San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active

AC-6 Least Privilege

Access Control family. 25 Control Correlation Identifiers map to this control, and 184 STIG rules implement those CCIs.

29CAT I (high)
155CAT II (medium)
0CAT III (low)
25CCIs
What this page is built from, and what it is not.

The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.

It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.

Where these rules come from

STIG benchmarkVersionRules mapped to AC-6
Microsoft Windows Server 2019V357
Microsoft Windows Server 2022V257
Microsoft Windows 10V334
Microsoft Windows 11V224
Red Hat Enterprise Linux 9V28
Red Hat Enterprise Linux 8V24

Control Correlation Identifiers mapped to AC-6

CCIDefinitionRev
CCI-000039Require that users of system accounts, or roles, with access to organization-defined security functions or security-relevant information, use non-privileged accounts or roles, when accessing nonsecurity functions.5, 4
CCI-000041Authorize network access to organization-defined privileged commands only for organization-defined compelling operational needs.5, 4
CCI-000042Document the rationale for authorized network access to organization-defined privileged commands in the security plan for the system.5, 4
CCI-000225Employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned organizational tasks.5, 4
CCI-001419Defines the security functions or security-relevant information to which users of system accounts, or roles, have access.5, 4
CCI-001420Defines the privileged commands to which network access is to be authorized only for organization-defined compelling operational needs.5, 4
CCI-001422Prohibit privileged access to the system by non-organizational users.5, 4
CCI-001558Defines the security functions (deployed in hardware, software, and firmware) for which access must be authorized.5, 4
CCI-002221Defines the security-relevant information for which access must be explicitly authorized.5, 4
CCI-002222Authorize access for organization-defined individuals or roles to organization-defined security functions (deployed in hardware, software, and firmware).5, 4
CCI-002223Authorize access for organization-defined individuals or roles to organization-defined security-relevant information.5, 4
CCI-002224Defines the compelling operational needs that must be met in order to be authorized network access to organization-defined privileged commands.5, 4
CCI-002225Provide separate processing domains to enable finer-grained allocation of user privileges.5, 4
CCI-002226Defines the personnel or roles to whom privileged accounts are to be restricted on the information system.5, 4
CCI-002227Restrict privileged accounts on the system to organization-defined personnel or roles.5, 4
CCI-002228Defines the frequency on which it conducts reviews of the privileges assigned to organization-defined roles or classes of users.5, 4
CCI-002229Defines the roles or classes of users that are to have their privileges reviewed on an organization-defined frequency.5, 4
CCI-002230Review, on an organization-defined frequency, the privileges assigned to organization-defined roles or classes of users to validate the need for such privileges.5, 4
CCI-002231Reassign or remove privileges, if necessary, to correctly reflect organizational mission and business needs.5, 4
CCI-002232Defines the software that is prevented from executing at a higher privilege than users executing the software.5, 4
CCI-002233Prevent the organization-defined software from executing at higher privilege levels than users executing the software.5, 4
CCI-002234Log the execution of privileged functions.5, 4
CCI-002235Prevent non-privileged users from executing privileged functions.5, 4
CCI-003685Defines the individuals or roles who authorize access to organization-defined security functions.5
CCI-003686Defines the individuals or roles who authorize access to organization-defined security-relevant information.5

STIG rules that implement AC-6

RuleSTIG IDSeverityRequirement
V-205737WN19-00-000170mediumWindows Server 2019 default permissions for the HKEY_LOCAL_MACHINE registry hive must be maintained.
V-205738WN19-DC-000010highWindows Server 2019 must only allow administrators responsible for the domain controller to have Administrator rights on the system.
V-205739WN19-DC-000070highWindows Server 2019 permissions on the Active Directory data files must only allow System and Administrators access.
V-205740WN19-DC-000080highWindows Server 2019 Active Directory SYSVOL directory must have the proper access control permissions.
V-205741WN19-DC-000090highWindows Server 2019 Active Directory Group Policy objects must have proper access control permissions.
V-205742WN19-DC-000100highWindows Server 2019 Active Directory Domain Controllers Organizational Unit (OU) object must have the proper access control permissions.
V-205743WN19-DC-000110highWindows Server 2019 organization created Active Directory Organizational Unit (OU) objects must have proper access control permissions.
V-205744WN19-DC-000350mediumWindows Server 2019 Add workstations to domain user right must only be assigned to the Administrators group on domain controllers.
V-205745WN19-DC-000420mediumWindows Server 2019 Enable computer and user accounts to be trusted for delegation user right must only be assigned to the Administrators group on domain controllers.
V-205746WN19-MS-000010highWindows Server 2019 must only allow Administrators responsible for the member server or standalone or nondomain-joined system to have Administrator rights on the system.
V-205747WN19-MS-000060mediumWindows Server 2019 must restrict remote calls to the Security Account Manager (SAM) to Administrators on domain-joined member servers and standalone or nondomain-joined systems.
V-205748WN19-MS-000130mediumWindows Server 2019 "Enable computer and user accounts to be trusted for delegation" user right must not be assigned to any groups or accounts on domain-joined member servers and standalone or nondomain-joined systems.
V-205749WN19-UR-000010mediumWindows Server 2019 Access Credential Manager as a trusted caller user right must not be assigned to any groups or accounts.
V-205750WN19-UR-000020highWindows Server 2019 Act as part of the operating system user right must not be assigned to any groups or accounts.
V-205751WN19-UR-000040mediumWindows Server 2019 Back up files and directories user right must only be assigned to the Administrators group.
V-205752WN19-UR-000050mediumWindows Server 2019 Create a pagefile user right must only be assigned to the Administrators group.
V-205753WN19-UR-000060highWindows Server 2019 Create a token object user right must not be assigned to any groups or accounts.
V-205754WN19-UR-000070mediumWindows Server 2019 Create global objects user right must only be assigned to Administrators, Service, Local Service, and Network Service.
V-205755WN19-UR-000080mediumWindows Server 2019 Create permanent shared objects user right must not be assigned to any groups or accounts.
V-205756WN19-UR-000090mediumWindows Server 2019 Create symbolic links user right must only be assigned to the Administrators group.
V-205757WN19-UR-000100highWindows Server 2019 Debug programs: user right must only be assigned to the Administrators group.
V-205758WN19-UR-000110mediumWindows Server 2019 Force shutdown from a remote system user right must only be assigned to the Administrators group.
V-205759WN19-UR-000120mediumWindows Server 2019 Generate security audits user right must only be assigned to Local Service and Network Service.
V-205760WN19-UR-000130mediumWindows Server 2019 Impersonate a client after authentication user right must only be assigned to Administrators, Service, Local Service, and Network Service.
V-205761WN19-UR-000140mediumWindows Server 2019 Increase scheduling priority: user right must only be assigned to the Administrators group.
V-205762WN19-UR-000150mediumWindows Server 2019 Load and unload device drivers user right must only be assigned to the Administrators group.
V-205763WN19-UR-000160mediumWindows Server 2019 Lock pages in memory user right must not be assigned to any groups or accounts.
V-205764WN19-UR-000180mediumWindows Server 2019 Modify firmware environment values user right must only be assigned to the Administrators group.
V-205765WN19-UR-000190mediumWindows Server 2019 Perform volume maintenance tasks user right must only be assigned to the Administrators group.
V-205766WN19-UR-000200mediumWindows Server 2019 Profile single process user right must only be assigned to the Administrators group.
V-205767WN19-UR-000210mediumWindows Server 2019 Restore files and directories user right must only be assigned to the Administrators group.
V-205768WN19-UR-000220mediumWindows Server 2019 Take ownership of files or other objects user right must only be assigned to the Administrators group.
V-205769WN19-AU-000090mediumWindows Server 2019 must be configured to audit Account Management - Other Account Management Events successes.
V-205770WN19-AU-000140mediumWindows Server 2019 must be configured to audit Detailed Tracking - Process Creation successes.
V-205771WN19-AU-000260mediumWindows Server 2019 must be configured to audit Policy Change - Audit Policy Change successes.
V-205772WN19-AU-000270mediumWindows Server 2019 must be configured to audit Policy Change - Audit Policy Change failures.
V-205773WN19-AU-000280mediumWindows Server 2019 must be configured to audit Policy Change - Authentication Policy Change successes.
V-205774WN19-AU-000290mediumWindows Server 2019 must be configured to audit Policy Change - Authorization Policy Change successes.
V-205775WN19-AU-000300mediumWindows Server 2019 must be configured to audit Privilege Use - Sensitive Privilege Use successes.
V-205776WN19-AU-000310mediumWindows Server 2019 must be configured to audit Privilege Use - Sensitive Privilege Use failures.
V-205777WN19-AU-000320mediumWindows Server 2019 must be configured to audit System - IPsec Driver successes.
V-205778WN19-AU-000330mediumWindows Server 2019 must be configured to audit System - IPsec Driver failures.
V-205779WN19-AU-000340mediumWindows Server 2019 must be configured to audit System - Other System Events successes.
V-205780WN19-AU-000350mediumWindows Server 2019 must be configured to audit System - Other System Events failures.
V-205781WN19-AU-000360mediumWindows Server 2019 must be configured to audit System - Security State Change successes.
V-205782WN19-AU-000370mediumWindows Server 2019 must be configured to audit System - Security System Extension successes.
V-205783WN19-AU-000380mediumWindows Server 2019 must be configured to audit System - System Integrity successes.
V-205784WN19-AU-000390mediumWindows Server 2019 must be configured to audit System - System Integrity failures.
V-205785WN19-DC-000170mediumWindows Server 2019 Active Directory Group Policy objects must be configured with proper audit settings.
V-205786WN19-DC-000180mediumWindows Server 2019 Active Directory Domain object must be configured with proper audit settings.
V-205787WN19-DC-000190mediumWindows Server 2019 Active Directory Infrastructure object must be configured with proper audit settings.
V-205788WN19-DC-000200mediumWindows Server 2019 Active Directory Domain Controllers Organizational Unit (OU) object must be configured with proper audit settings.
V-205789WN19-DC-000210mediumWindows Server 2019 Active Directory AdminSDHolder object must be configured with proper audit settings.
V-205790WN19-DC-000220mediumWindows Server 2019 Active Directory RID Manager$ object must be configured with proper audit settings.
V-205791WN19-DC-000240mediumWindows Server 2019 must be configured to audit DS Access - Directory Service Access successes.
V-205792WN19-DC-000250mediumWindows Server 2019 must be configured to audit DS Access - Directory Service Access failures.
V-205793WN19-DC-000260mediumWindows Server 2019 must be configured to audit DS Access - Directory Service Changes successes.
V-220712WN10-00-000070highOnly accounts responsible for the administration of a system must have Administrator rights on the system.
V-220750WN10-AU-000030mediumThe system must be configured to audit Account Management - Security Group Management successes.
V-220751WN10-AU-000035mediumThe system must be configured to audit Account Management - User Account Management failures.
V-220752WN10-AU-000040mediumThe system must be configured to audit Account Management - User Account Management successes.
V-220768WN10-AU-000105mediumThe system must be configured to audit Policy Change - Authentication Policy Change successes.
V-220770WN10-AU-000110mediumThe system must be configured to audit Privilege Use - Sensitive Privilege Use failures.
V-220771WN10-AU-000115mediumThe system must be configured to audit Privilege Use - Sensitive Privilege Use successes.
V-220775WN10-AU-000140mediumThe system must be configured to audit System - Security State Change successes.
V-220776WN10-AU-000150mediumThe system must be configured to audit System - Security System Extension successes.
V-220777WN10-AU-000155mediumThe system must be configured to audit System - System Integrity failures.
V-220778WN10-AU-000160mediumThe system must be configured to audit System - System Integrity successes.
V-220907WN10-RG-000005mediumDefault permissions for the HKEY_LOCAL_MACHINE registry hive must be maintained.
V-220933WN10-SO-000167mediumRemote calls to the Security Account Manager (SAM) must be restricted to Administrators.
V-220956WN10-UR-000005mediumThe Access Credential Manager as a trusted caller user right must not be assigned to any groups or accounts.
V-220958WN10-UR-000015highThe Act as part of the operating system user right must not be assigned to any groups or accounts.
V-220960WN10-UR-000030mediumThe Back up files and directories user right must only be assigned to the Administrators group.
V-220961WN10-UR-000035mediumThe Change the system time user right must only be assigned to Administrators and Local Service and NT SERVICE\autotimesvc.
V-220962WN10-UR-000040mediumThe Create a pagefile user right must only be assigned to the Administrators group.
V-220963WN10-UR-000045highThe Create a token object user right must not be assigned to any groups or accounts.
V-220964WN10-UR-000050mediumThe Create global objects user right must only be assigned to Administrators, Service, Local Service, and Network Service.
V-220965WN10-UR-000055mediumThe Create permanent shared objects user right must not be assigned to any groups or accounts.
V-220966WN10-UR-000060mediumThe Create symbolic links user right must only be assigned to the Administrators group.
V-220967WN10-UR-000065highThe Debug programs user right must only be assigned to the Administrators group.
V-220973WN10-UR-000095mediumThe Enable computer and user accounts to be trusted for delegation user right must not be assigned to any groups or accounts.
V-220974WN10-UR-000100mediumThe Force shutdown from a remote system user right must only be assigned to the Administrators group.
V-220975WN10-UR-000110mediumThe Impersonate a client after authentication user right must only be assigned to Administrators, Service, Local Service, and Network Service.
V-220976WN10-UR-000120mediumThe Load and unload device drivers user right must only be assigned to the Administrators group.
V-220977WN10-UR-000125mediumThe Lock pages in memory user right must not be assigned to any groups or accounts.
V-220979WN10-UR-000140mediumThe Modify firmware environment values user right must only be assigned to the Administrators group.
V-220980WN10-UR-000145mediumThe Perform volume maintenance tasks user right must only be assigned to the Administrators group.
V-220981WN10-UR-000150mediumThe Profile single process user right must only be assigned to the Administrators group.
V-220982WN10-UR-000160mediumThe Restore files and directories user right must only be assigned to the Administrators group.
V-220983WN10-UR-000165mediumThe Take ownership of files or other objects user right must only be assigned to the Administrators group.
V-230386RHEL-08-030000mediumThe RHEL 8 audit system must be configured to audit the execution of privileged functions and prevent all software from executing at higher privilege levels than users executing the software.
V-237642RHEL-08-010383mediumRHEL 8 must use the invoking user's password for privilege escalation when using "sudo".
V-253328WN11-AU-000110mediumThe system must be configured to audit Privilege Use - Sensitive Privilege Use failures.
V-253431WN11-RG-000005mediumDefault permissions for the HKEY_LOCAL_MACHINE registry hive must be maintained.
V-253457WN11-SO-000167mediumRemote calls to the Security Account Manager (SAM) must be restricted to Administrators.
V-253479WN11-UR-000005mediumThe "Access Credential Manager as a trusted caller" user right must not be assigned to any groups or accounts.
V-253481WN11-UR-000015highThe "Act as part of the operating system" user right must not be assigned to any groups or accounts.
V-253483WN11-UR-000030mediumThe "Back up files and directories" user right must only be assigned to the Administrators group.
V-253484WN11-UR-000035mediumThe "Change the system time" user right must only be assigned to Administrators and Local Service.
V-253485WN11-UR-000040mediumThe "Create a pagefile" user right must only be assigned to the Administrators group.
V-253486WN11-UR-000045highThe "Create a token object" user right must not be assigned to any groups or accounts.
V-253487WN11-UR-000050mediumThe "Create global objects" user right must only be assigned to Administrators, Service, Local Service, and Network Service.
V-253488WN11-UR-000055mediumThe "Create permanent shared objects" user right must not be assigned to any groups or accounts.
V-253489WN11-UR-000060mediumThe "Create symbolic links" user right must only be assigned to the Administrators group.
V-253490WN11-UR-000065highThe "Debug programs" user right must only be assigned to the Administrators group.
V-253496WN11-UR-000095mediumThe "Enable computer and user accounts to be trusted for delegation" user right must not be assigned to any groups or accounts.
V-253497WN11-UR-000100mediumThe "Force shutdown from a remote system" user right must only be assigned to the Administrators group.
V-253498WN11-UR-000110mediumThe "Impersonate a client after authentication" user right must only be assigned to Administrators, Service, Local Service, and Network Service.
V-253499WN11-UR-000120mediumThe "Load and unload device drivers" user right must only be assigned to the Administrators group.
V-253500WN11-UR-000125mediumThe "Lock pages in memory" user right must not be assigned to any groups or accounts.
V-253502WN11-UR-000140mediumThe "Modify firmware environment values" user right must only be assigned to the Administrators group.
V-253503WN11-UR-000145mediumThe "Perform volume maintenance tasks" user right must only be assigned to the Administrators group.
V-253504WN11-UR-000150mediumThe "Profile single process" user right must only be assigned to the Administrators group.
V-253505WN11-UR-000160mediumThe "Restore files and directories" user right must only be assigned to the Administrators group.
V-253506WN11-UR-000165mediumThe "Take ownership of files or other objects" user right must only be assigned to the Administrators group.
V-254254WN22-00-000170mediumWindows Server 2022 default permissions for the HKEY_LOCAL_MACHINE registry hive must be maintained.
V-254302WN22-AU-000090mediumWindows Server 2022 must be configured to audit Account Management - Other Account Management Events successes.
V-254307WN22-AU-000140mediumWindows Server 2022 must be configured to audit Detailed Tracking - Process Creation successes.
V-254319WN22-AU-000260mediumWindows Server 2022 must be configured to audit Policy Change - Audit Policy Change successes.
V-254320WN22-AU-000270mediumWindows Server 2022 must be configured to audit Policy Change - Audit Policy Change failures.
V-254321WN22-AU-000280mediumWindows Server 2022 must be configured to audit Policy Change - Authentication Policy Change successes.
V-254322WN22-AU-000290mediumWindows Server 2022 must be configured to audit Policy Change - Authorization Policy Change successes.
V-254323WN22-AU-000300mediumWindows Server 2022 must be configured to audit Privilege Use - Sensitive Privilege Use successes.
V-254324WN22-AU-000310mediumWindows Server 2022 must be configured to audit Privilege Use - Sensitive Privilege Use failures.
V-254325WN22-AU-000320mediumWindows Server 2022 must be configured to audit System - IPsec Driver successes.
V-254326WN22-AU-000330mediumWindows Server 2022 must be configured to audit System - IPsec Driver failures.
V-254327WN22-AU-000340mediumWindows Server 2022 must be configured to audit System - Other System Events successes.
V-254328WN22-AU-000350mediumWindows Server 2022 must be configured to audit System - Other System Events failures.
V-254329WN22-AU-000360mediumWindows Server 2022 must be configured to audit System - Security State Change successes.
V-254330WN22-AU-000370mediumWindows Server 2022 must be configured to audit System - Security System Extension successes.
V-254331WN22-AU-000380mediumWindows Server 2022 must be configured to audit System - System Integrity successes.
V-254332WN22-AU-000390mediumWindows Server 2022 must be configured to audit System - System Integrity failures.
V-254385WN22-DC-000010highWindows Server 2022 must only allow administrators responsible for the domain controller to have Administrator rights on the system.
V-254391WN22-DC-000070highWindows Server 2022 permissions on the Active Directory data files must only allow System and Administrators access.
V-254392WN22-DC-000080highWindows Server 2022 Active Directory SYSVOL directory must have the proper access control permissions.
V-254393WN22-DC-000090highWindows Server 2022 Active Directory Group Policy objects must have proper access control permissions.
V-254394WN22-DC-000100highWindows Server 2022 Active Directory Domain Controllers Organizational Unit (OU) object must have the proper access control permissions.
V-254395WN22-DC-000110highWindows Server 2022 organization created Active Directory Organizational Unit (OU) objects must have proper access control permissions.
V-254401WN22-DC-000170mediumWindows Server 2022 Active Directory Group Policy objects must be configured with proper audit settings.
V-254402WN22-DC-000180mediumWindows Server 2022 Active Directory Domain object must be configured with proper audit settings.
V-254403WN22-DC-000190mediumWindows Server 2022 Active Directory Infrastructure object must be configured with proper audit settings.
V-254404WN22-DC-000200mediumWindows Server 2022 Active Directory Domain Controllers Organizational Unit (OU) object must be configured with proper audit settings.
V-254405WN22-DC-000210mediumWindows Server 2022 Active Directory AdminSDHolder object must be configured with proper audit settings.
V-254406WN22-DC-000220mediumWindows Server 2022 Active Directory RID Manager$ object must be configured with proper audit settings.
V-254408WN22-DC-000240mediumWindows Server 2022 must be configured to audit DS Access - Directory Service Access successes.
V-254409WN22-DC-000250mediumWindows Server 2022 must be configured to audit DS Access - Directory Service Access failures.
V-254410WN22-DC-000260mediumWindows Server 2022 must be configured to audit DS Access - Directory Service Changes successes.
V-254419WN22-DC-000350mediumWindows Server 2022 Add workstations to domain user right must only be assigned to the Administrators group on domain controllers.
V-254426WN22-DC-000420mediumWindows Server 2022 Enable computer and user accounts to be trusted for delegation user right must only be assigned to the Administrators group on domain controllers.
V-254428WN22-MS-000010highWindows Server 2022 must only allow administrators responsible for the member server or standalone or nondomain-joined system to have Administrator rights on the system.
V-254433WN22-MS-000060mediumWindows Server 2022 must restrict remote calls to the Security Account Manager (SAM) to Administrators on domain-joined member servers and standalone or nondomain-joined systems.
V-254440WN22-MS-000130mediumWindows Server 2022 Enable computer and user accounts to be trusted for delegation user right must not be assigned to any groups or accounts on domain-joined member servers and standalone or nondomain-joined systems.
V-254491WN22-UR-000010mediumWindows Server 2022 Access Credential Manager as a trusted caller user right must not be assigned to any groups or accounts.
V-254492WN22-UR-000020highWindows Server 2022 Act as part of the operating system user right must not be assigned to any groups or accounts.
V-254494WN22-UR-000040mediumWindows Server 2022 back up files and directories user right must only be assigned to the Administrators group.
V-254495WN22-UR-000050mediumWindows Server 2022 create a pagefile user right must only be assigned to the Administrators group.
V-254496WN22-UR-000060highWindows Server 2022 create a token object user right must not be assigned to any groups or accounts.
V-254497WN22-UR-000070mediumWindows Server 2022 create global objects user right must only be assigned to Administrators, Service, Local Service, and Network Service.
V-254498WN22-UR-000080mediumWindows Server 2022 create permanent shared objects user right must not be assigned to any groups or accounts.
V-254499WN22-UR-000090mediumWindows Server 2022 create symbolic links user right must only be assigned to the Administrators group.
V-254500WN22-UR-000100highWindows Server 2022 debug programs user right must only be assigned to the Administrators group.
V-254501WN22-UR-000110mediumWindows Server 2022 force shutdown from a remote system user right must only be assigned to the Administrators group.
V-254502WN22-UR-000120mediumWindows Server 2022 generate security audits user right must only be assigned to Local Service and Network Service.
V-254503WN22-UR-000130mediumWindows Server 2022 impersonate a client after authentication user right must only be assigned to Administrators, Service, Local Service, and Network Service.
V-254504WN22-UR-000140mediumWindows Server 2022 increase scheduling priority: user right must only be assigned to the Administrators group.
V-254505WN22-UR-000150mediumWindows Server 2022 load and unload device drivers user right must only be assigned to the Administrators group.
V-254506WN22-UR-000160mediumWindows Server 2022 lock pages in memory user right must not be assigned to any groups or accounts.
V-254508WN22-UR-000180mediumWindows Server 2022 modify firmware environment values user right must only be assigned to the Administrators group.
V-254509WN22-UR-000190mediumWindows Server 2022 perform volume maintenance tasks user right must only be assigned to the Administrators group.
V-254510WN22-UR-000200mediumWindows Server 2022 profile single process user right must only be assigned to the Administrators group.
V-254511WN22-UR-000210mediumWindows Server 2022 restore files and directories user right must only be assigned to the Administrators group.
V-254512WN22-UR-000220mediumWindows Server 2022 take ownership of files or other objects user right must only be assigned to the Administrators group.
V-254520RHEL-08-040400mediumRHEL 8 must prevent nonprivileged users from executing privileged functions, including disabling, circumventing, or altering implemented security safeguards/countermeasures.
V-257589WN10-AU-000585mediumWindows 10 must have command line process auditing events enabled for failures.
V-257770WN11-AU-000585mediumWindows 11 must have command line process auditing events enabled for failures.
V-257784RHEL-09-211045highThe systemd Ctrl-Alt-Delete burst key sequence in RHEL 9 must be disabled.
V-257785RHEL-09-211050highThe x86 Ctrl-Alt-Delete key sequence must be disabled on RHEL 9.
V-257786RHEL-09-211055mediumRHEL 9 debug-shell systemd service must be disabled.
V-257801RHEL-09-213030mediumRHEL 9 must enable kernel parameters to enforce discretionary access control on hardlinks.
V-257802RHEL-09-213035mediumRHEL 9 must enable kernel parameters to enforce discretionary access control on symlinks.
V-258083RHEL-09-432010mediumRHEL 9 must have the sudo package installed.
V-258176RHEL-09-654010mediumRHEL 9 must audit uses of the "execve" system call.
V-272484RHEL-08-010455mediumRHEL 8 must elevate the SELinux context when an administrator calls the sudo command.
V-272496RHEL-09-431016mediumRHEL 9 must elevate the SELinux context when an administrator calls the sudo command.

Get this as data

The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/AC-6. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.