{
    "control": "AC-6",
    "title": "Least Privilege",
    "ccis": [
        {
            "cci": "CCI-000039",
            "definition": "Require that users of system accounts, or roles, with access to organization-defined security functions or security-relevant information, use non-privileged accounts or roles, when accessing nonsecurity functions."
        },
        {
            "cci": "CCI-000041",
            "definition": "Authorize network access to organization-defined privileged commands only for organization-defined compelling operational needs."
        },
        {
            "cci": "CCI-000042",
            "definition": "Document the rationale for authorized network access to organization-defined privileged commands in the security plan for the system."
        },
        {
            "cci": "CCI-000225",
            "definition": "Employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned organizational tasks."
        },
        {
            "cci": "CCI-001419",
            "definition": "Defines the security functions or security-relevant information to which users of system accounts, or roles, have access."
        },
        {
            "cci": "CCI-001420",
            "definition": "Defines the privileged commands to which network access is to be authorized only for organization-defined compelling operational needs."
        },
        {
            "cci": "CCI-001422",
            "definition": "Prohibit privileged access to the system by non-organizational users."
        },
        {
            "cci": "CCI-001558",
            "definition": "Defines the security functions (deployed in hardware, software, and firmware) for which access must be authorized."
        },
        {
            "cci": "CCI-002221",
            "definition": "Defines the security-relevant information for which access must be explicitly authorized."
        },
        {
            "cci": "CCI-002222",
            "definition": "Authorize access for organization-defined individuals or roles to organization-defined security functions (deployed in hardware, software, and firmware)."
        },
        {
            "cci": "CCI-002223",
            "definition": "Authorize access for organization-defined individuals or roles to organization-defined security-relevant information."
        },
        {
            "cci": "CCI-002224",
            "definition": "Defines the compelling operational needs that must be met in order to be authorized network access to organization-defined privileged commands."
        },
        {
            "cci": "CCI-002225",
            "definition": "Provide separate processing domains to enable finer-grained allocation of user privileges."
        },
        {
            "cci": "CCI-002226",
            "definition": "Defines the personnel or roles to whom privileged accounts are to be restricted on the information system."
        },
        {
            "cci": "CCI-002227",
            "definition": "Restrict privileged accounts on the system to organization-defined personnel or roles."
        },
        {
            "cci": "CCI-002228",
            "definition": "Defines the frequency on which it conducts reviews of the privileges assigned to organization-defined roles or classes of users."
        },
        {
            "cci": "CCI-002229",
            "definition": "Defines the roles or classes of users that are to have their privileges reviewed on an organization-defined frequency."
        },
        {
            "cci": "CCI-002230",
            "definition": "Review, on an organization-defined frequency, the privileges assigned to organization-defined roles or classes of users to validate the need for such privileges."
        },
        {
            "cci": "CCI-002231",
            "definition": "Reassign or remove privileges, if necessary, to correctly reflect organizational mission and business needs."
        },
        {
            "cci": "CCI-002232",
            "definition": "Defines the software that is prevented from executing at a higher privilege than users executing the software."
        },
        {
            "cci": "CCI-002233",
            "definition": "Prevent the organization-defined software from executing at higher privilege levels than users executing the software."
        },
        {
            "cci": "CCI-002234",
            "definition": "Log the execution of privileged functions."
        },
        {
            "cci": "CCI-002235",
            "definition": "Prevent non-privileged users from executing privileged functions."
        }
    ],
    "rules_mapped": 184,
    "rules": [
        {
            "rule": "V-220712",
            "stig_id": "WN10-00-000070",
            "title": "Only accounts responsible for the administration of a system must have Administrator rights on the system.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-220750",
            "stig_id": "WN10-AU-000030",
            "title": "The system must be configured to audit Account Management - Security Group Management successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-220751",
            "stig_id": "WN10-AU-000035",
            "title": "The system must be configured to audit Account Management - User Account Management failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-220752",
            "stig_id": "WN10-AU-000040",
            "title": "The system must be configured to audit Account Management - User Account Management successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-220768",
            "stig_id": "WN10-AU-000105",
            "title": "The system must be configured to audit Policy Change - Authentication Policy Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-220770",
            "stig_id": "WN10-AU-000110",
            "title": "The system must be configured to audit Privilege Use - Sensitive Privilege Use failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-220771",
            "stig_id": "WN10-AU-000115",
            "title": "The system must be configured to audit Privilege Use - Sensitive Privilege Use successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-220775",
            "stig_id": "WN10-AU-000140",
            "title": "The system must be configured to audit System - Security State Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-220776",
            "stig_id": "WN10-AU-000150",
            "title": "The system must be configured to audit System - Security System Extension successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-220777",
            "stig_id": "WN10-AU-000155",
            "title": "The system must be configured to audit System - System Integrity failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-220778",
            "stig_id": "WN10-AU-000160",
            "title": "The system must be configured to audit System - System Integrity successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-220907",
            "stig_id": "WN10-RG-000005",
            "title": "Default permissions for the HKEY_LOCAL_MACHINE registry hive must be maintained.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-220933",
            "stig_id": "WN10-SO-000167",
            "title": "Remote calls to the Security Account Manager (SAM) must be restricted to Administrators.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-220956",
            "stig_id": "WN10-UR-000005",
            "title": "The Access Credential Manager as a trusted caller user right must not be assigned to any groups or accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-220958",
            "stig_id": "WN10-UR-000015",
            "title": "The Act as part of the operating system user right must not be assigned to any groups or accounts.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-220960",
            "stig_id": "WN10-UR-000030",
            "title": "The Back up files and directories user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-220961",
            "stig_id": "WN10-UR-000035",
            "title": "The Change the system time user right must only be assigned to Administrators and Local Service and NT SERVICE\\autotimesvc.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-220962",
            "stig_id": "WN10-UR-000040",
            "title": "The Create a pagefile user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-220963",
            "stig_id": "WN10-UR-000045",
            "title": "The Create a token object user right must not be assigned to any groups or accounts.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-220964",
            "stig_id": "WN10-UR-000050",
            "title": "The Create global objects user right must only be assigned to Administrators, Service, Local Service, and Network Service.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-220965",
            "stig_id": "WN10-UR-000055",
            "title": "The Create permanent shared objects user right must not be assigned to any groups or accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-220966",
            "stig_id": "WN10-UR-000060",
            "title": "The Create symbolic links user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-220967",
            "stig_id": "WN10-UR-000065",
            "title": "The Debug programs user right must only be assigned to the Administrators group.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-220973",
            "stig_id": "WN10-UR-000095",
            "title": "The Enable computer and user accounts to be trusted for delegation user right must not be assigned to any groups or accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-220974",
            "stig_id": "WN10-UR-000100",
            "title": "The Force shutdown from a remote system user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-220975",
            "stig_id": "WN10-UR-000110",
            "title": "The Impersonate a client after authentication user right must only be assigned to Administrators, Service, Local Service, and Network Service.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-220976",
            "stig_id": "WN10-UR-000120",
            "title": "The Load and unload device drivers user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-220977",
            "stig_id": "WN10-UR-000125",
            "title": "The Lock pages in memory user right must not be assigned to any groups or accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-220979",
            "stig_id": "WN10-UR-000140",
            "title": "The Modify firmware environment values user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-220980",
            "stig_id": "WN10-UR-000145",
            "title": "The Perform volume maintenance tasks user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-220981",
            "stig_id": "WN10-UR-000150",
            "title": "The Profile single process user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-220982",
            "stig_id": "WN10-UR-000160",
            "title": "The Restore files and directories user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-220983",
            "stig_id": "WN10-UR-000165",
            "title": "The Take ownership of files or other objects user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-257589",
            "stig_id": "WN10-AU-000585",
            "title": "Windows 10 must have command line process auditing events enabled for failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002234"
            ]
        },
        {
            "rule": "V-253328",
            "stig_id": "WN11-AU-000110",
            "title": "The system must be configured to audit Privilege Use - Sensitive Privilege Use failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002234"
            ]
        },
        {
            "rule": "V-253431",
            "stig_id": "WN11-RG-000005",
            "title": "Default permissions for the HKEY_LOCAL_MACHINE registry hive must be maintained.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-253457",
            "stig_id": "WN11-SO-000167",
            "title": "Remote calls to the Security Account Manager (SAM) must be restricted to Administrators.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-253479",
            "stig_id": "WN11-UR-000005",
            "title": "The \"Access Credential Manager as a trusted caller\" user right must not be assigned to any groups or accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-253481",
            "stig_id": "WN11-UR-000015",
            "title": "The \"Act as part of the operating system\" user right must not be assigned to any groups or accounts.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-253483",
            "stig_id": "WN11-UR-000030",
            "title": "The \"Back up files and directories\" user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-253484",
            "stig_id": "WN11-UR-000035",
            "title": "The \"Change the system time\" user right must only be assigned to Administrators and Local Service.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-253485",
            "stig_id": "WN11-UR-000040",
            "title": "The \"Create a pagefile\" user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-253486",
            "stig_id": "WN11-UR-000045",
            "title": "The \"Create a token object\" user right must not be assigned to any groups or accounts.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-253487",
            "stig_id": "WN11-UR-000050",
            "title": "The \"Create global objects\" user right must only be assigned to Administrators, Service, Local Service, and Network Service.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-253488",
            "stig_id": "WN11-UR-000055",
            "title": "The \"Create permanent shared objects\" user right must not be assigned to any groups or accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-253489",
            "stig_id": "WN11-UR-000060",
            "title": "The \"Create symbolic links\" user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-253490",
            "stig_id": "WN11-UR-000065",
            "title": "The \"Debug programs\" user right must only be assigned to the Administrators group.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-253496",
            "stig_id": "WN11-UR-000095",
            "title": "The \"Enable computer and user accounts to be trusted for delegation\" user right must not be assigned to any groups or accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-253497",
            "stig_id": "WN11-UR-000100",
            "title": "The \"Force shutdown from a remote system\" user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-253498",
            "stig_id": "WN11-UR-000110",
            "title": "The \"Impersonate a client after authentication\" user right must only be assigned to Administrators, Service, Local Service, and Network Service.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-253499",
            "stig_id": "WN11-UR-000120",
            "title": "The \"Load and unload device drivers\" user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-253500",
            "stig_id": "WN11-UR-000125",
            "title": "The \"Lock pages in memory\" user right must not be assigned to any groups or accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-253502",
            "stig_id": "WN11-UR-000140",
            "title": "The \"Modify firmware environment values\" user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-253503",
            "stig_id": "WN11-UR-000145",
            "title": "The \"Perform volume maintenance tasks\" user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-253504",
            "stig_id": "WN11-UR-000150",
            "title": "The \"Profile single process\" user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-253505",
            "stig_id": "WN11-UR-000160",
            "title": "The \"Restore files and directories\" user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-253506",
            "stig_id": "WN11-UR-000165",
            "title": "The \"Take ownership of files or other objects\" user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-257770",
            "stig_id": "WN11-AU-000585",
            "title": "Windows 11 must have command line process auditing events enabled for failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205737",
            "stig_id": "WN19-00-000170",
            "title": "Windows Server 2019 default permissions for the HKEY_LOCAL_MACHINE registry hive must be maintained.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205738",
            "stig_id": "WN19-DC-000010",
            "title": "Windows Server 2019 must only allow administrators responsible for the domain controller to have Administrator rights on the system.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205739",
            "stig_id": "WN19-DC-000070",
            "title": "Windows Server 2019 permissions on the Active Directory data files must only allow System and Administrators access.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205740",
            "stig_id": "WN19-DC-000080",
            "title": "Windows Server 2019 Active Directory SYSVOL directory must have the proper access control permissions.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205741",
            "stig_id": "WN19-DC-000090",
            "title": "Windows Server 2019 Active Directory Group Policy objects must have proper access control permissions.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205742",
            "stig_id": "WN19-DC-000100",
            "title": "Windows Server 2019 Active Directory Domain Controllers Organizational Unit (OU) object must have the proper access control permissions.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205743",
            "stig_id": "WN19-DC-000110",
            "title": "Windows Server 2019 organization created Active Directory Organizational Unit (OU) objects must have proper access control permissions.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205744",
            "stig_id": "WN19-DC-000350",
            "title": "Windows Server 2019 Add workstations to domain user right must only be assigned to the Administrators group on domain controllers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205745",
            "stig_id": "WN19-DC-000420",
            "title": "Windows Server 2019 Enable computer and user accounts to be trusted for delegation user right must only be assigned to the Administrators group on domain controllers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205746",
            "stig_id": "WN19-MS-000010",
            "title": "Windows Server 2019 must only allow Administrators responsible for the member server or standalone or nondomain-joined system to have Administrator rights on the system.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205747",
            "stig_id": "WN19-MS-000060",
            "title": "Windows Server 2019 must restrict remote calls to the Security Account Manager (SAM) to Administrators on domain-joined member servers and standalone or nondomain-joined systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205748",
            "stig_id": "WN19-MS-000130",
            "title": "Windows Server 2019 \"Enable computer and user accounts to be trusted for delegation\" user right must not be assigned to any groups or accounts on domain-joined member servers and standalone or nondomain-joined systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205749",
            "stig_id": "WN19-UR-000010",
            "title": "Windows Server 2019 Access Credential Manager as a trusted caller user right must not be assigned to any groups or accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205750",
            "stig_id": "WN19-UR-000020",
            "title": "Windows Server 2019 Act as part of the operating system user right must not be assigned to any groups or accounts.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205751",
            "stig_id": "WN19-UR-000040",
            "title": "Windows Server 2019 Back up files and directories user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205752",
            "stig_id": "WN19-UR-000050",
            "title": "Windows Server 2019 Create a pagefile user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205753",
            "stig_id": "WN19-UR-000060",
            "title": "Windows Server 2019 Create a token object user right must not be assigned to any groups or accounts.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205754",
            "stig_id": "WN19-UR-000070",
            "title": "Windows Server 2019 Create global objects user right must only be assigned to Administrators, Service, Local Service, and Network Service.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205755",
            "stig_id": "WN19-UR-000080",
            "title": "Windows Server 2019 Create permanent shared objects user right must not be assigned to any groups or accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205756",
            "stig_id": "WN19-UR-000090",
            "title": "Windows Server 2019 Create symbolic links user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205757",
            "stig_id": "WN19-UR-000100",
            "title": "Windows Server 2019 Debug programs: user right must only be assigned to the Administrators group.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205758",
            "stig_id": "WN19-UR-000110",
            "title": "Windows Server 2019 Force shutdown from a remote system user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205759",
            "stig_id": "WN19-UR-000120",
            "title": "Windows Server 2019 Generate security audits user right must only be assigned to Local Service and Network Service.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205760",
            "stig_id": "WN19-UR-000130",
            "title": "Windows Server 2019 Impersonate a client after authentication user right must only be assigned to Administrators, Service, Local Service, and Network Service.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205761",
            "stig_id": "WN19-UR-000140",
            "title": "Windows Server 2019 Increase scheduling priority: user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205762",
            "stig_id": "WN19-UR-000150",
            "title": "Windows Server 2019 Load and unload device drivers user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205763",
            "stig_id": "WN19-UR-000160",
            "title": "Windows Server 2019 Lock pages in memory user right must not be assigned to any groups or accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205764",
            "stig_id": "WN19-UR-000180",
            "title": "Windows Server 2019 Modify firmware environment values user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205765",
            "stig_id": "WN19-UR-000190",
            "title": "Windows Server 2019 Perform volume maintenance tasks user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205766",
            "stig_id": "WN19-UR-000200",
            "title": "Windows Server 2019 Profile single process user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205767",
            "stig_id": "WN19-UR-000210",
            "title": "Windows Server 2019 Restore files and directories user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205768",
            "stig_id": "WN19-UR-000220",
            "title": "Windows Server 2019 Take ownership of files or other objects user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-205769",
            "stig_id": "WN19-AU-000090",
            "title": "Windows Server 2019 must be configured to audit Account Management - Other Account Management Events successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205770",
            "stig_id": "WN19-AU-000140",
            "title": "Windows Server 2019 must be configured to audit Detailed Tracking - Process Creation successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205771",
            "stig_id": "WN19-AU-000260",
            "title": "Windows Server 2019 must be configured to audit Policy Change - Audit Policy Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205772",
            "stig_id": "WN19-AU-000270",
            "title": "Windows Server 2019 must be configured to audit Policy Change - Audit Policy Change failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205773",
            "stig_id": "WN19-AU-000280",
            "title": "Windows Server 2019 must be configured to audit Policy Change - Authentication Policy Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205774",
            "stig_id": "WN19-AU-000290",
            "title": "Windows Server 2019 must be configured to audit Policy Change - Authorization Policy Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205775",
            "stig_id": "WN19-AU-000300",
            "title": "Windows Server 2019 must be configured to audit Privilege Use - Sensitive Privilege Use successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205776",
            "stig_id": "WN19-AU-000310",
            "title": "Windows Server 2019 must be configured to audit Privilege Use - Sensitive Privilege Use failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205777",
            "stig_id": "WN19-AU-000320",
            "title": "Windows Server 2019 must be configured to audit System - IPsec Driver successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205778",
            "stig_id": "WN19-AU-000330",
            "title": "Windows Server 2019 must be configured to audit System - IPsec Driver failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205779",
            "stig_id": "WN19-AU-000340",
            "title": "Windows Server 2019 must be configured to audit System - Other System Events successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205780",
            "stig_id": "WN19-AU-000350",
            "title": "Windows Server 2019 must be configured to audit System - Other System Events failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205781",
            "stig_id": "WN19-AU-000360",
            "title": "Windows Server 2019 must be configured to audit System - Security State Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205782",
            "stig_id": "WN19-AU-000370",
            "title": "Windows Server 2019 must be configured to audit System - Security System Extension successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205783",
            "stig_id": "WN19-AU-000380",
            "title": "Windows Server 2019 must be configured to audit System - System Integrity successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205784",
            "stig_id": "WN19-AU-000390",
            "title": "Windows Server 2019 must be configured to audit System - System Integrity failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205785",
            "stig_id": "WN19-DC-000170",
            "title": "Windows Server 2019 Active Directory Group Policy objects must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205786",
            "stig_id": "WN19-DC-000180",
            "title": "Windows Server 2019 Active Directory Domain object must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205787",
            "stig_id": "WN19-DC-000190",
            "title": "Windows Server 2019 Active Directory Infrastructure object must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205788",
            "stig_id": "WN19-DC-000200",
            "title": "Windows Server 2019 Active Directory Domain Controllers Organizational Unit (OU) object must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205789",
            "stig_id": "WN19-DC-000210",
            "title": "Windows Server 2019 Active Directory AdminSDHolder object must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205790",
            "stig_id": "WN19-DC-000220",
            "title": "Windows Server 2019 Active Directory RID Manager$ object must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205791",
            "stig_id": "WN19-DC-000240",
            "title": "Windows Server 2019 must be configured to audit DS Access - Directory Service Access successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205792",
            "stig_id": "WN19-DC-000250",
            "title": "Windows Server 2019 must be configured to audit DS Access - Directory Service Access failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205793",
            "stig_id": "WN19-DC-000260",
            "title": "Windows Server 2019 must be configured to audit DS Access - Directory Service Changes successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254254",
            "stig_id": "WN22-00-000170",
            "title": "Windows Server 2022 default permissions for the HKEY_LOCAL_MACHINE registry hive must be maintained.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254302",
            "stig_id": "WN22-AU-000090",
            "title": "Windows Server 2022 must be configured to audit Account Management - Other Account Management Events successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254307",
            "stig_id": "WN22-AU-000140",
            "title": "Windows Server 2022 must be configured to audit Detailed Tracking - Process Creation successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254319",
            "stig_id": "WN22-AU-000260",
            "title": "Windows Server 2022 must be configured to audit Policy Change - Audit Policy Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254320",
            "stig_id": "WN22-AU-000270",
            "title": "Windows Server 2022 must be configured to audit Policy Change - Audit Policy Change failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254321",
            "stig_id": "WN22-AU-000280",
            "title": "Windows Server 2022 must be configured to audit Policy Change - Authentication Policy Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254322",
            "stig_id": "WN22-AU-000290",
            "title": "Windows Server 2022 must be configured to audit Policy Change - Authorization Policy Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254323",
            "stig_id": "WN22-AU-000300",
            "title": "Windows Server 2022 must be configured to audit Privilege Use - Sensitive Privilege Use successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254324",
            "stig_id": "WN22-AU-000310",
            "title": "Windows Server 2022 must be configured to audit Privilege Use - Sensitive Privilege Use failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254325",
            "stig_id": "WN22-AU-000320",
            "title": "Windows Server 2022 must be configured to audit System - IPsec Driver successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254326",
            "stig_id": "WN22-AU-000330",
            "title": "Windows Server 2022 must be configured to audit System - IPsec Driver failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254327",
            "stig_id": "WN22-AU-000340",
            "title": "Windows Server 2022 must be configured to audit System - Other System Events successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254328",
            "stig_id": "WN22-AU-000350",
            "title": "Windows Server 2022 must be configured to audit System - Other System Events failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254329",
            "stig_id": "WN22-AU-000360",
            "title": "Windows Server 2022 must be configured to audit System - Security State Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254330",
            "stig_id": "WN22-AU-000370",
            "title": "Windows Server 2022 must be configured to audit System - Security System Extension successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254331",
            "stig_id": "WN22-AU-000380",
            "title": "Windows Server 2022 must be configured to audit System - System Integrity successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254332",
            "stig_id": "WN22-AU-000390",
            "title": "Windows Server 2022 must be configured to audit System - System Integrity failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254385",
            "stig_id": "WN22-DC-000010",
            "title": "Windows Server 2022 must only allow administrators responsible for the domain controller to have Administrator rights on the system.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254391",
            "stig_id": "WN22-DC-000070",
            "title": "Windows Server 2022 permissions on the Active Directory data files must only allow System and Administrators access.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-001314",
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254392",
            "stig_id": "WN22-DC-000080",
            "title": "Windows Server 2022 Active Directory SYSVOL directory must have the proper access control permissions.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254393",
            "stig_id": "WN22-DC-000090",
            "title": "Windows Server 2022 Active Directory Group Policy objects must have proper access control permissions.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254394",
            "stig_id": "WN22-DC-000100",
            "title": "Windows Server 2022 Active Directory Domain Controllers Organizational Unit (OU) object must have the proper access control permissions.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254395",
            "stig_id": "WN22-DC-000110",
            "title": "Windows Server 2022 organization created Active Directory Organizational Unit (OU) objects must have proper access control permissions.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254401",
            "stig_id": "WN22-DC-000170",
            "title": "Windows Server 2022 Active Directory Group Policy objects must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254402",
            "stig_id": "WN22-DC-000180",
            "title": "Windows Server 2022 Active Directory Domain object must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254403",
            "stig_id": "WN22-DC-000190",
            "title": "Windows Server 2022 Active Directory Infrastructure object must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254404",
            "stig_id": "WN22-DC-000200",
            "title": "Windows Server 2022 Active Directory Domain Controllers Organizational Unit (OU) object must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254405",
            "stig_id": "WN22-DC-000210",
            "title": "Windows Server 2022 Active Directory AdminSDHolder object must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254406",
            "stig_id": "WN22-DC-000220",
            "title": "Windows Server 2022 Active Directory RID Manager$ object must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254408",
            "stig_id": "WN22-DC-000240",
            "title": "Windows Server 2022 must be configured to audit DS Access - Directory Service Access successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254409",
            "stig_id": "WN22-DC-000250",
            "title": "Windows Server 2022 must be configured to audit DS Access - Directory Service Access failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254410",
            "stig_id": "WN22-DC-000260",
            "title": "Windows Server 2022 must be configured to audit DS Access - Directory Service Changes successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254419",
            "stig_id": "WN22-DC-000350",
            "title": "Windows Server 2022 Add workstations to domain user right must only be assigned to the Administrators group on domain controllers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254426",
            "stig_id": "WN22-DC-000420",
            "title": "Windows Server 2022 Enable computer and user accounts to be trusted for delegation user right must only be assigned to the Administrators group on domain controllers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254428",
            "stig_id": "WN22-MS-000010",
            "title": "Windows Server 2022 must only allow administrators responsible for the member server or standalone or nondomain-joined system to have Administrator rights on the system.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254433",
            "stig_id": "WN22-MS-000060",
            "title": "Windows Server 2022 must restrict remote calls to the Security Account Manager (SAM) to Administrators on domain-joined member servers and standalone or nondomain-joined systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254440",
            "stig_id": "WN22-MS-000130",
            "title": "Windows Server 2022 Enable computer and user accounts to be trusted for delegation user right must not be assigned to any groups or accounts on domain-joined member servers and standalone or nondomain-joined systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254491",
            "stig_id": "WN22-UR-000010",
            "title": "Windows Server 2022 Access Credential Manager as a trusted caller user right must not be assigned to any groups or accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254492",
            "stig_id": "WN22-UR-000020",
            "title": "Windows Server 2022 Act as part of the operating system user right must not be assigned to any groups or accounts.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254494",
            "stig_id": "WN22-UR-000040",
            "title": "Windows Server 2022 back up files and directories user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254495",
            "stig_id": "WN22-UR-000050",
            "title": "Windows Server 2022 create a pagefile user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254496",
            "stig_id": "WN22-UR-000060",
            "title": "Windows Server 2022 create a token object user right must not be assigned to any groups or accounts.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254497",
            "stig_id": "WN22-UR-000070",
            "title": "Windows Server 2022 create global objects user right must only be assigned to Administrators, Service, Local Service, and Network Service.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254498",
            "stig_id": "WN22-UR-000080",
            "title": "Windows Server 2022 create permanent shared objects user right must not be assigned to any groups or accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254499",
            "stig_id": "WN22-UR-000090",
            "title": "Windows Server 2022 create symbolic links user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254500",
            "stig_id": "WN22-UR-000100",
            "title": "Windows Server 2022 debug programs user right must only be assigned to the Administrators group.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254501",
            "stig_id": "WN22-UR-000110",
            "title": "Windows Server 2022 force shutdown from a remote system user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254502",
            "stig_id": "WN22-UR-000120",
            "title": "Windows Server 2022 generate security audits user right must only be assigned to Local Service and Network Service.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254503",
            "stig_id": "WN22-UR-000130",
            "title": "Windows Server 2022 impersonate a client after authentication user right must only be assigned to Administrators, Service, Local Service, and Network Service.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254504",
            "stig_id": "WN22-UR-000140",
            "title": "Windows Server 2022 increase scheduling priority: user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254505",
            "stig_id": "WN22-UR-000150",
            "title": "Windows Server 2022 load and unload device drivers user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254506",
            "stig_id": "WN22-UR-000160",
            "title": "Windows Server 2022 lock pages in memory user right must not be assigned to any groups or accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235",
                "CCI-002824"
            ]
        },
        {
            "rule": "V-254508",
            "stig_id": "WN22-UR-000180",
            "title": "Windows Server 2022 modify firmware environment values user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254509",
            "stig_id": "WN22-UR-000190",
            "title": "Windows Server 2022 perform volume maintenance tasks user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254510",
            "stig_id": "WN22-UR-000200",
            "title": "Windows Server 2022 profile single process user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254511",
            "stig_id": "WN22-UR-000210",
            "title": "Windows Server 2022 restore files and directories user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-254512",
            "stig_id": "WN22-UR-000220",
            "title": "Windows Server 2022 take ownership of files or other objects user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-230386",
            "stig_id": "RHEL-08-030000",
            "title": "The RHEL 8 audit system must be configured to audit the execution of privileged functions and prevent all software from executing at higher privilege levels than users executing the software.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-002233"
            ]
        },
        {
            "rule": "V-237642",
            "stig_id": "RHEL-08-010383",
            "title": "RHEL 8 must use the invoking user's password for privilege escalation when using \"sudo\".",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-002227"
            ]
        },
        {
            "rule": "V-254520",
            "stig_id": "RHEL-08-040400",
            "title": "RHEL 8 must prevent nonprivileged users from executing privileged functions, including disabling, circumventing, or altering implemented security safeguards/countermeasures.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-272484",
            "stig_id": "RHEL-08-010455",
            "title": "RHEL 8 must elevate the SELinux context when an administrator calls the sudo command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-257784",
            "stig_id": "RHEL-09-211045",
            "title": "The systemd Ctrl-Alt-Delete burst key sequence in RHEL 9 must be disabled.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-257785",
            "stig_id": "RHEL-09-211050",
            "title": "The x86 Ctrl-Alt-Delete key sequence must be disabled on RHEL 9.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-257786",
            "stig_id": "RHEL-09-211055",
            "title": "RHEL 9 debug-shell systemd service must be disabled.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-257801",
            "stig_id": "RHEL-09-213030",
            "title": "RHEL 9 must enable kernel parameters to enforce discretionary access control on hardlinks.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002165",
                "CCI-002235"
            ]
        },
        {
            "rule": "V-257802",
            "stig_id": "RHEL-09-213035",
            "title": "RHEL 9 must enable kernel parameters to enforce discretionary access control on symlinks.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002165",
                "CCI-002235"
            ]
        },
        {
            "rule": "V-258083",
            "stig_id": "RHEL-09-432010",
            "title": "RHEL 9 must have the sudo package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002235"
            ]
        },
        {
            "rule": "V-258176",
            "stig_id": "RHEL-09-654010",
            "title": "RHEL 9 must audit uses of the \"execve\" system call.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002233",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-272496",
            "stig_id": "RHEL-09-431016",
            "title": "RHEL 9 must elevate the SELinux context when an administrator calls the sudo command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002235"
            ]
        }
    ]
}