{
    "control": "MA-4",
    "title": "Nonlocal Maintenance",
    "ccis": [
        {
            "cci": "CCI-000873",
            "definition": "Approve nonlocal maintenance and diagnostic activities."
        },
        {
            "cci": "CCI-000874",
            "definition": "Monitor nonlocal maintenance and diagnostic activities."
        },
        {
            "cci": "CCI-000876",
            "definition": "Allow the use of nonlocal maintenance and diagnostic tools only as consistent with organizational policy and documented in the security plan for the system."
        },
        {
            "cci": "CCI-000877",
            "definition": "Employ strong authentication in the establishment of nonlocal maintenance and diagnostic sessions."
        },
        {
            "cci": "CCI-000878",
            "definition": "Maintain records for nonlocal maintenance and diagnostic activities."
        },
        {
            "cci": "CCI-000879",
            "definition": "The organization terminates sessions and network connections when nonlocal maintenance is completed."
        },
        {
            "cci": "CCI-000881",
            "definition": "The organization documents, in the security plan for the information system, the policies and procedures for the establishment and use of nonlocal maintenance and diagnostic connections."
        },
        {
            "cci": "CCI-000882",
            "definition": "Require that nonlocal maintenance and diagnostic services be performed from a system that implements a security capability comparable to the capability implemented on the system being serviced."
        },
        {
            "cci": "CCI-000883",
            "definition": "Remove the component to be serviced from the system prior to nonlocal maintenance or diagnostic services; sanitize the component (for organizational information)."
        },
        {
            "cci": "CCI-000884",
            "definition": "Protect nonlocal maintenance sessions by employing organization-defined authenticators that are replay resistant."
        },
        {
            "cci": "CCI-000886",
            "definition": "Defines the personnel or roles to be notified of the date and time of planned nonlocal maintenance."
        },
        {
            "cci": "CCI-000887",
            "definition": "Require the approval of each nonlocal maintenance session by organization-defined personnel or roles."
        },
        {
            "cci": "CCI-001631",
            "definition": "After the service is performed, inspect and sanitize the component (for potentially malicious software) before reconnecting the component to the system."
        },
        {
            "cci": "CCI-001632",
            "definition": "Protect nonlocal maintenance sessions by separating the maintenance session from other network sessions with the system by either physically separated communications paths or logically separated communications paths based upon encryption."
        },
        {
            "cci": "CCI-002884",
            "definition": "Log organization-defined audit events for nonlocal maintenance and diagnostic sessions."
        },
        {
            "cci": "CCI-002885",
            "definition": "Defines the audit events for logged for nonlocal maintenance and diagnostic sessions."
        },
        {
            "cci": "CCI-002886",
            "definition": "Review the audit records of the maintenance and diagnostic sessions to detect anomalous behavior."
        },
        {
            "cci": "CCI-002887",
            "definition": "Defines the authenticators that are replay resistant which will be employed to protect nonlocal maintenance sessions."
        },
        {
            "cci": "CCI-002888",
            "definition": "Defines the personnel or roles authorized to approve each nonlocal maintenance session."
        },
        {
            "cci": "CCI-002889",
            "definition": "Notify organization-defined personnel or roles of the date and time of planned nonlocal maintenance."
        },
        {
            "cci": "CCI-002890",
            "definition": "Implement organization-defined cryptographic mechanisms to protect the integrity of nonlocal maintenance and diagnostic communications."
        },
        {
            "cci": "CCI-002891",
            "definition": "Verify session and network connection termination after the completion of nonlocal maintenance and diagnostic sessions."
        },
        {
            "cci": "CCI-003123",
            "definition": "Implement organization-defined cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications."
        }
    ],
    "rules_mapped": 76,
    "rules": [
        {
            "rule": "V-220852",
            "stig_id": "WN10-CC-000290",
            "title": "Remote Desktop Services must be configured with the client connection encryption set to the required level.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000068",
                "CCI-002890"
            ]
        },
        {
            "rule": "V-220862",
            "stig_id": "WN10-CC-000330",
            "title": "The Windows Remote Management (WinRM) client must not use Basic authentication.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000877"
            ]
        },
        {
            "rule": "V-220863",
            "stig_id": "WN10-CC-000335",
            "title": "The Windows Remote Management (WinRM) client must not allow unencrypted traffic.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002890",
                "CCI-003123"
            ]
        },
        {
            "rule": "V-220865",
            "stig_id": "WN10-CC-000345",
            "title": "The Windows Remote Management (WinRM) service must not use Basic authentication.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000877"
            ]
        },
        {
            "rule": "V-220866",
            "stig_id": "WN10-CC-000350",
            "title": "The Windows Remote Management (WinRM) service must not allow unencrypted traffic.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002890",
                "CCI-003123"
            ]
        },
        {
            "rule": "V-220868",
            "stig_id": "WN10-CC-000360",
            "title": "The Windows Remote Management (WinRM) client must not use Digest authentication.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000877"
            ]
        },
        {
            "rule": "V-253416",
            "stig_id": "WN11-CC-000330",
            "title": "The Windows Remote Management (WinRM) client must not use Basic authentication.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000877"
            ]
        },
        {
            "rule": "V-253417",
            "stig_id": "WN11-CC-000335",
            "title": "The Windows Remote Management (WinRM) client must not allow unencrypted traffic.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002890"
            ]
        },
        {
            "rule": "V-253418",
            "stig_id": "WN11-CC-000345",
            "title": "The Windows Remote Management (WinRM) service must not use Basic authentication.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000877"
            ]
        },
        {
            "rule": "V-253419",
            "stig_id": "WN11-CC-000350",
            "title": "The Windows Remote Management (WinRM) service must not allow unencrypted traffic.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-003123"
            ]
        },
        {
            "rule": "V-253421",
            "stig_id": "WN11-CC-000360",
            "title": "The Windows Remote Management (WinRM) client must not use Digest authentication.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000877"
            ]
        },
        {
            "rule": "V-205711",
            "stig_id": "WN19-CC-000470",
            "title": "Windows Server 2019 Windows Remote Management (WinRM) client must not use Basic authentication.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000877"
            ]
        },
        {
            "rule": "V-205712",
            "stig_id": "WN19-CC-000490",
            "title": "Windows Server 2019 Windows Remote Management (WinRM) client must not use Digest authentication.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000877"
            ]
        },
        {
            "rule": "V-205713",
            "stig_id": "WN19-CC-000500",
            "title": "Windows Server 2019 Windows Remote Management (WinRM) service must not use Basic authentication.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000877"
            ]
        },
        {
            "rule": "V-205816",
            "stig_id": "WN19-CC-000480",
            "title": "Windows Server 2019 Windows Remote Management (WinRM) client must not allow unencrypted traffic.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002890",
                "CCI-003123"
            ]
        },
        {
            "rule": "V-205817",
            "stig_id": "WN19-CC-000510",
            "title": "Windows Server 2019 Windows Remote Management (WinRM) service must not allow unencrypted traffic.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002890",
                "CCI-003123"
            ]
        },
        {
            "rule": "V-254378",
            "stig_id": "WN22-CC-000470",
            "title": "Windows Server 2022 Windows Remote Management (WinRM) client must not use Basic authentication.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000877"
            ]
        },
        {
            "rule": "V-254379",
            "stig_id": "WN22-CC-000480",
            "title": "Windows Server 2022 Windows Remote Management (WinRM) client must not allow unencrypted traffic.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002890",
                "CCI-003123"
            ]
        },
        {
            "rule": "V-254380",
            "stig_id": "WN22-CC-000490",
            "title": "Windows Server 2022 Windows Remote Management (WinRM) client must not use Digest authentication.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000877"
            ]
        },
        {
            "rule": "V-254381",
            "stig_id": "WN22-CC-000500",
            "title": "Windows Server 2022 Windows Remote Management (WinRM) service must not use Basic authentication.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000877"
            ]
        },
        {
            "rule": "V-254382",
            "stig_id": "WN22-CC-000510",
            "title": "Windows Server 2022 Windows Remote Management (WinRM) service must not allow unencrypted traffic.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002890",
                "CCI-003123"
            ]
        },
        {
            "rule": "V-257796",
            "stig_id": "RHEL-09-212055",
            "title": "RHEL 9 must enable auditing of processes that start prior to the audit daemon.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001464",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-257986",
            "stig_id": "RHEL-09-255050",
            "title": "RHEL 9 must enable the Pluggable Authentication Module (PAM) interface for SSHD.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000877"
            ]
        },
        {
            "rule": "V-257996",
            "stig_id": "RHEL-09-255100",
            "title": "RHEL 9 must be configured so that all network connections associated with SSH traffic are terminated after 10 minutes of becoming unresponsive.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001133",
                "CCI-002361",
                "CCI-002891"
            ]
        },
        {
            "rule": "V-258151",
            "stig_id": "RHEL-09-653010",
            "title": "RHEL 9 audit package must be installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000131",
                "CCI-000132",
                "CCI-000133",
                "CCI-000134",
                "CCI-000135",
                "CCI-000154",
                "CCI-000158",
                "CCI-000159",
                "CCI-000169",
                "CCI-000172",
                "CCI-001464",
                "CCI-001487",
                "CCI-001814",
                "CCI-001875",
                "CCI-001876",
                "CCI-001877",
                "CCI-001878",
                "CCI-001879",
                "CCI-001880",
                "CCI-001881",
                "CCI-001882",
                "CCI-001889",
                "CCI-001914",
                "CCI-002884",
                "CCI-003938"
            ]
        },
        {
            "rule": "V-258152",
            "stig_id": "RHEL-09-653015",
            "title": "RHEL 9 audit service must be enabled.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000131",
                "CCI-000132",
                "CCI-000133",
                "CCI-000134",
                "CCI-000135",
                "CCI-000154",
                "CCI-000158",
                "CCI-000169",
                "CCI-000172",
                "CCI-001464",
                "CCI-001487",
                "CCI-001814",
                "CCI-001875",
                "CCI-001876",
                "CCI-001877",
                "CCI-001878",
                "CCI-001879",
                "CCI-001880",
                "CCI-001881",
                "CCI-001882",
                "CCI-001889",
                "CCI-001914",
                "CCI-002884",
                "CCI-003938",
                "CCI-004188"
            ]
        },
        {
            "rule": "V-258177",
            "stig_id": "RHEL-09-654015",
            "title": "RHEL 9 must audit all uses of the chmod, fchmod, and fchmodat system calls.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258178",
            "stig_id": "RHEL-09-654020",
            "title": "RHEL 9 must audit all uses of the chown, fchown, fchownat, and lchown system calls.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258179",
            "stig_id": "RHEL-09-654025",
            "title": "RHEL 9 must audit all uses of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258180",
            "stig_id": "RHEL-09-654030",
            "title": "RHEL 9 must audit all uses of umount system calls.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258181",
            "stig_id": "RHEL-09-654035",
            "title": "RHEL 9 must audit all uses of the chacl command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258182",
            "stig_id": "RHEL-09-654040",
            "title": "RHEL 9 must audit all uses of the setfacl command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258183",
            "stig_id": "RHEL-09-654045",
            "title": "RHEL 9 must audit all uses of the chcon command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258184",
            "stig_id": "RHEL-09-654050",
            "title": "RHEL 9 must audit all uses of the semanage command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258185",
            "stig_id": "RHEL-09-654055",
            "title": "RHEL 9 must audit all uses of the setfiles command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258186",
            "stig_id": "RHEL-09-654060",
            "title": "RHEL 9 must audit all uses of the setsebool command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258187",
            "stig_id": "RHEL-09-654065",
            "title": "RHEL 9 must audit all uses of the rename, unlink, rmdir, renameat, and unlinkat system calls.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258188",
            "stig_id": "RHEL-09-654070",
            "title": "RHEL 9 must audit all uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258189",
            "stig_id": "RHEL-09-654075",
            "title": "RHEL 9 must audit all uses of the delete_module system call.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258190",
            "stig_id": "RHEL-09-654080",
            "title": "RHEL 9 must audit all uses of the init_module and finit_module system calls.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258191",
            "stig_id": "RHEL-09-654085",
            "title": "RHEL 9 must audit all uses of the chage command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258192",
            "stig_id": "RHEL-09-654090",
            "title": "RHEL 9 must audit all uses of the chsh command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258193",
            "stig_id": "RHEL-09-654095",
            "title": "RHEL 9 must audit all uses of the crontab command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258194",
            "stig_id": "RHEL-09-654100",
            "title": "RHEL 9 must audit all uses of the gpasswd command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258195",
            "stig_id": "RHEL-09-654105",
            "title": "RHEL 9 must audit all uses of the kmod command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258196",
            "stig_id": "RHEL-09-654110",
            "title": "RHEL 9 must audit all uses of the newgrp command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258197",
            "stig_id": "RHEL-09-654115",
            "title": "RHEL 9 must audit all uses of the pam_timestamp_check command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258198",
            "stig_id": "RHEL-09-654120",
            "title": "RHEL 9 must audit all uses of the passwd command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258199",
            "stig_id": "RHEL-09-654125",
            "title": "RHEL 9 must audit all uses of the postdrop command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258200",
            "stig_id": "RHEL-09-654130",
            "title": "RHEL 9 must audit all uses of the postqueue command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258201",
            "stig_id": "RHEL-09-654135",
            "title": "RHEL 9 must audit all uses of the ssh-agent command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258202",
            "stig_id": "RHEL-09-654140",
            "title": "RHEL 9 must audit all uses of the ssh-keysign command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258203",
            "stig_id": "RHEL-09-654145",
            "title": "RHEL 9 must audit all uses of the su command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258204",
            "stig_id": "RHEL-09-654150",
            "title": "RHEL 9 must audit all uses of the sudo command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258205",
            "stig_id": "RHEL-09-654155",
            "title": "RHEL 9 must audit all uses of the sudoedit command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258206",
            "stig_id": "RHEL-09-654160",
            "title": "RHEL 9 must audit all uses of the unix_chkpwd command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258207",
            "stig_id": "RHEL-09-654165",
            "title": "RHEL 9 must audit all uses of the unix_update command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258208",
            "stig_id": "RHEL-09-654170",
            "title": "RHEL 9 must audit all uses of the userhelper command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258209",
            "stig_id": "RHEL-09-654175",
            "title": "RHEL 9 must audit all uses of the usermod command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258210",
            "stig_id": "RHEL-09-654180",
            "title": "RHEL 9 must audit all uses of the mount command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258215",
            "stig_id": "RHEL-09-654205",
            "title": "Successful/unsuccessful uses of the umount system call in RHEL 9 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258216",
            "stig_id": "RHEL-09-654210",
            "title": "Successful/unsuccessful uses of the umount2 system call in RHEL 9 must generate an audit record.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258217",
            "stig_id": "RHEL-09-654215",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258218",
            "stig_id": "RHEL-09-654220",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258219",
            "stig_id": "RHEL-09-654225",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258220",
            "stig_id": "RHEL-09-654230",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258221",
            "stig_id": "RHEL-09-654235",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258222",
            "stig_id": "RHEL-09-654240",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-001683",
                "CCI-001684",
                "CCI-001685",
                "CCI-001686",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258223",
            "stig_id": "RHEL-09-654245",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258224",
            "stig_id": "RHEL-09-654250",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/faillock.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258225",
            "stig_id": "RHEL-09-654255",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/lastlog.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258226",
            "stig_id": "RHEL-09-654260",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/tallylog.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000172",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258230",
            "stig_id": "RHEL-09-671010",
            "title": "RHEL 9 must enable FIPS mode.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000068",
                "CCI-000877",
                "CCI-002418",
                "CCI-002450"
            ]
        },
        {
            "rule": "V-258234",
            "stig_id": "RHEL-09-215100",
            "title": "RHEL 9 must have the crypto-policies package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002450",
                "CCI-002890",
                "CCI-003123"
            ]
        },
        {
            "rule": "V-258236",
            "stig_id": "RHEL-09-672020",
            "title": "RHEL 9 cryptographic policy must not be overridden.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002450",
                "CCI-002890",
                "CCI-003123"
            ]
        },
        {
            "rule": "V-258241",
            "stig_id": "RHEL-09-215105",
            "title": "RHEL 9 must implement a FIPS 140-3 compliant systemwide cryptographic policy.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002450",
                "CCI-002890",
                "CCI-003123"
            ]
        }
    ]
}