AC-6 Least Privilege
Access Control family. 25 Control Correlation Identifiers map to this control, and 184 STIG rules implement those CCIs.
The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.
It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.
Where these rules come from
| STIG benchmark | Version | Rules mapped to AC-6 |
|---|---|---|
| Microsoft Windows Server 2019 | V3 | 57 |
| Microsoft Windows Server 2022 | V2 | 57 |
| Microsoft Windows 10 | V3 | 34 |
| Microsoft Windows 11 | V2 | 24 |
| Red Hat Enterprise Linux 9 | V2 | 8 |
| Red Hat Enterprise Linux 8 | V2 | 4 |
Control Correlation Identifiers mapped to AC-6
| CCI | Definition | Rev |
|---|---|---|
| CCI-000039 | Require that users of system accounts, or roles, with access to organization-defined security functions or security-relevant information, use non-privileged accounts or roles, when accessing nonsecurity functions. | 5, 4 |
| CCI-000041 | Authorize network access to organization-defined privileged commands only for organization-defined compelling operational needs. | 5, 4 |
| CCI-000042 | Document the rationale for authorized network access to organization-defined privileged commands in the security plan for the system. | 5, 4 |
| CCI-000225 | Employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned organizational tasks. | 5, 4 |
| CCI-001419 | Defines the security functions or security-relevant information to which users of system accounts, or roles, have access. | 5, 4 |
| CCI-001420 | Defines the privileged commands to which network access is to be authorized only for organization-defined compelling operational needs. | 5, 4 |
| CCI-001422 | Prohibit privileged access to the system by non-organizational users. | 5, 4 |
| CCI-001558 | Defines the security functions (deployed in hardware, software, and firmware) for which access must be authorized. | 5, 4 |
| CCI-002221 | Defines the security-relevant information for which access must be explicitly authorized. | 5, 4 |
| CCI-002222 | Authorize access for organization-defined individuals or roles to organization-defined security functions (deployed in hardware, software, and firmware). | 5, 4 |
| CCI-002223 | Authorize access for organization-defined individuals or roles to organization-defined security-relevant information. | 5, 4 |
| CCI-002224 | Defines the compelling operational needs that must be met in order to be authorized network access to organization-defined privileged commands. | 5, 4 |
| CCI-002225 | Provide separate processing domains to enable finer-grained allocation of user privileges. | 5, 4 |
| CCI-002226 | Defines the personnel or roles to whom privileged accounts are to be restricted on the information system. | 5, 4 |
| CCI-002227 | Restrict privileged accounts on the system to organization-defined personnel or roles. | 5, 4 |
| CCI-002228 | Defines the frequency on which it conducts reviews of the privileges assigned to organization-defined roles or classes of users. | 5, 4 |
| CCI-002229 | Defines the roles or classes of users that are to have their privileges reviewed on an organization-defined frequency. | 5, 4 |
| CCI-002230 | Review, on an organization-defined frequency, the privileges assigned to organization-defined roles or classes of users to validate the need for such privileges. | 5, 4 |
| CCI-002231 | Reassign or remove privileges, if necessary, to correctly reflect organizational mission and business needs. | 5, 4 |
| CCI-002232 | Defines the software that is prevented from executing at a higher privilege than users executing the software. | 5, 4 |
| CCI-002233 | Prevent the organization-defined software from executing at higher privilege levels than users executing the software. | 5, 4 |
| CCI-002234 | Log the execution of privileged functions. | 5, 4 |
| CCI-002235 | Prevent non-privileged users from executing privileged functions. | 5, 4 |
| CCI-003685 | Defines the individuals or roles who authorize access to organization-defined security functions. | 5 |
| CCI-003686 | Defines the individuals or roles who authorize access to organization-defined security-relevant information. | 5 |
STIG rules that implement AC-6
| Rule | STIG ID | Severity | Requirement |
|---|---|---|---|
| V-205737 | WN19-00-000170 | medium | Windows Server 2019 default permissions for the HKEY_LOCAL_MACHINE registry hive must be maintained. |
| V-205738 | WN19-DC-000010 | high | Windows Server 2019 must only allow administrators responsible for the domain controller to have Administrator rights on the system. |
| V-205739 | WN19-DC-000070 | high | Windows Server 2019 permissions on the Active Directory data files must only allow System and Administrators access. |
| V-205740 | WN19-DC-000080 | high | Windows Server 2019 Active Directory SYSVOL directory must have the proper access control permissions. |
| V-205741 | WN19-DC-000090 | high | Windows Server 2019 Active Directory Group Policy objects must have proper access control permissions. |
| V-205742 | WN19-DC-000100 | high | Windows Server 2019 Active Directory Domain Controllers Organizational Unit (OU) object must have the proper access control permissions. |
| V-205743 | WN19-DC-000110 | high | Windows Server 2019 organization created Active Directory Organizational Unit (OU) objects must have proper access control permissions. |
| V-205744 | WN19-DC-000350 | medium | Windows Server 2019 Add workstations to domain user right must only be assigned to the Administrators group on domain controllers. |
| V-205745 | WN19-DC-000420 | medium | Windows Server 2019 Enable computer and user accounts to be trusted for delegation user right must only be assigned to the Administrators group on domain controllers. |
| V-205746 | WN19-MS-000010 | high | Windows Server 2019 must only allow Administrators responsible for the member server or standalone or nondomain-joined system to have Administrator rights on the system. |
| V-205747 | WN19-MS-000060 | medium | Windows Server 2019 must restrict remote calls to the Security Account Manager (SAM) to Administrators on domain-joined member servers and standalone or nondomain-joined systems. |
| V-205748 | WN19-MS-000130 | medium | Windows Server 2019 "Enable computer and user accounts to be trusted for delegation" user right must not be assigned to any groups or accounts on domain-joined member servers and standalone or nondomain-joined systems. |
| V-205749 | WN19-UR-000010 | medium | Windows Server 2019 Access Credential Manager as a trusted caller user right must not be assigned to any groups or accounts. |
| V-205750 | WN19-UR-000020 | high | Windows Server 2019 Act as part of the operating system user right must not be assigned to any groups or accounts. |
| V-205751 | WN19-UR-000040 | medium | Windows Server 2019 Back up files and directories user right must only be assigned to the Administrators group. |
| V-205752 | WN19-UR-000050 | medium | Windows Server 2019 Create a pagefile user right must only be assigned to the Administrators group. |
| V-205753 | WN19-UR-000060 | high | Windows Server 2019 Create a token object user right must not be assigned to any groups or accounts. |
| V-205754 | WN19-UR-000070 | medium | Windows Server 2019 Create global objects user right must only be assigned to Administrators, Service, Local Service, and Network Service. |
| V-205755 | WN19-UR-000080 | medium | Windows Server 2019 Create permanent shared objects user right must not be assigned to any groups or accounts. |
| V-205756 | WN19-UR-000090 | medium | Windows Server 2019 Create symbolic links user right must only be assigned to the Administrators group. |
| V-205757 | WN19-UR-000100 | high | Windows Server 2019 Debug programs: user right must only be assigned to the Administrators group. |
| V-205758 | WN19-UR-000110 | medium | Windows Server 2019 Force shutdown from a remote system user right must only be assigned to the Administrators group. |
| V-205759 | WN19-UR-000120 | medium | Windows Server 2019 Generate security audits user right must only be assigned to Local Service and Network Service. |
| V-205760 | WN19-UR-000130 | medium | Windows Server 2019 Impersonate a client after authentication user right must only be assigned to Administrators, Service, Local Service, and Network Service. |
| V-205761 | WN19-UR-000140 | medium | Windows Server 2019 Increase scheduling priority: user right must only be assigned to the Administrators group. |
| V-205762 | WN19-UR-000150 | medium | Windows Server 2019 Load and unload device drivers user right must only be assigned to the Administrators group. |
| V-205763 | WN19-UR-000160 | medium | Windows Server 2019 Lock pages in memory user right must not be assigned to any groups or accounts. |
| V-205764 | WN19-UR-000180 | medium | Windows Server 2019 Modify firmware environment values user right must only be assigned to the Administrators group. |
| V-205765 | WN19-UR-000190 | medium | Windows Server 2019 Perform volume maintenance tasks user right must only be assigned to the Administrators group. |
| V-205766 | WN19-UR-000200 | medium | Windows Server 2019 Profile single process user right must only be assigned to the Administrators group. |
| V-205767 | WN19-UR-000210 | medium | Windows Server 2019 Restore files and directories user right must only be assigned to the Administrators group. |
| V-205768 | WN19-UR-000220 | medium | Windows Server 2019 Take ownership of files or other objects user right must only be assigned to the Administrators group. |
| V-205769 | WN19-AU-000090 | medium | Windows Server 2019 must be configured to audit Account Management - Other Account Management Events successes. |
| V-205770 | WN19-AU-000140 | medium | Windows Server 2019 must be configured to audit Detailed Tracking - Process Creation successes. |
| V-205771 | WN19-AU-000260 | medium | Windows Server 2019 must be configured to audit Policy Change - Audit Policy Change successes. |
| V-205772 | WN19-AU-000270 | medium | Windows Server 2019 must be configured to audit Policy Change - Audit Policy Change failures. |
| V-205773 | WN19-AU-000280 | medium | Windows Server 2019 must be configured to audit Policy Change - Authentication Policy Change successes. |
| V-205774 | WN19-AU-000290 | medium | Windows Server 2019 must be configured to audit Policy Change - Authorization Policy Change successes. |
| V-205775 | WN19-AU-000300 | medium | Windows Server 2019 must be configured to audit Privilege Use - Sensitive Privilege Use successes. |
| V-205776 | WN19-AU-000310 | medium | Windows Server 2019 must be configured to audit Privilege Use - Sensitive Privilege Use failures. |
| V-205777 | WN19-AU-000320 | medium | Windows Server 2019 must be configured to audit System - IPsec Driver successes. |
| V-205778 | WN19-AU-000330 | medium | Windows Server 2019 must be configured to audit System - IPsec Driver failures. |
| V-205779 | WN19-AU-000340 | medium | Windows Server 2019 must be configured to audit System - Other System Events successes. |
| V-205780 | WN19-AU-000350 | medium | Windows Server 2019 must be configured to audit System - Other System Events failures. |
| V-205781 | WN19-AU-000360 | medium | Windows Server 2019 must be configured to audit System - Security State Change successes. |
| V-205782 | WN19-AU-000370 | medium | Windows Server 2019 must be configured to audit System - Security System Extension successes. |
| V-205783 | WN19-AU-000380 | medium | Windows Server 2019 must be configured to audit System - System Integrity successes. |
| V-205784 | WN19-AU-000390 | medium | Windows Server 2019 must be configured to audit System - System Integrity failures. |
| V-205785 | WN19-DC-000170 | medium | Windows Server 2019 Active Directory Group Policy objects must be configured with proper audit settings. |
| V-205786 | WN19-DC-000180 | medium | Windows Server 2019 Active Directory Domain object must be configured with proper audit settings. |
| V-205787 | WN19-DC-000190 | medium | Windows Server 2019 Active Directory Infrastructure object must be configured with proper audit settings. |
| V-205788 | WN19-DC-000200 | medium | Windows Server 2019 Active Directory Domain Controllers Organizational Unit (OU) object must be configured with proper audit settings. |
| V-205789 | WN19-DC-000210 | medium | Windows Server 2019 Active Directory AdminSDHolder object must be configured with proper audit settings. |
| V-205790 | WN19-DC-000220 | medium | Windows Server 2019 Active Directory RID Manager$ object must be configured with proper audit settings. |
| V-205791 | WN19-DC-000240 | medium | Windows Server 2019 must be configured to audit DS Access - Directory Service Access successes. |
| V-205792 | WN19-DC-000250 | medium | Windows Server 2019 must be configured to audit DS Access - Directory Service Access failures. |
| V-205793 | WN19-DC-000260 | medium | Windows Server 2019 must be configured to audit DS Access - Directory Service Changes successes. |
| V-220712 | WN10-00-000070 | high | Only accounts responsible for the administration of a system must have Administrator rights on the system. |
| V-220750 | WN10-AU-000030 | medium | The system must be configured to audit Account Management - Security Group Management successes. |
| V-220751 | WN10-AU-000035 | medium | The system must be configured to audit Account Management - User Account Management failures. |
| V-220752 | WN10-AU-000040 | medium | The system must be configured to audit Account Management - User Account Management successes. |
| V-220768 | WN10-AU-000105 | medium | The system must be configured to audit Policy Change - Authentication Policy Change successes. |
| V-220770 | WN10-AU-000110 | medium | The system must be configured to audit Privilege Use - Sensitive Privilege Use failures. |
| V-220771 | WN10-AU-000115 | medium | The system must be configured to audit Privilege Use - Sensitive Privilege Use successes. |
| V-220775 | WN10-AU-000140 | medium | The system must be configured to audit System - Security State Change successes. |
| V-220776 | WN10-AU-000150 | medium | The system must be configured to audit System - Security System Extension successes. |
| V-220777 | WN10-AU-000155 | medium | The system must be configured to audit System - System Integrity failures. |
| V-220778 | WN10-AU-000160 | medium | The system must be configured to audit System - System Integrity successes. |
| V-220907 | WN10-RG-000005 | medium | Default permissions for the HKEY_LOCAL_MACHINE registry hive must be maintained. |
| V-220933 | WN10-SO-000167 | medium | Remote calls to the Security Account Manager (SAM) must be restricted to Administrators. |
| V-220956 | WN10-UR-000005 | medium | The Access Credential Manager as a trusted caller user right must not be assigned to any groups or accounts. |
| V-220958 | WN10-UR-000015 | high | The Act as part of the operating system user right must not be assigned to any groups or accounts. |
| V-220960 | WN10-UR-000030 | medium | The Back up files and directories user right must only be assigned to the Administrators group. |
| V-220961 | WN10-UR-000035 | medium | The Change the system time user right must only be assigned to Administrators and Local Service and NT SERVICE\autotimesvc. |
| V-220962 | WN10-UR-000040 | medium | The Create a pagefile user right must only be assigned to the Administrators group. |
| V-220963 | WN10-UR-000045 | high | The Create a token object user right must not be assigned to any groups or accounts. |
| V-220964 | WN10-UR-000050 | medium | The Create global objects user right must only be assigned to Administrators, Service, Local Service, and Network Service. |
| V-220965 | WN10-UR-000055 | medium | The Create permanent shared objects user right must not be assigned to any groups or accounts. |
| V-220966 | WN10-UR-000060 | medium | The Create symbolic links user right must only be assigned to the Administrators group. |
| V-220967 | WN10-UR-000065 | high | The Debug programs user right must only be assigned to the Administrators group. |
| V-220973 | WN10-UR-000095 | medium | The Enable computer and user accounts to be trusted for delegation user right must not be assigned to any groups or accounts. |
| V-220974 | WN10-UR-000100 | medium | The Force shutdown from a remote system user right must only be assigned to the Administrators group. |
| V-220975 | WN10-UR-000110 | medium | The Impersonate a client after authentication user right must only be assigned to Administrators, Service, Local Service, and Network Service. |
| V-220976 | WN10-UR-000120 | medium | The Load and unload device drivers user right must only be assigned to the Administrators group. |
| V-220977 | WN10-UR-000125 | medium | The Lock pages in memory user right must not be assigned to any groups or accounts. |
| V-220979 | WN10-UR-000140 | medium | The Modify firmware environment values user right must only be assigned to the Administrators group. |
| V-220980 | WN10-UR-000145 | medium | The Perform volume maintenance tasks user right must only be assigned to the Administrators group. |
| V-220981 | WN10-UR-000150 | medium | The Profile single process user right must only be assigned to the Administrators group. |
| V-220982 | WN10-UR-000160 | medium | The Restore files and directories user right must only be assigned to the Administrators group. |
| V-220983 | WN10-UR-000165 | medium | The Take ownership of files or other objects user right must only be assigned to the Administrators group. |
| V-230386 | RHEL-08-030000 | medium | The RHEL 8 audit system must be configured to audit the execution of privileged functions and prevent all software from executing at higher privilege levels than users executing the software. |
| V-237642 | RHEL-08-010383 | medium | RHEL 8 must use the invoking user's password for privilege escalation when using "sudo". |
| V-253328 | WN11-AU-000110 | medium | The system must be configured to audit Privilege Use - Sensitive Privilege Use failures. |
| V-253431 | WN11-RG-000005 | medium | Default permissions for the HKEY_LOCAL_MACHINE registry hive must be maintained. |
| V-253457 | WN11-SO-000167 | medium | Remote calls to the Security Account Manager (SAM) must be restricted to Administrators. |
| V-253479 | WN11-UR-000005 | medium | The "Access Credential Manager as a trusted caller" user right must not be assigned to any groups or accounts. |
| V-253481 | WN11-UR-000015 | high | The "Act as part of the operating system" user right must not be assigned to any groups or accounts. |
| V-253483 | WN11-UR-000030 | medium | The "Back up files and directories" user right must only be assigned to the Administrators group. |
| V-253484 | WN11-UR-000035 | medium | The "Change the system time" user right must only be assigned to Administrators and Local Service. |
| V-253485 | WN11-UR-000040 | medium | The "Create a pagefile" user right must only be assigned to the Administrators group. |
| V-253486 | WN11-UR-000045 | high | The "Create a token object" user right must not be assigned to any groups or accounts. |
| V-253487 | WN11-UR-000050 | medium | The "Create global objects" user right must only be assigned to Administrators, Service, Local Service, and Network Service. |
| V-253488 | WN11-UR-000055 | medium | The "Create permanent shared objects" user right must not be assigned to any groups or accounts. |
| V-253489 | WN11-UR-000060 | medium | The "Create symbolic links" user right must only be assigned to the Administrators group. |
| V-253490 | WN11-UR-000065 | high | The "Debug programs" user right must only be assigned to the Administrators group. |
| V-253496 | WN11-UR-000095 | medium | The "Enable computer and user accounts to be trusted for delegation" user right must not be assigned to any groups or accounts. |
| V-253497 | WN11-UR-000100 | medium | The "Force shutdown from a remote system" user right must only be assigned to the Administrators group. |
| V-253498 | WN11-UR-000110 | medium | The "Impersonate a client after authentication" user right must only be assigned to Administrators, Service, Local Service, and Network Service. |
| V-253499 | WN11-UR-000120 | medium | The "Load and unload device drivers" user right must only be assigned to the Administrators group. |
| V-253500 | WN11-UR-000125 | medium | The "Lock pages in memory" user right must not be assigned to any groups or accounts. |
| V-253502 | WN11-UR-000140 | medium | The "Modify firmware environment values" user right must only be assigned to the Administrators group. |
| V-253503 | WN11-UR-000145 | medium | The "Perform volume maintenance tasks" user right must only be assigned to the Administrators group. |
| V-253504 | WN11-UR-000150 | medium | The "Profile single process" user right must only be assigned to the Administrators group. |
| V-253505 | WN11-UR-000160 | medium | The "Restore files and directories" user right must only be assigned to the Administrators group. |
| V-253506 | WN11-UR-000165 | medium | The "Take ownership of files or other objects" user right must only be assigned to the Administrators group. |
| V-254254 | WN22-00-000170 | medium | Windows Server 2022 default permissions for the HKEY_LOCAL_MACHINE registry hive must be maintained. |
| V-254302 | WN22-AU-000090 | medium | Windows Server 2022 must be configured to audit Account Management - Other Account Management Events successes. |
| V-254307 | WN22-AU-000140 | medium | Windows Server 2022 must be configured to audit Detailed Tracking - Process Creation successes. |
| V-254319 | WN22-AU-000260 | medium | Windows Server 2022 must be configured to audit Policy Change - Audit Policy Change successes. |
| V-254320 | WN22-AU-000270 | medium | Windows Server 2022 must be configured to audit Policy Change - Audit Policy Change failures. |
| V-254321 | WN22-AU-000280 | medium | Windows Server 2022 must be configured to audit Policy Change - Authentication Policy Change successes. |
| V-254322 | WN22-AU-000290 | medium | Windows Server 2022 must be configured to audit Policy Change - Authorization Policy Change successes. |
| V-254323 | WN22-AU-000300 | medium | Windows Server 2022 must be configured to audit Privilege Use - Sensitive Privilege Use successes. |
| V-254324 | WN22-AU-000310 | medium | Windows Server 2022 must be configured to audit Privilege Use - Sensitive Privilege Use failures. |
| V-254325 | WN22-AU-000320 | medium | Windows Server 2022 must be configured to audit System - IPsec Driver successes. |
| V-254326 | WN22-AU-000330 | medium | Windows Server 2022 must be configured to audit System - IPsec Driver failures. |
| V-254327 | WN22-AU-000340 | medium | Windows Server 2022 must be configured to audit System - Other System Events successes. |
| V-254328 | WN22-AU-000350 | medium | Windows Server 2022 must be configured to audit System - Other System Events failures. |
| V-254329 | WN22-AU-000360 | medium | Windows Server 2022 must be configured to audit System - Security State Change successes. |
| V-254330 | WN22-AU-000370 | medium | Windows Server 2022 must be configured to audit System - Security System Extension successes. |
| V-254331 | WN22-AU-000380 | medium | Windows Server 2022 must be configured to audit System - System Integrity successes. |
| V-254332 | WN22-AU-000390 | medium | Windows Server 2022 must be configured to audit System - System Integrity failures. |
| V-254385 | WN22-DC-000010 | high | Windows Server 2022 must only allow administrators responsible for the domain controller to have Administrator rights on the system. |
| V-254391 | WN22-DC-000070 | high | Windows Server 2022 permissions on the Active Directory data files must only allow System and Administrators access. |
| V-254392 | WN22-DC-000080 | high | Windows Server 2022 Active Directory SYSVOL directory must have the proper access control permissions. |
| V-254393 | WN22-DC-000090 | high | Windows Server 2022 Active Directory Group Policy objects must have proper access control permissions. |
| V-254394 | WN22-DC-000100 | high | Windows Server 2022 Active Directory Domain Controllers Organizational Unit (OU) object must have the proper access control permissions. |
| V-254395 | WN22-DC-000110 | high | Windows Server 2022 organization created Active Directory Organizational Unit (OU) objects must have proper access control permissions. |
| V-254401 | WN22-DC-000170 | medium | Windows Server 2022 Active Directory Group Policy objects must be configured with proper audit settings. |
| V-254402 | WN22-DC-000180 | medium | Windows Server 2022 Active Directory Domain object must be configured with proper audit settings. |
| V-254403 | WN22-DC-000190 | medium | Windows Server 2022 Active Directory Infrastructure object must be configured with proper audit settings. |
| V-254404 | WN22-DC-000200 | medium | Windows Server 2022 Active Directory Domain Controllers Organizational Unit (OU) object must be configured with proper audit settings. |
| V-254405 | WN22-DC-000210 | medium | Windows Server 2022 Active Directory AdminSDHolder object must be configured with proper audit settings. |
| V-254406 | WN22-DC-000220 | medium | Windows Server 2022 Active Directory RID Manager$ object must be configured with proper audit settings. |
| V-254408 | WN22-DC-000240 | medium | Windows Server 2022 must be configured to audit DS Access - Directory Service Access successes. |
| V-254409 | WN22-DC-000250 | medium | Windows Server 2022 must be configured to audit DS Access - Directory Service Access failures. |
| V-254410 | WN22-DC-000260 | medium | Windows Server 2022 must be configured to audit DS Access - Directory Service Changes successes. |
| V-254419 | WN22-DC-000350 | medium | Windows Server 2022 Add workstations to domain user right must only be assigned to the Administrators group on domain controllers. |
| V-254426 | WN22-DC-000420 | medium | Windows Server 2022 Enable computer and user accounts to be trusted for delegation user right must only be assigned to the Administrators group on domain controllers. |
| V-254428 | WN22-MS-000010 | high | Windows Server 2022 must only allow administrators responsible for the member server or standalone or nondomain-joined system to have Administrator rights on the system. |
| V-254433 | WN22-MS-000060 | medium | Windows Server 2022 must restrict remote calls to the Security Account Manager (SAM) to Administrators on domain-joined member servers and standalone or nondomain-joined systems. |
| V-254440 | WN22-MS-000130 | medium | Windows Server 2022 Enable computer and user accounts to be trusted for delegation user right must not be assigned to any groups or accounts on domain-joined member servers and standalone or nondomain-joined systems. |
| V-254491 | WN22-UR-000010 | medium | Windows Server 2022 Access Credential Manager as a trusted caller user right must not be assigned to any groups or accounts. |
| V-254492 | WN22-UR-000020 | high | Windows Server 2022 Act as part of the operating system user right must not be assigned to any groups or accounts. |
| V-254494 | WN22-UR-000040 | medium | Windows Server 2022 back up files and directories user right must only be assigned to the Administrators group. |
| V-254495 | WN22-UR-000050 | medium | Windows Server 2022 create a pagefile user right must only be assigned to the Administrators group. |
| V-254496 | WN22-UR-000060 | high | Windows Server 2022 create a token object user right must not be assigned to any groups or accounts. |
| V-254497 | WN22-UR-000070 | medium | Windows Server 2022 create global objects user right must only be assigned to Administrators, Service, Local Service, and Network Service. |
| V-254498 | WN22-UR-000080 | medium | Windows Server 2022 create permanent shared objects user right must not be assigned to any groups or accounts. |
| V-254499 | WN22-UR-000090 | medium | Windows Server 2022 create symbolic links user right must only be assigned to the Administrators group. |
| V-254500 | WN22-UR-000100 | high | Windows Server 2022 debug programs user right must only be assigned to the Administrators group. |
| V-254501 | WN22-UR-000110 | medium | Windows Server 2022 force shutdown from a remote system user right must only be assigned to the Administrators group. |
| V-254502 | WN22-UR-000120 | medium | Windows Server 2022 generate security audits user right must only be assigned to Local Service and Network Service. |
| V-254503 | WN22-UR-000130 | medium | Windows Server 2022 impersonate a client after authentication user right must only be assigned to Administrators, Service, Local Service, and Network Service. |
| V-254504 | WN22-UR-000140 | medium | Windows Server 2022 increase scheduling priority: user right must only be assigned to the Administrators group. |
| V-254505 | WN22-UR-000150 | medium | Windows Server 2022 load and unload device drivers user right must only be assigned to the Administrators group. |
| V-254506 | WN22-UR-000160 | medium | Windows Server 2022 lock pages in memory user right must not be assigned to any groups or accounts. |
| V-254508 | WN22-UR-000180 | medium | Windows Server 2022 modify firmware environment values user right must only be assigned to the Administrators group. |
| V-254509 | WN22-UR-000190 | medium | Windows Server 2022 perform volume maintenance tasks user right must only be assigned to the Administrators group. |
| V-254510 | WN22-UR-000200 | medium | Windows Server 2022 profile single process user right must only be assigned to the Administrators group. |
| V-254511 | WN22-UR-000210 | medium | Windows Server 2022 restore files and directories user right must only be assigned to the Administrators group. |
| V-254512 | WN22-UR-000220 | medium | Windows Server 2022 take ownership of files or other objects user right must only be assigned to the Administrators group. |
| V-254520 | RHEL-08-040400 | medium | RHEL 8 must prevent nonprivileged users from executing privileged functions, including disabling, circumventing, or altering implemented security safeguards/countermeasures. |
| V-257589 | WN10-AU-000585 | medium | Windows 10 must have command line process auditing events enabled for failures. |
| V-257770 | WN11-AU-000585 | medium | Windows 11 must have command line process auditing events enabled for failures. |
| V-257784 | RHEL-09-211045 | high | The systemd Ctrl-Alt-Delete burst key sequence in RHEL 9 must be disabled. |
| V-257785 | RHEL-09-211050 | high | The x86 Ctrl-Alt-Delete key sequence must be disabled on RHEL 9. |
| V-257786 | RHEL-09-211055 | medium | RHEL 9 debug-shell systemd service must be disabled. |
| V-257801 | RHEL-09-213030 | medium | RHEL 9 must enable kernel parameters to enforce discretionary access control on hardlinks. |
| V-257802 | RHEL-09-213035 | medium | RHEL 9 must enable kernel parameters to enforce discretionary access control on symlinks. |
| V-258083 | RHEL-09-432010 | medium | RHEL 9 must have the sudo package installed. |
| V-258176 | RHEL-09-654010 | medium | RHEL 9 must audit uses of the "execve" system call. |
| V-272484 | RHEL-08-010455 | medium | RHEL 8 must elevate the SELinux context when an administrator calls the sudo command. |
| V-272496 | RHEL-09-431016 | medium | RHEL 9 must elevate the SELinux context when an administrator calls the sudo command. |
Get this as data
The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/AC-6. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.