{
    "control": "CM-6",
    "title": "Configuration Settings",
    "ccis": [
        {
            "cci": "CCI-000363",
            "definition": "The organization defines security configuration checklists to be used to establish and document configuration settings for the information system technology products employed."
        },
        {
            "cci": "CCI-000364",
            "definition": "The organization establishes configuration settings for information technology products employed within the information system using organization-defined security configuration checklists."
        },
        {
            "cci": "CCI-000365",
            "definition": "The organization documents configuration settings for information technology products employed within the information system using organization-defined security configuration checklists that reflect the most restrictive mode consistent with operational requirements."
        },
        {
            "cci": "CCI-000366",
            "definition": "Implement the security configuration settings."
        },
        {
            "cci": "CCI-000367",
            "definition": "Identify any deviations from the established configuration settings for organization-defined system components based on organization-defined operational requirements."
        },
        {
            "cci": "CCI-000368",
            "definition": "Document any deviations from the established configuration settings for organization-defined system components based on organization-defined operational requirements."
        },
        {
            "cci": "CCI-000369",
            "definition": "Approve any deviations from the established configuration settings for organization-defined system components based on organization-defined operational requirements."
        },
        {
            "cci": "CCI-000370",
            "definition": "Manage configuration settings for organization-defined system components using organization-defined automated mechanisms."
        },
        {
            "cci": "CCI-000371",
            "definition": "Apply configuration settings for organization-defined system components using organization-defined automated mechanisms."
        },
        {
            "cci": "CCI-000372",
            "definition": "Verify configuration settings for organization-defined system components using organization-defined automated mechanisms."
        },
        {
            "cci": "CCI-001502",
            "definition": "The organization monitors changes to the configuration settings in accordance with organizational policies and procedures."
        },
        {
            "cci": "CCI-001503",
            "definition": "The organization controls changes to the configuration settings in accordance with organizational policies and procedures."
        },
        {
            "cci": "CCI-001588",
            "definition": "The organization-defined security configuration checklists reflect the most restrictive mode consistent with operational requirements."
        },
        {
            "cci": "CCI-001755",
            "definition": "Defines the system components for which any deviation from the established configuration settings are to be identified, documented, and approved."
        },
        {
            "cci": "CCI-001756",
            "definition": "Defines the operational requirements on which the configuration settings for the organization-defined system components are to be based."
        },
        {
            "cci": "CCI-001757",
            "definition": "Defines the actions to employ when responding to unauthorized changes to the organization-defined configuration settings."
        },
        {
            "cci": "CCI-001758",
            "definition": "Defines the configuration settings for which to employ organization-defined actions in response to unauthorized changes."
        },
        {
            "cci": "CCI-001759",
            "definition": "Take organization-defined actions in response to unauthorized changes to organization-defined configuration settings."
        },
        {
            "cci": "CCI-002059",
            "definition": "Defines the system components for which the organization will employ automated mechanisms to centrally manage, apply, and verify configuration settings."
        }
    ],
    "rules_mapped": 525,
    "rules": [
        {
            "rule": "V-221574",
            "stig_id": "DTBC-0025",
            "title": "Network prediction must be disabled.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242383",
            "stig_id": "CNTR-K8-000290",
            "title": "User-managed resources must be created in dedicated namespaces.",
            "severity": "high",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242408",
            "stig_id": "CNTR-K8-000900",
            "title": "The Kubernetes manifest files must have least privileges.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366",
                "CCI-001499"
            ]
        },
        {
            "rule": "V-242444",
            "stig_id": "CNTR-K8-003110",
            "title": "The Kubernetes component manifests must be owned by root.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242445",
            "stig_id": "CNTR-K8-003120",
            "title": "The Kubernetes component etcd must be owned by etcd.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242446",
            "stig_id": "CNTR-K8-003130",
            "title": "The Kubernetes conf files must be owned by root.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242447",
            "stig_id": "CNTR-K8-003140",
            "title": "The Kubernetes Kube Proxy kubeconfig must have file permissions set to 644 or more restrictive.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242448",
            "stig_id": "CNTR-K8-003150",
            "title": "The Kubernetes Kube Proxy kubeconfig must be owned by root.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242449",
            "stig_id": "CNTR-K8-003160",
            "title": "The Kubernetes Kubelet certificate authority file must have file permissions set to 644 or more restrictive.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242450",
            "stig_id": "CNTR-K8-003170",
            "title": "The Kubernetes Kubelet certificate authority must be owned by root.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242451",
            "stig_id": "CNTR-K8-003180",
            "title": "The Kubernetes component PKI must be owned by root.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242452",
            "stig_id": "CNTR-K8-003190",
            "title": "The Kubernetes kubelet KubeConfig must have file permissions set to 644 or more restrictive.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242453",
            "stig_id": "CNTR-K8-003200",
            "title": "The Kubernetes kubelet KubeConfig file must be owned by root.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242454",
            "stig_id": "CNTR-K8-003210",
            "title": "The Kubernetes kubeadm.conf must be owned by root.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242455",
            "stig_id": "CNTR-K8-003220",
            "title": "The Kubernetes kubeadm.conf must have file permissions set to 644 or more restrictive.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242456",
            "stig_id": "CNTR-K8-003230",
            "title": "The Kubernetes kubelet config must have file permissions set to 644 or more restrictive.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242457",
            "stig_id": "CNTR-K8-003240",
            "title": "The Kubernetes kubelet config must be owned by root.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242459",
            "stig_id": "CNTR-K8-003260",
            "title": "The Kubernetes etcd must have file permissions set to 644 or more restrictive.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242460",
            "stig_id": "CNTR-K8-003270",
            "title": "The Kubernetes admin kubeconfig must have file permissions set to 644 or more restrictive.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242461",
            "stig_id": "CNTR-K8-003280",
            "title": "Kubernetes API Server audit logs must be enabled.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242462",
            "stig_id": "CNTR-K8-003290",
            "title": "The Kubernetes API Server must be set to audit log max size.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242463",
            "stig_id": "CNTR-K8-003300",
            "title": "The Kubernetes API Server must be set to audit log maximum backup.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242464",
            "stig_id": "CNTR-K8-003310",
            "title": "The Kubernetes API Server audit log retention must be set.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242465",
            "stig_id": "CNTR-K8-003320",
            "title": "The Kubernetes API Server audit log path must be set.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242466",
            "stig_id": "CNTR-K8-003330",
            "title": "The Kubernetes PKI CRT must have file permissions set to 644 or more restrictive.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-242467",
            "stig_id": "CNTR-K8-003340",
            "title": "The Kubernetes PKI keys must have file permissions set to 600 or more restrictive.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220697",
            "stig_id": "WN10-00-000005",
            "title": "Domain-joined systems must use Windows 10 Enterprise Edition 64-bit version.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220698",
            "stig_id": "WN10-00-000010",
            "title": "Windows 10 domain-joined systems must have a Trusted Platform Module (TPM) enabled and ready for use.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220699",
            "stig_id": "WN10-00-000015",
            "title": "Windows 10 systems must have Unified Extensible Firmware Interface (UEFI) firmware and be configured to run in UEFI mode, not Legacy BIOS.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220700",
            "stig_id": "WN10-00-000020",
            "title": "Secure Boot must be enabled on Windows 10 systems.",
            "severity": "low",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220701",
            "stig_id": "WN10-00-000025",
            "title": "Windows 10 must employ automated mechanisms to determine the state of system components with regard to flaw remediation using the following frequency: Continuously, where ESS is used; 30 days, for any additional internal network scans not covered by ESS; and annually, for external scans by Computer Network Defense Service Provider (CNDSP).",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220706",
            "stig_id": "WN10-00-000040",
            "title": "Windows 10 systems must be maintained at a supported servicing level.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220707",
            "stig_id": "WN10-00-000045",
            "title": "The Windows 10 system must use an anti-virus program.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220709",
            "stig_id": "WN10-00-000055",
            "title": "Alternate operating systems must not be permitted on the same system.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220713",
            "stig_id": "WN10-00-000075",
            "title": "Only accounts responsible for the backup operations must be members of the Backup Operators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220715",
            "stig_id": "WN10-00-000085",
            "title": "Standard local user accounts must not exist on a system in a domain.",
            "severity": "low",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220723",
            "stig_id": "WN10-00-000130",
            "title": "Software certificate installation files must be removed from Windows 10.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220724",
            "stig_id": "WN10-00-000135",
            "title": "A host-based firewall must be installed and enabled on the system.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220725",
            "stig_id": "WN10-00-000140",
            "title": "Inbound exceptions to the firewall on Windows 10 domain workstations must only allow authorized remote management hosts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220733",
            "stig_id": "WN10-00-000190",
            "title": "Orphaned security identifiers (SIDs) must be removed from user rights on Windows 10.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220736",
            "stig_id": "WN10-00-000230",
            "title": "The system must notify the user when a Bluetooth device attempts to connect.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220737",
            "stig_id": "WN10-00-000240",
            "title": "Administrative accounts must not be used with applications that access the Internet, such as web browsers, or with potential Internet sources, such as email.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220795",
            "stig_id": "WN10-CC-000020",
            "title": "IPv6 source routing must be configured to highest protection.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220796",
            "stig_id": "WN10-CC-000025",
            "title": "The system must be configured to prevent IP source routing.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220797",
            "stig_id": "WN10-CC-000030",
            "title": "The system must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF) generated routes.",
            "severity": "low",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220802",
            "stig_id": "WN10-CC-000040",
            "title": "Insecure logons to an SMB server must be disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220806",
            "stig_id": "WN10-CC-000055",
            "title": "Simultaneous connections to the internet or a Windows domain must be limited.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220807",
            "stig_id": "WN10-CC-000060",
            "title": "Connections to non-domain networks when connected to a domain authenticated network must be blocked.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220808",
            "stig_id": "WN10-CC-000065",
            "title": "Wi-Fi Sense must be disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220810",
            "stig_id": "WN10-CC-000068",
            "title": "Windows 10 must be configured to enable Remote host allows delegation of non-exportable credentials.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220811",
            "stig_id": "WN10-CC-000070",
            "title": "Virtualization Based Security must be enabled on Windows 10 with the platform security level configured to Secure Boot or Secure Boot with DMA Protection.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220812",
            "stig_id": "WN10-CC-000075",
            "title": "Credential Guard must be running on Windows 10 domain-joined systems.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220813",
            "stig_id": "WN10-CC-000085",
            "title": "Early Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220814",
            "stig_id": "WN10-CC-000090",
            "title": "Group Policy objects must be reprocessed even if they have not changed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220818",
            "stig_id": "WN10-CC-000115",
            "title": "Systems must at least attempt device authentication using certificates.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220825",
            "stig_id": "WN10-CC-000170",
            "title": "The setting to allow Microsoft accounts to be optional for modern style apps must be enabled.",
            "severity": "low",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220830",
            "stig_id": "WN10-CC-000195",
            "title": "Enhanced anti-spoofing for facial recognition must be enabled on Window 10.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220833",
            "stig_id": "WN10-CC-000204",
            "title": "If Enhanced diagnostic data is enabled it must be limited to the minimum required to support Windows Analytics.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220834",
            "stig_id": "WN10-CC-000205",
            "title": "Windows Telemetry must not be configured to Full.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220835",
            "stig_id": "WN10-CC-000206",
            "title": "Windows Update must not obtain updates from other PCs on the internet.",
            "severity": "low",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220839",
            "stig_id": "WN10-CC-000225",
            "title": "File Explorer shell protocol must run in protected mode.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220840",
            "stig_id": "WN10-CC-000230",
            "title": "Users must not be allowed to ignore Windows Defender SmartScreen filter warnings for malicious websites in Microsoft Edge.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220841",
            "stig_id": "WN10-CC-000235",
            "title": "Users must not be allowed to ignore Windows Defender SmartScreen filter warnings for unverified files in Microsoft Edge.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220842",
            "stig_id": "WN10-CC-000238",
            "title": "Windows 10 must be configured to prevent certificate error overrides in Microsoft Edge.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220843",
            "stig_id": "WN10-CC-000245",
            "title": "The password manager function in the Edge browser must be disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220844",
            "stig_id": "WN10-CC-000250",
            "title": "The Windows Defender SmartScreen filter for Microsoft Edge must be enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220846",
            "stig_id": "WN10-CC-000255",
            "title": "The use of a hardware security device with Windows Hello for Business must be enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220847",
            "stig_id": "WN10-CC-000260",
            "title": "Windows 10 must be configured to require a minimum pin length of six characters or greater.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220853",
            "stig_id": "WN10-CC-000295",
            "title": "Attachments must be prevented from being downloaded from RSS feeds.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220858",
            "stig_id": "WN10-CC-000320",
            "title": "Users must be notified if a web-based program attempts to install software.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220859",
            "stig_id": "WN10-CC-000325",
            "title": "Automatically signing in the last interactive user after a system-initiated restart must be disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220910",
            "stig_id": "WN10-SO-000015",
            "title": "Local accounts with blank passwords must be restricted to prevent access from the network.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220911",
            "stig_id": "WN10-SO-000020",
            "title": "The built-in administrator account must be renamed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220912",
            "stig_id": "WN10-SO-000025",
            "title": "The built-in guest account must be renamed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220917",
            "stig_id": "WN10-SO-000050",
            "title": "The computer account password must not be prevented from being reset.",
            "severity": "low",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220918",
            "stig_id": "WN10-SO-000055",
            "title": "The maximum age for machine account passwords must be configured to 30 days or less.",
            "severity": "low",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220923",
            "stig_id": "WN10-SO-000085",
            "title": "Caching of logon credentials must be limited.",
            "severity": "low",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220924",
            "stig_id": "WN10-SO-000095",
            "title": "The Smart Card removal option must be configured to Force Logoff or Lock Workstation.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220928",
            "stig_id": "WN10-SO-000140",
            "title": "Anonymous SID/Name translation must not be allowed.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220929",
            "stig_id": "WN10-SO-000145",
            "title": "Anonymous enumeration of SAM accounts must not be allowed.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220931",
            "stig_id": "WN10-SO-000160",
            "title": "The system must be configured to prevent anonymous users from having the same rights as the Everyone group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220934",
            "stig_id": "WN10-SO-000180",
            "title": "NTLM must be prevented from falling back to a Null session.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220935",
            "stig_id": "WN10-SO-000185",
            "title": "PKU2U authentication using online identities must be prevented.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220938",
            "stig_id": "WN10-SO-000205",
            "title": "The LanMan authentication level must be set to send NTLMv2 response only, and to refuse LM and NTLM.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220939",
            "stig_id": "WN10-SO-000210",
            "title": "The system must be configured to the required LDAP client signing level.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220940",
            "stig_id": "WN10-SO-000215",
            "title": "The system must be configured to meet the minimum session security requirement for NTLM SSP based clients.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220941",
            "stig_id": "WN10-SO-000220",
            "title": "The system must be configured to meet the minimum session security requirement for NTLM SSP based servers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220943",
            "stig_id": "WN10-SO-000240",
            "title": "The default permissions of global system objects must be increased.",
            "severity": "low",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-220955",
            "stig_id": "WN10-UC-000020",
            "title": "Zone information must be preserved when saving attachments.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-250319",
            "stig_id": "WN10-CC-000050",
            "title": "Hardened UNC paths must be defined to require mutual authentication and integrity for at least the \\\\*\\SYSVOL and \\\\*\\NETLOGON shares.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-252903",
            "stig_id": "WN10-CC-000080",
            "title": "Virtualization-based protection of code integrity must be enabled.",
            "severity": "low",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-256894",
            "stig_id": "WN10-CC-000391",
            "title": "Internet Explorer must be disabled for Windows 10.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-268319",
            "stig_id": "WN10-CC-000063",
            "title": "Windows 10 systems must use either Group Policy or an approved Mobile Device Management (MDM) product to enforce STIG compliance.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253254",
            "stig_id": "WN11-00-000005",
            "title": "Domain-joined systems must use Windows 11 Enterprise Edition 64-bit version.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253258",
            "stig_id": "WN11-00-000025",
            "title": "Windows 11 must employ automated mechanisms to determine the state of system components with regard to flaw remediation using the following frequency: Continuously, where ESS is used; 30 days, for any additional internal network scans not covered by ESS; and annually, for external scans by Computer Network Defense Service Provider (CNDSP).",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253263",
            "stig_id": "WN11-00-000040",
            "title": "Windows 11 systems must be maintained at a supported servicing level.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253264",
            "stig_id": "WN11-00-000045",
            "title": "The Windows 11 system must use an antivirus program.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253266",
            "stig_id": "WN11-00-000055",
            "title": "Alternate operating systems must not be permitted on the same system.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253270",
            "stig_id": "WN11-00-000075",
            "title": "Only accounts responsible for the backup operations must be members of the Backup Operators group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253272",
            "stig_id": "WN11-00-000085",
            "title": "Standard local user accounts must not exist on a system in a domain.",
            "severity": "low",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253280",
            "stig_id": "WN11-00-000130",
            "title": "Software certificate installation files must be removed from Windows 11.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253281",
            "stig_id": "WN11-00-000135",
            "title": "A host-based firewall must be installed and enabled on the system.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253282",
            "stig_id": "WN11-00-000140",
            "title": "Inbound exceptions to the firewall on Windows 11 domain workstations must only allow authorized remote management hosts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253290",
            "stig_id": "WN11-00-000190",
            "title": "Orphaned security identifiers (SIDs) must be removed from user rights on Windows 11.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253293",
            "stig_id": "WN11-00-000230",
            "title": "The system must notify the user when a Bluetooth device attempts to connect.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253294",
            "stig_id": "WN11-00-000240",
            "title": "Administrative accounts must not be used with applications that access the internet, such as web browsers, or with potential internet sources, such as email.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253353",
            "stig_id": "WN11-CC-000020",
            "title": "IPv6 source routing must be configured to highest protection.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253354",
            "stig_id": "WN11-CC-000025",
            "title": "The system must be configured to prevent IP source routing.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253355",
            "stig_id": "WN11-CC-000030",
            "title": "The system must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF) generated routes.",
            "severity": "low",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253360",
            "stig_id": "WN11-CC-000040",
            "title": "Insecure logons to an SMB server must be disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253362",
            "stig_id": "WN11-CC-000050",
            "title": "Hardened UNC Paths must be defined to require mutual authentication and integrity for at least the \\\\*\\SYSVOL and \\\\*\\NETLOGON shares.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253365",
            "stig_id": "WN11-CC-000060",
            "title": "Connections to non-domain networks when connected to a domain authenticated network must be blocked.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253366",
            "stig_id": "WN11-CC-000065",
            "title": "Wi-Fi Sense must be disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253368",
            "stig_id": "WN11-CC-000068",
            "title": "Windows 11 must be configured to enable Remote host allows delegation of non-exportable credentials.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253369",
            "stig_id": "WN11-CC-000070",
            "title": "Virtualization-based Security must be enabled on Windows 11 with the platform security level configured to Secure Boot or Secure Boot with DMA Protection.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253370",
            "stig_id": "WN11-CC-000075",
            "title": "Credential Guard must be running on Windows 11 domain-joined systems.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253371",
            "stig_id": "WN11-CC-000080",
            "title": "Virtualization-based protection of code integrity must be enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253372",
            "stig_id": "WN11-CC-000085",
            "title": "Early Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253373",
            "stig_id": "WN11-CC-000090",
            "title": "Group Policy objects must be reprocessed even if they have not changed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253377",
            "stig_id": "WN11-CC-000115",
            "title": "Systems must at least attempt device authentication using certificates.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253384",
            "stig_id": "WN11-CC-000170",
            "title": "The setting to allow Microsoft accounts to be optional for modern style apps must be enabled.",
            "severity": "low",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253389",
            "stig_id": "WN11-CC-000195",
            "title": "Enhanced anti-spoofing for facial recognition must be enabled on Windows 11.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253392",
            "stig_id": "WN11-CC-000204",
            "title": "Enhanced diagnostic data must be limited to the minimum required to support Windows Analytics.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253394",
            "stig_id": "WN11-CC-000206",
            "title": "Windows Update must not obtain updates from other PCs on the internet.",
            "severity": "low",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253398",
            "stig_id": "WN11-CC-000225",
            "title": "File Explorer shell protocol must run in protected mode.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253400",
            "stig_id": "WN11-CC-000255",
            "title": "The use of a hardware security device with Windows Hello for Business must be enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253401",
            "stig_id": "WN11-CC-000260",
            "title": "Windows 11 must be configured to require a minimum pin length of six characters or greater.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253407",
            "stig_id": "WN11-CC-000295",
            "title": "Attachments must be prevented from being downloaded from RSS feeds.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253412",
            "stig_id": "WN11-CC-000320",
            "title": "Users must be notified if a web-based program attempts to install software.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253413",
            "stig_id": "WN11-CC-000325",
            "title": "Automatically signing in the last interactive user after a system-initiated restart must be disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253434",
            "stig_id": "WN11-SO-000015",
            "title": "Local accounts with blank passwords must be restricted to prevent access from the network.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253435",
            "stig_id": "WN11-SO-000020",
            "title": "The built-in administrator account must be renamed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253436",
            "stig_id": "WN11-SO-000025",
            "title": "The built-in guest account must be renamed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253441",
            "stig_id": "WN11-SO-000050",
            "title": "The computer account password must not be prevented from being reset.",
            "severity": "low",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253442",
            "stig_id": "WN11-SO-000055",
            "title": "The maximum age for machine account passwords must be configured to 30 days or less.",
            "severity": "low",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253447",
            "stig_id": "WN11-SO-000085",
            "title": "Caching of logon credentials must be limited.",
            "severity": "low",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253448",
            "stig_id": "WN11-SO-000095",
            "title": "The Smart Card removal option must be configured to Force Logoff or Lock Workstation.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253452",
            "stig_id": "WN11-SO-000140",
            "title": "Anonymous SID/Name translation must not be allowed.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253453",
            "stig_id": "WN11-SO-000145",
            "title": "Anonymous enumeration of SAM accounts must not be allowed.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253455",
            "stig_id": "WN11-SO-000160",
            "title": "The system must be configured to prevent anonymous users from having the same rights as the Everyone group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253458",
            "stig_id": "WN11-SO-000180",
            "title": "NTLM must be prevented from falling back to a Null session.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253459",
            "stig_id": "WN11-SO-000185",
            "title": "PKU2U authentication using online identities must be prevented.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253462",
            "stig_id": "WN11-SO-000205",
            "title": "The LanMan authentication level must be set to send NTLMv2 response only, and to refuse LM and NTLM.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253463",
            "stig_id": "WN11-SO-000210",
            "title": "The system must be configured to the required LDAP client signing level.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253464",
            "stig_id": "WN11-SO-000215",
            "title": "The system must be configured to meet the minimum session security requirement for NTLM SSP based clients.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253465",
            "stig_id": "WN11-SO-000220",
            "title": "The system must be configured to meet the minimum session security requirement for NTLM SSP based servers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253467",
            "stig_id": "WN11-SO-000240",
            "title": "The default permissions of global system objects must be increased.",
            "severity": "low",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-253478",
            "stig_id": "WN11-UC-000020",
            "title": "Zone information must be preserved when saving attachments.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-256893",
            "stig_id": "WN11-CC-000391",
            "title": "Internet Explorer must be disabled for Windows 11.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-268318",
            "stig_id": "WN11-CC-000063",
            "title": "Windows 11 systems must use either Group Policy or an approved Mobile Device Management (MDM) product to enforce STIG compliance.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205728",
            "stig_id": "WN19-00-000290",
            "title": "Windows Server 2019 must employ automated mechanisms to determine the state of system components with regard to flaw remediation using the following frequency: continuously, where Endpoint Security Solution (ESS) is used; 30 days, for any additional internal network scans not covered by ESS; and annually, for external scans by Computer Network Defense Service Provider (CNDSP).",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205838",
            "stig_id": "WN19-AU-000180",
            "title": "Windows Server 2019 must be configured to audit logoff successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205844",
            "stig_id": "WN19-00-000010",
            "title": "Windows Server 2019 users with Administrative privileges must have separate accounts for administrative duties and normal operational tasks.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205845",
            "stig_id": "WN19-00-000030",
            "title": "Windows Server 2019 administrative accounts must not be used with applications that access the Internet, such as web browsers, or with potential Internet sources, such as email.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205846",
            "stig_id": "WN19-00-000040",
            "title": "Windows Server 2019 members of the Backup Operators group must have separate accounts for backup duties and normal operational tasks.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205847",
            "stig_id": "WN19-00-000060",
            "title": "Windows Server 2019 manually managed application account passwords must be changed at least annually or when a system administrator with knowledge of the password leaves the organization.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205848",
            "stig_id": "WN19-00-000090",
            "title": "Windows Server 2019 domain-joined systems must have a Trusted Platform Module (TPM) enabled and ready for use.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205849",
            "stig_id": "WN19-00-000100",
            "title": "Windows Server 2019 must be maintained at a supported servicing level.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205850",
            "stig_id": "WN19-00-000110",
            "title": "Windows Server 2019 must use an anti-virus program.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205851",
            "stig_id": "WN19-00-000120",
            "title": "Windows Server 2019 must have a host-based intrusion detection or prevention system.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205852",
            "stig_id": "WN19-00-000240",
            "title": "Windows Server 2019 must have software certificate installation files removed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205853",
            "stig_id": "WN19-00-000420",
            "title": "Windows Server 2019 FTP servers must be configured to prevent anonymous logons.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205854",
            "stig_id": "WN19-00-000430",
            "title": "Windows Server 2019 FTP servers must be configured to prevent access to the system drive.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205855",
            "stig_id": "WN19-00-000450",
            "title": "Windows Server 2019 must have orphaned security identifiers (SIDs) removed from user rights.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205856",
            "stig_id": "WN19-00-000460",
            "title": "Windows Server 2019 systems must have Unified Extensible Firmware Interface (UEFI) firmware and be configured to run in UEFI mode, not Legacy BIOS.",
            "severity": "low",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205857",
            "stig_id": "WN19-00-000470",
            "title": "Windows Server 2019 must have Secure Boot enabled.",
            "severity": "low",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205858",
            "stig_id": "WN19-CC-000030",
            "title": "Windows Server 2019 Internet Protocol version 6 (IPv6) source routing must be configured to the highest protection level to prevent IP source routing.",
            "severity": "low",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205859",
            "stig_id": "WN19-CC-000040",
            "title": "Windows Server 2019 source routing must be configured to the highest protection level to prevent Internet Protocol (IP) source routing.",
            "severity": "low",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205860",
            "stig_id": "WN19-CC-000050",
            "title": "Windows Server 2019 must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF)-generated routes.",
            "severity": "low",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205861",
            "stig_id": "WN19-CC-000070",
            "title": "Windows Server 2019 insecure logons to an SMB server must be disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205862",
            "stig_id": "WN19-CC-000080",
            "title": "Windows Server 2019 hardened Universal Naming Convention (UNC) paths must be defined to require mutual authentication and integrity for at least the \\\\*\\SYSVOL and \\\\*\\NETLOGON shares.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205863",
            "stig_id": "WN19-CC-000100",
            "title": "Windows Server 2019 must be configured to enable Remote host allows delegation of non-exportable credentials.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205864",
            "stig_id": "WN19-CC-000110",
            "title": "Windows Server 2019 virtualization-based security must be enabled with the platform security level configured to Secure Boot or Secure Boot with DMA Protection.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205865",
            "stig_id": "WN19-CC-000130",
            "title": "Windows Server 2019 Early Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers identified as bad.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205866",
            "stig_id": "WN19-CC-000140",
            "title": "Windows Server 2019 group policy objects must be reprocessed even if they have not changed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205867",
            "stig_id": "WN19-CC-000180",
            "title": "Windows Server 2019 users must be prompted to authenticate when the system wakes from sleep (on battery).",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205868",
            "stig_id": "WN19-CC-000190",
            "title": "Windows Server 2019 users must be prompted to authenticate when the system wakes from sleep (plugged in).",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205869",
            "stig_id": "WN19-CC-000250",
            "title": "Windows Server 2019 Telemetry must be configured to Security or Basic.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205870",
            "stig_id": "WN19-CC-000260",
            "title": "Windows Server 2019 Windows Update must not obtain updates from other PCs on the Internet.",
            "severity": "low",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205871",
            "stig_id": "WN19-CC-000320",
            "title": "Windows Server 2019 Turning off File Explorer heap termination on corruption must be disabled.",
            "severity": "low",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205872",
            "stig_id": "WN19-CC-000330",
            "title": "Windows Server 2019 File Explorer shell protocol must run in protected mode.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205873",
            "stig_id": "WN19-CC-000390",
            "title": "Windows Server 2019 must prevent attachments from being downloaded from RSS feeds.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205874",
            "stig_id": "WN19-CC-000440",
            "title": "Windows Server 2019 users must be notified if a web-based program attempts to install software.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205875",
            "stig_id": "WN19-DC-000150",
            "title": "Windows Server 2019 directory data (outside the root DSE) of a non-public directory must be configured to prevent anonymous access.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205876",
            "stig_id": "WN19-DC-000330",
            "title": "Windows Server 2019 domain controllers must be configured to allow reset of machine account passwords.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205877",
            "stig_id": "WN19-DC-000430",
            "title": "The password for the krbtgt account on a domain must be reset at least every 180 days.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205906",
            "stig_id": "WN19-MS-000050",
            "title": "Windows Server 2019 must limit the caching of logon credentials to four or less on domain-joined member servers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205907",
            "stig_id": "WN19-MS-000140",
            "title": "Windows Server 2019 must be running Credential Guard on domain-joined member servers.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205908",
            "stig_id": "WN19-SO-000020",
            "title": "Windows Server 2019 must prevent local accounts with blank passwords from being used from the network.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205909",
            "stig_id": "WN19-SO-000030",
            "title": "Windows Server 2019 built-in administrator account must be renamed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205910",
            "stig_id": "WN19-SO-000040",
            "title": "Windows Server 2019 built-in guest account must be renamed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205911",
            "stig_id": "WN19-SO-000100",
            "title": "Windows Server 2019 maximum age for machine account passwords must be configured to 30 days or less.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205912",
            "stig_id": "WN19-SO-000150",
            "title": "Windows Server 2019 Smart Card removal option must be configured to Force Logoff or Lock Workstation.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205913",
            "stig_id": "WN19-SO-000210",
            "title": "Windows Server 2019 must not allow anonymous SID/Name translation.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205914",
            "stig_id": "WN19-SO-000220",
            "title": "Windows Server 2019 must not allow anonymous enumeration of Security Account Manager (SAM) accounts.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205915",
            "stig_id": "WN19-SO-000240",
            "title": "Windows Server 2019 must be configured to prevent anonymous users from having the same permissions as the Everyone group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205916",
            "stig_id": "WN19-SO-000260",
            "title": "Windows Server 2019 services using Local System that use Negotiate when reverting to NTLM authentication must use the computer identity instead of authenticating anonymously.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205917",
            "stig_id": "WN19-SO-000270",
            "title": "Windows Server 2019 must prevent NTLM from falling back to a Null session.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205918",
            "stig_id": "WN19-SO-000280",
            "title": "Windows Server 2019 must prevent PKU2U authentication using online identities.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205919",
            "stig_id": "WN19-SO-000310",
            "title": "Windows Server 2019 LAN Manager authentication level must be configured to send NTLMv2 response only and to refuse LM and NTLM.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205920",
            "stig_id": "WN19-SO-000320",
            "title": "Windows Server 2019 must be configured to at least negotiate signing for LDAP client signing.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205921",
            "stig_id": "WN19-SO-000330",
            "title": "Windows Server 2019 session security for NTLM SSP-based clients must be configured to require NTLMv2 session security and 128-bit encryption.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205922",
            "stig_id": "WN19-SO-000340",
            "title": "Windows Server 2019 session security for NTLM SSP-based servers must be configured to require NTLMv2 session security and 128-bit encryption.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205923",
            "stig_id": "WN19-SO-000370",
            "title": "Windows Server 2019 default permissions of global system objects must be strengthened.",
            "severity": "low",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205924",
            "stig_id": "WN19-UC-000010",
            "title": "Windows Server 2019 must preserve zone information when saving attachments.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-205925",
            "stig_id": "WN19-CC-000450",
            "title": "Windows Server 2019 must disable automatically signing in the last interactive user after a system-initiated restart.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-214936",
            "stig_id": "WN19-00-000280",
            "title": "Windows Server 2019 must have a host-based firewall installed and enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000366",
                "CCI-002080"
            ]
        },
        {
            "rule": "V-254238",
            "stig_id": "WN22-00-000010",
            "title": "Windows Server 2022 users with Administrative privileges must have separate accounts for administrative duties and normal operational tasks.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254240",
            "stig_id": "WN22-00-000030",
            "title": "Windows Server 2022 administrative accounts must not be used with applications that access the internet, such as web browsers, or with potential internet sources, such as email.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366",
                "CCI-001312"
            ]
        },
        {
            "rule": "V-254241",
            "stig_id": "WN22-00-000040",
            "title": "Windows Server 2022 members of the Backup Operators group must have separate accounts for backup duties and normal operational tasks.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254243",
            "stig_id": "WN22-00-000060",
            "title": "Windows Server 2022 manually managed application account passwords must be changed at least annually or when a system administrator with knowledge of the password leaves the organization.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254246",
            "stig_id": "WN22-00-000090",
            "title": "Windows Server 2022 domain-joined systems must have a Trusted Platform Module (TPM) enabled and ready for use.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254247",
            "stig_id": "WN22-00-000100",
            "title": "Windows Server 2022 must be maintained at a supported servicing level.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254248",
            "stig_id": "WN22-00-000110",
            "title": "Windows Server 2022 must use an antivirus program.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254249",
            "stig_id": "WN22-00-000120",
            "title": "Windows Server 2022 must have a host-based intrusion detection or prevention system.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254261",
            "stig_id": "WN22-00-000240",
            "title": "Windows Server 2022 must have software certificate installation files removed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254265",
            "stig_id": "WN22-00-000280",
            "title": "Windows Server 2022 must have a host-based firewall installed and enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366",
                "CCI-002080"
            ]
        },
        {
            "rule": "V-254266",
            "stig_id": "WN22-00-000290",
            "title": "Windows Server 2022 must employ automated mechanisms to determine the state of system components with regard to flaw remediation using the following frequency: continuously, where Endpoint Security Solution (ESS) is used; 30 days, for any additional internal network scans not covered by ESS; and annually, for external scans by Computer Network Defense Service Provider (CNDSP).",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254279",
            "stig_id": "WN22-00-000420",
            "title": "Windows Server 2022 FTP servers must be configured to prevent anonymous logons.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254280",
            "stig_id": "WN22-00-000430",
            "title": "Windows Server 2022 FTP servers must be configured to prevent access to the system drive.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254282",
            "stig_id": "WN22-00-000450",
            "title": "Windows Server 2022 must have orphaned security identifiers (SIDs) removed from user rights.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254283",
            "stig_id": "WN22-00-000460",
            "title": "Windows Server 2022 systems must have Unified Extensible Firmware Interface (UEFI) firmware and be configured to run in UEFI mode, not Legacy BIOS.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254284",
            "stig_id": "WN22-00-000470",
            "title": "Windows Server 2022 must have Secure Boot enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254335",
            "stig_id": "WN22-CC-000030",
            "title": "Windows Server 2022 Internet Protocol version 6 (IPv6) source routing must be configured to the highest protection level to prevent IP source routing.",
            "severity": "low",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254336",
            "stig_id": "WN22-CC-000040",
            "title": "Windows Server 2022 source routing must be configured to the highest protection level to prevent Internet Protocol (IP) source routing.",
            "severity": "low",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254337",
            "stig_id": "WN22-CC-000050",
            "title": "Windows Server 2022 must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF)-generated routes.",
            "severity": "low",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254339",
            "stig_id": "WN22-CC-000070",
            "title": "Windows Server 2022 insecure logons to an SMB server must be disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254340",
            "stig_id": "WN22-CC-000080",
            "title": "Windows Server 2022 hardened Universal Naming Convention (UNC) paths must be defined to require mutual authentication and integrity for at least the \\\\*\\SYSVOL and \\\\*\\NETLOGON shares.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254342",
            "stig_id": "WN22-CC-000100",
            "title": "Windows Server 2022 must be configured to enable Remote host allows delegation of nonexportable credentials.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254343",
            "stig_id": "WN22-CC-000110",
            "title": "Windows Server 2022 virtualization-based security must be enabled with the platform security level configured to Secure Boot or Secure Boot with DMA Protection.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254344",
            "stig_id": "WN22-CC-000130",
            "title": "Windows Server 2022 Early Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers identified as bad.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254345",
            "stig_id": "WN22-CC-000140",
            "title": "Windows Server 2022 group policy objects must be reprocessed even if they have not changed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254349",
            "stig_id": "WN22-CC-000180",
            "title": "Windows Server 2022 users must be prompted to authenticate when the system wakes from sleep (on battery).",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254350",
            "stig_id": "WN22-CC-000190",
            "title": "Windows Server 2022 users must be prompted to authenticate when the system wakes from sleep (plugged in).",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254356",
            "stig_id": "WN22-CC-000250",
            "title": "Windows Server 2022 Diagnostic Data must be configured to send \"required diagnostic data\" or \"optional diagnostic data\".",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254357",
            "stig_id": "WN22-CC-000260",
            "title": "Windows Server 2022 Windows Update must not obtain updates from other PCs on the internet.",
            "severity": "low",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254363",
            "stig_id": "WN22-CC-000320",
            "title": "Windows Server 2022 Turning off File Explorer heap termination on corruption must be disabled.",
            "severity": "low",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254364",
            "stig_id": "WN22-CC-000330",
            "title": "Windows Server 2022 File Explorer shell protocol must run in protected mode.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254370",
            "stig_id": "WN22-CC-000390",
            "title": "Windows Server 2022 must prevent attachments from being downloaded from RSS feeds.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254375",
            "stig_id": "WN22-CC-000440",
            "title": "Windows Server 2022 users must be notified if a web-based program attempts to install software.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254376",
            "stig_id": "WN22-CC-000450",
            "title": "Windows Server 2022 must disable automatically signing in the last interactive user after a system-initiated restart.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254399",
            "stig_id": "WN22-DC-000150",
            "title": "Windows Server 2022 directory data (outside the root DSE) of a nonpublic directory must be configured to prevent anonymous access.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254417",
            "stig_id": "WN22-DC-000330",
            "title": "Windows Server 2022 domain controllers must be configured to allow reset of machine account passwords.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254427",
            "stig_id": "WN22-DC-000430",
            "title": "The password for the krbtgt account on a domain must be reset at least every 180 days.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254432",
            "stig_id": "WN22-MS-000050",
            "title": "Windows Server 2022 must limit the caching of logon credentials to four or less on domain-joined member servers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254441",
            "stig_id": "WN22-MS-000140",
            "title": "Windows Server 2022 must be running Credential Guard on domain-joined member servers.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254446",
            "stig_id": "WN22-SO-000020",
            "title": "Windows Server 2022 must prevent local accounts with blank passwords from being used from the network.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254447",
            "stig_id": "WN22-SO-000030",
            "title": "Windows Server 2022 built-in administrator account must be renamed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254448",
            "stig_id": "WN22-SO-000040",
            "title": "Windows Server 2022 built-in guest account must be renamed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254454",
            "stig_id": "WN22-SO-000100",
            "title": "Windows Server 2022 maximum age for machine account passwords must be configured to 30 days or less.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254459",
            "stig_id": "WN22-SO-000150",
            "title": "Windows Server 2022 Smart Card removal option must be configured to Force Logoff or Lock Workstation.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254465",
            "stig_id": "WN22-SO-000210",
            "title": "Windows Server 2022 must not allow anonymous SID/Name translation.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254466",
            "stig_id": "WN22-SO-000220",
            "title": "Windows Server 2022 must not allow anonymous enumeration of Security Account Manager (SAM) accounts.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254468",
            "stig_id": "WN22-SO-000240",
            "title": "Windows Server 2022 must be configured to prevent anonymous users from having the same permissions as the Everyone group.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254470",
            "stig_id": "WN22-SO-000260",
            "title": "Windows Server 2022 services using Local System that use Negotiate when reverting to NTLM authentication must use the computer identity instead of authenticating anonymously.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254471",
            "stig_id": "WN22-SO-000270",
            "title": "Windows Server 2022 must prevent NTLM from falling back to a Null session.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254472",
            "stig_id": "WN22-SO-000280",
            "title": "Windows Server 2022 must prevent PKU2U authentication using online identities.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254475",
            "stig_id": "WN22-SO-000310",
            "title": "Windows Server 2022 LAN Manager authentication level must be configured to send NTLMv2 response only and to refuse LM and NTLM.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254476",
            "stig_id": "WN22-SO-000320",
            "title": "Windows Server 2022 must be configured to at least negotiate signing for LDAP client signing.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254477",
            "stig_id": "WN22-SO-000330",
            "title": "Windows Server 2022 session security for NTLM SSP-based clients must be configured to require NTLMv2 session security and 128-bit encryption.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254478",
            "stig_id": "WN22-SO-000340",
            "title": "Windows Server 2022 session security for NTLM SSP-based servers must be configured to require NTLMv2 session security and 128-bit encryption.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254481",
            "stig_id": "WN22-SO-000370",
            "title": "Windows Server 2022 default permissions of global system objects must be strengthened.",
            "severity": "low",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-254490",
            "stig_id": "WN22-UC-000010",
            "title": "Windows Server 2022 must preserve zone information when saving attachments.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230221",
            "stig_id": "RHEL-08-010000",
            "title": "RHEL 8 must be a vendor-supported release.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230222",
            "stig_id": "RHEL-08-010010",
            "title": "RHEL 8 vendor packaged system security patches and updates must be installed and up to date.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230253",
            "stig_id": "RHEL-08-010292",
            "title": "RHEL 8 must ensure the SSH server uses strong entropy.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230283",
            "stig_id": "RHEL-08-010460",
            "title": "There must be no shosts.equiv files on the RHEL 8 operating system.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230284",
            "stig_id": "RHEL-08-010470",
            "title": "There must be no .shosts files on the RHEL 8 operating system.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230285",
            "stig_id": "RHEL-08-010471",
            "title": "RHEL 8 must enable the hardware random number generator entropy gatherer service.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230286",
            "stig_id": "RHEL-08-010480",
            "title": "The RHEL 8 SSH public host key files must have mode 0644 or less permissive.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230287",
            "stig_id": "RHEL-08-010490",
            "title": "The RHEL 8 SSH private host key files must have mode 0640 or less permissive.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230288",
            "stig_id": "RHEL-08-010500",
            "title": "The RHEL 8 SSH daemon must perform strict mode checking of home directory configuration files.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230290",
            "stig_id": "RHEL-08-010520",
            "title": "The RHEL 8 SSH daemon must not allow authentication using known host’s authentication.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230291",
            "stig_id": "RHEL-08-010521",
            "title": "The RHEL 8 SSH daemon must not allow Kerberos authentication, except to fulfill documented and validated mission requirements.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230292",
            "stig_id": "RHEL-08-010540",
            "title": "RHEL 8 must use a separate file system for /var.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230293",
            "stig_id": "RHEL-08-010541",
            "title": "RHEL 8 must use a separate file system for /var/log.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230294",
            "stig_id": "RHEL-08-010542",
            "title": "RHEL 8 must use a separate file system for the system audit data path.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230295",
            "stig_id": "RHEL-08-010543",
            "title": "A separate RHEL 8 filesystem must be used for the /tmp directory.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230298",
            "stig_id": "RHEL-08-010561",
            "title": "The rsyslog service must be running in RHEL 8.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230299",
            "stig_id": "RHEL-08-010570",
            "title": "RHEL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230300",
            "stig_id": "RHEL-08-010571",
            "title": "RHEL 8 must prevent files with the setuid and setgid bit set from being executed on the /boot directory.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230301",
            "stig_id": "RHEL-08-010580",
            "title": "RHEL 8 must prevent special devices on non-root local partitions.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230302",
            "stig_id": "RHEL-08-010590",
            "title": "RHEL 8 must prevent code from being executed on file systems that contain user home directories.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230303",
            "stig_id": "RHEL-08-010600",
            "title": "RHEL 8 must prevent special devices on file systems that are used with removable media.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230304",
            "stig_id": "RHEL-08-010610",
            "title": "RHEL 8 must prevent code from being executed on file systems that are used with removable media.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230305",
            "stig_id": "RHEL-08-010620",
            "title": "RHEL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that are used with removable media.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230306",
            "stig_id": "RHEL-08-010630",
            "title": "RHEL 8 must prevent code from being executed on file systems that are imported via Network File System (NFS).",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230307",
            "stig_id": "RHEL-08-010640",
            "title": "RHEL 8 must prevent special devices on file systems that are imported via Network File System (NFS).",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230308",
            "stig_id": "RHEL-08-010650",
            "title": "RHEL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that are imported via Network File System (NFS).",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230309",
            "stig_id": "RHEL-08-010660",
            "title": "Local RHEL 8 initialization files must not execute world-writable programs.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230310",
            "stig_id": "RHEL-08-010670",
            "title": "RHEL 8 must disable kernel dumps unless needed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230311",
            "stig_id": "RHEL-08-010671",
            "title": "RHEL 8 must disable the kernel.core_pattern.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230312",
            "stig_id": "RHEL-08-010672",
            "title": "RHEL 8 must disable acquiring, saving, and processing core dumps.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230313",
            "stig_id": "RHEL-08-010673",
            "title": "RHEL 8 must disable core dumps for all users.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230314",
            "stig_id": "RHEL-08-010674",
            "title": "RHEL 8 must disable storing core dumps.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230315",
            "stig_id": "RHEL-08-010675",
            "title": "RHEL 8 must disable core dump backtraces.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230316",
            "stig_id": "RHEL-08-010680",
            "title": "For RHEL 8 systems using Domain Name Servers (DNS) resolution, at least two name servers must be configured.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230317",
            "stig_id": "RHEL-08-010690",
            "title": "Executable search paths within the initialization files of all local interactive RHEL 8 users must only contain paths that resolve to the system default or the users home directory.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230318",
            "stig_id": "RHEL-08-010700",
            "title": "All RHEL 8 world-writable directories must be owned by root, sys, bin, or an application user.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230319",
            "stig_id": "RHEL-08-010710",
            "title": "All RHEL 8 world-writable directories must be group-owned by root, sys, bin, or an application group.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230320",
            "stig_id": "RHEL-08-010720",
            "title": "All RHEL 8 local interactive users must have a home directory assigned in the /etc/passwd file.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230321",
            "stig_id": "RHEL-08-010730",
            "title": "All RHEL 8 local interactive user home directories must have mode 0750 or less permissive.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230322",
            "stig_id": "RHEL-08-010740",
            "title": "All RHEL 8 local interactive user home directories must be group-owned by the home directory owner’s primary group.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230323",
            "stig_id": "RHEL-08-010750",
            "title": "All RHEL 8 local interactive user home directories defined in the /etc/passwd file must exist.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230324",
            "stig_id": "RHEL-08-010760",
            "title": "All RHEL 8 local interactive user accounts must be assigned a home directory upon creation.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230325",
            "stig_id": "RHEL-08-010770",
            "title": "All RHEL 8 local initialization files must have mode 0740 or less permissive.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230326",
            "stig_id": "RHEL-08-010780",
            "title": "All RHEL 8 local files and directories must have a valid owner.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230327",
            "stig_id": "RHEL-08-010790",
            "title": "All RHEL 8 local files and directories must have a valid group owner.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230328",
            "stig_id": "RHEL-08-010800",
            "title": "A separate RHEL 8 filesystem must be used for user home directories (such as /home or an equivalent).",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230329",
            "stig_id": "RHEL-08-010820",
            "title": "Unattended or automatic logon via the RHEL 8 graphical user interface must not be allowed.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230330",
            "stig_id": "RHEL-08-010830",
            "title": "RHEL 8 must not allow users to override SSH environment variables.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230356",
            "stig_id": "RHEL-08-020100",
            "title": "RHEL 8 must ensure the password complexity module is enabled in the password-auth file.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230377",
            "stig_id": "RHEL-08-020300",
            "title": "RHEL 8 must prevent the use of dictionary words for passwords.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230378",
            "stig_id": "RHEL-08-020310",
            "title": "RHEL 8 must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230379",
            "stig_id": "RHEL-08-020320",
            "title": "RHEL 8 must not have unnecessary accounts.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230380",
            "stig_id": "RHEL-08-020330",
            "title": "RHEL 8 must not allow accounts configured with blank or null passwords.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230383",
            "stig_id": "RHEL-08-020351",
            "title": "RHEL 8 must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230384",
            "stig_id": "RHEL-08-020352",
            "title": "RHEL 8 must set the umask value to 077 for all local interactive user accounts.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230385",
            "stig_id": "RHEL-08-020353",
            "title": "RHEL 8 must define default permissions for logon and non-logon shells.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230387",
            "stig_id": "RHEL-08-030010",
            "title": "Cron logging must be implemented in RHEL 8.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230393",
            "stig_id": "RHEL-08-030061",
            "title": "The RHEL 8 audit system must audit local events.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230395",
            "stig_id": "RHEL-08-030063",
            "title": "RHEL 8 must resolve audit information before writing to disk.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230477",
            "stig_id": "RHEL-08-030670",
            "title": "RHEL 8 must have the packages required for offloading audit logs installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230478",
            "stig_id": "RHEL-08-030680",
            "title": "RHEL 8 must have the packages required for encrypting offloaded audit logs installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230529",
            "stig_id": "RHEL-08-040170",
            "title": "The x86 Ctrl-Alt-Delete key sequence must be disabled on RHEL 8.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230530",
            "stig_id": "RHEL-08-040171",
            "title": "The x86 Ctrl-Alt-Delete key sequence in RHEL 8 must be disabled if a graphical user interface is installed.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230531",
            "stig_id": "RHEL-08-040172",
            "title": "The systemd Ctrl-Alt-Delete burst key sequence in RHEL 8 must be disabled.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230532",
            "stig_id": "RHEL-08-040180",
            "title": "The debug-shell systemd service must be disabled on RHEL 8.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230533",
            "stig_id": "RHEL-08-040190",
            "title": "The Trivial File Transfer Protocol (TFTP) server package must not be installed if not required for RHEL 8 operational support.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230534",
            "stig_id": "RHEL-08-040200",
            "title": "The root account must be the only account having unrestricted access to the RHEL 8 system.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230535",
            "stig_id": "RHEL-08-040210",
            "title": "RHEL 8 must prevent IPv6 Internet Control Message Protocol (ICMP) redirect messages from being accepted.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230536",
            "stig_id": "RHEL-08-040220",
            "title": "RHEL 8 must not send Internet Control Message Protocol (ICMP) redirects.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230537",
            "stig_id": "RHEL-08-040230",
            "title": "RHEL 8 must not respond to Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230538",
            "stig_id": "RHEL-08-040240",
            "title": "RHEL 8 must not forward IPv6 source-routed packets.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230539",
            "stig_id": "RHEL-08-040250",
            "title": "RHEL 8 must not forward IPv6 source-routed packets by default.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230540",
            "stig_id": "RHEL-08-040260",
            "title": "RHEL 8 must not enable IPv6 packet forwarding unless the system is a router.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230541",
            "stig_id": "RHEL-08-040261",
            "title": "RHEL 8 must not accept router advertisements on all IPv6 interfaces.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230542",
            "stig_id": "RHEL-08-040262",
            "title": "RHEL 8 must not accept router advertisements on all IPv6 interfaces by default.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230543",
            "stig_id": "RHEL-08-040270",
            "title": "RHEL 8 must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230544",
            "stig_id": "RHEL-08-040280",
            "title": "RHEL 8 must ignore IPv6 Internet Control Message Protocol (ICMP) redirect messages.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230545",
            "stig_id": "RHEL-08-040281",
            "title": "RHEL 8 must disable access to network bpf syscall from unprivileged processes.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230546",
            "stig_id": "RHEL-08-040282",
            "title": "RHEL 8 must restrict usage of ptrace to descendant  processes.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230547",
            "stig_id": "RHEL-08-040283",
            "title": "RHEL 8 must restrict exposed kernel pointer addresses access.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230548",
            "stig_id": "RHEL-08-040284",
            "title": "RHEL 8 must disable the use of user namespaces.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230549",
            "stig_id": "RHEL-08-040285",
            "title": "RHEL 8 must use reverse path filtering on all IPv4 interfaces.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230550",
            "stig_id": "RHEL-08-040290",
            "title": "RHEL 8 must be configured to prevent unrestricted mail relaying.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230551",
            "stig_id": "RHEL-08-040300",
            "title": "The RHEL 8 file integrity tool must be configured to verify extended attributes.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230552",
            "stig_id": "RHEL-08-040310",
            "title": "The RHEL 8 file integrity tool must be configured to verify Access Control Lists (ACLs).",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230553",
            "stig_id": "RHEL-08-040320",
            "title": "The graphical display manager must not be installed on RHEL 8 unless approved.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230554",
            "stig_id": "RHEL-08-040330",
            "title": "RHEL 8 network interfaces must not be in promiscuous mode.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230555",
            "stig_id": "RHEL-08-040340",
            "title": "RHEL 8 remote X connections for interactive users must be disabled unless to fulfill documented and validated mission requirements.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230556",
            "stig_id": "RHEL-08-040341",
            "title": "The RHEL 8 SSH daemon must prevent remote hosts from connecting to the proxy display.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230557",
            "stig_id": "RHEL-08-040350",
            "title": "If the Trivial File Transfer Protocol (TFTP) server is required, the RHEL 8 TFTP daemon must be configured to operate in secure mode.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230558",
            "stig_id": "RHEL-08-040360",
            "title": "A File Transfer Protocol (FTP) server package must not be installed unless mission essential on RHEL 8.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230560",
            "stig_id": "RHEL-08-040380",
            "title": "The iprutils package must not be installed unless mission essential on RHEL 8.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-230561",
            "stig_id": "RHEL-08-040390",
            "title": "The tuned package must not be installed unless mission essential on RHEL 8.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-237641",
            "stig_id": "RHEL-08-010382",
            "title": "RHEL 8 must restrict privilege elevation to authorized personnel.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-244527",
            "stig_id": "RHEL-08-010472",
            "title": "RHEL 8 must have the packages required to use the hardware random number generator entropy gatherer service.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-244528",
            "stig_id": "RHEL-08-010522",
            "title": "The RHEL 8 SSH daemon must not allow GSSAPI authentication, except to fulfill documented and validated mission requirements.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-244529",
            "stig_id": "RHEL-08-010544",
            "title": "RHEL 8 must use a separate file system for /var/tmp.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-244530",
            "stig_id": "RHEL-08-010572",
            "title": "RHEL 8 must prevent files with the setuid and setgid bit set from being executed on the /boot/efi directory.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-244531",
            "stig_id": "RHEL-08-010731",
            "title": "All RHEL 8 local interactive user home directory files must have mode 0750 or less permissive.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-244532",
            "stig_id": "RHEL-08-010741",
            "title": "RHEL 8 must be configured so that all files and directories contained in local interactive user home directories are group-owned by a group of which the home directory owner is a member.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-244536",
            "stig_id": "RHEL-08-020032",
            "title": "RHEL 8 must disable the user list at logon for graphical user interfaces.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-244541",
            "stig_id": "RHEL-08-020332",
            "title": "RHEL 8 must not allow blank or null passwords in the password-auth file.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-244550",
            "stig_id": "RHEL-08-040209",
            "title": "RHEL 8 must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-244551",
            "stig_id": "RHEL-08-040239",
            "title": "RHEL 8 must not forward IPv4 source-routed packets.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-244552",
            "stig_id": "RHEL-08-040249",
            "title": "RHEL 8 must not forward IPv4 source-routed packets by default.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-244553",
            "stig_id": "RHEL-08-040279",
            "title": "RHEL 8 must ignore IPv4 Internet Control Message Protocol (ICMP) redirect messages.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-244554",
            "stig_id": "RHEL-08-040286",
            "title": "RHEL 8 must enable hardening for the Berkeley Packet Filter Just-in-time compiler.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-250317",
            "stig_id": "RHEL-08-040259",
            "title": "RHEL 8 must not enable IPv4 packet forwarding unless the system is a router.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-251706",
            "stig_id": "RHEL-08-010121",
            "title": "The RHEL 8 operating system must not have accounts configured with blank or null passwords.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-251711",
            "stig_id": "RHEL-08-010379",
            "title": "RHEL 8 must specify the default \"include\" directory for the /etc/sudoers file.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-251713",
            "stig_id": "RHEL-08-020101",
            "title": "RHEL 8 must ensure the password complexity module is enabled in the system-auth file.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-251716",
            "stig_id": "RHEL-08-020104",
            "title": "RHEL 8 systems, version 8.4 and above, must ensure the password complexity module is configured for three retries or less.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-251718",
            "stig_id": "RHEL-08-040321",
            "title": "The graphical display manager must not be the default target on RHEL 8 unless approved.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-268322",
            "stig_id": "RHEL-08-020331",
            "title": "RHEL 8 must not allow blank or null passwords in the system-auth file.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257777",
            "stig_id": "RHEL-09-211010",
            "title": "RHEL 9 must be a vendor-supported release.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257778",
            "stig_id": "RHEL-09-211015",
            "title": "RHEL 9 vendor packaged system security patches and updates must be installed and up to date.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257781",
            "stig_id": "RHEL-09-211030",
            "title": "The graphical display manager must not be the default target on RHEL 9 unless approved.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257782",
            "stig_id": "RHEL-09-211035",
            "title": "RHEL 9 must enable the hardware random number generator entropy gatherer service.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257788",
            "stig_id": "RHEL-09-212015",
            "title": "RHEL 9 must disable the ability of systemd to spawn an interactive boot process.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257790",
            "stig_id": "RHEL-09-212025",
            "title": "RHEL 9 /boot/grub2/grub.cfg file must be group-owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257791",
            "stig_id": "RHEL-09-212030",
            "title": "RHEL 9 /boot/grub2/grub.cfg file must be owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257803",
            "stig_id": "RHEL-09-213040",
            "title": "RHEL 9 must disable the kernel.core_pattern.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257812",
            "stig_id": "RHEL-09-213085",
            "title": "RHEL 9 must disable core dump backtraces.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257813",
            "stig_id": "RHEL-09-213090",
            "title": "RHEL 9 must disable storing core dumps.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257814",
            "stig_id": "RHEL-09-213095",
            "title": "RHEL 9 must disable core dumps for all users.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257815",
            "stig_id": "RHEL-09-213100",
            "title": "RHEL 9 must disable acquiring, saving, and processing core dumps.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257816",
            "stig_id": "RHEL-09-213105",
            "title": "RHEL 9 must disable the use of user namespaces.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257818",
            "stig_id": "RHEL-09-213115",
            "title": "The kdump service on RHEL 9 must be disabled.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257823",
            "stig_id": "RHEL-09-214030",
            "title": "RHEL 9 must be configured so that the cryptographic hashes of system files match vendor values.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257835",
            "stig_id": "RHEL-09-215060",
            "title": "RHEL 9 must not have a Trivial File Transfer Protocol (TFTP) server package installed.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257836",
            "stig_id": "RHEL-09-215065",
            "title": "RHEL 9 must not have the quagga package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257837",
            "stig_id": "RHEL-09-215070",
            "title": "A graphical display manager must not be installed on RHEL 9 unless approved.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257839",
            "stig_id": "RHEL-09-215080",
            "title": "RHEL 9 must have the gnutls-utils package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257840",
            "stig_id": "RHEL-09-215085",
            "title": "RHEL 9 must have the nss-tools package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257841",
            "stig_id": "RHEL-09-215090",
            "title": "RHEL 9 must have the rng-tools package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257843",
            "stig_id": "RHEL-09-231010",
            "title": "A separate RHEL 9 file system must be used for user home directories (such as /home or an equivalent).",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257844",
            "stig_id": "RHEL-09-231015",
            "title": "RHEL 9 must use a separate file system for /tmp.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257845",
            "stig_id": "RHEL-09-231020",
            "title": "RHEL 9 must use a separate file system for /var.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257846",
            "stig_id": "RHEL-09-231025",
            "title": "RHEL 9 must use a separate file system for /var/log.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257848",
            "stig_id": "RHEL-09-231035",
            "title": "RHEL 9 must use a separate file system for /var/tmp.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257852",
            "stig_id": "RHEL-09-231055",
            "title": "RHEL 9 must prevent code from being executed on file systems that contain user home directories.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257854",
            "stig_id": "RHEL-09-231065",
            "title": "RHEL 9 must prevent special devices on file systems that are imported via Network File System (NFS).",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257855",
            "stig_id": "RHEL-09-231070",
            "title": "RHEL 9  must prevent code from being executed on file systems that are imported via Network File System (NFS).",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257856",
            "stig_id": "RHEL-09-231075",
            "title": "RHEL 9 must prevent files with the setuid and setgid bit set from being executed on file systems that are imported via Network File System (NFS).",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257857",
            "stig_id": "RHEL-09-231080",
            "title": "RHEL 9 must prevent code from being executed on file systems that are used with removable media.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257858",
            "stig_id": "RHEL-09-231085",
            "title": "RHEL 9 must prevent special devices on file systems that are used with removable media.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257859",
            "stig_id": "RHEL-09-231090",
            "title": "RHEL 9 must prevent files with the setuid and setgid bit set from being executed on file systems that are used with removable media.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257881",
            "stig_id": "RHEL-09-231200",
            "title": "RHEL 9 must prevent special devices on non-root local partitions.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257888",
            "stig_id": "RHEL-09-232040",
            "title": "RHEL 9 permissions of cron configuration files and directories must not be modified from the operating system defaults.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257889",
            "stig_id": "RHEL-09-232045",
            "title": "All RHEL 9 local initialization files must have mode 0740 or less permissive.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257890",
            "stig_id": "RHEL-09-232050",
            "title": "All RHEL 9 local interactive user home directories must have mode 0750 or less permissive.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257891",
            "stig_id": "RHEL-09-232055",
            "title": "RHEL 9 /etc/group file must have mode 0644 or less permissive to prevent unauthorized access.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257892",
            "stig_id": "RHEL-09-232060",
            "title": "RHEL 9 /etc/group- file must have mode 0644 or less permissive to prevent unauthorized access.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257893",
            "stig_id": "RHEL-09-232065",
            "title": "RHEL 9 /etc/gshadow file must have mode 0000 or less permissive to prevent unauthorized access.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257894",
            "stig_id": "RHEL-09-232070",
            "title": "RHEL 9 /etc/gshadow- file must have mode 0000 or less permissive to prevent unauthorized access.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257895",
            "stig_id": "RHEL-09-232075",
            "title": "RHEL 9 /etc/passwd file must have mode 0644 or less permissive to prevent unauthorized access.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257896",
            "stig_id": "RHEL-09-232080",
            "title": "RHEL 9 /etc/passwd- file must have mode 0644 or less permissive to prevent unauthorized access.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257897",
            "stig_id": "RHEL-09-232085",
            "title": "RHEL 9 /etc/shadow- file must have mode 0000 or less permissive to prevent unauthorized access.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257898",
            "stig_id": "RHEL-09-232090",
            "title": "RHEL 9 /etc/group file must be owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257899",
            "stig_id": "RHEL-09-232095",
            "title": "RHEL 9 /etc/group file must be group-owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257900",
            "stig_id": "RHEL-09-232100",
            "title": "RHEL 9 /etc/group- file must be owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257901",
            "stig_id": "RHEL-09-232105",
            "title": "RHEL 9 /etc/group- file must be group-owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257902",
            "stig_id": "RHEL-09-232110",
            "title": "RHEL 9 /etc/gshadow file must be owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257903",
            "stig_id": "RHEL-09-232115",
            "title": "RHEL 9 /etc/gshadow file must be group-owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257904",
            "stig_id": "RHEL-09-232120",
            "title": "RHEL 9 /etc/gshadow- file must be owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257905",
            "stig_id": "RHEL-09-232125",
            "title": "RHEL 9 /etc/gshadow- file must be group-owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257906",
            "stig_id": "RHEL-09-232130",
            "title": "RHEL 9 /etc/passwd file must be owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257907",
            "stig_id": "RHEL-09-232135",
            "title": "RHEL 9 /etc/passwd file must be group-owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257908",
            "stig_id": "RHEL-09-232140",
            "title": "RHEL 9 /etc/passwd- file must be owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257909",
            "stig_id": "RHEL-09-232145",
            "title": "RHEL 9 /etc/passwd- file must be group-owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257910",
            "stig_id": "RHEL-09-232150",
            "title": "RHEL 9 /etc/shadow file must be owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257911",
            "stig_id": "RHEL-09-232155",
            "title": "RHEL 9 /etc/shadow file must be group-owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257912",
            "stig_id": "RHEL-09-232160",
            "title": "RHEL 9 /etc/shadow- file must be owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257913",
            "stig_id": "RHEL-09-232165",
            "title": "RHEL 9 /etc/shadow- file must be group-owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257926",
            "stig_id": "RHEL-09-232230",
            "title": "RHEL 9 cron configuration files directory must be owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257927",
            "stig_id": "RHEL-09-232235",
            "title": "RHEL 9 cron configuration files directory must be group-owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257930",
            "stig_id": "RHEL-09-232250",
            "title": "All RHEL 9 local files and directories must have a valid group owner.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257931",
            "stig_id": "RHEL-09-232255",
            "title": "All RHEL 9 local files and directories must have a valid owner.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257932",
            "stig_id": "RHEL-09-232260",
            "title": "RHEL 9 must be configured so that all system device files are correctly labeled to prevent unauthorized modification.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257934",
            "stig_id": "RHEL-09-232270",
            "title": "RHEL 9 /etc/shadow file must have mode 0000 to prevent unauthorized access.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257937",
            "stig_id": "RHEL-09-251020",
            "title": "A RHEL 9 firewall must employ a deny-all, allow-by-exception policy for allowing connections to other systems.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257941",
            "stig_id": "RHEL-09-251040",
            "title": "RHEL 9 network interfaces must not be in promiscuous mode.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257942",
            "stig_id": "RHEL-09-251045",
            "title": "RHEL 9 must enable hardening for the Berkeley Packet Filter just-in-time compiler.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257948",
            "stig_id": "RHEL-09-252035",
            "title": "RHEL 9 systems using Domain Name Servers (DNS) resolution must have at least two name servers configured.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257949",
            "stig_id": "RHEL-09-252040",
            "title": "RHEL 9 must configure a DNS processing mode in Network Manager.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257950",
            "stig_id": "RHEL-09-252045",
            "title": "RHEL 9 must not have unauthorized IP tunnels configured.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257951",
            "stig_id": "RHEL-09-252050",
            "title": "RHEL 9 must be configured to prevent unrestricted mail relaying.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257955",
            "stig_id": "RHEL-09-252070",
            "title": "There must be no shosts.equiv files on RHEL 9.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257956",
            "stig_id": "RHEL-09-252075",
            "title": "There must be no .shosts files on RHEL 9.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257958",
            "stig_id": "RHEL-09-253015",
            "title": "RHEL 9 must ignore Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257959",
            "stig_id": "RHEL-09-253020",
            "title": "RHEL 9 must not forward Internet Protocol version 4 (IPv4) source-routed packets.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257960",
            "stig_id": "RHEL-09-253025",
            "title": "RHEL 9 must log IPv4 packets with impossible addresses.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257961",
            "stig_id": "RHEL-09-253030",
            "title": "RHEL 9 must log IPv4 packets with impossible addresses by default.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257962",
            "stig_id": "RHEL-09-253035",
            "title": "RHEL 9 must use reverse path filtering on all IPv4 interfaces.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257963",
            "stig_id": "RHEL-09-253040",
            "title": "RHEL 9 must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257964",
            "stig_id": "RHEL-09-253045",
            "title": "RHEL 9 must not forward IPv4 source-routed packets by default.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257965",
            "stig_id": "RHEL-09-253050",
            "title": "RHEL 9 must use a reverse-path filter for IPv4 network traffic when possible by default.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257966",
            "stig_id": "RHEL-09-253055",
            "title": "RHEL 9 must not respond to Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257967",
            "stig_id": "RHEL-09-253060",
            "title": "RHEL 9 must limit the number of bogus Internet Control Message Protocol (ICMP) response errors logs.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257968",
            "stig_id": "RHEL-09-253065",
            "title": "RHEL 9 must not send Internet Control Message Protocol (ICMP) redirects.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257969",
            "stig_id": "RHEL-09-253070",
            "title": "RHEL 9 must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257970",
            "stig_id": "RHEL-09-253075",
            "title": "RHEL 9 must not enable IPv4 packet forwarding unless the system is a router.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257971",
            "stig_id": "RHEL-09-254010",
            "title": "RHEL 9 must not accept router advertisements on all IPv6 interfaces.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257972",
            "stig_id": "RHEL-09-254015",
            "title": "RHEL 9 must ignore IPv6 Internet Control Message Protocol (ICMP) redirect messages.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257973",
            "stig_id": "RHEL-09-254020",
            "title": "RHEL 9 must not forward IPv6 source-routed packets.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257974",
            "stig_id": "RHEL-09-254025",
            "title": "RHEL 9 must not enable IPv6 packet forwarding unless the system is a router.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257975",
            "stig_id": "RHEL-09-254030",
            "title": "RHEL 9 must not accept router advertisements on all IPv6 interfaces by default.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257976",
            "stig_id": "RHEL-09-254035",
            "title": "RHEL 9 must prevent IPv6 Internet Control Message Protocol (ICMP) redirect messages from being accepted.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257977",
            "stig_id": "RHEL-09-254040",
            "title": "RHEL 9 must not forward IPv6 source-routed packets by default.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257980",
            "stig_id": "RHEL-09-255020",
            "title": "RHEL 9 must have the openssh-clients package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257992",
            "stig_id": "RHEL-09-255080",
            "title": "RHEL 9 must not allow a noncertificate trusted host SSH logon to the system.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257993",
            "stig_id": "RHEL-09-255085",
            "title": "RHEL 9 must not allow users to override SSH environment variables.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257997",
            "stig_id": "RHEL-09-255105",
            "title": "RHEL 9 SSH server configuration file must be group-owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257998",
            "stig_id": "RHEL-09-255110",
            "title": "The RHEL 9 SSH server configuration file must be owned by root.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-257999",
            "stig_id": "RHEL-09-255115",
            "title": "RHEL 9 SSH server configuration files' permissions must not be modified.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258000",
            "stig_id": "RHEL-09-255120",
            "title": "RHEL 9 SSH private host key files must have mode 0640 or less permissive.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258001",
            "stig_id": "RHEL-09-255125",
            "title": "RHEL 9 SSH public host key files must have mode 0644 or less permissive.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258002",
            "stig_id": "RHEL-09-255130",
            "title": "RHEL 9 SSH daemon must not allow compression or must only allow compression after successful authentication.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258005",
            "stig_id": "RHEL-09-255145",
            "title": "RHEL 9 SSH daemon must not allow rhosts authentication.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258006",
            "stig_id": "RHEL-09-255150",
            "title": "RHEL 9 SSH daemon must not allow known hosts authentication.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258007",
            "stig_id": "RHEL-09-255155",
            "title": "RHEL 9 SSH daemon must disable remote X connections for interactive users.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258008",
            "stig_id": "RHEL-09-255160",
            "title": "RHEL 9 SSH daemon must perform strict mode checking of home directory configuration files.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258009",
            "stig_id": "RHEL-09-255165",
            "title": "RHEL 9 SSH daemon must display the date and time of the last successful account logon upon an SSH logon.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258011",
            "stig_id": "RHEL-09-255175",
            "title": "RHEL 9 SSH daemon must prevent remote hosts from connecting to the proxy display.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258018",
            "stig_id": "RHEL-09-271040",
            "title": "RHEL 9 must not allow unattended or automatic logon via the graphical user interface.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258028",
            "stig_id": "RHEL-09-271090",
            "title": "RHEL 9 effective dconf policy must match the policy keyfiles.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258029",
            "stig_id": "RHEL-09-271095",
            "title": "RHEL 9 must disable the ability of a user to restart the system from the login screen.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258030",
            "stig_id": "RHEL-09-271100",
            "title": "RHEL 9 must prevent a user from overriding the disable-restart-buttons setting for the graphical user interface.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258031",
            "stig_id": "RHEL-09-271105",
            "title": "RHEL 9 must disable the ability of a user to accidentally press Ctrl-Alt-Del and cause a system to shut down or reboot.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258032",
            "stig_id": "RHEL-09-271110",
            "title": "RHEL 9 must prevent a user from overriding the Ctrl-Alt-Del sequence settings for the graphical user interface.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258033",
            "stig_id": "RHEL-09-271115",
            "title": "RHEL 9 must disable the user list at logon for graphical user interfaces.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258043",
            "stig_id": "RHEL-09-411020",
            "title": "All RHEL 9 local interactive user accounts must be assigned a home directory upon creation.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258044",
            "stig_id": "RHEL-09-411025",
            "title": "RHEL 9 must set the umask value to 077 for all local interactive user accounts.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258046",
            "stig_id": "RHEL-09-411035",
            "title": "RHEL 9 system accounts must not have an interactive login shell.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258050",
            "stig_id": "RHEL-09-411055",
            "title": "Executable search paths within the initialization files of all local interactive RHEL 9 users must only contain paths that resolve to the system default or the users home directory.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258051",
            "stig_id": "RHEL-09-411060",
            "title": "All RHEL 9 local interactive users must have a home directory assigned in the /etc/passwd file.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258052",
            "stig_id": "RHEL-09-411065",
            "title": "All RHEL 9 local interactive user home directories defined in the /etc/passwd file must exist.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258053",
            "stig_id": "RHEL-09-411070",
            "title": "All RHEL 9 local interactive user home directories must be group-owned by the home directory owner's primary group.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258058",
            "stig_id": "RHEL-09-411095",
            "title": "RHEL 9 must not have unauthorized accounts.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258059",
            "stig_id": "RHEL-09-411100",
            "title": "The root account must be the only account having unrestricted access to RHEL 9 system.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258062",
            "stig_id": "RHEL-09-411115",
            "title": "Local RHEL 9 initialization files must not execute world-writable programs.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258071",
            "stig_id": "RHEL-09-412050",
            "title": "RHEL 9 must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258072",
            "stig_id": "RHEL-09-412055",
            "title": "RHEL 9 must define default permissions for the bash shell.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258073",
            "stig_id": "RHEL-09-412060",
            "title": "RHEL 9 must define default permissions for the c shell.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258074",
            "stig_id": "RHEL-09-412065",
            "title": "RHEL 9 must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258075",
            "stig_id": "RHEL-09-412070",
            "title": "RHEL 9 must define default permissions for the system default profile.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258076",
            "stig_id": "RHEL-09-412075",
            "title": "RHEL 9 must display the date and time of the last successful account logon upon logon.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258082",
            "stig_id": "RHEL-09-431030",
            "title": "RHEL 9 policycoreutils-python-utils package must be installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258085",
            "stig_id": "RHEL-09-432020",
            "title": "RHEL 9 must use the invoking user's password for privilege escalation when using \"sudo\".",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258087",
            "stig_id": "RHEL-09-432030",
            "title": "RHEL 9 must restrict privilege elevation to authorized personnel.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258094",
            "stig_id": "RHEL-09-611025",
            "title": "RHEL 9 must not allow blank or null passwords.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258098",
            "stig_id": "RHEL-09-611045",
            "title": "RHEL 9 must ensure the password complexity module is enabled in the system-auth file.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258110",
            "stig_id": "RHEL-09-611105",
            "title": "RHEL 9 must prevent the use of dictionary words for passwords.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258120",
            "stig_id": "RHEL-09-611155",
            "title": "RHEL 9 must not have accounts configured with blank or null passwords.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258136",
            "stig_id": "RHEL-09-651020",
            "title": "RHEL 9 must use a file integrity tool that is configured to use FIPS 140-3-approved cryptographic hashes for validating file contents and directories.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258138",
            "stig_id": "RHEL-09-651030",
            "title": "RHEL 9 must be configured so that the file integrity tool verifies Access Control Lists (ACLs).",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258139",
            "stig_id": "RHEL-09-651035",
            "title": "RHEL 9 must be configured so that the file integrity tool verifies extended attributes.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258142",
            "stig_id": "RHEL-09-652020",
            "title": "The rsyslog service on RHEL 9 must be active.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258143",
            "stig_id": "RHEL-09-652025",
            "title": "RHEL 9 must be configured so that the rsyslog daemon does not accept log messages from other servers unless the server is being used for log aggregation.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258150",
            "stig_id": "RHEL-09-652060",
            "title": "RHEL 9 must use cron logging.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        },
        {
            "rule": "V-258169",
            "stig_id": "RHEL-09-653100",
            "title": "RHEL 9 must produce audit records containing information to establish the identity of any individual or process associated with the event.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366",
                "CCI-001487"
            ]
        },
        {
            "rule": "V-258170",
            "stig_id": "RHEL-09-653105",
            "title": "RHEL 9 must write audit records to disk.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000366"
            ]
        }
    ]
}