{
    "control": "AU-3",
    "title": "Content of Audit Records",
    "ccis": [
        {
            "cci": "CCI-000130",
            "definition": "Ensure that audit records contain information that establishes what type of event occurred."
        },
        {
            "cci": "CCI-000131",
            "definition": "Ensure that audit records containing information that establishes when the event occurred."
        },
        {
            "cci": "CCI-000132",
            "definition": "Ensure that audit records containing information that establishes where the event occurred."
        },
        {
            "cci": "CCI-000133",
            "definition": "Ensure that audit records containing information that establishes the source of the event."
        },
        {
            "cci": "CCI-000134",
            "definition": "Ensure that audit records containing information that establishes the outcome of the event."
        },
        {
            "cci": "CCI-000135",
            "definition": "Generate audit records containing the organization-defined additional information that is to be included in the audit records."
        },
        {
            "cci": "CCI-001487",
            "definition": "Ensure that audit records containing information that establishes the identity of any individuals, subjects, or objects/entities associated with the event."
        },
        {
            "cci": "CCI-001488",
            "definition": "Defines the additional information to be included in the audit records."
        },
        {
            "cci": "CCI-001844",
            "definition": "The information system provides centralized management and configuration of the content to be captured in audit records generated by organization-defined information system components."
        },
        {
            "cci": "CCI-001845",
            "definition": "The information system provides centralized configuration of the content to be captured in audit records generated by organization-defined information system components."
        },
        {
            "cci": "CCI-001846",
            "definition": "The organization defines information system components that will generate the audit records which are to be captured for centralized management of the content."
        },
        {
            "cci": "CCI-001847",
            "definition": "The organization defines information system components that will generate the audit records which are to be captured for centralized configuration of the content."
        }
    ],
    "rules_mapped": 76,
    "rules": [
        {
            "rule": "V-242403",
            "stig_id": "CNTR-K8-000700",
            "title": "Kubernetes API Server must generate audit records that identify what type of event has occurred, identify the source of the event, contain the event results, identify any users, and identify any containers associated with the event.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000018",
                "CCI-000130",
                "CCI-000131",
                "CCI-000132",
                "CCI-000133",
                "CCI-000134",
                "CCI-000135",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001487",
                "CCI-002264"
            ]
        },
        {
            "rule": "V-220786",
            "stig_id": "WN10-AU-000555",
            "title": "Windows 10 must be configured to audit Other Policy Change Events Failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000130"
            ]
        },
        {
            "rule": "V-220787",
            "stig_id": "WN10-AU-000560",
            "title": "Windows 10 must be configured to audit other Logon/Logoff Events Successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000130"
            ]
        },
        {
            "rule": "V-220788",
            "stig_id": "WN10-AU-000565",
            "title": "Windows 10 must be configured to audit other Logon/Logoff Events Failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000130"
            ]
        },
        {
            "rule": "V-220789",
            "stig_id": "WN10-AU-000570",
            "title": "Windows 10 must be configured to audit Detailed File Share Failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000130"
            ]
        },
        {
            "rule": "V-220790",
            "stig_id": "WN10-AU-000575",
            "title": "Windows 10 must be configured to audit MPSSVC Rule-Level Policy Change Successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000130"
            ]
        },
        {
            "rule": "V-220791",
            "stig_id": "WN10-AU-000580",
            "title": "Windows 10 must be configured to audit MPSSVC Rule-Level Policy Change Failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000130"
            ]
        },
        {
            "rule": "V-220809",
            "stig_id": "WN10-CC-000066",
            "title": "Command line data must be included in process creation events.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000135"
            ]
        },
        {
            "rule": "V-220860",
            "stig_id": "WN10-CC-000326",
            "title": "PowerShell script block logging must be enabled on Windows 10.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000135"
            ]
        },
        {
            "rule": "V-252896",
            "stig_id": "WN10-CC-000327",
            "title": "PowerShell Transcription must be enabled on Windows 10.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000132",
                "CCI-000134"
            ]
        },
        {
            "rule": "V-253343",
            "stig_id": "WN11-AU-000550",
            "title": "Windows 11 must be configured to audit Other Policy Change Events Successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000130"
            ]
        },
        {
            "rule": "V-253344",
            "stig_id": "WN11-AU-000555",
            "title": "Windows 11 must be configured to audit Other Policy Change Events Failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000130"
            ]
        },
        {
            "rule": "V-253345",
            "stig_id": "WN11-AU-000560",
            "title": "Windows 11 must be configured to audit other Logon/Logoff Events Successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000130"
            ]
        },
        {
            "rule": "V-253346",
            "stig_id": "WN11-AU-000565",
            "title": "Windows 11 must be configured to audit other Logon/Logoff Events Failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000130"
            ]
        },
        {
            "rule": "V-253347",
            "stig_id": "WN11-AU-000570",
            "title": "Windows 11 must be configured to audit Detailed File Share Failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000130"
            ]
        },
        {
            "rule": "V-253348",
            "stig_id": "WN11-AU-000575",
            "title": "Windows 11 must be configured to audit MPSSVC Rule-Level Policy Change Successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000130"
            ]
        },
        {
            "rule": "V-253349",
            "stig_id": "WN11-AU-000580",
            "title": "Windows 11 must be configured to audit MPSSVC Rule-Level Policy Change Failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000130"
            ]
        },
        {
            "rule": "V-253367",
            "stig_id": "WN11-CC-000066",
            "title": "Command line data must be included in process creation events.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000135"
            ]
        },
        {
            "rule": "V-253414",
            "stig_id": "WN11-CC-000326",
            "title": "PowerShell script block logging must be enabled on Windows 11.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000135"
            ]
        },
        {
            "rule": "V-253415",
            "stig_id": "WN11-CC-000327",
            "title": "PowerShell Transcription must be enabled on Windows 11.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000134"
            ]
        },
        {
            "rule": "V-205638",
            "stig_id": "WN19-CC-000090",
            "title": "Windows Server 2019 command line data must be included in process creation events.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000135"
            ]
        },
        {
            "rule": "V-205639",
            "stig_id": "WN19-CC-000460",
            "title": "Windows Server 2019 PowerShell script block logging must be enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000135"
            ]
        },
        {
            "rule": "V-257503",
            "stig_id": "WN19-CC-000530",
            "title": "Windows Server 2019 must have PowerShell Transcription enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000134"
            ]
        },
        {
            "rule": "V-254341",
            "stig_id": "WN22-CC-000090",
            "title": "Windows Server 2022 command line data must be included in process creation events.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000135"
            ]
        },
        {
            "rule": "V-254377",
            "stig_id": "WN22-CC-000460",
            "title": "Windows Server 2022 PowerShell script block logging must be enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000135"
            ]
        },
        {
            "rule": "V-254384",
            "stig_id": "WN22-CC-000530",
            "title": "Windows Server 2022 must have PowerShell Transcription enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000134"
            ]
        },
        {
            "rule": "V-257796",
            "stig_id": "RHEL-09-212055",
            "title": "RHEL 9 must enable auditing of processes that start prior to the audit daemon.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001464",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258045",
            "stig_id": "RHEL-09-411030",
            "title": "RHEL 9 duplicate User IDs (UIDs) must not exist for interactive users.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000135",
                "CCI-000764",
                "CCI-000804"
            ]
        },
        {
            "rule": "V-258151",
            "stig_id": "RHEL-09-653010",
            "title": "RHEL 9 audit package must be installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000131",
                "CCI-000132",
                "CCI-000133",
                "CCI-000134",
                "CCI-000135",
                "CCI-000154",
                "CCI-000158",
                "CCI-000159",
                "CCI-000169",
                "CCI-000172",
                "CCI-001464",
                "CCI-001487",
                "CCI-001814",
                "CCI-001875",
                "CCI-001876",
                "CCI-001877",
                "CCI-001878",
                "CCI-001879",
                "CCI-001880",
                "CCI-001881",
                "CCI-001882",
                "CCI-001889",
                "CCI-001914",
                "CCI-002884",
                "CCI-003938"
            ]
        },
        {
            "rule": "V-258152",
            "stig_id": "RHEL-09-653015",
            "title": "RHEL 9 audit service must be enabled.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000131",
                "CCI-000132",
                "CCI-000133",
                "CCI-000134",
                "CCI-000135",
                "CCI-000154",
                "CCI-000158",
                "CCI-000169",
                "CCI-000172",
                "CCI-001464",
                "CCI-001487",
                "CCI-001814",
                "CCI-001875",
                "CCI-001876",
                "CCI-001877",
                "CCI-001878",
                "CCI-001879",
                "CCI-001880",
                "CCI-001881",
                "CCI-001882",
                "CCI-001889",
                "CCI-001914",
                "CCI-002884",
                "CCI-003938",
                "CCI-004188"
            ]
        },
        {
            "rule": "V-258161",
            "stig_id": "RHEL-09-653060",
            "title": "RHEL 9 must label all offloaded audit logs before sending them to the central log server.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000132",
                "CCI-001851"
            ]
        },
        {
            "rule": "V-258169",
            "stig_id": "RHEL-09-653100",
            "title": "RHEL 9 must produce audit records containing information to establish the identity of any individual or process associated with the event.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366",
                "CCI-001487"
            ]
        },
        {
            "rule": "V-258177",
            "stig_id": "RHEL-09-654015",
            "title": "RHEL 9 must audit all uses of the chmod, fchmod, and fchmodat system calls.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258178",
            "stig_id": "RHEL-09-654020",
            "title": "RHEL 9 must audit all uses of the chown, fchown, fchownat, and lchown system calls.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258179",
            "stig_id": "RHEL-09-654025",
            "title": "RHEL 9 must audit all uses of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258180",
            "stig_id": "RHEL-09-654030",
            "title": "RHEL 9 must audit all uses of umount system calls.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258181",
            "stig_id": "RHEL-09-654035",
            "title": "RHEL 9 must audit all uses of the chacl command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258182",
            "stig_id": "RHEL-09-654040",
            "title": "RHEL 9 must audit all uses of the setfacl command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258183",
            "stig_id": "RHEL-09-654045",
            "title": "RHEL 9 must audit all uses of the chcon command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258184",
            "stig_id": "RHEL-09-654050",
            "title": "RHEL 9 must audit all uses of the semanage command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258185",
            "stig_id": "RHEL-09-654055",
            "title": "RHEL 9 must audit all uses of the setfiles command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258186",
            "stig_id": "RHEL-09-654060",
            "title": "RHEL 9 must audit all uses of the setsebool command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258187",
            "stig_id": "RHEL-09-654065",
            "title": "RHEL 9 must audit all uses of the rename, unlink, rmdir, renameat, and unlinkat system calls.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258188",
            "stig_id": "RHEL-09-654070",
            "title": "RHEL 9 must audit all uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258189",
            "stig_id": "RHEL-09-654075",
            "title": "RHEL 9 must audit all uses of the delete_module system call.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258190",
            "stig_id": "RHEL-09-654080",
            "title": "RHEL 9 must audit all uses of the init_module and finit_module system calls.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258191",
            "stig_id": "RHEL-09-654085",
            "title": "RHEL 9 must audit all uses of the chage command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258192",
            "stig_id": "RHEL-09-654090",
            "title": "RHEL 9 must audit all uses of the chsh command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258193",
            "stig_id": "RHEL-09-654095",
            "title": "RHEL 9 must audit all uses of the crontab command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258194",
            "stig_id": "RHEL-09-654100",
            "title": "RHEL 9 must audit all uses of the gpasswd command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258195",
            "stig_id": "RHEL-09-654105",
            "title": "RHEL 9 must audit all uses of the kmod command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258196",
            "stig_id": "RHEL-09-654110",
            "title": "RHEL 9 must audit all uses of the newgrp command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258197",
            "stig_id": "RHEL-09-654115",
            "title": "RHEL 9 must audit all uses of the pam_timestamp_check command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258198",
            "stig_id": "RHEL-09-654120",
            "title": "RHEL 9 must audit all uses of the passwd command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258199",
            "stig_id": "RHEL-09-654125",
            "title": "RHEL 9 must audit all uses of the postdrop command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258200",
            "stig_id": "RHEL-09-654130",
            "title": "RHEL 9 must audit all uses of the postqueue command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258201",
            "stig_id": "RHEL-09-654135",
            "title": "RHEL 9 must audit all uses of the ssh-agent command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258202",
            "stig_id": "RHEL-09-654140",
            "title": "RHEL 9 must audit all uses of the ssh-keysign command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258203",
            "stig_id": "RHEL-09-654145",
            "title": "RHEL 9 must audit all uses of the su command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258204",
            "stig_id": "RHEL-09-654150",
            "title": "RHEL 9 must audit all uses of the sudo command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258205",
            "stig_id": "RHEL-09-654155",
            "title": "RHEL 9 must audit all uses of the sudoedit command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258206",
            "stig_id": "RHEL-09-654160",
            "title": "RHEL 9 must audit all uses of the unix_chkpwd command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258207",
            "stig_id": "RHEL-09-654165",
            "title": "RHEL 9 must audit all uses of the unix_update command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258208",
            "stig_id": "RHEL-09-654170",
            "title": "RHEL 9 must audit all uses of the userhelper command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258209",
            "stig_id": "RHEL-09-654175",
            "title": "RHEL 9 must audit all uses of the usermod command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258210",
            "stig_id": "RHEL-09-654180",
            "title": "RHEL 9 must audit all uses of the mount command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258215",
            "stig_id": "RHEL-09-654205",
            "title": "Successful/unsuccessful uses of the umount system call in RHEL 9 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258216",
            "stig_id": "RHEL-09-654210",
            "title": "Successful/unsuccessful uses of the umount2 system call in RHEL 9 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258217",
            "stig_id": "RHEL-09-654215",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258218",
            "stig_id": "RHEL-09-654220",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258219",
            "stig_id": "RHEL-09-654225",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258220",
            "stig_id": "RHEL-09-654230",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258221",
            "stig_id": "RHEL-09-654235",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258222",
            "stig_id": "RHEL-09-654240",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-001683",
                "CCI-001684",
                "CCI-001685",
                "CCI-001686",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258223",
            "stig_id": "RHEL-09-654245",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258225",
            "stig_id": "RHEL-09-654255",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/lastlog.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        }
    ]
}