "Defines privileged commands for which dual authorization is to be enforced."
        },
        {
            "cci": "CCI-001411",
            "definition": "Defines security-relevant information to which the system prevents access except during secure, non-operable system states."
        },
        {
            "cci": "CCI-002152",
            "definition": "Defines other actions necessary for which dual authorization is to be enforced."
        },
        {
            "cci": "CCI-002153",
            "definition": "Defines the mandatory access control policies that are to be enforced over all subjects and objects."
        },
        {
            "cci": "CCI-002154",
            "definition": "Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy, and where the policy is uniformly enforced across the covered subjects and objects within the system."
        },
        {
            "cci": "CCI-002155",
            "definition": "Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information is constrained from passing the information to unauthorized subjects or objects."
        },
        {
            "cci": "CCI-002156",
            "definition": "Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information is constrained from granting its privileges to other subjects."
        },
        {
            "cci": "CCI-002157",
            "definition": "Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information is constrained from changing one or more security attributes on subjects, objects, the system, or system components."
        },
        {
            "cci": "CCI-002158",
            "definition": "Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information is constrained from choosing the security attributes to be associated with newly created or modified objects."
        },
        {
            "cci": "CCI-002159",
            "definition": "Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information is constrained from choosing the attribute values to be associated with newly created or modified objects."
        },
        {
            "cci": "CCI-002160",
            "definition": "Enforce organization-defined mandatory access control policy over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information is constrained from changing the rules governing access control."
        },
        {
            "cci": "CCI-002161",
            "definition": "Defines subjects which may explicitly be granted organization-defined privileges such that they are not limited by any of the mandatory access control constraints."
        },
        {
            "cci": "CCI-002162",
            "definition": "Defines the privileges that may explicitly be granted to organization-defined subjects such that they are not limited by any of the mandatory access control constraints."
        },
        {
            "cci": "CCI-002163",
            "definition": "Defines the discretionary access control policies the information system is to enforce over subjects and objects."
        },
        {
            "cci": "CCI-002164",
            "definition": "Enforce organization-defined discretionary access control policy that over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information can do one or more of the following: pass the information to any other subjects or objects; grant its privileges to other subjects; change security attributes on subjects, objects, the system, or the system's components; choose the security attributes to be associated with newly created or revised objects; and/or change the rules governing access control."
        },
        {
            "cci": "CCI-002165",
            "definition": "Enforce organization-defined discretionary access control policies over defined subjects and objects."
        },
        {
            "cci": "CCI-002166",
            "definition": "Defines the role-based access control policies to enforce over all subjects and objects."
        },
        {
            "cci": "CCI-002167",
            "definition": "The organization defines the subjects over which the information system will enforce a role-based access control policy."
        },
        {
            "cci": "CCI-002168",
            "definition": "The organization defines the objects over which the information system will enforce a role-based access control policy."
        },
        {
            "cci": "CCI-002169",
            "definition": "Enforce a role-based access control policy over defined subjects and objects based upon organization-defined roles and users authorized to assume such roles."
        },
        {
            "cci": "CCI-002170",
            "definition": "Control access based upon organization-defined roles and users authorized to assume such roles."
        },
        {
            "cci": "CCI-002171",
            "definition": "The information system enforces a role-based access control policy over organization-defined subjects."
        },
        {
            "cci": "CCI-002172",
            "definition": "The information system enforces a role-based access control policy over organization-defined objects."
        },
        {
            "cci": "CCI-002173",
            "definition": "Defines the roles authorized to control access based upon the role-based access control policy."
        },
        {
            "cci": "CCI-002174",
            "definition": "Defines the users authorized to control access based upon the role-based access control policy."
        },
        {
            "cci": "CCI-002175",
            "definition": "The information system controls access based upon organization-defined roles authorized to assume such roles, employing the organization-defined role-based access control policy."
        },
        {
            "cci": "CCI-002176",
            "definition": "The information system controls access based upon organization-defined users authorized to assume such roles, employing the organization-defined role-based access control policy."
        },
        {
            "cci": "CCI-002177",
            "definition": "Defines the rules governing the timing of revocation of access authorizations."
        },
        {
            "cci": "CCI-002178",
            "definition": "Enforce the revocation of access authorizations resulting from changes to the security attributes of subjects based on organization-defined rules governing the timing of revocations of access authorizations."
        },
        {
            "cci": "CCI-002179",
            "definition": "Enforce the revocation of access authorizations resulting from changes to the security attributes of objects based on organization-defined rules governing the timing of revocations of access authorizations."
        },
        {
            "cci": "CCI-002180",
            "definition": "Defines the controls the organization-defined system or system component is to provide to protect information released outside the established system boundary."
        },
        {
            "cci": "CCI-002181",
            "definition": "Defines system or system components that are to provide organization-defined controls to protect information received outside the established system boundary."
        },
        {
            "cci": "CCI-002182",
            "definition": "Release information outside of the established system boundary only if organization-defined system or system components provides organization-defined controls."
        },
        {
            "cci": "CCI-002183",
            "definition": "Defines the controls to be used to validate the appropriateness of the information designated for release."
        },
        {
            "cci": "CCI-002184",
            "definition": "Release information outside of the established system boundary only if organization-defined controls are used to validate the appropriateness of the information designated for release."
        },
        {
            "cci": "CCI-002185",
            "definition": "Defines the conditions on which it will employ an audited override of automated access control mechanisms."
        },
        {
            "cci": "CCI-002186",
            "definition": "Employ an audited override of automated access control mechanisms under organization-defined conditions by organization-defined roles."
        },
        {
            "cci": "CCI-003014",
            "definition": "Enforce organization-defined mandatory access control policies over all subjects and objects."
        },
        {
            "cci": "CCI-003015",
            "definition": "Specifies that organization-defined subjects may explicitly be granted organization-defined privileges such that they are not limited by any defined subset (or all) of the above constraints."
        }
    ],
    "rules_mapped": 92,
    "rules": [
        {
            "rule": "V-242382",
            "stig_id": "CNTR-K8-000270",
            "title": "The Kubernetes API Server must enable Node,RBAC as the authorization mode.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-242384",
            "stig_id": "CNTR-K8-000300",
            "title": "The Kubernetes Scheduler must have secure binding.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-242385",
            "stig_id": "CNTR-K8-000310",
            "title": "The Kubernetes Controller Manager must have secure binding.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-242386",
            "stig_id": "CNTR-K8-000320",
            "title": "The Kubernetes API server must have the insecure port flag disabled.",
            "severity": "high",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-242387",
            "stig_id": "CNTR-K8-000330",
            "title": "The Kubernetes Kubelet must have the \"readOnlyPort\" flag disabled.",
            "severity": "high",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-242388",
            "stig_id": "CNTR-K8-000340",
            "title": "The Kubernetes API server must have the insecure bind address not set.",
            "severity": "high",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-242389",
            "stig_id": "CNTR-K8-000350",
            "title": "The Kubernetes API server must have the secure port set.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-242390",
            "stig_id": "CNTR-K8-000360",
            "title": "The Kubernetes API server must have anonymous authentication disabled.",
            "severity": "high",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-242391",
            "stig_id": "CNTR-K8-000370",
            "title": "The Kubernetes Kubelet must have anonymous authentication disabled.",
            "severity": "high",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-242392",
            "stig_id": "CNTR-K8-000380",
            "title": "The Kubernetes kubelet must enable explicit authorization.",
            "severity": "high",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-242393",
            "stig_id": "CNTR-K8-000400",
            "title": "Kubernetes Worker Nodes must not have sshd service running.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-242394",
            "stig_id": "CNTR-K8-000410",
            "title": "Kubernetes Worker Nodes must not have the sshd service enabled.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-242395",
            "stig_id": "CNTR-K8-000420",
            "title": "Kubernetes dashboard must not be enabled.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-242396",
            "stig_id": "CNTR-K8-000430",
            "title": "Kubernetes Kubectl cp command must give expected access and results.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-242397",
            "stig_id": "CNTR-K8-000440",
            "title": "The Kubernetes kubelet staticPodPath must not enable static pods.",
            "severity": "high",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-242398",
            "stig_id": "CNTR-K8-000450",
            "title": "Kubernetes DynamicAuditing must not be enabled.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-242399",
            "stig_id": "CNTR-K8-000460",
            "title": "Kubernetes DynamicKubeletConfig must not be enabled.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-242400",
            "stig_id": "CNTR-K8-000470",
            "title": "The Kubernetes API server must have Alpha APIs disabled.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-274882",
            "stig_id": "CNTR-K8-001162",
            "title": "Kubernetes Secrets must be encrypted at rest.",
            "severity": "high",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-220708",
            "stig_id": "WN10-00-000050",
            "title": "Local volumes must be formatted using NTFS.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-220717",
            "stig_id": "WN10-00-000095",
            "title": "Permissions for system files and directories must conform to minimum requirements.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002165"
            ]
        },
        {
            "rule": "V-220957",
            "stig_id": "WN10-UR-000010",
            "title": "The Access this computer from the network user right must only be assigned to the Administrators and Remote Desktop Users groups.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-220959",
            "stig_id": "WN10-UR-000025",
            "title": "The Allow log on locally user right must only be assigned to the Administrators and Users groups.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-220968",
            "stig_id": "WN10-UR-000070",
            "title": "The Deny access to this computer from the network user right on workstations must be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-220969",
            "stig_id": "WN10-UR-000075",
            "title": "The \"Deny log on as a batch job\" user right on domain-joined workstations must be configured to prevent access from highly privileged domain accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-220970",
            "stig_id": "WN10-UR-000080",
            "title": "The Deny log on as a service user right on Windows 10 domain-joined workstations must be configured to prevent access from highly privileged domain accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-220971",
            "stig_id": "WN10-UR-000085",
            "title": "The Deny log on locally user right on workstations must be configured to prevent access from highly privileged domain accounts on domain systems and unauthenticated access on all systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-220972",
            "stig_id": "WN10-UR-000090",
            "title": "The Deny log on through Remote Desktop Services user right on Windows 10 workstations must at a minimum be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000213",
                "CCI-002314"
            ]
        },
        {
            "rule": "V-253265",
            "stig_id": "WN11-00-000050",
            "title": "Local volumes must be formatted using NTFS.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-253269",
            "stig_id": "WN11-00-000070",
            "title": "Only accounts responsible for the administration of a system must have Administrator rights on the system.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002165"
            ]
        },
        {
            "rule": "V-253271",
            "stig_id": "WN11-00-000080",
            "title": "Only authorized user accounts must be allowed to create or run virtual machines on Windows 11 systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002165"
            ]
        },
        {
            "rule": "V-253274",
            "stig_id": "WN11-00-000095",
            "title": "Permissions for system files and directories must conform to minimum requirements.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002165"
            ]
        },
        {
            "rule": "V-253480",
            "stig_id": "WN11-UR-000010",
            "title": "The \"Access this computer from the network\" user right must only be assigned to the Administrators and Remote Desktop Users groups.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-253482",
            "stig_id": "WN11-UR-000025",
            "title": "The \"Allow log on locally\" user right must only be assigned to the Administrators and Users groups.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-253491",
            "stig_id": "WN11-UR-000070",
            "title": "The \"Deny access to this computer from the network\" user right on workstations must be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-253492",
            "stig_id": "WN11-UR-000075",
            "title": "The \"Deny log on as a batch job\" user right on domain-joined workstations must be configured to prevent access from highly privileged domain accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-253493",
            "stig_id": "WN11-UR-000080",
            "title": "The \"Deny log on as a service\" user right on Windows 11 domain-joined workstations must be configured to prevent access from highly privileged domain accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-253494",
            "stig_id": "WN11-UR-000085",
            "title": "The \"Deny log on locally\" user right on workstations must be configured to prevent access from highly privileged domain accounts on domain systems and unauthenticated access on all systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-253495",
            "stig_id": "WN11-UR-000090",
            "title": "The \"Deny log on through Remote Desktop Services\" user right on Windows 11 workstations must be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000213",
                "CCI-002314"
            ]
        },
        {
            "rule": "V-205663",
            "stig_id": "WN19-00-000130",
            "title": "Windows Server 2019 local volumes must use a format that supports NTFS attributes.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-205664",
            "stig_id": "WN19-00-000180",
            "title": "Windows Server 2019 non-administrative accounts or groups must only have print permissions on printer shares.",
            "severity": "low",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-205665",
            "stig_id": "WN19-DC-000340",
            "title": "Windows Server 2019 Access this computer from the network user right must only be assigned to the Administrators, Authenticated Users, and \nEnterprise Domain Controllers groups on domain controllers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-205666",
            "stig_id": "WN19-DC-000360",
            "title": "Windows Server 2019 Allow log on through Remote Desktop Services user right must only be assigned to the Administrators group on domain controllers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-205667",
            "stig_id": "WN19-DC-000370",
            "title": "Windows Server 2019 Deny access to this computer from the network user right on domain controllers must be configured to prevent unauthenticated access.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-205668",
            "stig_id": "WN19-DC-000380",
            "title": "Windows Server 2019 Deny log on as a batch job user right on domain controllers must be configured to prevent unauthenticated access.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-205669",
            "stig_id": "WN19-DC-000390",
            "title": "Windows Server 2019 Deny log on as a service user right must be configured to include no accounts or groups (blank) on domain controllers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-205670",
            "stig_id": "WN19-DC-000400",
            "title": "Windows Server 2019 Deny log on locally user right on domain controllers must be configured to prevent unauthenticated access.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-205671",
            "stig_id": "WN19-MS-000070",
            "title": "Windows Server 2019 \"Access this computer from the network\" user right must only be assigned to the Administrators and Authenticated Users groups on domain-joined member servers and standalone or nondomain-joined systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-205672",
            "stig_id": "WN19-MS-000080",
            "title": "Windows Server 2019 \"Deny access to this computer from the network\" user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and local accounts and from unauthenticated access on all systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-205673",
            "stig_id": "WN19-MS-000090",
            "title": "Windows Server 2019 \"Deny log on as a batch job\" user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and from unauthenticated access on all systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-205674",
            "stig_id": "WN19-MS-000100",
            "title": "Windows Server 2019 \"Deny log on as a service\" user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts. No other groups or accounts must be assigned this right.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-205675",
            "stig_id": "WN19-MS-000110",
            "title": "Windows Server 2019 \"Deny log on locally\" user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and from unauthenticated access on all systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-205676",
            "stig_id": "WN19-UR-000030",
            "title": "Windows Server 2019 Allow log on locally user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-205734",
            "stig_id": "WN19-00-000140",
            "title": "Windows Server 2019 permissions for the system drive root directory (usually C:\\) must conform to minimum requirements.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002165"
            ]
        },
        {
            "rule": "V-205735",
            "stig_id": "WN19-00-000150",
            "title": "Windows Server 2019 permissions for program file directories must conform to minimum requirements.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002165"
            ]
        },
        {
            "rule": "V-205736",
            "stig_id": "WN19-00-000160",
            "title": "Windows Server 2019 permissions for the Windows installation directory must conform to minimum requirements.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002165"
            ]
        },
        {
            "rule": "V-271428",
            "stig_id": "WN19-DC-000391",
            "title": "Windows Server 2019 must be configured for certificate-based authentication for domain controllers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-271429",
            "stig_id": "WN19-DC-000401",
            "title": "Windows Server 2019 must be configured for named-based strong mappings for certificates.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-254250",
            "stig_id": "WN22-00-000130",
            "title": "Windows Server 2022 local volumes must use a format that supports NTFS attributes.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-254251",
            "stig_id": "WN22-00-000140",
            "title": "Windows Server 2022 permissions for the system drive root directory (usually C:\\) must conform to minimum requirements.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002165"
            ]
        },
        {
            "rule": "V-254252",
            "stig_id": "WN22-00-000150",
            "title": "Windows Server 2022 permissions for program file directories must conform to minimum requirements.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002165"
            ]
        },
        {
            "rule": "V-254253",
            "stig_id": "WN22-00-000160",
            "title": "Windows Server 2022 permissions for the Windows installation directory must conform to minimum requirements.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002165"
            ]
        },
        {
            "rule": "V-254255",
            "stig_id": "WN22-00-000180",
            "title": "Windows Server 2022 nonadministrative accounts or groups must only have print permissions on printer shares.",
            "severity": "low",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-254418",
            "stig_id": "WN22-DC-000340",
            "title": "Windows Server 2022 Access this computer from the network user right must only be assigned to the Administrators, Authenticated Users, and \nEnterprise Domain Controllers groups on domain controllers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-254420",
            "stig_id": "WN22-DC-000360",
            "title": "Windows Server 2022 Allow log on through Remote Desktop Services user right must only be assigned to the Administrators group on domain controllers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-254421",
            "stig_id": "WN22-DC-000370",
            "title": "Windows Server 2022 Deny access to this computer from the network user right on domain controllers must be configured to prevent unauthenticated access.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-254422",
            "stig_id": "WN22-DC-000380",
            "title": "Windows Server 2022 Deny log on as a batch job user right on domain controllers must be configured to prevent unauthenticated access.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-254423",
            "stig_id": "WN22-DC-000390",
            "title": "Windows Server 2022 Deny log on as a service user right must be configured to include no accounts or groups (blank) on domain controllers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-254424",
            "stig_id": "WN22-DC-000400",
            "title": "Windows Server 2022 Deny log on locally user right on domain controllers must be configured to prevent unauthenticated access.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-254434",
            "stig_id": "WN22-MS-000070",
            "title": "Windows Server 2022 Access this computer from the network user right must only be assigned to the Administrators and Authenticated Users groups on domain-joined member servers and standalone or nondomain-joined systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-254435",
            "stig_id": "WN22-MS-000080",
            "title": "Windows Server 2022 Deny access to this computer from the network user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and local accounts and from unauthenticated access on all systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-254436",
            "stig_id": "WN22-MS-000090",
            "title": "Windows Server 2022 Deny log on as a batch job user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and from unauthenticated access on all systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-254437",
            "stig_id": "WN22-MS-000100",
            "title": "Windows Server 2022 Deny log on as a service user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts. No other groups or accounts must be assigned this right.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-254438",
            "stig_id": "WN22-MS-000110",
            "title": "Windows Server 2022 Deny log on locally user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and from unauthenticated access on all systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-254493",
            "stig_id": "WN22-UR-000030",
            "title": "Windows Server 2022 Allow log on locally user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-271426",
            "stig_id": "WN22-DC-000405",
            "title": "Windows Server 2022 must be configured for certificate-based authentication for domain controllers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-271427",
            "stig_id": "WN22-DC-000406",
            "title": "Windows Server 2022 must be configured for name-based strong mappings for certificates.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-230234",
            "stig_id": "RHEL-08-010140",
            "title": "RHEL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must require authentication upon booting into single-user mode and maintenance.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-230235",
            "stig_id": "RHEL-08-010150",
            "title": "RHEL 8 operating systems booted with a BIOS must require authentication upon booting into single-user and maintenance modes.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-230236",
            "stig_id": "RHEL-08-010151",
            "title": "RHEL 8 operating systems must require authentication upon booting into rescue mode.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-230267",
            "stig_id": "RHEL-08-010373",
            "title": "RHEL 8 must enable kernel parameters to enforce discretionary access control on symlinks.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-002165"
            ]
        },
        {
            "rule": "V-230268",
            "stig_id": "RHEL-08-010374",
            "title": "RHEL 8 must enable kernel parameters to enforce discretionary access control on hardlinks.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-002165"
            ]
        },
        {
            "rule": "V-244521",
            "stig_id": "RHEL-08-010141",
            "title": "RHEL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must require a unique superusers name upon booting into single-user mode and maintenance.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-244522",
            "stig_id": "RHEL-08-010149",
            "title": "RHEL 8 operating systems booted with a BIOS must require  a unique superusers name upon booting into single-user and maintenance modes.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-244523",
            "stig_id": "RHEL-08-010152",
            "title": "RHEL 8 operating systems must require authentication upon booting into emergency mode.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-257787",
            "stig_id": "RHEL-09-212010",
            "title": "RHEL 9 must require a boot loader superuser password.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-257789",
            "stig_id": "RHEL-09-212020",
            "title": "RHEL 9 must require a unique superusers name upon booting into single-user and maintenance modes.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-257801",
            "stig_id": "RHEL-09-213030",
            "title": "RHEL 9 must enable kernel parameters to enforce discretionary access control on hardlinks.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002165",
                "CCI-002235"
            ]
        },
        {
            "rule": "V-257802",
            "stig_id": "RHEL-09-213035",
            "title": "RHEL 9 must enable kernel parameters to enforce discretionary access control on symlinks.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002165",
                "CCI-002235"
            ]
        },
        {
            "rule": "V-258088",
            "stig_id": "RHEL-09-432035",
            "title": "RHEL 9 must restrict the use of the \"su\" command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002038",
                "CCI-002165",
                "CCI-004895"
            ]
        },
        {
            "rule": "V-258128",
            "stig_id": "RHEL-09-611195",
            "title": "RHEL 9 must require authentication to access emergency mode.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000213"
            ]
        },
        {
            "rule": "V-258129",
            "stig_id": "RHEL-09-611200",
            "title": "RHEL 9 must require authentication to access single-user mode.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000213"
            ]
        }
    ]
}