San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active

AU-12 Audit Record Generation

Audit and Accountability family. 18 Control Correlation Identifiers map to this control, and 270 STIG rules implement those CCIs.

0CAT I (high)
265CAT II (medium)
5CAT III (low)
18CCIs
What this page is built from, and what it is not.

The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.

It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.

Where these rules come from

STIG benchmarkVersionRules mapped to AU-12
Red Hat Enterprise Linux 9V258
Red Hat Enterprise Linux 8V249
Microsoft Windows Server 2019V344
Microsoft Windows Server 2022V244
Microsoft Windows 10V333
Microsoft Windows 11V231
Google Chrome Current WindowsV210
KubernetesV21

Control Correlation Identifiers mapped to AU-12

CCIDefinitionRev
CCI-000169Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2 a on organization-defined information system components.5, 4
CCI-000171Allow organization-defined personnel or roles to select the event types that are to be logged by specific components of the system.5, 4
CCI-000172Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.5, 4
CCI-000173Defines the level of tolerance for relationship between time stamps of individual records in the audit trail that will be used for correlation.5, 4
CCI-000174Compile audit records from organization-defined information system components into a system-wide (logical or physical) audit trail that is time-correlated to within an organization-defined level of tolerance for relationship between time stamps of individual records in the audit trail.5, 4
CCI-001353Produce a system-wide (logical or physical) audit trail composed of audit records in a standardized format.5, 4
CCI-001459Defines system components that provide audit record generation capability.5, 4
CCI-001576The information system produces a system-wide (logical or physical) audit trail of information system audit records.4
CCI-001577Defines the system components from which audit records are to be compiled into the system-wide audit trail.5, 4
CCI-001910Defines the personnel or roles allowed to select which event types are to be logged by specific components of the system.5, 4
CCI-001911Defines the selectable event criteria to be used as the basis for changes to the auditing to be performed on organization-defined system components, by organization-defined individuals or roles, within organization-defined time thresholds.5, 4
CCI-001912Defines the time thresholds for organization-defined individuals or roles to change the auditing to be performed based on organization-defined selectable event criteria.5, 4
CCI-001913Defines the individuals or roles that are to be provided the capability to change the auditing to be performed based on organization-defined selectable event criteria, within organization-defined time thresholds.5, 4
CCI-001914Provide the capability for organization-defined individuals or roles to change the logging to be performed on organization-defined system components based on organization-defined selectable event criteria within organization-defined time thresholds.5, 4
CCI-002047Defines the system components on which the auditing that is to be performed can be changed by organization-defined individuals or roles.5, 4
CCI-003834Implement the capability for organization-defined individuals or roles to change the auditing to be performed on organization-defined system components based on organization-defined selectable event criteria within organization-defined time thresholds.5
CCI-003835Provide the capability for auditing the parameters of user query events for data sets containing personally identifiable information.5
CCI-003836Implement the capability for auditing the parameters of user query events for data sets containing personally identifiable information.5

STIG rules that implement AU-12

RuleSTIG IDSeverityRequirement
V-205625WN19-AU-000100mediumWindows Server 2019 must be configured to audit Account Management - Security Group Management successes.
V-205626WN19-AU-000110mediumWindows Server 2019 must be configured to audit Account Management - User Account Management successes.
V-205627WN19-AU-000120mediumWindows Server 2019 must be configured to audit Account Management - User Account Management failures.
V-205628WN19-DC-000230mediumWindows Server 2019 must be configured to audit Account Management - Computer Account Management successes.
V-205634WN19-AU-000190mediumWindows Server 2019 must be configured to audit logon successes.
V-205635WN19-AU-000200mediumWindows Server 2019 must be configured to audit logon failures.
V-205643WN19-UR-000170mediumWindows Server 2019 Manage auditing and security log user right must only be assigned to the Administrators group.
V-205644WN19-SO-000050mediumWindows Server 2019 must force audit policy subcategory settings to override audit policy category settings.
V-205730WN19-AU-000160mediumWindows Server 2019 must be configured to audit Logon/Logoff - Account Lockout failures.
V-205769WN19-AU-000090mediumWindows Server 2019 must be configured to audit Account Management - Other Account Management Events successes.
V-205770WN19-AU-000140mediumWindows Server 2019 must be configured to audit Detailed Tracking - Process Creation successes.
V-205771WN19-AU-000260mediumWindows Server 2019 must be configured to audit Policy Change - Audit Policy Change successes.
V-205772WN19-AU-000270mediumWindows Server 2019 must be configured to audit Policy Change - Audit Policy Change failures.
V-205773WN19-AU-000280mediumWindows Server 2019 must be configured to audit Policy Change - Authentication Policy Change successes.
V-205774WN19-AU-000290mediumWindows Server 2019 must be configured to audit Policy Change - Authorization Policy Change successes.
V-205775WN19-AU-000300mediumWindows Server 2019 must be configured to audit Privilege Use - Sensitive Privilege Use successes.
V-205776WN19-AU-000310mediumWindows Server 2019 must be configured to audit Privilege Use - Sensitive Privilege Use failures.
V-205777WN19-AU-000320mediumWindows Server 2019 must be configured to audit System - IPsec Driver successes.
V-205778WN19-AU-000330mediumWindows Server 2019 must be configured to audit System - IPsec Driver failures.
V-205779WN19-AU-000340mediumWindows Server 2019 must be configured to audit System - Other System Events successes.
V-205780WN19-AU-000350mediumWindows Server 2019 must be configured to audit System - Other System Events failures.
V-205781WN19-AU-000360mediumWindows Server 2019 must be configured to audit System - Security State Change successes.
V-205782WN19-AU-000370mediumWindows Server 2019 must be configured to audit System - Security System Extension successes.
V-205783WN19-AU-000380mediumWindows Server 2019 must be configured to audit System - System Integrity successes.
V-205784WN19-AU-000390mediumWindows Server 2019 must be configured to audit System - System Integrity failures.
V-205785WN19-DC-000170mediumWindows Server 2019 Active Directory Group Policy objects must be configured with proper audit settings.
V-205786WN19-DC-000180mediumWindows Server 2019 Active Directory Domain object must be configured with proper audit settings.
V-205787WN19-DC-000190mediumWindows Server 2019 Active Directory Infrastructure object must be configured with proper audit settings.
V-205788WN19-DC-000200mediumWindows Server 2019 Active Directory Domain Controllers Organizational Unit (OU) object must be configured with proper audit settings.
V-205789WN19-DC-000210mediumWindows Server 2019 Active Directory AdminSDHolder object must be configured with proper audit settings.
V-205790WN19-DC-000220mediumWindows Server 2019 Active Directory RID Manager$ object must be configured with proper audit settings.
V-205791WN19-DC-000240mediumWindows Server 2019 must be configured to audit DS Access - Directory Service Access successes.
V-205792WN19-DC-000250mediumWindows Server 2019 must be configured to audit DS Access - Directory Service Access failures.
V-205793WN19-DC-000260mediumWindows Server 2019 must be configured to audit DS Access - Directory Service Changes successes.
V-205832WN19-AU-000070mediumWindows Server 2019 must be configured to audit Account Logon - Credential Validation successes.
V-205833WN19-AU-000080mediumWindows Server 2019 must be configured to audit Account Logon - Credential Validation failures.
V-205834WN19-AU-000170mediumWindows Server 2019 must be configured to audit Logon/Logoff - Group Membership successes.
V-205835WN19-AU-000210mediumWindows Server 2019 must be configured to audit Logon/Logoff - Special Logon successes.
V-205836WN19-AU-000220mediumWindows Server 2019 must be configured to audit Object Access - Other Object Access Events successes.
V-205837WN19-AU-000230mediumWindows Server 2019 must be configured to audit Object Access - Other Object Access Events failures.
V-205838WN19-AU-000180mediumWindows Server 2019 must be configured to audit logoff successes.
V-205839WN19-AU-000130mediumWindows Server 2019 must be configured to audit Detailed Tracking - Plug and Play Events successes.
V-205840WN19-AU-000240mediumWindows Server 2019 must be configured to audit Object Access - Removable Storage successes.
V-205841WN19-AU-000250mediumWindows Server 2019 must be configured to audit Object Access - Removable Storage failures.
V-220748WN10-AU-000005mediumThe system must be configured to audit Account Logon - Credential Validation failures.
V-220749WN10-AU-000010mediumThe system must be configured to audit Account Logon - Credential Validation successes.
V-220750WN10-AU-000030mediumThe system must be configured to audit Account Management - Security Group Management successes.
V-220751WN10-AU-000035mediumThe system must be configured to audit Account Management - User Account Management failures.
V-220752WN10-AU-000040mediumThe system must be configured to audit Account Management - User Account Management successes.
V-220753WN10-AU-000045mediumThe system must be configured to audit Detailed Tracking - PNP Activity successes.
V-220754WN10-AU-000050mediumThe system must be configured to audit Detailed Tracking - Process Creation successes.
V-220755WN10-AU-000054mediumThe system must be configured to audit Logon/Logoff - Account Lockout failures.
V-220756WN10-AU-000060mediumThe system must be configured to audit Logon/Logoff - Group Membership successes.
V-220757WN10-AU-000065mediumThe system must be configured to audit Logon/Logoff - Logoff successes.
V-220758WN10-AU-000070mediumThe system must be configured to audit Logon/Logoff - Logon failures.
V-220759WN10-AU-000075mediumThe system must be configured to audit Logon/Logoff - Logon successes.
V-220760WN10-AU-000080mediumThe system must be configured to audit Logon/Logoff - Special Logon successes.
V-220761WN10-AU-000081mediumWindows 10 must be configured to audit Object Access - File Share failures.
V-220762WN10-AU-000082mediumWindows 10 must be configured to audit Object Access - File Share successes.
V-220763WN10-AU-000083mediumWindows 10 must be configured to audit Object Access - Other Object Access Events successes.
V-220764WN10-AU-000084mediumWindows 10 must be configured to audit Object Access - Other Object Access Events failures.
V-220765WN10-AU-000085mediumThe system must be configured to audit Object Access - Removable Storage failures.
V-220766WN10-AU-000090mediumThe system must be configured to audit Object Access - Removable Storage successes.
V-220767WN10-AU-000100mediumThe system must be configured to audit Policy Change - Audit Policy Change successes.
V-220768WN10-AU-000105mediumThe system must be configured to audit Policy Change - Authentication Policy Change successes.
V-220769WN10-AU-000107mediumThe system must be configured to audit Policy Change - Authorization Policy Change successes.
V-220770WN10-AU-000110mediumThe system must be configured to audit Privilege Use - Sensitive Privilege Use failures.
V-220771WN10-AU-000115mediumThe system must be configured to audit Privilege Use - Sensitive Privilege Use successes.
V-220772WN10-AU-000120mediumThe system must be configured to audit System - IPSec Driver failures.
V-220773WN10-AU-000130mediumThe system must be configured to audit System - Other System Events successes.
V-220774WN10-AU-000135mediumThe system must be configured to audit System - Other System Events failures.
V-220775WN10-AU-000140mediumThe system must be configured to audit System - Security State Change successes.
V-220776WN10-AU-000150mediumThe system must be configured to audit System - Security System Extension successes.
V-220777WN10-AU-000155mediumThe system must be configured to audit System - System Integrity failures.
V-220778WN10-AU-000160mediumThe system must be configured to audit System - System Integrity successes.
V-220913WN10-SO-000030mediumAudit policy using subcategories must be enabled.
V-220978WN10-UR-000130mediumThe Manage auditing and security log user right must only be assigned to the Administrators group.
V-221562DTBC-0005mediumExtensions installation must be blocklisted by default.
V-221586DTBC-0052mediumDeletion of browser history must be disabled.
V-221587DTBC-0053mediumPrompt for download location must be enabled.
V-221588DTBC-0055mediumDownload restrictions must be configured.
V-230404RHEL-08-030130mediumRHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
V-230405RHEL-08-030140mediumRHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.
V-230406RHEL-08-030150mediumRHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
V-230407RHEL-08-030160mediumRHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
V-230408RHEL-08-030170mediumRHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
V-230409RHEL-08-030171mediumRHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.
V-230410RHEL-08-030172mediumRHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/.
V-230411RHEL-08-030180mediumThe RHEL 8 audit package must be installed.
V-230412RHEL-08-030190mediumSuccessful/unsuccessful uses of the su command in RHEL 8 must generate an audit record.
V-230413RHEL-08-030200mediumThe RHEL 8 audit system must be configured to audit any usage of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls.
V-230418RHEL-08-030250mediumSuccessful/unsuccessful uses of the chage command in RHEL 8 must generate an audit record.
V-230419RHEL-08-030260mediumSuccessful/unsuccessful uses of the chcon command in RHEL 8 must generate an audit record.
V-230421RHEL-08-030280mediumSuccessful/unsuccessful uses of the ssh-agent in RHEL 8 must generate an audit record.
V-230422RHEL-08-030290mediumSuccessful/unsuccessful uses of the passwd command in RHEL 8 must generate an audit record.
V-230423RHEL-08-030300mediumSuccessful/unsuccessful uses of the mount command in RHEL 8 must generate an audit record.
V-230424RHEL-08-030301mediumSuccessful/unsuccessful uses of the umount command in RHEL 8 must generate an audit record.
V-230425RHEL-08-030302mediumSuccessful/unsuccessful uses of the mount syscall in RHEL 8 must generate an audit record.
V-230426RHEL-08-030310mediumSuccessful/unsuccessful uses of the unix_update in RHEL 8 must generate an audit record.
V-230427RHEL-08-030311mediumSuccessful/unsuccessful uses of postdrop in RHEL 8 must generate an audit record.
V-230428RHEL-08-030312mediumSuccessful/unsuccessful uses of postqueue in RHEL 8 must generate an audit record.
V-230429RHEL-08-030313mediumSuccessful/unsuccessful uses of semanage in RHEL 8 must generate an audit record.
V-230430RHEL-08-030314mediumSuccessful/unsuccessful uses of setfiles in RHEL 8 must generate an audit record.
V-230431RHEL-08-030315mediumSuccessful/unsuccessful uses of userhelper in RHEL 8 must generate an audit record.
V-230432RHEL-08-030316mediumSuccessful/unsuccessful uses of setsebool in RHEL 8 must generate an audit record.
V-230433RHEL-08-030317mediumSuccessful/unsuccessful uses of unix_chkpwd in RHEL 8 must generate an audit record.
V-230434RHEL-08-030320mediumSuccessful/unsuccessful uses of the ssh-keysign in RHEL 8 must generate an audit record.
V-230435RHEL-08-030330mediumSuccessful/unsuccessful uses of the setfacl command in RHEL 8 must generate an audit record.
V-230436RHEL-08-030340mediumSuccessful/unsuccessful uses of the pam_timestamp_check command in RHEL 8 must generate an audit record.
V-230437RHEL-08-030350mediumSuccessful/unsuccessful uses of the newgrp command in RHEL 8 must generate an audit record.
V-230438RHEL-08-030360mediumSuccessful/unsuccessful uses of the init_module and finit_module system calls in RHEL 8 must generate an audit record.
V-230439RHEL-08-030361mediumSuccessful/unsuccessful uses of the rename, unlink, rmdir, renameat, and unlinkat system calls in RHEL 8 must generate an audit record.
V-230444RHEL-08-030370mediumSuccessful/unsuccessful uses of the gpasswd command in RHEL 8 must generate an audit record.
V-230446RHEL-08-030390mediumSuccessful/unsuccessful uses of the delete_module command in RHEL 8 must generate an audit record.
V-230447RHEL-08-030400mediumSuccessful/unsuccessful uses of the crontab command in RHEL 8 must generate an audit record.
V-230448RHEL-08-030410mediumSuccessful/unsuccessful uses of the chsh command in RHEL 8 must generate an audit record.
V-230449RHEL-08-030420mediumSuccessful/unsuccessful uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls in RHEL 8 must generate an audit record.
V-230455RHEL-08-030480mediumSuccessful/unsuccessful uses of the chown, fchown, fchownat, and lchown system calls in RHEL 8 must generate an audit record.
V-230456RHEL-08-030490mediumSuccessful/unsuccessful uses of the chmod, fchmod, and fchmodat system calls in RHEL 8 must generate an audit record.
V-230462RHEL-08-030550mediumSuccessful/unsuccessful uses of the sudo command in RHEL 8 must generate an audit record.
V-230463RHEL-08-030560mediumSuccessful/unsuccessful uses of the usermod command in RHEL 8 must generate an audit record.
V-230464RHEL-08-030570mediumSuccessful/unsuccessful uses of the chacl command in RHEL 8 must generate an audit record.
V-230465RHEL-08-030580mediumSuccessful/unsuccessful uses of the kmod command in RHEL 8 must generate an audit record.
V-230466RHEL-08-030590mediumSuccessful/unsuccessful modifications to the faillock log file in RHEL 8 must generate an audit record.
V-230467RHEL-08-030600mediumSuccessful/unsuccessful modifications to the lastlog file in RHEL 8 must generate an audit record.
V-230468RHEL-08-030601lowRHEL 8 must enable auditing of processes that start prior to the audit daemon.
V-230470RHEL-08-030603lowRHEL 8 must enable Linux audit logging for the USBGuard daemon.
V-230471RHEL-08-030610mediumRHEL 8 must allow only the Information System Security Manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.
V-242403CNTR-K8-000700mediumKubernetes API Server must generate audit records that identify what type of event has occurred, identify the source of the event, contain the event results, identify any users, and identify any containers associated with the event.
V-244542RHEL-08-030181mediumRHEL 8 audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.
V-253268WN11-00-000065lowUnused accounts must be disabled or removed from the system after 35 days of inactivity.
V-253306WN11-AU-000005mediumThe system must be configured to audit Account Logon - Credential Validation failures.
V-253307WN11-AU-000010mediumThe system must be configured to audit Account Logon - Credential Validation successes.
V-253308WN11-AU-000030mediumThe system must be configured to audit Account Management - Security Group Management successes.
V-253311WN11-AU-000045mediumThe system must be configured to audit Detailed Tracking - PNP Activity successes.
V-253312WN11-AU-000050mediumThe system must be configured to audit Detailed Tracking - Process Creation successes.
V-253313WN11-AU-000054mediumThe system must be configured to audit Logon/Logoff - Account Lockout failures.
V-253314WN11-AU-000060mediumThe system must be configured to audit Logon/Logoff - Group Membership successes.
V-253316WN11-AU-000070mediumThe system must be configured to audit Logon/Logoff - Logon failures.
V-253317WN11-AU-000075mediumThe system must be configured to audit Logon/Logoff - Logon successes.
V-253318WN11-AU-000080mediumThe system must be configured to audit Logon/Logoff - Special Logon successes.
V-253319WN11-AU-000081mediumWindows 11 must be configured to audit Object Access - File Share failures.
V-253320WN11-AU-000082mediumWindows 11 must be configured to audit Object Access - File Share successes.
V-253321WN11-AU-000083mediumWindows 11 must be configured to audit Object Access - Other Object Access Events successes.
V-253322WN11-AU-000084mediumWindows 11 must be configured to audit Object Access - Other Object Access Events failures.
V-253323WN11-AU-000085mediumThe system must be configured to audit Object Access - Removable Storage failures.
V-253324WN11-AU-000090mediumThe system must be configured to audit Object Access - Removable Storage successes.
V-253325WN11-AU-000100mediumThe system must be configured to audit Policy Change - Audit Policy Change successes.
V-253326WN11-AU-000105mediumThe system must be configured to audit Policy Change - Authentication Policy Change successes.
V-253327WN11-AU-000107mediumThe system must be configured to audit Policy Change - Authorization Policy Change successes.
V-253329WN11-AU-000115mediumThe system must be configured to audit Privilege Use - Sensitive Privilege Use successes.
V-253330WN11-AU-000120mediumThe system must be configured to audit System - IPsec Driver failures.
V-253331WN11-AU-000130mediumThe system must be configured to audit System - Other System Events successes.
V-253332WN11-AU-000135mediumThe system must be configured to audit System - Other System Events failures.
V-253333WN11-AU-000140mediumThe system must be configured to audit System - Security State Change successes.
V-253334WN11-AU-000150mediumThe system must be configured to audit System - Security System Extension successes.
V-253335WN11-AU-000155mediumThe system must be configured to audit System - System Integrity failures.
V-253336WN11-AU-000160mediumThe system must be configured to audit System - System Integrity successes.
V-253426WN11-EP-000310mediumWindows 11 Kernel (Direct Memory Access) DMA Protection must be enabled.
V-253437WN11-SO-000030mediumAudit policy using subcategories must be enabled.
V-253501WN11-UR-000130mediumThe "Manage auditing and security log" user right must only be assigned to the Administrators group.
V-254300WN22-AU-000070mediumWindows Server 2022 must be configured to audit Account Logon - Credential Validation successes.
V-254301WN22-AU-000080mediumWindows Server 2022 must be configured to audit Account Logon - Credential Validation failures.
V-254302WN22-AU-000090mediumWindows Server 2022 must be configured to audit Account Management - Other Account Management Events successes.
V-254303WN22-AU-000100mediumWindows Server 2022 must be configured to audit Account Management - Security Group Management successes.
V-254304WN22-AU-000110mediumWindows Server 2022 must be configured to audit Account Management - User Account Management successes.
V-254305WN22-AU-000120mediumWindows Server 2022 must be configured to audit Account Management - User Account Management failures.
V-254306WN22-AU-000130mediumWindows Server 2022 must be configured to audit Detailed Tracking - Plug and Play Events successes.
V-254307WN22-AU-000140mediumWindows Server 2022 must be configured to audit Detailed Tracking - Process Creation successes.
V-254309WN22-AU-000160mediumWindows Server 2022 must be configured to audit Logon/Logoff - Account Lockout failures.
V-254310WN22-AU-000170mediumWindows Server 2022 must be configured to audit Logon/Logoff - Group Membership successes.
V-254311WN22-AU-000180mediumWindows Server 2022 must be configured to audit logoff successes.
V-254312WN22-AU-000190mediumWindows Server 2022 must be configured to audit logon successes.
V-254313WN22-AU-000200mediumWindows Server 2022 must be configured to audit logon failures.
V-254314WN22-AU-000210mediumWindows Server 2022 must be configured to audit Logon/Logoff - Special Logon successes.
V-254315WN22-AU-000220mediumWindows Server 2022 must be configured to audit Object Access - Other Object Access Events successes.
V-254316WN22-AU-000230mediumWindows Server 2022 must be configured to audit Object Access - Other Object Access Events failures.
V-254317WN22-AU-000240mediumWindows Server 2022 must be configured to audit Object Access - Removable Storage successes.
V-254318WN22-AU-000250mediumWindows Server 2022 must be configured to audit Object Access - Removable Storage failures.
V-254319WN22-AU-000260mediumWindows Server 2022 must be configured to audit Policy Change - Audit Policy Change successes.
V-254320WN22-AU-000270mediumWindows Server 2022 must be configured to audit Policy Change - Audit Policy Change failures.
V-254321WN22-AU-000280mediumWindows Server 2022 must be configured to audit Policy Change - Authentication Policy Change successes.
V-254322WN22-AU-000290mediumWindows Server 2022 must be configured to audit Policy Change - Authorization Policy Change successes.
V-254323WN22-AU-000300mediumWindows Server 2022 must be configured to audit Privilege Use - Sensitive Privilege Use successes.
V-254324WN22-AU-000310mediumWindows Server 2022 must be configured to audit Privilege Use - Sensitive Privilege Use failures.
V-254325WN22-AU-000320mediumWindows Server 2022 must be configured to audit System - IPsec Driver successes.
V-254326WN22-AU-000330mediumWindows Server 2022 must be configured to audit System - IPsec Driver failures.
V-254327WN22-AU-000340mediumWindows Server 2022 must be configured to audit System - Other System Events successes.
V-254328WN22-AU-000350mediumWindows Server 2022 must be configured to audit System - Other System Events failures.
V-254329WN22-AU-000360mediumWindows Server 2022 must be configured to audit System - Security State Change successes.
V-254330WN22-AU-000370mediumWindows Server 2022 must be configured to audit System - Security System Extension successes.
V-254331WN22-AU-000380mediumWindows Server 2022 must be configured to audit System - System Integrity successes.
V-254332WN22-AU-000390mediumWindows Server 2022 must be configured to audit System - System Integrity failures.
V-254401WN22-DC-000170mediumWindows Server 2022 Active Directory Group Policy objects must be configured with proper audit settings.
V-254402WN22-DC-000180mediumWindows Server 2022 Active Directory Domain object must be configured with proper audit settings.
V-254403WN22-DC-000190mediumWindows Server 2022 Active Directory Infrastructure object must be configured with proper audit settings.
V-254404WN22-DC-000200mediumWindows Server 2022 Active Directory Domain Controllers Organizational Unit (OU) object must be configured with proper audit settings.
V-254405WN22-DC-000210mediumWindows Server 2022 Active Directory AdminSDHolder object must be configured with proper audit settings.
V-254406WN22-DC-000220mediumWindows Server 2022 Active Directory RID Manager$ object must be configured with proper audit settings.
V-254407WN22-DC-000230mediumWindows Server 2022 must be configured to audit Account Management - Computer Account Management successes.
V-254408WN22-DC-000240mediumWindows Server 2022 must be configured to audit DS Access - Directory Service Access successes.
V-254409WN22-DC-000250mediumWindows Server 2022 must be configured to audit DS Access - Directory Service Access failures.
V-254410WN22-DC-000260mediumWindows Server 2022 must be configured to audit DS Access - Directory Service Changes successes.
V-254449WN22-SO-000050mediumWindows Server 2022 must force audit policy subcategory settings to override audit policy category settings.
V-254507WN22-UR-000170mediumWindows Server 2022 manage auditing and security log user right must only be assigned to the Administrators group.
V-257796RHEL-09-212055lowRHEL 9 must enable auditing of processes that start prior to the audit daemon.
V-258037RHEL-09-291025lowRHEL 9 must enable Linux audit logging for the USBGuard daemon.
V-258151RHEL-09-653010mediumRHEL 9 audit package must be installed.
V-258152RHEL-09-653015mediumRHEL 9 audit service must be enabled.
V-258164RHEL-09-653075mediumRHEL 9 audit system must audit local events.
V-258171RHEL-09-653110mediumRHEL 9 must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.
V-258172RHEL-09-653115mediumRHEL 9 /etc/audit/auditd.conf file must have 0640 or less permissive to prevent unauthorized access.
V-258177RHEL-09-654015mediumRHEL 9 must audit all uses of the chmod, fchmod, and fchmodat system calls.
V-258178RHEL-09-654020mediumRHEL 9 must audit all uses of the chown, fchown, fchownat, and lchown system calls.
V-258179RHEL-09-654025mediumRHEL 9 must audit all uses of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls.
V-258180RHEL-09-654030mediumRHEL 9 must audit all uses of umount system calls.
V-258181RHEL-09-654035mediumRHEL 9 must audit all uses of the chacl command.
V-258182RHEL-09-654040mediumRHEL 9 must audit all uses of the setfacl command.
V-258183RHEL-09-654045mediumRHEL 9 must audit all uses of the chcon command.
V-258184RHEL-09-654050mediumRHEL 9 must audit all uses of the semanage command.
V-258185RHEL-09-654055mediumRHEL 9 must audit all uses of the setfiles command.
V-258186RHEL-09-654060mediumRHEL 9 must audit all uses of the setsebool command.
V-258187RHEL-09-654065mediumRHEL 9 must audit all uses of the rename, unlink, rmdir, renameat, and unlinkat system calls.
V-258188RHEL-09-654070mediumRHEL 9 must audit all uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls.
V-258189RHEL-09-654075mediumRHEL 9 must audit all uses of the delete_module system call.
V-258190RHEL-09-654080mediumRHEL 9 must audit all uses of the init_module and finit_module system calls.
V-258191RHEL-09-654085mediumRHEL 9 must audit all uses of the chage command.
V-258192RHEL-09-654090mediumRHEL 9 must audit all uses of the chsh command.
V-258193RHEL-09-654095mediumRHEL 9 must audit all uses of the crontab command.
V-258194RHEL-09-654100mediumRHEL 9 must audit all uses of the gpasswd command.
V-258195RHEL-09-654105mediumRHEL 9 must audit all uses of the kmod command.
V-258196RHEL-09-654110mediumRHEL 9 must audit all uses of the newgrp command.
V-258197RHEL-09-654115mediumRHEL 9 must audit all uses of the pam_timestamp_check command.
V-258198RHEL-09-654120mediumRHEL 9 must audit all uses of the passwd command.
V-258199RHEL-09-654125mediumRHEL 9 must audit all uses of the postdrop command.
V-258200RHEL-09-654130mediumRHEL 9 must audit all uses of the postqueue command.
V-258201RHEL-09-654135mediumRHEL 9 must audit all uses of the ssh-agent command.
V-258202RHEL-09-654140mediumRHEL 9 must audit all uses of the ssh-keysign command.
V-258203RHEL-09-654145mediumRHEL 9 must audit all uses of the su command.
V-258204RHEL-09-654150mediumRHEL 9 must audit all uses of the sudo command.
V-258205RHEL-09-654155mediumRHEL 9 must audit all uses of the sudoedit command.
V-258206RHEL-09-654160mediumRHEL 9 must audit all uses of the unix_chkpwd command.
V-258207RHEL-09-654165mediumRHEL 9 must audit all uses of the unix_update command.
V-258208RHEL-09-654170mediumRHEL 9 must audit all uses of the userhelper command.
V-258209RHEL-09-654175mediumRHEL 9 must audit all uses of the usermod command.
V-258210RHEL-09-654180mediumRHEL 9 must audit all uses of the mount command.
V-258211RHEL-09-654185mediumSuccessful/unsuccessful uses of the init command in RHEL 9 must generate an audit record.
V-258212RHEL-09-654190mediumSuccessful/unsuccessful uses of the poweroff command in RHEL 9 must generate an audit record.
V-258213RHEL-09-654195mediumSuccessful/unsuccessful uses of the reboot command in RHEL 9 must generate an audit record.
V-258214RHEL-09-654200mediumSuccessful/unsuccessful uses of the shutdown command in RHEL 9 must generate an audit record.
V-258215RHEL-09-654205mediumSuccessful/unsuccessful uses of the umount system call in RHEL 9 must generate an audit record.
V-258216RHEL-09-654210mediumSuccessful/unsuccessful uses of the umount2 system call in RHEL 9 must generate an audit record.
V-258217RHEL-09-654215mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.
V-258218RHEL-09-654220mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory.
V-258219RHEL-09-654225mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
V-258220RHEL-09-654230mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
V-258221RHEL-09-654235mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
V-258222RHEL-09-654240mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
V-258223RHEL-09-654245mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
V-258224RHEL-09-654250mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/faillock.
V-258225RHEL-09-654255mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/lastlog.
V-258226RHEL-09-654260mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/tallylog.
V-258228RHEL-09-654270mediumRHEL 9 audit system must protect logon UIDs from unauthorized change.
V-274877RHEL-08-030655mediumRHEL 8 must audit any script or executable called by cron as root or by any privileged user.
V-275780DTBC-0075mediumCreate Themes with AI must be disabled.
V-275781DTBC-0076mediumDevTools Generative AI features must be disabled.
V-275782DTBC-0077mediumGenAI local foundational model must be disabled.
V-275783DTBC-0078mediumHelp Me Write must be disabled.
V-275784DTBC-0079mediumAI-powered History Search must be disabled.
V-275785DTBC-0080mediumTab Compare Settings must be disabled.

Get this as data

The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/AU-12. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.