{
    "control": "AU-9",
    "title": "Protection of Audit Information",
    "ccis": [
        {
            "cci": "CCI-000162",
            "definition": "Protect audit information from unauthorized access."
        },
        {
            "cci": "CCI-000163",
            "definition": "Protect audit information from unauthorized modification."
        },
        {
            "cci": "CCI-000164",
            "definition": "Protect audit information from unauthorized deletion."
        },
        {
            "cci": "CCI-000165",
            "definition": "Write audit records to hardware-enforced, write-once media."
        },
        {
            "cci": "CCI-001348",
            "definition": "Store audit records on an organization-defined frequency in a repository that is part of a physically different system or system component than the system or component being audited."
        },
        {
            "cci": "CCI-001349",
            "definition": "Defines a frequency for storing audit records in a repository that is part of a physically different system or system component than the system or component being audited."
        },
        {
            "cci": "CCI-001350",
            "definition": "Implement cryptographic mechanisms to protect the integrity of audit information."
        },
        {
            "cci": "CCI-001351",
            "definition": "Authorize access to management of audit logging functionality to only an organization-defined subset of privileged users or roles."
        },
        {
            "cci": "CCI-001493",
            "definition": "Protect audit tools from unauthorized access."
        },
        {
            "cci": "CCI-001494",
            "definition": "Protect audit tools from unauthorized modification."
        },
        {
            "cci": "CCI-001495",
            "definition": "Protect audit tools from unauthorized deletion."
        },
        {
            "cci": "CCI-001496",
            "definition": "Implement cryptographic mechanisms to protect the integrity of audit tools."
        },
        {
            "cci": "CCI-001575",
            "definition": "The organization defines the system or system component for storing audit records that is a different system or system component than the system or component being audited."
        },
        {
            "cci": "CCI-001894",
            "definition": "Defines the subset of privileged users who will be authorized access to the management of audit functionality."
        },
        {
            "cci": "CCI-001895",
            "definition": "Defines the audit information requiring dual authorization for movement or deletion actions."
        },
        {
            "cci": "CCI-001896",
            "definition": "Enforce dual authorization for movement and/or deletion of organization-defined audit information."
        },
        {
            "cci": "CCI-001897",
            "definition": "Defines the subset of privileged users or roles who will be authorized read-only access to audit information."
        },
        {
            "cci": "CCI-001898",
            "definition": "Authorize read-only access to audit information to an organization-defined subset of privileged users or roles."
        }
    ],
    "rules_mapped": 41,
    "rules": [
        {
            "rule": "V-220782",
            "stig_id": "WN10-AU-000515",
            "title": "Windows 10 permissions for the Application event log must prevent access by non-privileged accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000162",
                "CCI-000163",
                "CCI-000164"
            ]
        },
        {
            "rule": "V-220783",
            "stig_id": "WN10-AU-000520",
            "title": "Windows 10 permissions for the Security event log must prevent access by non-privileged accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000162",
                "CCI-000163",
                "CCI-000164"
            ]
        },
        {
            "rule": "V-220784",
            "stig_id": "WN10-AU-000525",
            "title": "Windows 10 permissions for the System event log must prevent access by non-privileged accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000162",
                "CCI-000163",
                "CCI-000164"
            ]
        },
        {
            "rule": "V-220978",
            "stig_id": "WN10-UR-000130",
            "title": "The Manage auditing and security log user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000162",
                "CCI-000163",
                "CCI-000164",
                "CCI-000171",
                "CCI-001914"
            ]
        },
        {
            "rule": "V-253340",
            "stig_id": "WN11-AU-000515",
            "title": "Windows 11 permissions for the Application event log must prevent access by non-privileged accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000162"
            ]
        },
        {
            "rule": "V-253341",
            "stig_id": "WN11-AU-000520",
            "title": "Windows 11 permissions for the Security event log must prevent access by non-privileged accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000162"
            ]
        },
        {
            "rule": "V-253342",
            "stig_id": "WN11-AU-000525",
            "title": "Windows 11 permissions for the System event log must prevent access by non-privileged accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000162"
            ]
        },
        {
            "rule": "V-253501",
            "stig_id": "WN11-UR-000130",
            "title": "The \"Manage auditing and security log\" user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000162",
                "CCI-000171"
            ]
        },
        {
            "rule": "V-205640",
            "stig_id": "WN19-AU-000030",
            "title": "Windows Server 2019 permissions for the Application event log must prevent access by non-privileged accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000162",
                "CCI-000163",
                "CCI-000164"
            ]
        },
        {
            "rule": "V-205641",
            "stig_id": "WN19-AU-000040",
            "title": "Windows Server 2019 permissions for the Security event log must prevent access by non-privileged accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000162",
                "CCI-000163",
                "CCI-000164"
            ]
        },
        {
            "rule": "V-205642",
            "stig_id": "WN19-AU-000050",
            "title": "Windows Server 2019 permissions for the System event log must prevent access by non-privileged accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000162",
                "CCI-000163",
                "CCI-000164"
            ]
        },
        {
            "rule": "V-205643",
            "stig_id": "WN19-UR-000170",
            "title": "Windows Server 2019 Manage auditing and security log user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000162",
                "CCI-000163",
                "CCI-000164",
                "CCI-000171",
                "CCI-001914"
            ]
        },
        {
            "rule": "V-205731",
            "stig_id": "WN19-AU-000060",
            "title": "Windows Server 2019 Event Viewer must be protected from unauthorized modification and deletion.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-001494",
                "CCI-001495"
            ]
        },
        {
            "rule": "V-254296",
            "stig_id": "WN22-AU-000030",
            "title": "Windows Server 2022 permissions for the Application event log must prevent access by nonprivileged accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000162",
                "CCI-000163",
                "CCI-000164"
            ]
        },
        {
            "rule": "V-254297",
            "stig_id": "WN22-AU-000040",
            "title": "Windows Server 2022 permissions for the Security event log must prevent access by nonprivileged accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000162",
                "CCI-000163",
                "CCI-000164"
            ]
        },
        {
            "rule": "V-254298",
            "stig_id": "WN22-AU-000050",
            "title": "Windows Server 2022 permissions for the System event log must prevent access by nonprivileged accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000162",
                "CCI-000163",
                "CCI-000164"
            ]
        },
        {
            "rule": "V-254299",
            "stig_id": "WN22-AU-000060",
            "title": "Windows Server 2022 Event Viewer must be protected from unauthorized modification and deletion.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-001494",
                "CCI-001495"
            ]
        },
        {
            "rule": "V-254507",
            "stig_id": "WN22-UR-000170",
            "title": "Windows Server 2022 manage auditing and security log user right must only be assigned to the Administrators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000162",
                "CCI-000163",
                "CCI-000164",
                "CCI-000171",
                "CCI-001914"
            ]
        },
        {
            "rule": "V-230396",
            "stig_id": "RHEL-08-030070",
            "title": "RHEL 8 audit logs must have a mode of 0600 or less permissive to prevent unauthorized read access.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000162"
            ]
        },
        {
            "rule": "V-230397",
            "stig_id": "RHEL-08-030080",
            "title": "RHEL 8 audit logs must be owned by root to prevent unauthorized read access.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000162"
            ]
        },
        {
            "rule": "V-230398",
            "stig_id": "RHEL-08-030090",
            "title": "RHEL 8 audit logs must be group-owned by root to prevent unauthorized read access.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000162"
            ]
        },
        {
            "rule": "V-230399",
            "stig_id": "RHEL-08-030100",
            "title": "RHEL 8 audit log directory must be owned by root to prevent unauthorized read access.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000162"
            ]
        },
        {
            "rule": "V-230400",
            "stig_id": "RHEL-08-030110",
            "title": "RHEL 8 audit log directory must be group-owned by root to prevent unauthorized read access.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000162"
            ]
        },
        {
            "rule": "V-230401",
            "stig_id": "RHEL-08-030120",
            "title": "RHEL 8 audit log directory must have a mode of 0700 or less permissive to prevent unauthorized read access.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000162"
            ]
        },
        {
            "rule": "V-230402",
            "stig_id": "RHEL-08-030121",
            "title": "RHEL 8 audit system must protect auditing rules from unauthorized change.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000162"
            ]
        },
        {
            "rule": "V-230403",
            "stig_id": "RHEL-08-030122",
            "title": "RHEL 8 audit system must protect logon UIDs from unauthorized change.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000162"
            ]
        },
        {
            "rule": "V-230472",
            "stig_id": "RHEL-08-030620",
            "title": "RHEL 8 audit tools must have a mode of 0755 or less permissive.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001493"
            ]
        },
        {
            "rule": "V-230473",
            "stig_id": "RHEL-08-030630",
            "title": "RHEL 8 audit tools must be owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001493"
            ]
        },
        {
            "rule": "V-230474",
            "stig_id": "RHEL-08-030640",
            "title": "RHEL 8 audit tools must be group-owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001493"
            ]
        },
        {
            "rule": "V-230475",
            "stig_id": "RHEL-08-030650",
            "title": "RHEL 8 must use cryptographic mechanisms to protect the integrity of audit tools.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001496"
            ]
        },
        {
            "rule": "V-257887",
            "stig_id": "RHEL-09-232035",
            "title": "RHEL 9 audit tools must have a mode of 0755 or less permissive.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001493"
            ]
        },
        {
            "rule": "V-257924",
            "stig_id": "RHEL-09-232220",
            "title": "RHEL 9 audit tools must be owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001493"
            ]
        },
        {
            "rule": "V-257925",
            "stig_id": "RHEL-09-232225",
            "title": "RHEL 9 audit tools must be group-owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001493"
            ]
        },
        {
            "rule": "V-258137",
            "stig_id": "RHEL-09-651025",
            "title": "RHEL 9 must use cryptographic mechanisms to protect the integrity of audit tools.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001493",
                "CCI-001494",
                "CCI-001495",
                "CCI-001496"
            ]
        },
        {
            "rule": "V-258165",
            "stig_id": "RHEL-09-653080",
            "title": "RHEL 9 audit logs must be group-owned by root or by a restricted logging group to prevent unauthorized read access.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000162",
                "CCI-000163",
                "CCI-000164",
                "CCI-001314"
            ]
        },
        {
            "rule": "V-258166",
            "stig_id": "RHEL-09-653085",
            "title": "RHEL 9 audit log directory must be owned by root to prevent unauthorized read access.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000162",
                "CCI-000163",
                "CCI-000164",
                "CCI-001314"
            ]
        },
        {
            "rule": "V-258167",
            "stig_id": "RHEL-09-653090",
            "title": "RHEL 9 audit logs file must have mode 0600 or less permissive to prevent unauthorized access to the audit log.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000162",
                "CCI-000163",
                "CCI-000164",
                "CCI-001314"
            ]
        },
        {
            "rule": "V-258228",
            "stig_id": "RHEL-09-654270",
            "title": "RHEL 9 audit system must protect logon UIDs from unauthorized change.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000162",
                "CCI-000163",
                "CCI-000164",
                "CCI-000172"
            ]
        },
        {
            "rule": "V-258229",
            "stig_id": "RHEL-09-654275",
            "title": "RHEL 9 audit system must protect auditing rules from unauthorized change.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000162",
                "CCI-000163",
                "CCI-000164"
            ]
        },
        {
            "rule": "V-270175",
            "stig_id": "RHEL-09-232103",
            "title": "RHEL 9 \"/etc/audit/\" must be owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000162"
            ]
        },
        {
            "rule": "V-270176",
            "stig_id": "RHEL-09-232104",
            "title": "RHEL 9 \"/etc/audit/\" must be group-owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000162"
            ]
        }
    ]
}