{
    "control": "AU-12",
    "title": "Audit Record Generation",
    "ccis": [
        {
            "cci": "CCI-000169",
            "definition": "Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2 a on organization-defined information system components."
        },
        {
            "cci": "CCI-000171",
            "definition": "Allow organization-defined personnel or roles to select the event types that are to be logged by specific components of the system."
        },
        {
            "cci": "CCI-000172",
            "definition": "Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3."
        },
        {
            "cci": "CCI-000173",
            "definition": "Defines the level of tolerance for relationship between time stamps of individual records in the audit trail that will be used for correlation."
        },
        {
            "cci": "CCI-000174",
            "definition": "Compile audit records from organization-defined information system components into a system-wide (logical or physical) audit trail that is time-correlated to within an organization-defined level of tolerance for relationship between time stamps of individual records in the audit trail."
        },
        {
            "cci": "CCI-001353",
            "definition": "Produce a system-wide (logical or physical) audit trail composed of audit records in a standardized format."
        },
        {
            "cci": "CCI-001459",
            "definition": "Defines system components that provide audit record generation capability."
        },
        {
            "cci": "CCI-001576",
            "definition": "The information system produces a system-wide (logical or physical) audit trail of information system audit records."
        },
        {
            "cci": "CCI-001577",
            "definition": "Defines the system components from which audit records are to be compiled into the system-wide audit trail."
        },
        {
            "cci": "CCI-001910",
            "definition": "Defines the personnel or roles allowed to select which event types are to be logged by specific components of the system."
        },
        {
            "cci": "CCI-001911",
            "definition": "Defines the selectable event criteria to be used as the basis for changes to the auditing to be performed on organization-defined system components, by organization-defined individuals or roles, within organization-defined time thresholds."
        },
        {
            "cci": "CCI-001912",
            "definition": "Defines the time thresholds for organization-defined individuals or roles to change the auditing to be performed based on organization-defined selectable event criteria."
        },
        {
            "cci": "CCI-001913",
            "definition": "Defines the individuals or roles that are to be provided the capability to change the auditing to be performed based on organization-defined selectable event criteria, within organization-defined time thresholds."
        },
        {
            "cci": "CCI-001914",
            "definition": "Provide the capability for organization-defined individuals or roles to change the logging to be performed on organization-defined system components based on organization-defined selectable event criteria within organization-defined time thresholds."
        },
        {
            "cci": "CCI-002047",
            "definition": "Defines the system components on which the auditing that is to be performed can be changed by organization-defined individuals or roles."
        }
    ],
    "rules_mapped": 270,
    "rules": [
        {
            "rule": "V-221562",
            "stig_id": "DTBC-0005",
            "title": "Extensions installation must be blocklisted by default.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-221586",
            "stig_id": "DTBC-0052",
            "title": "Deletion of browser history must be disabled.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-221587",
            "stig_id": "DTBC-0053",
            "title": "Prompt for download location must be enabled.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-221588",
            "stig_id": "DTBC-0055",
            "title": "Download restrictions must be configured.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-275780",
            "stig_id": "DTBC-0075",
            "title": "Create Themes with AI must be disabled.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-275781",
            "stig_id": "DTBC-0076",
            "title": "DevTools Generative AI features must be disabled.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-275782",
            "stig_id": "DTBC-0077",
            "title": "GenAI local foundational model must be disabled.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-275783",
            "stig_id": "DTBC-0078",
            "title": "Help Me Write must be disabled.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-275784",
            "stig_id": "DTBC-0079",
            "title": "AI-powered History Search must be disabled.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-275785",
            "stig_id": "DTBC-0080",
            "title": "Tab Compare Settings must be disabled.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-242403",
            "stig_id": "CNTR-K8-000700",
            "title": "Kubernetes API Server must generate audit records that identify what type of event has occurred, identify the source of the event, contain the event results, identify any users, and identify any containers associated with the event.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000018",
                "CCI-000130",
                "CCI-000131",
                "CCI-000132",
                "CCI-000133",
                "CCI-000134",
                "CCI-000135",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001487",
                "CCI-002264"
            ]
        },
        {
            "rule": "V-220748",
            "stig_id": "WN10-AU-000005",
            "title": "The system must be configured to audit Account Logon - Credential Validation failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-220749",
            "stig_id": "WN10-AU-000010",
            "title": "The system must be configured to audit Account Logon - Credential Validation successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-220750",
            "stig_id": "WN10-AU-000030",
            "title": "The system must be configured to audit Account Management - Security Group Management successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-220751",
            "stig_id": "WN10-AU-000035",
            "title": "The system must be configured to audit Account Management - User Account Management failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-220752",
            "stig_id": "WN10-AU-000040",
            "title": "The system must be configured to audit Account Management - User Account Management successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-220753",
            "stig_id": "WN10-AU-000045",
            "title": "The system must be configured to audit Detailed Tracking - PNP Activity successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172",
                "CCI-001814",
                "CCI-003938"
            ]
        },
        {
            "rule": "V-220754",
            "stig_id": "WN10-AU-000050",
            "title": "The system must be configured to audit Detailed Tracking - Process Creation successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172",
                "CCI-001814",
                "CCI-003938"
            ]
        },
        {
            "rule": "V-220755",
            "stig_id": "WN10-AU-000054",
            "title": "The system must be configured to audit Logon/Logoff - Account Lockout failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-220756",
            "stig_id": "WN10-AU-000060",
            "title": "The system must be configured to audit Logon/Logoff - Group Membership successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-220757",
            "stig_id": "WN10-AU-000065",
            "title": "The system must be configured to audit Logon/Logoff - Logoff successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000067",
                "CCI-000172"
            ]
        },
        {
            "rule": "V-220758",
            "stig_id": "WN10-AU-000070",
            "title": "The system must be configured to audit Logon/Logoff - Logon failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000067",
                "CCI-000172"
            ]
        },
        {
            "rule": "V-220759",
            "stig_id": "WN10-AU-000075",
            "title": "The system must be configured to audit Logon/Logoff - Logon successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000067",
                "CCI-000172"
            ]
        },
        {
            "rule": "V-220760",
            "stig_id": "WN10-AU-000080",
            "title": "The system must be configured to audit Logon/Logoff - Special Logon successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-220761",
            "stig_id": "WN10-AU-000081",
            "title": "Windows 10 must be configured to audit Object Access - File Share failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-220762",
            "stig_id": "WN10-AU-000082",
            "title": "Windows 10 must be configured to audit Object Access - File Share successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-220763",
            "stig_id": "WN10-AU-000083",
            "title": "Windows 10 must be configured to audit Object Access - Other Object Access Events successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-220764",
            "stig_id": "WN10-AU-000084",
            "title": "Windows 10 must be configured to audit Object Access - Other Object Access Events failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-220765",
            "stig_id": "WN10-AU-000085",
            "title": "The system must be configured to audit Object Access - Removable Storage failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-220766",
            "stig_id": "WN10-AU-000090",
            "title": "The system must be configured to audit Object Access - Removable Storage successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-220767",
            "stig_id": "WN10-AU-000100",
            "title": "The system must be configured to audit Policy Change - Audit Policy Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-220768",
            "stig_id": "WN10-AU-000105",
            "title": "The system must be configured to audit Policy Change - Authentication Policy Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-220769",
            "stig_id": "WN10-AU-000107",
            "title": "The system must be configured to audit Policy Change - Authorization Policy Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-220770",
            "stig_id": "WN10-AU-000110",
            "title": "The system must be configured to audit Privilege Use - Sensitive Privilege Use failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-220771",
            "stig_id": "WN10-AU-000115",
            "title": "The system must be configured to audit Privilege Use - Sensitive Privilege Use successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-220772",
            "stig_id": "WN10-AU-000120",
            "title": "The system must be configured to audit System - IPSec Driver failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-220773",
            "stig_id": "WN10-AU-000130",
            "title": "The system must be configured to audit System - Other System Events successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-220774",
            "stig_id": "WN10-AU-000135",
            "title": "The system must be configured to audit System - Other System Events failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-220775",
            "stig_id": "WN10-AU-000140",
            "title": "The system must be configured to audit System - Security State Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-220776",
            "stig_id": "WN10-AU-000150",
            "title": "The system must be configured to audit System - Security System Extension successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-220777",
            "stig_id": "WN10-AU-000155",
            "title": "The system must be configured to audit System - System Integrity failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-220778",
            "stig_id": "WN10-AU-000160",
            "title": "The system must be configured to audit System - System Integrity successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-220913",
            "stig_id": "WN10-SO-000030",
            "title": "Audit policy using subcategories must be enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-220978",
            "stig_id": "WN10-UR-000130",
            "title": "The Manage auditing and security log user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000162",
                "CCI-000163",
                "CCI-000164",
                "CCI-000171",
                "CCI-001914"
            ]
        },
        {
            "rule": "V-253268",
            "stig_id": "WN11-00-000065",
            "title": "Unused accounts must be disabled or removed from the system after 35 days of inactivity.",
            "severity": "low",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172",
                "CCI-000795",
                "CCI-003627"
            ]
        },
        {
            "rule": "V-253306",
            "stig_id": "WN11-AU-000005",
            "title": "The system must be configured to audit Account Logon - Credential Validation failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253307",
            "stig_id": "WN11-AU-000010",
            "title": "The system must be configured to audit Account Logon - Credential Validation successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253308",
            "stig_id": "WN11-AU-000030",
            "title": "The system must be configured to audit Account Management - Security Group Management successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-001914"
            ]
        },
        {
            "rule": "V-253311",
            "stig_id": "WN11-AU-000045",
            "title": "The system must be configured to audit Detailed Tracking - PNP Activity successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172",
                "CCI-001814",
                "CCI-003938"
            ]
        },
        {
            "rule": "V-253312",
            "stig_id": "WN11-AU-000050",
            "title": "The system must be configured to audit Detailed Tracking - Process Creation successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172",
                "CCI-001814",
                "CCI-003938"
            ]
        },
        {
            "rule": "V-253313",
            "stig_id": "WN11-AU-000054",
            "title": "The system must be configured to audit Logon/Logoff - Account Lockout failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253314",
            "stig_id": "WN11-AU-000060",
            "title": "The system must be configured to audit Logon/Logoff - Group Membership successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253316",
            "stig_id": "WN11-AU-000070",
            "title": "The system must be configured to audit Logon/Logoff - Logon failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253317",
            "stig_id": "WN11-AU-000075",
            "title": "The system must be configured to audit Logon/Logoff - Logon successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253318",
            "stig_id": "WN11-AU-000080",
            "title": "The system must be configured to audit Logon/Logoff - Special Logon successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253319",
            "stig_id": "WN11-AU-000081",
            "title": "Windows 11 must be configured to audit Object Access - File Share failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253320",
            "stig_id": "WN11-AU-000082",
            "title": "Windows 11 must be configured to audit Object Access - File Share successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253321",
            "stig_id": "WN11-AU-000083",
            "title": "Windows 11 must be configured to audit Object Access - Other Object Access Events successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253322",
            "stig_id": "WN11-AU-000084",
            "title": "Windows 11 must be configured to audit Object Access - Other Object Access Events failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253323",
            "stig_id": "WN11-AU-000085",
            "title": "The system must be configured to audit Object Access - Removable Storage failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253324",
            "stig_id": "WN11-AU-000090",
            "title": "The system must be configured to audit Object Access - Removable Storage successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253325",
            "stig_id": "WN11-AU-000100",
            "title": "The system must be configured to audit Policy Change - Audit Policy Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253326",
            "stig_id": "WN11-AU-000105",
            "title": "The system must be configured to audit Policy Change - Authentication Policy Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253327",
            "stig_id": "WN11-AU-000107",
            "title": "The system must be configured to audit Policy Change - Authorization Policy Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253329",
            "stig_id": "WN11-AU-000115",
            "title": "The system must be configured to audit Privilege Use - Sensitive Privilege Use successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253330",
            "stig_id": "WN11-AU-000120",
            "title": "The system must be configured to audit System - IPsec Driver failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253331",
            "stig_id": "WN11-AU-000130",
            "title": "The system must be configured to audit System - Other System Events successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253332",
            "stig_id": "WN11-AU-000135",
            "title": "The system must be configured to audit System - Other System Events failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253333",
            "stig_id": "WN11-AU-000140",
            "title": "The system must be configured to audit System - Security State Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253334",
            "stig_id": "WN11-AU-000150",
            "title": "The system must be configured to audit System - Security System Extension successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253335",
            "stig_id": "WN11-AU-000155",
            "title": "The system must be configured to audit System - System Integrity failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253336",
            "stig_id": "WN11-AU-000160",
            "title": "The system must be configured to audit System - System Integrity successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253426",
            "stig_id": "WN11-EP-000310",
            "title": "Windows 11 Kernel (Direct Memory Access) DMA Protection must be enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-253437",
            "stig_id": "WN11-SO-000030",
            "title": "Audit policy using subcategories must be enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-253501",
            "stig_id": "WN11-UR-000130",
            "title": "The \"Manage auditing and security log\" user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000162",
                "CCI-000171"
            ]
        },
        {
            "rule": "V-205625",
            "stig_id": "WN19-AU-000100",
            "title": "Windows Server 2019 must be configured to audit Account Management - Security Group Management successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130"
            ]
        },
        {
            "rule": "V-205626",
            "stig_id": "WN19-AU-000110",
            "title": "Windows Server 2019 must be configured to audit Account Management - User Account Management successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130"
            ]
        },
        {
            "rule": "V-205627",
            "stig_id": "WN19-AU-000120",
            "title": "Windows Server 2019 must be configured to audit Account Management - User Account Management failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130"
            ]
        },
        {
            "rule": "V-205628",
            "stig_id": "WN19-DC-000230",
            "title": "Windows Server 2019 must be configured to audit Account Management - Computer Account Management successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130"
            ]
        },
        {
            "rule": "V-205634",
            "stig_id": "WN19-AU-000190",
            "title": "Windows Server 2019 must be configured to audit logon successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000067",
                "CCI-000172"
            ]
        },
        {
            "rule": "V-205635",
            "stig_id": "WN19-AU-000200",
            "title": "Windows Server 2019 must be configured to audit logon failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000067",
                "CCI-000172"
            ]
        },
        {
            "rule": "V-205643",
            "stig_id": "WN19-UR-000170",
            "title": "Windows Server 2019 Manage auditing and security log user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000162",
                "CCI-000163",
                "CCI-000164",
                "CCI-000171",
                "CCI-001914"
            ]
        },
        {
            "rule": "V-205644",
            "stig_id": "WN19-SO-000050",
            "title": "Windows Server 2019 must force audit policy subcategory settings to override audit policy category settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-205730",
            "stig_id": "WN19-AU-000160",
            "title": "Windows Server 2019 must be configured to audit Logon/Logoff - Account Lockout failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-001404"
            ]
        },
        {
            "rule": "V-205769",
            "stig_id": "WN19-AU-000090",
            "title": "Windows Server 2019 must be configured to audit Account Management - Other Account Management Events successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205770",
            "stig_id": "WN19-AU-000140",
            "title": "Windows Server 2019 must be configured to audit Detailed Tracking - Process Creation successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205771",
            "stig_id": "WN19-AU-000260",
            "title": "Windows Server 2019 must be configured to audit Policy Change - Audit Policy Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205772",
            "stig_id": "WN19-AU-000270",
            "title": "Windows Server 2019 must be configured to audit Policy Change - Audit Policy Change failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205773",
            "stig_id": "WN19-AU-000280",
            "title": "Windows Server 2019 must be configured to audit Policy Change - Authentication Policy Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205774",
            "stig_id": "WN19-AU-000290",
            "title": "Windows Server 2019 must be configured to audit Policy Change - Authorization Policy Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205775",
            "stig_id": "WN19-AU-000300",
            "title": "Windows Server 2019 must be configured to audit Privilege Use - Sensitive Privilege Use successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205776",
            "stig_id": "WN19-AU-000310",
            "title": "Windows Server 2019 must be configured to audit Privilege Use - Sensitive Privilege Use failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205777",
            "stig_id": "WN19-AU-000320",
            "title": "Windows Server 2019 must be configured to audit System - IPsec Driver successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205778",
            "stig_id": "WN19-AU-000330",
            "title": "Windows Server 2019 must be configured to audit System - IPsec Driver failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205779",
            "stig_id": "WN19-AU-000340",
            "title": "Windows Server 2019 must be configured to audit System - Other System Events successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205780",
            "stig_id": "WN19-AU-000350",
            "title": "Windows Server 2019 must be configured to audit System - Other System Events failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205781",
            "stig_id": "WN19-AU-000360",
            "title": "Windows Server 2019 must be configured to audit System - Security State Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205782",
            "stig_id": "WN19-AU-000370",
            "title": "Windows Server 2019 must be configured to audit System - Security System Extension successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205783",
            "stig_id": "WN19-AU-000380",
            "title": "Windows Server 2019 must be configured to audit System - System Integrity successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205784",
            "stig_id": "WN19-AU-000390",
            "title": "Windows Server 2019 must be configured to audit System - System Integrity failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205785",
            "stig_id": "WN19-DC-000170",
            "title": "Windows Server 2019 Active Directory Group Policy objects must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205786",
            "stig_id": "WN19-DC-000180",
            "title": "Windows Server 2019 Active Directory Domain object must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205787",
            "stig_id": "WN19-DC-000190",
            "title": "Windows Server 2019 Active Directory Infrastructure object must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205788",
            "stig_id": "WN19-DC-000200",
            "title": "Windows Server 2019 Active Directory Domain Controllers Organizational Unit (OU) object must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205789",
            "stig_id": "WN19-DC-000210",
            "title": "Windows Server 2019 Active Directory AdminSDHolder object must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205790",
            "stig_id": "WN19-DC-000220",
            "title": "Windows Server 2019 Active Directory RID Manager$ object must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205791",
            "stig_id": "WN19-DC-000240",
            "title": "Windows Server 2019 must be configured to audit DS Access - Directory Service Access successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205792",
            "stig_id": "WN19-DC-000250",
            "title": "Windows Server 2019 must be configured to audit DS Access - Directory Service Access failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205793",
            "stig_id": "WN19-DC-000260",
            "title": "Windows Server 2019 must be configured to audit DS Access - Directory Service Changes successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-205832",
            "stig_id": "WN19-AU-000070",
            "title": "Windows Server 2019 must be configured to audit Account Logon - Credential Validation successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-205833",
            "stig_id": "WN19-AU-000080",
            "title": "Windows Server 2019 must be configured to audit Account Logon - Credential Validation failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-205834",
            "stig_id": "WN19-AU-000170",
            "title": "Windows Server 2019 must be configured to audit Logon/Logoff - Group Membership successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-205835",
            "stig_id": "WN19-AU-000210",
            "title": "Windows Server 2019 must be configured to audit Logon/Logoff - Special Logon successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-205836",
            "stig_id": "WN19-AU-000220",
            "title": "Windows Server 2019 must be configured to audit Object Access - Other Object Access Events successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-205837",
            "stig_id": "WN19-AU-000230",
            "title": "Windows Server 2019 must be configured to audit Object Access - Other Object Access Events failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-205838",
            "stig_id": "WN19-AU-000180",
            "title": "Windows Server 2019 must be configured to audit logoff successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205839",
            "stig_id": "WN19-AU-000130",
            "title": "Windows Server 2019 must be configured to audit Detailed Tracking - Plug and Play Events successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-205840",
            "stig_id": "WN19-AU-000240",
            "title": "Windows Server 2019 must be configured to audit Object Access - Removable Storage successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-205841",
            "stig_id": "WN19-AU-000250",
            "title": "Windows Server 2019 must be configured to audit Object Access - Removable Storage failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-254300",
            "stig_id": "WN22-AU-000070",
            "title": "Windows Server 2022 must be configured to audit Account Logon - Credential Validation successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-254301",
            "stig_id": "WN22-AU-000080",
            "title": "Windows Server 2022 must be configured to audit Account Logon - Credential Validation failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-254302",
            "stig_id": "WN22-AU-000090",
            "title": "Windows Server 2022 must be configured to audit Account Management - Other Account Management Events successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254303",
            "stig_id": "WN22-AU-000100",
            "title": "Windows Server 2022 must be configured to audit Account Management - Security Group Management successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130"
            ]
        },
        {
            "rule": "V-254304",
            "stig_id": "WN22-AU-000110",
            "title": "Windows Server 2022 must be configured to audit Account Management - User Account Management successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130"
            ]
        },
        {
            "rule": "V-254305",
            "stig_id": "WN22-AU-000120",
            "title": "Windows Server 2022 must be configured to audit Account Management - User Account Management failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130"
            ]
        },
        {
            "rule": "V-254306",
            "stig_id": "WN22-AU-000130",
            "title": "Windows Server 2022 must be configured to audit Detailed Tracking - Plug and Play Events successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-254307",
            "stig_id": "WN22-AU-000140",
            "title": "Windows Server 2022 must be configured to audit Detailed Tracking - Process Creation successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254309",
            "stig_id": "WN22-AU-000160",
            "title": "Windows Server 2022 must be configured to audit Logon/Logoff - Account Lockout failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-001404"
            ]
        },
        {
            "rule": "V-254310",
            "stig_id": "WN22-AU-000170",
            "title": "Windows Server 2022 must be configured to audit Logon/Logoff - Group Membership successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-254311",
            "stig_id": "WN22-AU-000180",
            "title": "Windows Server 2022 must be configured to audit logoff successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-254312",
            "stig_id": "WN22-AU-000190",
            "title": "Windows Server 2022 must be configured to audit logon successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000067",
                "CCI-000172"
            ]
        },
        {
            "rule": "V-254313",
            "stig_id": "WN22-AU-000200",
            "title": "Windows Server 2022 must be configured to audit logon failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000067",
                "CCI-000172"
            ]
        },
        {
            "rule": "V-254314",
            "stig_id": "WN22-AU-000210",
            "title": "Windows Server 2022 must be configured to audit Logon/Logoff - Special Logon successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-254315",
            "stig_id": "WN22-AU-000220",
            "title": "Windows Server 2022 must be configured to audit Object Access - Other Object Access Events successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-254316",
            "stig_id": "WN22-AU-000230",
            "title": "Windows Server 2022 must be configured to audit Object Access - Other Object Access Events failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-254317",
            "stig_id": "WN22-AU-000240",
            "title": "Windows Server 2022 must be configured to audit Object Access - Removable Storage successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-254318",
            "stig_id": "WN22-AU-000250",
            "title": "Windows Server 2022 must be configured to audit Object Access - Removable Storage failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-254319",
            "stig_id": "WN22-AU-000260",
            "title": "Windows Server 2022 must be configured to audit Policy Change - Audit Policy Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254320",
            "stig_id": "WN22-AU-000270",
            "title": "Windows Server 2022 must be configured to audit Policy Change - Audit Policy Change failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254321",
            "stig_id": "WN22-AU-000280",
            "title": "Windows Server 2022 must be configured to audit Policy Change - Authentication Policy Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254322",
            "stig_id": "WN22-AU-000290",
            "title": "Windows Server 2022 must be configured to audit Policy Change - Authorization Policy Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254323",
            "stig_id": "WN22-AU-000300",
            "title": "Windows Server 2022 must be configured to audit Privilege Use - Sensitive Privilege Use successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254324",
            "stig_id": "WN22-AU-000310",
            "title": "Windows Server 2022 must be configured to audit Privilege Use - Sensitive Privilege Use failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254325",
            "stig_id": "WN22-AU-000320",
            "title": "Windows Server 2022 must be configured to audit System - IPsec Driver successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254326",
            "stig_id": "WN22-AU-000330",
            "title": "Windows Server 2022 must be configured to audit System - IPsec Driver failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254327",
            "stig_id": "WN22-AU-000340",
            "title": "Windows Server 2022 must be configured to audit System - Other System Events successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254328",
            "stig_id": "WN22-AU-000350",
            "title": "Windows Server 2022 must be configured to audit System - Other System Events failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254329",
            "stig_id": "WN22-AU-000360",
            "title": "Windows Server 2022 must be configured to audit System - Security State Change successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254330",
            "stig_id": "WN22-AU-000370",
            "title": "Windows Server 2022 must be configured to audit System - Security System Extension successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254331",
            "stig_id": "WN22-AU-000380",
            "title": "Windows Server 2022 must be configured to audit System - System Integrity successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254332",
            "stig_id": "WN22-AU-000390",
            "title": "Windows Server 2022 must be configured to audit System - System Integrity failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254401",
            "stig_id": "WN22-DC-000170",
            "title": "Windows Server 2022 Active Directory Group Policy objects must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254402",
            "stig_id": "WN22-DC-000180",
            "title": "Windows Server 2022 Active Directory Domain object must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254403",
            "stig_id": "WN22-DC-000190",
            "title": "Windows Server 2022 Active Directory Infrastructure object must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254404",
            "stig_id": "WN22-DC-000200",
            "title": "Windows Server 2022 Active Directory Domain Controllers Organizational Unit (OU) object must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254405",
            "stig_id": "WN22-DC-000210",
            "title": "Windows Server 2022 Active Directory AdminSDHolder object must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254406",
            "stig_id": "WN22-DC-000220",
            "title": "Windows Server 2022 Active Directory RID Manager$ object must be configured with proper audit settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254407",
            "stig_id": "WN22-DC-000230",
            "title": "Windows Server 2022 must be configured to audit Account Management - Computer Account Management successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130"
            ]
        },
        {
            "rule": "V-254408",
            "stig_id": "WN22-DC-000240",
            "title": "Windows Server 2022 must be configured to audit DS Access - Directory Service Access successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254409",
            "stig_id": "WN22-DC-000250",
            "title": "Windows Server 2022 must be configured to audit DS Access - Directory Service Access failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254410",
            "stig_id": "WN22-DC-000260",
            "title": "Windows Server 2022 must be configured to audit DS Access - Directory Service Changes successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-254449",
            "stig_id": "WN22-SO-000050",
            "title": "Windows Server 2022 must force audit policy subcategory settings to override audit policy category settings.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-254507",
            "stig_id": "WN22-UR-000170",
            "title": "Windows Server 2022 manage auditing and security log user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000162",
                "CCI-000163",
                "CCI-000164",
                "CCI-000171",
                "CCI-001914"
            ]
        },
        {
            "rule": "V-230404",
            "stig_id": "RHEL-08-030130",
            "title": "RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230405",
            "stig_id": "RHEL-08-030140",
            "title": "RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230406",
            "stig_id": "RHEL-08-030150",
            "title": "RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230407",
            "stig_id": "RHEL-08-030160",
            "title": "RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230408",
            "stig_id": "RHEL-08-030170",
            "title": "RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230409",
            "stig_id": "RHEL-08-030171",
            "title": "RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230410",
            "stig_id": "RHEL-08-030172",
            "title": "RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230411",
            "stig_id": "RHEL-08-030180",
            "title": "The RHEL 8 audit package must be installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230412",
            "stig_id": "RHEL-08-030190",
            "title": "Successful/unsuccessful uses of the su command in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230413",
            "stig_id": "RHEL-08-030200",
            "title": "The RHEL 8 audit system must be configured to audit any usage of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230418",
            "stig_id": "RHEL-08-030250",
            "title": "Successful/unsuccessful uses of the chage command in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230419",
            "stig_id": "RHEL-08-030260",
            "title": "Successful/unsuccessful uses of the chcon command in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230421",
            "stig_id": "RHEL-08-030280",
            "title": "Successful/unsuccessful uses of the ssh-agent in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230422",
            "stig_id": "RHEL-08-030290",
            "title": "Successful/unsuccessful uses of the passwd command in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230423",
            "stig_id": "RHEL-08-030300",
            "title": "Successful/unsuccessful uses of the mount command in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230424",
            "stig_id": "RHEL-08-030301",
            "title": "Successful/unsuccessful uses of the umount command in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230425",
            "stig_id": "RHEL-08-030302",
            "title": "Successful/unsuccessful uses of the mount syscall in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230426",
            "stig_id": "RHEL-08-030310",
            "title": "Successful/unsuccessful uses of the unix_update in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230427",
            "stig_id": "RHEL-08-030311",
            "title": "Successful/unsuccessful uses of postdrop in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230428",
            "stig_id": "RHEL-08-030312",
            "title": "Successful/unsuccessful uses of postqueue in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230429",
            "stig_id": "RHEL-08-030313",
            "title": "Successful/unsuccessful uses of semanage in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230430",
            "stig_id": "RHEL-08-030314",
            "title": "Successful/unsuccessful uses of setfiles in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230431",
            "stig_id": "RHEL-08-030315",
            "title": "Successful/unsuccessful uses of userhelper in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230432",
            "stig_id": "RHEL-08-030316",
            "title": "Successful/unsuccessful uses of setsebool in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230433",
            "stig_id": "RHEL-08-030317",
            "title": "Successful/unsuccessful uses of unix_chkpwd in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230434",
            "stig_id": "RHEL-08-030320",
            "title": "Successful/unsuccessful uses of the ssh-keysign in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230435",
            "stig_id": "RHEL-08-030330",
            "title": "Successful/unsuccessful uses of the setfacl command in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230436",
            "stig_id": "RHEL-08-030340",
            "title": "Successful/unsuccessful uses of the pam_timestamp_check command in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230437",
            "stig_id": "RHEL-08-030350",
            "title": "Successful/unsuccessful uses of the newgrp command in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230438",
            "stig_id": "RHEL-08-030360",
            "title": "Successful/unsuccessful uses of the init_module and finit_module system calls in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230439",
            "stig_id": "RHEL-08-030361",
            "title": "Successful/unsuccessful uses of the rename, unlink, rmdir, renameat, and unlinkat system calls in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230444",
            "stig_id": "RHEL-08-030370",
            "title": "Successful/unsuccessful uses of the gpasswd command in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230446",
            "stig_id": "RHEL-08-030390",
            "title": "Successful/unsuccessful uses of the delete_module command in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230447",
            "stig_id": "RHEL-08-030400",
            "title": "Successful/unsuccessful uses of the crontab command in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230448",
            "stig_id": "RHEL-08-030410",
            "title": "Successful/unsuccessful uses of the chsh command in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230449",
            "stig_id": "RHEL-08-030420",
            "title": "Successful/unsuccessful uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230455",
            "stig_id": "RHEL-08-030480",
            "title": "Successful/unsuccessful uses of the chown, fchown, fchownat, and lchown system calls in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230456",
            "stig_id": "RHEL-08-030490",
            "title": "Successful/unsuccessful uses of the chmod, fchmod, and fchmodat system calls in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230462",
            "stig_id": "RHEL-08-030550",
            "title": "Successful/unsuccessful uses of the sudo command in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230463",
            "stig_id": "RHEL-08-030560",
            "title": "Successful/unsuccessful uses of the usermod command in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230464",
            "stig_id": "RHEL-08-030570",
            "title": "Successful/unsuccessful uses of the chacl command in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230465",
            "stig_id": "RHEL-08-030580",
            "title": "Successful/unsuccessful uses of the kmod command in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230466",
            "stig_id": "RHEL-08-030590",
            "title": "Successful/unsuccessful modifications to the faillock log file in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230467",
            "stig_id": "RHEL-08-030600",
            "title": "Successful/unsuccessful modifications to the lastlog file in RHEL 8 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230468",
            "stig_id": "RHEL-08-030601",
            "title": "RHEL 8 must enable auditing of processes that start prior to the audit daemon.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230470",
            "stig_id": "RHEL-08-030603",
            "title": "RHEL 8 must enable Linux audit logging for the USBGuard daemon.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-230471",
            "stig_id": "RHEL-08-030610",
            "title": "RHEL 8 must allow only the Information System Security Manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000171"
            ]
        },
        {
            "rule": "V-244542",
            "stig_id": "RHEL-08-030181",
            "title": "RHEL 8 audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-274877",
            "stig_id": "RHEL-08-030655",
            "title": "RHEL 8 must audit any script or executable called by cron as root or by any privileged user.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-257796",
            "stig_id": "RHEL-09-212055",
            "title": "RHEL 9 must enable auditing of processes that start prior to the audit daemon.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001464",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258037",
            "stig_id": "RHEL-09-291025",
            "title": "RHEL 9 must enable Linux audit logging for the USBGuard daemon.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-258151",
            "stig_id": "RHEL-09-653010",
            "title": "RHEL 9 audit package must be installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000131",
                "CCI-000132",
                "CCI-000133",
                "CCI-000134",
                "CCI-000135",
                "CCI-000154",
                "CCI-000158",
                "CCI-000159",
                "CCI-000169",
                "CCI-000172",
                "CCI-001464",
                "CCI-001487",
                "CCI-001814",
                "CCI-001875",
                "CCI-001876",
                "CCI-001877",
                "CCI-001878",
                "CCI-001879",
                "CCI-001880",
                "CCI-001881",
                "CCI-001882",
                "CCI-001889",
                "CCI-001914",
                "CCI-002884",
                "CCI-003938"
            ]
        },
        {
            "rule": "V-258152",
            "stig_id": "RHEL-09-653015",
            "title": "RHEL 9 audit service must be enabled.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000131",
                "CCI-000132",
                "CCI-000133",
                "CCI-000134",
                "CCI-000135",
                "CCI-000154",
                "CCI-000158",
                "CCI-000169",
                "CCI-000172",
                "CCI-001464",
                "CCI-001487",
                "CCI-001814",
                "CCI-001875",
                "CCI-001876",
                "CCI-001877",
                "CCI-001878",
                "CCI-001879",
                "CCI-001880",
                "CCI-001881",
                "CCI-001882",
                "CCI-001889",
                "CCI-001914",
                "CCI-002884",
                "CCI-003938",
                "CCI-004188"
            ]
        },
        {
            "rule": "V-258164",
            "stig_id": "RHEL-09-653075",
            "title": "RHEL 9 audit system must audit local events.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000169"
            ]
        },
        {
            "rule": "V-258171",
            "stig_id": "RHEL-09-653110",
            "title": "RHEL 9 must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000171"
            ]
        },
        {
            "rule": "V-258172",
            "stig_id": "RHEL-09-653115",
            "title": "RHEL 9 /etc/audit/auditd.conf file must have 0640 or less permissive to prevent unauthorized access.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000171"
            ]
        },
        {
            "rule": "V-258177",
            "stig_id": "RHEL-09-654015",
            "title": "RHEL 9 must audit all uses of the chmod, fchmod, and fchmodat system calls.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258178",
            "stig_id": "RHEL-09-654020",
            "title": "RHEL 9 must audit all uses of the chown, fchown, fchownat, and lchown system calls.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258179",
            "stig_id": "RHEL-09-654025",
            "title": "RHEL 9 must audit all uses of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258180",
            "stig_id": "RHEL-09-654030",
            "title": "RHEL 9 must audit all uses of umount system calls.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258181",
            "stig_id": "RHEL-09-654035",
            "title": "RHEL 9 must audit all uses of the chacl command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258182",
            "stig_id": "RHEL-09-654040",
            "title": "RHEL 9 must audit all uses of the setfacl command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258183",
            "stig_id": "RHEL-09-654045",
            "title": "RHEL 9 must audit all uses of the chcon command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258184",
            "stig_id": "RHEL-09-654050",
            "title": "RHEL 9 must audit all uses of the semanage command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258185",
            "stig_id": "RHEL-09-654055",
            "title": "RHEL 9 must audit all uses of the setfiles command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258186",
            "stig_id": "RHEL-09-654060",
            "title": "RHEL 9 must audit all uses of the setsebool command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258187",
            "stig_id": "RHEL-09-654065",
            "title": "RHEL 9 must audit all uses of the rename, unlink, rmdir, renameat, and unlinkat system calls.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258188",
            "stig_id": "RHEL-09-654070",
            "title": "RHEL 9 must audit all uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258189",
            "stig_id": "RHEL-09-654075",
            "title": "RHEL 9 must audit all uses of the delete_module system call.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258190",
            "stig_id": "RHEL-09-654080",
            "title": "RHEL 9 must audit all uses of the init_module and finit_module system calls.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258191",
            "stig_id": "RHEL-09-654085",
            "title": "RHEL 9 must audit all uses of the chage command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258192",
            "stig_id": "RHEL-09-654090",
            "title": "RHEL 9 must audit all uses of the chsh command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258193",
            "stig_id": "RHEL-09-654095",
            "title": "RHEL 9 must audit all uses of the crontab command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258194",
            "stig_id": "RHEL-09-654100",
            "title": "RHEL 9 must audit all uses of the gpasswd command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258195",
            "stig_id": "RHEL-09-654105",
            "title": "RHEL 9 must audit all uses of the kmod command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258196",
            "stig_id": "RHEL-09-654110",
            "title": "RHEL 9 must audit all uses of the newgrp command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258197",
            "stig_id": "RHEL-09-654115",
            "title": "RHEL 9 must audit all uses of the pam_timestamp_check command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258198",
            "stig_id": "RHEL-09-654120",
            "title": "RHEL 9 must audit all uses of the passwd command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258199",
            "stig_id": "RHEL-09-654125",
            "title": "RHEL 9 must audit all uses of the postdrop command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258200",
            "stig_id": "RHEL-09-654130",
            "title": "RHEL 9 must audit all uses of the postqueue command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258201",
            "stig_id": "RHEL-09-654135",
            "title": "RHEL 9 must audit all uses of the ssh-agent command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258202",
            "stig_id": "RHEL-09-654140",
            "title": "RHEL 9 must audit all uses of the ssh-keysign command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258203",
            "stig_id": "RHEL-09-654145",
            "title": "RHEL 9 must audit all uses of the su command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258204",
            "stig_id": "RHEL-09-654150",
            "title": "RHEL 9 must audit all uses of the sudo command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258205",
            "stig_id": "RHEL-09-654155",
            "title": "RHEL 9 must audit all uses of the sudoedit command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258206",
            "stig_id": "RHEL-09-654160",
            "title": "RHEL 9 must audit all uses of the unix_chkpwd command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258207",
            "stig_id": "RHEL-09-654165",
            "title": "RHEL 9 must audit all uses of the unix_update command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258208",
            "stig_id": "RHEL-09-654170",
            "title": "RHEL 9 must audit all uses of the userhelper command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258209",
            "stig_id": "RHEL-09-654175",
            "title": "RHEL 9 must audit all uses of the usermod command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258210",
            "stig_id": "RHEL-09-654180",
            "title": "RHEL 9 must audit all uses of the mount command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258211",
            "stig_id": "RHEL-09-654185",
            "title": "Successful/unsuccessful uses of the init command in RHEL 9 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-258212",
            "stig_id": "RHEL-09-654190",
            "title": "Successful/unsuccessful uses of the poweroff command in RHEL 9 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-258213",
            "stig_id": "RHEL-09-654195",
            "title": "Successful/unsuccessful uses of the reboot command in RHEL 9 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-258214",
            "stig_id": "RHEL-09-654200",
            "title": "Successful/unsuccessful uses of the shutdown command in RHEL 9 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000172"
            ]
        },
        {
            "rule": "V-258215",
            "stig_id": "RHEL-09-654205",
            "title": "Successful/unsuccessful uses of the umount system call in RHEL 9 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258216",
            "stig_id": "RHEL-09-654210",
            "title": "Successful/unsuccessful uses of the umount2 system call in RHEL 9 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258217",
            "stig_id": "RHEL-09-654215",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258218",
            "stig_id": "RHEL-09-654220",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258219",
            "stig_id": "RHEL-09-654225",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258220",
            "stig_id": "RHEL-09-654230",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258221",
            "stig_id": "RHEL-09-654235",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258222",
            "stig_id": "RHEL-09-654240",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-001683",
                "CCI-001684",
                "CCI-001685",
                "CCI-001686",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258223",
            "stig_id": "RHEL-09-654245",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258224",
            "stig_id": "RHEL-09-654250",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/faillock.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258225",
            "stig_id": "RHEL-09-654255",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/lastlog.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258226",
            "stig_id": "RHEL-09-654260",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/tallylog.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258228",
            "stig_id": "RHEL-09-654270",
            "title": "RHEL 9 audit system must protect logon UIDs from unauthorized change.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000162",
                "CCI-000163",
                "CCI-000164",
                "CCI-000172"
            ]
        }
    ]
}