{
    "control": "CM-5",
    "title": "Access Restrictions for Change",
    "ccis": [
        {
            "cci": "CCI-000338",
            "definition": "The organization defines physical access restrictions associated with changes to the information system."
        },
        {
            "cci": "CCI-000339",
            "definition": "The organization documents physical access restrictions associated with changes to the information system."
        },
        {
            "cci": "CCI-000340",
            "definition": "Approve physical access restrictions associated with changes to the system."
        },
        {
            "cci": "CCI-000341",
            "definition": "Enforce physical access restrictions associated with changes to the system."
        },
        {
            "cci": "CCI-000342",
            "definition": "The organization defines logical access restrictions associated with changes to the information system."
        },
        {
            "cci": "CCI-000343",
            "definition": "The organization documents logical access restrictions associated with changes to the information system."
        },
        {
            "cci": "CCI-000344",
            "definition": "Approve logical access restrictions associated with changes to the system."
        },
        {
            "cci": "CCI-000345",
            "definition": "Enforce logical access restrictions associated with changes to the system."
        },
        {
            "cci": "CCI-000348",
            "definition": "The organization defines a frequency with which to conduct reviews of information system changes."
        },
        {
            "cci": "CCI-000349",
            "definition": "The organization reviews information system changes per organization-defined frequency to determine whether unauthorized changes have occurred."
        },
        {
            "cci": "CCI-000350",
            "definition": "The organization reviews information system changes upon organization-defined circumstances to determine whether unauthorized changes have occurred."
        },
        {
            "cci": "CCI-000353",
            "definition": "Defines system components requiring enforcement of a dual authorization for system changes."
        },
        {
            "cci": "CCI-000354",
            "definition": "Enforce dual authorization for implementing changes to organization-defined system components."
        },
        {
            "cci": "CCI-001499",
            "definition": "Limit privileges to change software resident within software libraries."
        },
        {
            "cci": "CCI-001747",
            "definition": "The organization defines critical software components the information system will prevent from being installed without verification the component has been digitally signed using a certificate that is recognized and approved by the organization."
        },
        {
            "cci": "CCI-001748",
            "definition": "The organization defines critical firmware components the information system will prevent from being installed without verification the component has been digitally signed using a certificate that is recognized and approved by the organization."
        },
        {
            "cci": "CCI-001749",
            "definition": "The information system prevents the installation of organization-defined software components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization."
        },
        {
            "cci": "CCI-001750",
            "definition": "The information system prevents the installation of organization-defined firmware components without verification the firmware component has been digitally signed using a certificate that is recognized and approved by the organization."
        },
        {
            "cci": "CCI-001751",
            "definition": "Defines system-level information requiring enforcement of a dual authorization for system changes."
        },
        {
            "cci": "CCI-001752",
            "definition": "Enforce dual authorization for implementing changes to organization-defined system-level information."
        },
        {
            "cci": "CCI-001753",
            "definition": "Limit privileges to change system components within a production or operational environment."
        },
        {
            "cci": "CCI-001754",
            "definition": "Limit privileges to change system-related information within a production or operational environment."
        },
        {
            "cci": "CCI-001813",
            "definition": "Enforce access restrictions using organization-defined mechanisms."
        },
        {
            "cci": "CCI-001814",
            "definition": "The Information system supports auditing of the enforcement actions."
        },
        {
            "cci": "CCI-001826",
            "definition": "The organization defines the circumstances upon which the organization reviews the information system changes to determine whether unauthorized changes have occurred."
        },
        {
            "cci": "CCI-001827",
            "definition": "The organization defines the frequency with which to review information system privileges."
        },
        {
            "cci": "CCI-001828",
            "definition": "The organization defines the frequency with which to reevaluate information system privileges."
        },
        {
            "cci": "CCI-001829",
            "definition": "The organization reviews information system privileges per an organization-defined frequency."
        },
        {
            "cci": "CCI-001830",
            "definition": "The organization reevaluates information system privileges per an organization-defined frequency."
        }
    ],
    "rules_mapped": 41,
    "rules": [
        {
            "rule": "V-242404",
            "stig_id": "CNTR-K8-000850",
            "title": "Kubernetes Kubelet must deny hostname override.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-001499"
            ]
        },
        {
            "rule": "V-242405",
            "stig_id": "CNTR-K8-000860",
            "title": "The Kubernetes manifests must be owned by root.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-001499"
            ]
        },
        {
            "rule": "V-242406",
            "stig_id": "CNTR-K8-000880",
            "title": "The Kubernetes KubeletConfiguration file must be owned by root.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-001499"
            ]
        },
        {
            "rule": "V-242407",
            "stig_id": "CNTR-K8-000890",
            "title": "The Kubernetes KubeletConfiguration files must have file permissions set to 644 or more restrictive.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-001499"
            ]
        },
        {
            "rule": "V-242408",
            "stig_id": "CNTR-K8-000900",
            "title": "The Kubernetes manifest files must have least privileges.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366",
                "CCI-001499"
            ]
        },
        {
            "rule": "V-220753",
            "stig_id": "WN10-AU-000045",
            "title": "The system must be configured to audit Detailed Tracking - PNP Activity successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172",
                "CCI-001814",
                "CCI-003938"
            ]
        },
        {
            "rule": "V-220754",
            "stig_id": "WN10-AU-000050",
            "title": "The system must be configured to audit Detailed Tracking - Process Creation successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000172",
                "CCI-001814",
                "CCI-003938"
            ]
        },
        {
            "rule": "V-253311",
            "stig_id": "WN11-AU-000045",
            "title": "The system must be configured to audit Detailed Tracking - PNP Activity successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172",
                "CCI-001814",
                "CCI-003938"
            ]
        },
        {
            "rule": "V-253312",
            "stig_id": "WN11-AU-000050",
            "title": "The system must be configured to audit Detailed Tracking - Process Creation successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000172",
                "CCI-001814",
                "CCI-003938"
            ]
        },
        {
            "rule": "V-230257",
            "stig_id": "RHEL-08-010300",
            "title": "RHEL 8 system commands must have mode 755 or less permissive.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001499"
            ]
        },
        {
            "rule": "V-230258",
            "stig_id": "RHEL-08-010310",
            "title": "RHEL 8 system commands must be owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001499"
            ]
        },
        {
            "rule": "V-230259",
            "stig_id": "RHEL-08-010320",
            "title": "RHEL 8 system commands must be group-owned by root or a system account.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001499"
            ]
        },
        {
            "rule": "V-230260",
            "stig_id": "RHEL-08-010330",
            "title": "RHEL 8 library files must have mode 755 or less permissive.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001499"
            ]
        },
        {
            "rule": "V-230261",
            "stig_id": "RHEL-08-010340",
            "title": "RHEL 8 library files must be owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001499"
            ]
        },
        {
            "rule": "V-230262",
            "stig_id": "RHEL-08-010350",
            "title": "RHEL 8 library files must be group-owned by root or a system account.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001499"
            ]
        },
        {
            "rule": "V-230264",
            "stig_id": "RHEL-08-010370",
            "title": "RHEL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components from a repository without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001749",
                "CCI-003992"
            ]
        },
        {
            "rule": "V-230265",
            "stig_id": "RHEL-08-010371",
            "title": "RHEL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components of local packages without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001749",
                "CCI-003992"
            ]
        },
        {
            "rule": "V-230266",
            "stig_id": "RHEL-08-010372",
            "title": "RHEL 8 must prevent the loading of a new kernel for later execution.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001749",
                "CCI-003992"
            ]
        },
        {
            "rule": "V-251707",
            "stig_id": "RHEL-08-010331",
            "title": "RHEL 8 library directories must have mode 755 or less permissive.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001499"
            ]
        },
        {
            "rule": "V-251708",
            "stig_id": "RHEL-08-010341",
            "title": "RHEL 8 library directories must be owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001499"
            ]
        },
        {
            "rule": "V-251709",
            "stig_id": "RHEL-08-010351",
            "title": "RHEL 8 library directories must be group-owned by root or a system account.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001499"
            ]
        },
        {
            "rule": "V-256973",
            "stig_id": "RHEL-08-010019",
            "title": "RHEL 8 must ensure cryptographic verification of vendor software packages.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001749",
                "CCI-003992"
            ]
        },
        {
            "rule": "V-257799",
            "stig_id": "RHEL-09-213020",
            "title": "RHEL 9 must prevent the loading of a new kernel for later execution.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001749",
                "CCI-003992"
            ]
        },
        {
            "rule": "V-257819",
            "stig_id": "RHEL-09-214010",
            "title": "RHEL 9 must ensure cryptographic verification of vendor software packages.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001749",
                "CCI-003992"
            ]
        },
        {
            "rule": "V-257820",
            "stig_id": "RHEL-09-214015",
            "title": "RHEL 9 must check the GPG signature of software packages originating from external software repositories before installation.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001749",
                "CCI-003992"
            ]
        },
        {
            "rule": "V-257821",
            "stig_id": "RHEL-09-214020",
            "title": "RHEL 9 must check the GPG signature of locally installed software packages before installation.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001749",
                "CCI-003992"
            ]
        },
        {
            "rule": "V-257822",
            "stig_id": "RHEL-09-214025",
            "title": "RHEL 9 must have GPG signature verification enabled for all software repositories.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001749",
                "CCI-003992"
            ]
        },
        {
            "rule": "V-257825",
            "stig_id": "RHEL-09-215010",
            "title": "RHEL 9 subscription-manager package must be installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001749",
                "CCI-003992"
            ]
        },
        {
            "rule": "V-257882",
            "stig_id": "RHEL-09-232010",
            "title": "RHEL 9 system commands must have mode 755 or less permissive.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001499"
            ]
        },
        {
            "rule": "V-257883",
            "stig_id": "RHEL-09-232015",
            "title": "RHEL 9 library directories must have mode 755 or less permissive.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001499"
            ]
        },
        {
            "rule": "V-257884",
            "stig_id": "RHEL-09-232020",
            "title": "RHEL 9 library files must have mode 755 or less permissive.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001499"
            ]
        },
        {
            "rule": "V-257918",
            "stig_id": "RHEL-09-232190",
            "title": "RHEL 9 system commands must be owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001499"
            ]
        },
        {
            "rule": "V-257919",
            "stig_id": "RHEL-09-232195",
            "title": "RHEL 9 system commands must be group-owned by root or a system account.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001499"
            ]
        },
        {
            "rule": "V-257920",
            "stig_id": "RHEL-09-232200",
            "title": "RHEL 9 library files must be owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001499"
            ]
        },
        {
            "rule": "V-257921",
            "stig_id": "RHEL-09-232205",
            "title": "RHEL 9 library files must be group-owned by root or a system account.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001499"
            ]
        },
        {
            "rule": "V-257922",
            "stig_id": "RHEL-09-232210",
            "title": "RHEL 9 library directories must be owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001499"
            ]
        },
        {
            "rule": "V-257923",
            "stig_id": "RHEL-09-232215",
            "title": "RHEL 9 library directories must be group-owned by root or a system account.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001499"
            ]
        },
        {
            "rule": "V-258003",
            "stig_id": "RHEL-09-255135",
            "title": "RHEL 9 SSH daemon must not allow GSSAPI authentication.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001813"
            ]
        },
        {
            "rule": "V-258004",
            "stig_id": "RHEL-09-255140",
            "title": "RHEL 9 SSH daemon must not allow Kerberos authentication.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001813"
            ]
        },
        {
            "rule": "V-258151",
            "stig_id": "RHEL-09-653010",
            "title": "RHEL 9 audit package must be installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000131",
                "CCI-000132",
                "CCI-000133",
                "CCI-000134",
                "CCI-000135",
                "CCI-000154",
                "CCI-000158",
                "CCI-000159",
                "CCI-000169",
                "CCI-000172",
                "CCI-001464",
                "CCI-001487",
                "CCI-001814",
                "CCI-001875",
                "CCI-001876",
                "CCI-001877",
                "CCI-001878",
                "CCI-001879",
                "CCI-001880",
                "CCI-001881",
                "CCI-001882",
                "CCI-001889",
                "CCI-001914",
                "CCI-002884",
                "CCI-003938"
            ]
        },
        {
            "rule": "V-258152",
            "stig_id": "RHEL-09-653015",
            "title": "RHEL 9 audit service must be enabled.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000131",
                "CCI-000132",
                "CCI-000133",
                "CCI-000134",
                "CCI-000135",
                "CCI-000154",
                "CCI-000158",
                "CCI-000169",
                "CCI-000172",
                "CCI-001464",
                "CCI-001487",
                "CCI-001814",
                "CCI-001875",
                "CCI-001876",
                "CCI-001877",
                "CCI-001878",
                "CCI-001879",
                "CCI-001880",
                "CCI-001881",
                "CCI-001882",
                "CCI-001889",
                "CCI-001914",
                "CCI-002884",
                "CCI-003938",
                "CCI-004188"
            ]
        }
    ]
}