{
    "control": "SC-4",
    "title": "Information in Shared System Resources",
    "ccis": [
        {
            "cci": "CCI-001090",
            "definition": "Prevent unauthorized and unintended information transfer via shared system resources."
        },
        {
            "cci": "CCI-002383",
            "definition": "Defines the procedures to be employed to prevent unauthorized information transfer via shared resources when system processing explicitly switches between different information classification levels or security categories."
        },
        {
            "cci": "CCI-002384",
            "definition": "Prevent unauthorized information transfer via shared resources in accordance with organization-defined procedures when system processing explicitly switches between different information classification levels or security categories."
        }
    ],
    "rules_mapped": 28,
    "rules": [
        {
            "rule": "V-220710",
            "stig_id": "WN10-00-000060",
            "title": "Non system-created file shares on a system must limit access to groups that require it.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-220823",
            "stig_id": "WN10-CC-000155",
            "title": "Solicited Remote Assistance must not be allowed.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-220849",
            "stig_id": "WN10-CC-000275",
            "title": "Local drives must be prevented from sharing with Remote Desktop Session Hosts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-220902",
            "stig_id": "WN10-EP-000310",
            "title": "Windows 10 Kernel (Direct Memory Access) DMA Protection must be enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-220930",
            "stig_id": "WN10-SO-000150",
            "title": "Anonymous enumeration of shares must be restricted.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-220932",
            "stig_id": "WN10-SO-000165",
            "title": "Anonymous access to Named Pipes and Shares must be restricted.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-253267",
            "stig_id": "WN11-00-000060",
            "title": "Non-system-created file shares on a system must limit access to groups that require it.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-253382",
            "stig_id": "WN11-CC-000155",
            "title": "Solicited Remote Assistance must not be allowed.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-253403",
            "stig_id": "WN11-CC-000275",
            "title": "Local drives must be prevented from sharing with Remote Desktop Session Hosts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-253454",
            "stig_id": "WN11-SO-000150",
            "title": "Anonymous enumeration of shares must be restricted.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-253456",
            "stig_id": "WN11-SO-000165",
            "title": "Anonymous access to Named Pipes and Shares must be restricted.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-205721",
            "stig_id": "WN19-00-000230",
            "title": "Windows Server 2019 non-system-created file shares must limit access to groups that require it.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-205722",
            "stig_id": "WN19-CC-000350",
            "title": "Windows Server 2019 Remote Desktop Services must prevent drive redirection.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-205723",
            "stig_id": "WN19-DC-000120",
            "title": "Windows Server 2019 data files owned by users must be on a different logical partition from the directory server data files.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-205724",
            "stig_id": "WN19-SO-000230",
            "title": "Windows Server 2019 must not allow anonymous enumeration of shares.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-205725",
            "stig_id": "WN19-SO-000250",
            "title": "Windows Server 2019 must restrict anonymous access to Named Pipes and Shares.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-254260",
            "stig_id": "WN22-00-000230",
            "title": "Windows Server 2022 nonsystem-created file shares must limit access to groups that require it.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-254366",
            "stig_id": "WN22-CC-000350",
            "title": "Windows Server 2022 Remote Desktop Services must prevent drive redirection.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-254396",
            "stig_id": "WN22-DC-000120",
            "title": "Windows Server 2022 data files owned by users must be on a different logical partition from the directory server data files.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-254467",
            "stig_id": "WN22-SO-000230",
            "title": "Windows Server 2022 must not allow anonymous enumeration of shares.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-254469",
            "stig_id": "WN22-SO-000250",
            "title": "Windows Server 2022 must restrict anonymous access to Named Pipes and Shares.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-230243",
            "stig_id": "RHEL-08-010190",
            "title": "A sticky bit must be set on all RHEL 8 public directories to prevent unauthorized and unintended information transferred via shared system resources.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-230269",
            "stig_id": "RHEL-08-010375",
            "title": "RHEL 8 must restrict access to the kernel message buffer.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-230270",
            "stig_id": "RHEL-08-010376",
            "title": "RHEL 8 must prevent kernel profiling by unprivileged users.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-257797",
            "stig_id": "RHEL-09-213010",
            "title": "RHEL 9 must restrict access to the kernel message buffer.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001082",
                "CCI-001090"
            ]
        },
        {
            "rule": "V-257798",
            "stig_id": "RHEL-09-213015",
            "title": "RHEL 9 must prevent kernel profiling by nonprivileged users.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001082",
                "CCI-001090"
            ]
        },
        {
            "rule": "V-257928",
            "stig_id": "RHEL-09-232240",
            "title": "All RHEL 9 world-writable directories must be owned by root, sys, bin, or an application user.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001090"
            ]
        },
        {
            "rule": "V-257929",
            "stig_id": "RHEL-09-232245",
            "title": "A sticky bit must be set on all RHEL 9 public directories.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001090"
            ]
        }
    ]
}