AU-12 Audit Record Generation
Audit and Accountability family. 18 Control Correlation Identifiers map to this control, and 270 STIG rules implement those CCIs.
The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.
It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.
Where these rules come from
| STIG benchmark | Version | Rules mapped to AU-12 |
|---|---|---|
| Red Hat Enterprise Linux 9 | V2 | 58 |
| Red Hat Enterprise Linux 8 | V2 | 49 |
| Microsoft Windows Server 2019 | V3 | 44 |
| Microsoft Windows Server 2022 | V2 | 44 |
| Microsoft Windows 10 | V3 | 33 |
| Microsoft Windows 11 | V2 | 31 |
| Google Chrome Current Windows | V2 | 10 |
| Kubernetes | V2 | 1 |
Control Correlation Identifiers mapped to AU-12
| CCI | Definition | Rev |
|---|---|---|
| CCI-000169 | Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2 a on organization-defined information system components. | 5, 4 |
| CCI-000171 | Allow organization-defined personnel or roles to select the event types that are to be logged by specific components of the system. | 5, 4 |
| CCI-000172 | Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3. | 5, 4 |
| CCI-000173 | Defines the level of tolerance for relationship between time stamps of individual records in the audit trail that will be used for correlation. | 5, 4 |
| CCI-000174 | Compile audit records from organization-defined information system components into a system-wide (logical or physical) audit trail that is time-correlated to within an organization-defined level of tolerance for relationship between time stamps of individual records in the audit trail. | 5, 4 |
| CCI-001353 | Produce a system-wide (logical or physical) audit trail composed of audit records in a standardized format. | 5, 4 |
| CCI-001459 | Defines system components that provide audit record generation capability. | 5, 4 |
| CCI-001576 | The information system produces a system-wide (logical or physical) audit trail of information system audit records. | 4 |
| CCI-001577 | Defines the system components from which audit records are to be compiled into the system-wide audit trail. | 5, 4 |
| CCI-001910 | Defines the personnel or roles allowed to select which event types are to be logged by specific components of the system. | 5, 4 |
| CCI-001911 | Defines the selectable event criteria to be used as the basis for changes to the auditing to be performed on organization-defined system components, by organization-defined individuals or roles, within organization-defined time thresholds. | 5, 4 |
| CCI-001912 | Defines the time thresholds for organization-defined individuals or roles to change the auditing to be performed based on organization-defined selectable event criteria. | 5, 4 |
| CCI-001913 | Defines the individuals or roles that are to be provided the capability to change the auditing to be performed based on organization-defined selectable event criteria, within organization-defined time thresholds. | 5, 4 |
| CCI-001914 | Provide the capability for organization-defined individuals or roles to change the logging to be performed on organization-defined system components based on organization-defined selectable event criteria within organization-defined time thresholds. | 5, 4 |
| CCI-002047 | Defines the system components on which the auditing that is to be performed can be changed by organization-defined individuals or roles. | 5, 4 |
| CCI-003834 | Implement the capability for organization-defined individuals or roles to change the auditing to be performed on organization-defined system components based on organization-defined selectable event criteria within organization-defined time thresholds. | 5 |
| CCI-003835 | Provide the capability for auditing the parameters of user query events for data sets containing personally identifiable information. | 5 |
| CCI-003836 | Implement the capability for auditing the parameters of user query events for data sets containing personally identifiable information. | 5 |
STIG rules that implement AU-12
| Rule | STIG ID | Severity | Requirement |
|---|---|---|---|
| V-205625 | WN19-AU-000100 | medium | Windows Server 2019 must be configured to audit Account Management - Security Group Management successes. |
| V-205626 | WN19-AU-000110 | medium | Windows Server 2019 must be configured to audit Account Management - User Account Management successes. |
| V-205627 | WN19-AU-000120 | medium | Windows Server 2019 must be configured to audit Account Management - User Account Management failures. |
| V-205628 | WN19-DC-000230 | medium | Windows Server 2019 must be configured to audit Account Management - Computer Account Management successes. |
| V-205634 | WN19-AU-000190 | medium | Windows Server 2019 must be configured to audit logon successes. |
| V-205635 | WN19-AU-000200 | medium | Windows Server 2019 must be configured to audit logon failures. |
| V-205643 | WN19-UR-000170 | medium | Windows Server 2019 Manage auditing and security log user right must only be assigned to the Administrators group. |
| V-205644 | WN19-SO-000050 | medium | Windows Server 2019 must force audit policy subcategory settings to override audit policy category settings. |
| V-205730 | WN19-AU-000160 | medium | Windows Server 2019 must be configured to audit Logon/Logoff - Account Lockout failures. |
| V-205769 | WN19-AU-000090 | medium | Windows Server 2019 must be configured to audit Account Management - Other Account Management Events successes. |
| V-205770 | WN19-AU-000140 | medium | Windows Server 2019 must be configured to audit Detailed Tracking - Process Creation successes. |
| V-205771 | WN19-AU-000260 | medium | Windows Server 2019 must be configured to audit Policy Change - Audit Policy Change successes. |
| V-205772 | WN19-AU-000270 | medium | Windows Server 2019 must be configured to audit Policy Change - Audit Policy Change failures. |
| V-205773 | WN19-AU-000280 | medium | Windows Server 2019 must be configured to audit Policy Change - Authentication Policy Change successes. |
| V-205774 | WN19-AU-000290 | medium | Windows Server 2019 must be configured to audit Policy Change - Authorization Policy Change successes. |
| V-205775 | WN19-AU-000300 | medium | Windows Server 2019 must be configured to audit Privilege Use - Sensitive Privilege Use successes. |
| V-205776 | WN19-AU-000310 | medium | Windows Server 2019 must be configured to audit Privilege Use - Sensitive Privilege Use failures. |
| V-205777 | WN19-AU-000320 | medium | Windows Server 2019 must be configured to audit System - IPsec Driver successes. |
| V-205778 | WN19-AU-000330 | medium | Windows Server 2019 must be configured to audit System - IPsec Driver failures. |
| V-205779 | WN19-AU-000340 | medium | Windows Server 2019 must be configured to audit System - Other System Events successes. |
| V-205780 | WN19-AU-000350 | medium | Windows Server 2019 must be configured to audit System - Other System Events failures. |
| V-205781 | WN19-AU-000360 | medium | Windows Server 2019 must be configured to audit System - Security State Change successes. |
| V-205782 | WN19-AU-000370 | medium | Windows Server 2019 must be configured to audit System - Security System Extension successes. |
| V-205783 | WN19-AU-000380 | medium | Windows Server 2019 must be configured to audit System - System Integrity successes. |
| V-205784 | WN19-AU-000390 | medium | Windows Server 2019 must be configured to audit System - System Integrity failures. |
| V-205785 | WN19-DC-000170 | medium | Windows Server 2019 Active Directory Group Policy objects must be configured with proper audit settings. |
| V-205786 | WN19-DC-000180 | medium | Windows Server 2019 Active Directory Domain object must be configured with proper audit settings. |
| V-205787 | WN19-DC-000190 | medium | Windows Server 2019 Active Directory Infrastructure object must be configured with proper audit settings. |
| V-205788 | WN19-DC-000200 | medium | Windows Server 2019 Active Directory Domain Controllers Organizational Unit (OU) object must be configured with proper audit settings. |
| V-205789 | WN19-DC-000210 | medium | Windows Server 2019 Active Directory AdminSDHolder object must be configured with proper audit settings. |
| V-205790 | WN19-DC-000220 | medium | Windows Server 2019 Active Directory RID Manager$ object must be configured with proper audit settings. |
| V-205791 | WN19-DC-000240 | medium | Windows Server 2019 must be configured to audit DS Access - Directory Service Access successes. |
| V-205792 | WN19-DC-000250 | medium | Windows Server 2019 must be configured to audit DS Access - Directory Service Access failures. |
| V-205793 | WN19-DC-000260 | medium | Windows Server 2019 must be configured to audit DS Access - Directory Service Changes successes. |
| V-205832 | WN19-AU-000070 | medium | Windows Server 2019 must be configured to audit Account Logon - Credential Validation successes. |
| V-205833 | WN19-AU-000080 | medium | Windows Server 2019 must be configured to audit Account Logon - Credential Validation failures. |
| V-205834 | WN19-AU-000170 | medium | Windows Server 2019 must be configured to audit Logon/Logoff - Group Membership successes. |
| V-205835 | WN19-AU-000210 | medium | Windows Server 2019 must be configured to audit Logon/Logoff - Special Logon successes. |
| V-205836 | WN19-AU-000220 | medium | Windows Server 2019 must be configured to audit Object Access - Other Object Access Events successes. |
| V-205837 | WN19-AU-000230 | medium | Windows Server 2019 must be configured to audit Object Access - Other Object Access Events failures. |
| V-205838 | WN19-AU-000180 | medium | Windows Server 2019 must be configured to audit logoff successes. |
| V-205839 | WN19-AU-000130 | medium | Windows Server 2019 must be configured to audit Detailed Tracking - Plug and Play Events successes. |
| V-205840 | WN19-AU-000240 | medium | Windows Server 2019 must be configured to audit Object Access - Removable Storage successes. |
| V-205841 | WN19-AU-000250 | medium | Windows Server 2019 must be configured to audit Object Access - Removable Storage failures. |
| V-220748 | WN10-AU-000005 | medium | The system must be configured to audit Account Logon - Credential Validation failures. |
| V-220749 | WN10-AU-000010 | medium | The system must be configured to audit Account Logon - Credential Validation successes. |
| V-220750 | WN10-AU-000030 | medium | The system must be configured to audit Account Management - Security Group Management successes. |
| V-220751 | WN10-AU-000035 | medium | The system must be configured to audit Account Management - User Account Management failures. |
| V-220752 | WN10-AU-000040 | medium | The system must be configured to audit Account Management - User Account Management successes. |
| V-220753 | WN10-AU-000045 | medium | The system must be configured to audit Detailed Tracking - PNP Activity successes. |
| V-220754 | WN10-AU-000050 | medium | The system must be configured to audit Detailed Tracking - Process Creation successes. |
| V-220755 | WN10-AU-000054 | medium | The system must be configured to audit Logon/Logoff - Account Lockout failures. |
| V-220756 | WN10-AU-000060 | medium | The system must be configured to audit Logon/Logoff - Group Membership successes. |
| V-220757 | WN10-AU-000065 | medium | The system must be configured to audit Logon/Logoff - Logoff successes. |
| V-220758 | WN10-AU-000070 | medium | The system must be configured to audit Logon/Logoff - Logon failures. |
| V-220759 | WN10-AU-000075 | medium | The system must be configured to audit Logon/Logoff - Logon successes. |
| V-220760 | WN10-AU-000080 | medium | The system must be configured to audit Logon/Logoff - Special Logon successes. |
| V-220761 | WN10-AU-000081 | medium | Windows 10 must be configured to audit Object Access - File Share failures. |
| V-220762 | WN10-AU-000082 | medium | Windows 10 must be configured to audit Object Access - File Share successes. |
| V-220763 | WN10-AU-000083 | medium | Windows 10 must be configured to audit Object Access - Other Object Access Events successes. |
| V-220764 | WN10-AU-000084 | medium | Windows 10 must be configured to audit Object Access - Other Object Access Events failures. |
| V-220765 | WN10-AU-000085 | medium | The system must be configured to audit Object Access - Removable Storage failures. |
| V-220766 | WN10-AU-000090 | medium | The system must be configured to audit Object Access - Removable Storage successes. |
| V-220767 | WN10-AU-000100 | medium | The system must be configured to audit Policy Change - Audit Policy Change successes. |
| V-220768 | WN10-AU-000105 | medium | The system must be configured to audit Policy Change - Authentication Policy Change successes. |
| V-220769 | WN10-AU-000107 | medium | The system must be configured to audit Policy Change - Authorization Policy Change successes. |
| V-220770 | WN10-AU-000110 | medium | The system must be configured to audit Privilege Use - Sensitive Privilege Use failures. |
| V-220771 | WN10-AU-000115 | medium | The system must be configured to audit Privilege Use - Sensitive Privilege Use successes. |
| V-220772 | WN10-AU-000120 | medium | The system must be configured to audit System - IPSec Driver failures. |
| V-220773 | WN10-AU-000130 | medium | The system must be configured to audit System - Other System Events successes. |
| V-220774 | WN10-AU-000135 | medium | The system must be configured to audit System - Other System Events failures. |
| V-220775 | WN10-AU-000140 | medium | The system must be configured to audit System - Security State Change successes. |
| V-220776 | WN10-AU-000150 | medium | The system must be configured to audit System - Security System Extension successes. |
| V-220777 | WN10-AU-000155 | medium | The system must be configured to audit System - System Integrity failures. |
| V-220778 | WN10-AU-000160 | medium | The system must be configured to audit System - System Integrity successes. |
| V-220913 | WN10-SO-000030 | medium | Audit policy using subcategories must be enabled. |
| V-220978 | WN10-UR-000130 | medium | The Manage auditing and security log user right must only be assigned to the Administrators group. |
| V-221562 | DTBC-0005 | medium | Extensions installation must be blocklisted by default. |
| V-221586 | DTBC-0052 | medium | Deletion of browser history must be disabled. |
| V-221587 | DTBC-0053 | medium | Prompt for download location must be enabled. |
| V-221588 | DTBC-0055 | medium | Download restrictions must be configured. |
| V-230404 | RHEL-08-030130 | medium | RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow. |
| V-230405 | RHEL-08-030140 | medium | RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd. |
| V-230406 | RHEL-08-030150 | medium | RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd. |
| V-230407 | RHEL-08-030160 | medium | RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow. |
| V-230408 | RHEL-08-030170 | medium | RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group. |
| V-230409 | RHEL-08-030171 | medium | RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers. |
| V-230410 | RHEL-08-030172 | medium | RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/. |
| V-230411 | RHEL-08-030180 | medium | The RHEL 8 audit package must be installed. |
| V-230412 | RHEL-08-030190 | medium | Successful/unsuccessful uses of the su command in RHEL 8 must generate an audit record. |
| V-230413 | RHEL-08-030200 | medium | The RHEL 8 audit system must be configured to audit any usage of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls. |
| V-230418 | RHEL-08-030250 | medium | Successful/unsuccessful uses of the chage command in RHEL 8 must generate an audit record. |
| V-230419 | RHEL-08-030260 | medium | Successful/unsuccessful uses of the chcon command in RHEL 8 must generate an audit record. |
| V-230421 | RHEL-08-030280 | medium | Successful/unsuccessful uses of the ssh-agent in RHEL 8 must generate an audit record. |
| V-230422 | RHEL-08-030290 | medium | Successful/unsuccessful uses of the passwd command in RHEL 8 must generate an audit record. |
| V-230423 | RHEL-08-030300 | medium | Successful/unsuccessful uses of the mount command in RHEL 8 must generate an audit record. |
| V-230424 | RHEL-08-030301 | medium | Successful/unsuccessful uses of the umount command in RHEL 8 must generate an audit record. |
| V-230425 | RHEL-08-030302 | medium | Successful/unsuccessful uses of the mount syscall in RHEL 8 must generate an audit record. |
| V-230426 | RHEL-08-030310 | medium | Successful/unsuccessful uses of the unix_update in RHEL 8 must generate an audit record. |
| V-230427 | RHEL-08-030311 | medium | Successful/unsuccessful uses of postdrop in RHEL 8 must generate an audit record. |
| V-230428 | RHEL-08-030312 | medium | Successful/unsuccessful uses of postqueue in RHEL 8 must generate an audit record. |
| V-230429 | RHEL-08-030313 | medium | Successful/unsuccessful uses of semanage in RHEL 8 must generate an audit record. |
| V-230430 | RHEL-08-030314 | medium | Successful/unsuccessful uses of setfiles in RHEL 8 must generate an audit record. |
| V-230431 | RHEL-08-030315 | medium | Successful/unsuccessful uses of userhelper in RHEL 8 must generate an audit record. |
| V-230432 | RHEL-08-030316 | medium | Successful/unsuccessful uses of setsebool in RHEL 8 must generate an audit record. |
| V-230433 | RHEL-08-030317 | medium | Successful/unsuccessful uses of unix_chkpwd in RHEL 8 must generate an audit record. |
| V-230434 | RHEL-08-030320 | medium | Successful/unsuccessful uses of the ssh-keysign in RHEL 8 must generate an audit record. |
| V-230435 | RHEL-08-030330 | medium | Successful/unsuccessful uses of the setfacl command in RHEL 8 must generate an audit record. |
| V-230436 | RHEL-08-030340 | medium | Successful/unsuccessful uses of the pam_timestamp_check command in RHEL 8 must generate an audit record. |
| V-230437 | RHEL-08-030350 | medium | Successful/unsuccessful uses of the newgrp command in RHEL 8 must generate an audit record. |
| V-230438 | RHEL-08-030360 | medium | Successful/unsuccessful uses of the init_module and finit_module system calls in RHEL 8 must generate an audit record. |
| V-230439 | RHEL-08-030361 | medium | Successful/unsuccessful uses of the rename, unlink, rmdir, renameat, and unlinkat system calls in RHEL 8 must generate an audit record. |
| V-230444 | RHEL-08-030370 | medium | Successful/unsuccessful uses of the gpasswd command in RHEL 8 must generate an audit record. |
| V-230446 | RHEL-08-030390 | medium | Successful/unsuccessful uses of the delete_module command in RHEL 8 must generate an audit record. |
| V-230447 | RHEL-08-030400 | medium | Successful/unsuccessful uses of the crontab command in RHEL 8 must generate an audit record. |
| V-230448 | RHEL-08-030410 | medium | Successful/unsuccessful uses of the chsh command in RHEL 8 must generate an audit record. |
| V-230449 | RHEL-08-030420 | medium | Successful/unsuccessful uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls in RHEL 8 must generate an audit record. |
| V-230455 | RHEL-08-030480 | medium | Successful/unsuccessful uses of the chown, fchown, fchownat, and lchown system calls in RHEL 8 must generate an audit record. |
| V-230456 | RHEL-08-030490 | medium | Successful/unsuccessful uses of the chmod, fchmod, and fchmodat system calls in RHEL 8 must generate an audit record. |
| V-230462 | RHEL-08-030550 | medium | Successful/unsuccessful uses of the sudo command in RHEL 8 must generate an audit record. |
| V-230463 | RHEL-08-030560 | medium | Successful/unsuccessful uses of the usermod command in RHEL 8 must generate an audit record. |
| V-230464 | RHEL-08-030570 | medium | Successful/unsuccessful uses of the chacl command in RHEL 8 must generate an audit record. |
| V-230465 | RHEL-08-030580 | medium | Successful/unsuccessful uses of the kmod command in RHEL 8 must generate an audit record. |
| V-230466 | RHEL-08-030590 | medium | Successful/unsuccessful modifications to the faillock log file in RHEL 8 must generate an audit record. |
| V-230467 | RHEL-08-030600 | medium | Successful/unsuccessful modifications to the lastlog file in RHEL 8 must generate an audit record. |
| V-230468 | RHEL-08-030601 | low | RHEL 8 must enable auditing of processes that start prior to the audit daemon. |
| V-230470 | RHEL-08-030603 | low | RHEL 8 must enable Linux audit logging for the USBGuard daemon. |
| V-230471 | RHEL-08-030610 | medium | RHEL 8 must allow only the Information System Security Manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited. |
| V-242403 | CNTR-K8-000700 | medium | Kubernetes API Server must generate audit records that identify what type of event has occurred, identify the source of the event, contain the event results, identify any users, and identify any containers associated with the event. |
| V-244542 | RHEL-08-030181 | medium | RHEL 8 audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events. |
| V-253268 | WN11-00-000065 | low | Unused accounts must be disabled or removed from the system after 35 days of inactivity. |
| V-253306 | WN11-AU-000005 | medium | The system must be configured to audit Account Logon - Credential Validation failures. |
| V-253307 | WN11-AU-000010 | medium | The system must be configured to audit Account Logon - Credential Validation successes. |
| V-253308 | WN11-AU-000030 | medium | The system must be configured to audit Account Management - Security Group Management successes. |
| V-253311 | WN11-AU-000045 | medium | The system must be configured to audit Detailed Tracking - PNP Activity successes. |
| V-253312 | WN11-AU-000050 | medium | The system must be configured to audit Detailed Tracking - Process Creation successes. |
| V-253313 | WN11-AU-000054 | medium | The system must be configured to audit Logon/Logoff - Account Lockout failures. |
| V-253314 | WN11-AU-000060 | medium | The system must be configured to audit Logon/Logoff - Group Membership successes. |
| V-253316 | WN11-AU-000070 | medium | The system must be configured to audit Logon/Logoff - Logon failures. |
| V-253317 | WN11-AU-000075 | medium | The system must be configured to audit Logon/Logoff - Logon successes. |
| V-253318 | WN11-AU-000080 | medium | The system must be configured to audit Logon/Logoff - Special Logon successes. |
| V-253319 | WN11-AU-000081 | medium | Windows 11 must be configured to audit Object Access - File Share failures. |
| V-253320 | WN11-AU-000082 | medium | Windows 11 must be configured to audit Object Access - File Share successes. |
| V-253321 | WN11-AU-000083 | medium | Windows 11 must be configured to audit Object Access - Other Object Access Events successes. |
| V-253322 | WN11-AU-000084 | medium | Windows 11 must be configured to audit Object Access - Other Object Access Events failures. |
| V-253323 | WN11-AU-000085 | medium | The system must be configured to audit Object Access - Removable Storage failures. |
| V-253324 | WN11-AU-000090 | medium | The system must be configured to audit Object Access - Removable Storage successes. |
| V-253325 | WN11-AU-000100 | medium | The system must be configured to audit Policy Change - Audit Policy Change successes. |
| V-253326 | WN11-AU-000105 | medium | The system must be configured to audit Policy Change - Authentication Policy Change successes. |
| V-253327 | WN11-AU-000107 | medium | The system must be configured to audit Policy Change - Authorization Policy Change successes. |
| V-253329 | WN11-AU-000115 | medium | The system must be configured to audit Privilege Use - Sensitive Privilege Use successes. |
| V-253330 | WN11-AU-000120 | medium | The system must be configured to audit System - IPsec Driver failures. |
| V-253331 | WN11-AU-000130 | medium | The system must be configured to audit System - Other System Events successes. |
| V-253332 | WN11-AU-000135 | medium | The system must be configured to audit System - Other System Events failures. |
| V-253333 | WN11-AU-000140 | medium | The system must be configured to audit System - Security State Change successes. |
| V-253334 | WN11-AU-000150 | medium | The system must be configured to audit System - Security System Extension successes. |
| V-253335 | WN11-AU-000155 | medium | The system must be configured to audit System - System Integrity failures. |
| V-253336 | WN11-AU-000160 | medium | The system must be configured to audit System - System Integrity successes. |
| V-253426 | WN11-EP-000310 | medium | Windows 11 Kernel (Direct Memory Access) DMA Protection must be enabled. |
| V-253437 | WN11-SO-000030 | medium | Audit policy using subcategories must be enabled. |
| V-253501 | WN11-UR-000130 | medium | The "Manage auditing and security log" user right must only be assigned to the Administrators group. |
| V-254300 | WN22-AU-000070 | medium | Windows Server 2022 must be configured to audit Account Logon - Credential Validation successes. |
| V-254301 | WN22-AU-000080 | medium | Windows Server 2022 must be configured to audit Account Logon - Credential Validation failures. |
| V-254302 | WN22-AU-000090 | medium | Windows Server 2022 must be configured to audit Account Management - Other Account Management Events successes. |
| V-254303 | WN22-AU-000100 | medium | Windows Server 2022 must be configured to audit Account Management - Security Group Management successes. |
| V-254304 | WN22-AU-000110 | medium | Windows Server 2022 must be configured to audit Account Management - User Account Management successes. |
| V-254305 | WN22-AU-000120 | medium | Windows Server 2022 must be configured to audit Account Management - User Account Management failures. |
| V-254306 | WN22-AU-000130 | medium | Windows Server 2022 must be configured to audit Detailed Tracking - Plug and Play Events successes. |
| V-254307 | WN22-AU-000140 | medium | Windows Server 2022 must be configured to audit Detailed Tracking - Process Creation successes. |
| V-254309 | WN22-AU-000160 | medium | Windows Server 2022 must be configured to audit Logon/Logoff - Account Lockout failures. |
| V-254310 | WN22-AU-000170 | medium | Windows Server 2022 must be configured to audit Logon/Logoff - Group Membership successes. |
| V-254311 | WN22-AU-000180 | medium | Windows Server 2022 must be configured to audit logoff successes. |
| V-254312 | WN22-AU-000190 | medium | Windows Server 2022 must be configured to audit logon successes. |
| V-254313 | WN22-AU-000200 | medium | Windows Server 2022 must be configured to audit logon failures. |
| V-254314 | WN22-AU-000210 | medium | Windows Server 2022 must be configured to audit Logon/Logoff - Special Logon successes. |
| V-254315 | WN22-AU-000220 | medium | Windows Server 2022 must be configured to audit Object Access - Other Object Access Events successes. |
| V-254316 | WN22-AU-000230 | medium | Windows Server 2022 must be configured to audit Object Access - Other Object Access Events failures. |
| V-254317 | WN22-AU-000240 | medium | Windows Server 2022 must be configured to audit Object Access - Removable Storage successes. |
| V-254318 | WN22-AU-000250 | medium | Windows Server 2022 must be configured to audit Object Access - Removable Storage failures. |
| V-254319 | WN22-AU-000260 | medium | Windows Server 2022 must be configured to audit Policy Change - Audit Policy Change successes. |
| V-254320 | WN22-AU-000270 | medium | Windows Server 2022 must be configured to audit Policy Change - Audit Policy Change failures. |
| V-254321 | WN22-AU-000280 | medium | Windows Server 2022 must be configured to audit Policy Change - Authentication Policy Change successes. |
| V-254322 | WN22-AU-000290 | medium | Windows Server 2022 must be configured to audit Policy Change - Authorization Policy Change successes. |
| V-254323 | WN22-AU-000300 | medium | Windows Server 2022 must be configured to audit Privilege Use - Sensitive Privilege Use successes. |
| V-254324 | WN22-AU-000310 | medium | Windows Server 2022 must be configured to audit Privilege Use - Sensitive Privilege Use failures. |
| V-254325 | WN22-AU-000320 | medium | Windows Server 2022 must be configured to audit System - IPsec Driver successes. |
| V-254326 | WN22-AU-000330 | medium | Windows Server 2022 must be configured to audit System - IPsec Driver failures. |
| V-254327 | WN22-AU-000340 | medium | Windows Server 2022 must be configured to audit System - Other System Events successes. |
| V-254328 | WN22-AU-000350 | medium | Windows Server 2022 must be configured to audit System - Other System Events failures. |
| V-254329 | WN22-AU-000360 | medium | Windows Server 2022 must be configured to audit System - Security State Change successes. |
| V-254330 | WN22-AU-000370 | medium | Windows Server 2022 must be configured to audit System - Security System Extension successes. |
| V-254331 | WN22-AU-000380 | medium | Windows Server 2022 must be configured to audit System - System Integrity successes. |
| V-254332 | WN22-AU-000390 | medium | Windows Server 2022 must be configured to audit System - System Integrity failures. |
| V-254401 | WN22-DC-000170 | medium | Windows Server 2022 Active Directory Group Policy objects must be configured with proper audit settings. |
| V-254402 | WN22-DC-000180 | medium | Windows Server 2022 Active Directory Domain object must be configured with proper audit settings. |
| V-254403 | WN22-DC-000190 | medium | Windows Server 2022 Active Directory Infrastructure object must be configured with proper audit settings. |
| V-254404 | WN22-DC-000200 | medium | Windows Server 2022 Active Directory Domain Controllers Organizational Unit (OU) object must be configured with proper audit settings. |
| V-254405 | WN22-DC-000210 | medium | Windows Server 2022 Active Directory AdminSDHolder object must be configured with proper audit settings. |
| V-254406 | WN22-DC-000220 | medium | Windows Server 2022 Active Directory RID Manager$ object must be configured with proper audit settings. |
| V-254407 | WN22-DC-000230 | medium | Windows Server 2022 must be configured to audit Account Management - Computer Account Management successes. |
| V-254408 | WN22-DC-000240 | medium | Windows Server 2022 must be configured to audit DS Access - Directory Service Access successes. |
| V-254409 | WN22-DC-000250 | medium | Windows Server 2022 must be configured to audit DS Access - Directory Service Access failures. |
| V-254410 | WN22-DC-000260 | medium | Windows Server 2022 must be configured to audit DS Access - Directory Service Changes successes. |
| V-254449 | WN22-SO-000050 | medium | Windows Server 2022 must force audit policy subcategory settings to override audit policy category settings. |
| V-254507 | WN22-UR-000170 | medium | Windows Server 2022 manage auditing and security log user right must only be assigned to the Administrators group. |
| V-257796 | RHEL-09-212055 | low | RHEL 9 must enable auditing of processes that start prior to the audit daemon. |
| V-258037 | RHEL-09-291025 | low | RHEL 9 must enable Linux audit logging for the USBGuard daemon. |
| V-258151 | RHEL-09-653010 | medium | RHEL 9 audit package must be installed. |
| V-258152 | RHEL-09-653015 | medium | RHEL 9 audit service must be enabled. |
| V-258164 | RHEL-09-653075 | medium | RHEL 9 audit system must audit local events. |
| V-258171 | RHEL-09-653110 | medium | RHEL 9 must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited. |
| V-258172 | RHEL-09-653115 | medium | RHEL 9 /etc/audit/auditd.conf file must have 0640 or less permissive to prevent unauthorized access. |
| V-258177 | RHEL-09-654015 | medium | RHEL 9 must audit all uses of the chmod, fchmod, and fchmodat system calls. |
| V-258178 | RHEL-09-654020 | medium | RHEL 9 must audit all uses of the chown, fchown, fchownat, and lchown system calls. |
| V-258179 | RHEL-09-654025 | medium | RHEL 9 must audit all uses of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls. |
| V-258180 | RHEL-09-654030 | medium | RHEL 9 must audit all uses of umount system calls. |
| V-258181 | RHEL-09-654035 | medium | RHEL 9 must audit all uses of the chacl command. |
| V-258182 | RHEL-09-654040 | medium | RHEL 9 must audit all uses of the setfacl command. |
| V-258183 | RHEL-09-654045 | medium | RHEL 9 must audit all uses of the chcon command. |
| V-258184 | RHEL-09-654050 | medium | RHEL 9 must audit all uses of the semanage command. |
| V-258185 | RHEL-09-654055 | medium | RHEL 9 must audit all uses of the setfiles command. |
| V-258186 | RHEL-09-654060 | medium | RHEL 9 must audit all uses of the setsebool command. |
| V-258187 | RHEL-09-654065 | medium | RHEL 9 must audit all uses of the rename, unlink, rmdir, renameat, and unlinkat system calls. |
| V-258188 | RHEL-09-654070 | medium | RHEL 9 must audit all uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls. |
| V-258189 | RHEL-09-654075 | medium | RHEL 9 must audit all uses of the delete_module system call. |
| V-258190 | RHEL-09-654080 | medium | RHEL 9 must audit all uses of the init_module and finit_module system calls. |
| V-258191 | RHEL-09-654085 | medium | RHEL 9 must audit all uses of the chage command. |
| V-258192 | RHEL-09-654090 | medium | RHEL 9 must audit all uses of the chsh command. |
| V-258193 | RHEL-09-654095 | medium | RHEL 9 must audit all uses of the crontab command. |
| V-258194 | RHEL-09-654100 | medium | RHEL 9 must audit all uses of the gpasswd command. |
| V-258195 | RHEL-09-654105 | medium | RHEL 9 must audit all uses of the kmod command. |
| V-258196 | RHEL-09-654110 | medium | RHEL 9 must audit all uses of the newgrp command. |
| V-258197 | RHEL-09-654115 | medium | RHEL 9 must audit all uses of the pam_timestamp_check command. |
| V-258198 | RHEL-09-654120 | medium | RHEL 9 must audit all uses of the passwd command. |
| V-258199 | RHEL-09-654125 | medium | RHEL 9 must audit all uses of the postdrop command. |
| V-258200 | RHEL-09-654130 | medium | RHEL 9 must audit all uses of the postqueue command. |
| V-258201 | RHEL-09-654135 | medium | RHEL 9 must audit all uses of the ssh-agent command. |
| V-258202 | RHEL-09-654140 | medium | RHEL 9 must audit all uses of the ssh-keysign command. |
| V-258203 | RHEL-09-654145 | medium | RHEL 9 must audit all uses of the su command. |
| V-258204 | RHEL-09-654150 | medium | RHEL 9 must audit all uses of the sudo command. |
| V-258205 | RHEL-09-654155 | medium | RHEL 9 must audit all uses of the sudoedit command. |
| V-258206 | RHEL-09-654160 | medium | RHEL 9 must audit all uses of the unix_chkpwd command. |
| V-258207 | RHEL-09-654165 | medium | RHEL 9 must audit all uses of the unix_update command. |
| V-258208 | RHEL-09-654170 | medium | RHEL 9 must audit all uses of the userhelper command. |
| V-258209 | RHEL-09-654175 | medium | RHEL 9 must audit all uses of the usermod command. |
| V-258210 | RHEL-09-654180 | medium | RHEL 9 must audit all uses of the mount command. |
| V-258211 | RHEL-09-654185 | medium | Successful/unsuccessful uses of the init command in RHEL 9 must generate an audit record. |
| V-258212 | RHEL-09-654190 | medium | Successful/unsuccessful uses of the poweroff command in RHEL 9 must generate an audit record. |
| V-258213 | RHEL-09-654195 | medium | Successful/unsuccessful uses of the reboot command in RHEL 9 must generate an audit record. |
| V-258214 | RHEL-09-654200 | medium | Successful/unsuccessful uses of the shutdown command in RHEL 9 must generate an audit record. |
| V-258215 | RHEL-09-654205 | medium | Successful/unsuccessful uses of the umount system call in RHEL 9 must generate an audit record. |
| V-258216 | RHEL-09-654210 | medium | Successful/unsuccessful uses of the umount2 system call in RHEL 9 must generate an audit record. |
| V-258217 | RHEL-09-654215 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers. |
| V-258218 | RHEL-09-654220 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory. |
| V-258219 | RHEL-09-654225 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group. |
| V-258220 | RHEL-09-654230 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow. |
| V-258221 | RHEL-09-654235 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd. |
| V-258222 | RHEL-09-654240 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd. |
| V-258223 | RHEL-09-654245 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow. |
| V-258224 | RHEL-09-654250 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/faillock. |
| V-258225 | RHEL-09-654255 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/lastlog. |
| V-258226 | RHEL-09-654260 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/tallylog. |
| V-258228 | RHEL-09-654270 | medium | RHEL 9 audit system must protect logon UIDs from unauthorized change. |
| V-274877 | RHEL-08-030655 | medium | RHEL 8 must audit any script or executable called by cron as root or by any privileged user. |
| V-275780 | DTBC-0075 | medium | Create Themes with AI must be disabled. |
| V-275781 | DTBC-0076 | medium | DevTools Generative AI features must be disabled. |
| V-275782 | DTBC-0077 | medium | GenAI local foundational model must be disabled. |
| V-275783 | DTBC-0078 | medium | Help Me Write must be disabled. |
| V-275784 | DTBC-0079 | medium | AI-powered History Search must be disabled. |
| V-275785 | DTBC-0080 | medium | Tab Compare Settings must be disabled. |
Get this as data
The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/AU-12. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.