San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active

CM-6 Configuration Settings

Configuration Management family. 26 Control Correlation Identifiers map to this control, and 525 STIG rules implement those CCIs.

53CAT I (high)
425CAT II (medium)
47CAT III (low)
26CCIs
What this page is built from, and what it is not.

The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.

It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.

Where these rules come from

STIG benchmarkVersionRules mapped to CM-6
Red Hat Enterprise Linux 9V2148
Red Hat Enterprise Linux 8V2114
Microsoft Windows 10V367
Microsoft Windows Server 2019V357
Microsoft Windows 11V257
Microsoft Windows Server 2022V256
KubernetesV225
Google Chrome Current WindowsV21

Control Correlation Identifiers mapped to CM-6

CCIDefinitionRev
CCI-000363The organization defines security configuration checklists to be used to establish and document configuration settings for the information system technology products employed.4
CCI-000364The organization establishes configuration settings for information technology products employed within the information system using organization-defined security configuration checklists.4
CCI-000365The organization documents configuration settings for information technology products employed within the information system using organization-defined security configuration checklists that reflect the most restrictive mode consistent with operational requirements.4
CCI-000366Implement the security configuration settings.5, 4
CCI-000367Identify any deviations from the established configuration settings for organization-defined system components based on organization-defined operational requirements.5, 4
CCI-000368Document any deviations from the established configuration settings for organization-defined system components based on organization-defined operational requirements.5, 4
CCI-000369Approve any deviations from the established configuration settings for organization-defined system components based on organization-defined operational requirements.5, 4
CCI-000370Manage configuration settings for organization-defined system components using organization-defined automated mechanisms.5, 4
CCI-000371Apply configuration settings for organization-defined system components using organization-defined automated mechanisms.5, 4
CCI-000372Verify configuration settings for organization-defined system components using organization-defined automated mechanisms.5, 4
CCI-001502The organization monitors changes to the configuration settings in accordance with organizational policies and procedures.4
CCI-001503The organization controls changes to the configuration settings in accordance with organizational policies and procedures.4
CCI-001588The organization-defined security configuration checklists reflect the most restrictive mode consistent with operational requirements.4
CCI-001755Defines the system components for which any deviation from the established configuration settings are to be identified, documented, and approved.5, 4
CCI-001756Defines the operational requirements on which the configuration settings for the organization-defined system components are to be based.5, 4
CCI-001757Defines the actions to employ when responding to unauthorized changes to the organization-defined configuration settings.5, 4
CCI-001758Defines the configuration settings for which to employ organization-defined actions in response to unauthorized changes.5, 4
CCI-001759Take organization-defined actions in response to unauthorized changes to organization-defined configuration settings.5, 4
CCI-002059Defines the system components for which the organization will employ automated mechanisms to centrally manage, apply, and verify configuration settings.5, 4
CCI-003941Establish and document configuration settings for components employed within the system that reflect the most restrictive mode consistent with operational requirements using organization-defined common secure configurations.5
CCI-003942Defines the common secure configurations for establishing and documenting configuration settings within the system, that reflect the most restrictive mode consistent with operational requirements.5
CCI-003943Monitor changes to the configuration settings in accordance with organizational policies.5
CCI-003944Monitor changes to the configuration settings in accordance with organizational procedures.5
CCI-003945Control changes to the configuration settings in accordance with organizational policies.5
CCI-003946Control changes to the configuration settings in accordance with organizational procedures.5
CCI-003947Defines the automated mechanisms for managing, applying, and verifying configuration settings.5

STIG rules that implement CM-6

Showing the first 300 of 525. The complete set is available from the API endpoint linked below.

RuleSTIG IDSeverityRequirement
V-205728WN19-00-000290mediumWindows Server 2019 must employ automated mechanisms to determine the state of system components with regard to flaw remediation using the following frequency: continuously, where Endpoint Security Solution (ESS) is used; 30 days, for any additional internal network scans not covered by ESS; and annually, for external scans by Computer Network Defense Service Provider (CNDSP).
V-205838WN19-AU-000180mediumWindows Server 2019 must be configured to audit logoff successes.
V-205844WN19-00-000010highWindows Server 2019 users with Administrative privileges must have separate accounts for administrative duties and normal operational tasks.
V-205845WN19-00-000030highWindows Server 2019 administrative accounts must not be used with applications that access the Internet, such as web browsers, or with potential Internet sources, such as email.
V-205846WN19-00-000040mediumWindows Server 2019 members of the Backup Operators group must have separate accounts for backup duties and normal operational tasks.
V-205847WN19-00-000060mediumWindows Server 2019 manually managed application account passwords must be changed at least annually or when a system administrator with knowledge of the password leaves the organization.
V-205848WN19-00-000090mediumWindows Server 2019 domain-joined systems must have a Trusted Platform Module (TPM) enabled and ready for use.
V-205849WN19-00-000100highWindows Server 2019 must be maintained at a supported servicing level.
V-205850WN19-00-000110highWindows Server 2019 must use an anti-virus program.
V-205851WN19-00-000120mediumWindows Server 2019 must have a host-based intrusion detection or prevention system.
V-205852WN19-00-000240mediumWindows Server 2019 must have software certificate installation files removed.
V-205853WN19-00-000420mediumWindows Server 2019 FTP servers must be configured to prevent anonymous logons.
V-205854WN19-00-000430mediumWindows Server 2019 FTP servers must be configured to prevent access to the system drive.
V-205855WN19-00-000450mediumWindows Server 2019 must have orphaned security identifiers (SIDs) removed from user rights.
V-205856WN19-00-000460lowWindows Server 2019 systems must have Unified Extensible Firmware Interface (UEFI) firmware and be configured to run in UEFI mode, not Legacy BIOS.
V-205857WN19-00-000470lowWindows Server 2019 must have Secure Boot enabled.
V-205858WN19-CC-000030lowWindows Server 2019 Internet Protocol version 6 (IPv6) source routing must be configured to the highest protection level to prevent IP source routing.
V-205859WN19-CC-000040lowWindows Server 2019 source routing must be configured to the highest protection level to prevent Internet Protocol (IP) source routing.
V-205860WN19-CC-000050lowWindows Server 2019 must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF)-generated routes.
V-205861WN19-CC-000070mediumWindows Server 2019 insecure logons to an SMB server must be disabled.
V-205862WN19-CC-000080mediumWindows Server 2019 hardened Universal Naming Convention (UNC) paths must be defined to require mutual authentication and integrity for at least the \\*\SYSVOL and \\*\NETLOGON shares.
V-205863WN19-CC-000100mediumWindows Server 2019 must be configured to enable Remote host allows delegation of non-exportable credentials.
V-205864WN19-CC-000110mediumWindows Server 2019 virtualization-based security must be enabled with the platform security level configured to Secure Boot or Secure Boot with DMA Protection.
V-205865WN19-CC-000130mediumWindows Server 2019 Early Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers identified as bad.
V-205866WN19-CC-000140mediumWindows Server 2019 group policy objects must be reprocessed even if they have not changed.
V-205867WN19-CC-000180mediumWindows Server 2019 users must be prompted to authenticate when the system wakes from sleep (on battery).
V-205868WN19-CC-000190mediumWindows Server 2019 users must be prompted to authenticate when the system wakes from sleep (plugged in).
V-205869WN19-CC-000250mediumWindows Server 2019 Telemetry must be configured to Security or Basic.
V-205870WN19-CC-000260lowWindows Server 2019 Windows Update must not obtain updates from other PCs on the Internet.
V-205871WN19-CC-000320lowWindows Server 2019 Turning off File Explorer heap termination on corruption must be disabled.
V-205872WN19-CC-000330mediumWindows Server 2019 File Explorer shell protocol must run in protected mode.
V-205873WN19-CC-000390mediumWindows Server 2019 must prevent attachments from being downloaded from RSS feeds.
V-205874WN19-CC-000440mediumWindows Server 2019 users must be notified if a web-based program attempts to install software.
V-205875WN19-DC-000150highWindows Server 2019 directory data (outside the root DSE) of a non-public directory must be configured to prevent anonymous access.
V-205876WN19-DC-000330mediumWindows Server 2019 domain controllers must be configured to allow reset of machine account passwords.
V-205877WN19-DC-000430mediumThe password for the krbtgt account on a domain must be reset at least every 180 days.
V-205906WN19-MS-000050mediumWindows Server 2019 must limit the caching of logon credentials to four or less on domain-joined member servers.
V-205907WN19-MS-000140highWindows Server 2019 must be running Credential Guard on domain-joined member servers.
V-205908WN19-SO-000020highWindows Server 2019 must prevent local accounts with blank passwords from being used from the network.
V-205909WN19-SO-000030mediumWindows Server 2019 built-in administrator account must be renamed.
V-205910WN19-SO-000040mediumWindows Server 2019 built-in guest account must be renamed.
V-205911WN19-SO-000100mediumWindows Server 2019 maximum age for machine account passwords must be configured to 30 days or less.
V-205912WN19-SO-000150mediumWindows Server 2019 Smart Card removal option must be configured to Force Logoff or Lock Workstation.
V-205913WN19-SO-000210highWindows Server 2019 must not allow anonymous SID/Name translation.
V-205914WN19-SO-000220highWindows Server 2019 must not allow anonymous enumeration of Security Account Manager (SAM) accounts.
V-205915WN19-SO-000240mediumWindows Server 2019 must be configured to prevent anonymous users from having the same permissions as the Everyone group.
V-205916WN19-SO-000260mediumWindows Server 2019 services using Local System that use Negotiate when reverting to NTLM authentication must use the computer identity instead of authenticating anonymously.
V-205917WN19-SO-000270mediumWindows Server 2019 must prevent NTLM from falling back to a Null session.
V-205918WN19-SO-000280mediumWindows Server 2019 must prevent PKU2U authentication using online identities.
V-205919WN19-SO-000310highWindows Server 2019 LAN Manager authentication level must be configured to send NTLMv2 response only and to refuse LM and NTLM.
V-205920WN19-SO-000320mediumWindows Server 2019 must be configured to at least negotiate signing for LDAP client signing.
V-205921WN19-SO-000330mediumWindows Server 2019 session security for NTLM SSP-based clients must be configured to require NTLMv2 session security and 128-bit encryption.
V-205922WN19-SO-000340mediumWindows Server 2019 session security for NTLM SSP-based servers must be configured to require NTLMv2 session security and 128-bit encryption.
V-205923WN19-SO-000370lowWindows Server 2019 default permissions of global system objects must be strengthened.
V-205924WN19-UC-000010mediumWindows Server 2019 must preserve zone information when saving attachments.
V-205925WN19-CC-000450mediumWindows Server 2019 must disable automatically signing in the last interactive user after a system-initiated restart.
V-214936WN19-00-000280mediumWindows Server 2019 must have a host-based firewall installed and enabled.
V-220697WN10-00-000005mediumDomain-joined systems must use Windows 10 Enterprise Edition 64-bit version.
V-220698WN10-00-000010mediumWindows 10 domain-joined systems must have a Trusted Platform Module (TPM) enabled and ready for use.
V-220699WN10-00-000015mediumWindows 10 systems must have Unified Extensible Firmware Interface (UEFI) firmware and be configured to run in UEFI mode, not Legacy BIOS.
V-220700WN10-00-000020lowSecure Boot must be enabled on Windows 10 systems.
V-220701WN10-00-000025mediumWindows 10 must employ automated mechanisms to determine the state of system components with regard to flaw remediation using the following frequency: Continuously, where ESS is used; 30 days, for any additional internal network scans not covered by ESS; and annually, for external scans by Computer Network Defense Service Provider (CNDSP).
V-220706WN10-00-000040highWindows 10 systems must be maintained at a supported servicing level.
V-220707WN10-00-000045highThe Windows 10 system must use an anti-virus program.
V-220709WN10-00-000055mediumAlternate operating systems must not be permitted on the same system.
V-220713WN10-00-000075mediumOnly accounts responsible for the backup operations must be members of the Backup Operators group.
V-220715WN10-00-000085lowStandard local user accounts must not exist on a system in a domain.
V-220723WN10-00-000130mediumSoftware certificate installation files must be removed from Windows 10.
V-220724WN10-00-000135mediumA host-based firewall must be installed and enabled on the system.
V-220725WN10-00-000140mediumInbound exceptions to the firewall on Windows 10 domain workstations must only allow authorized remote management hosts.
V-220733WN10-00-000190mediumOrphaned security identifiers (SIDs) must be removed from user rights on Windows 10.
V-220736WN10-00-000230mediumThe system must notify the user when a Bluetooth device attempts to connect.
V-220737WN10-00-000240highAdministrative accounts must not be used with applications that access the Internet, such as web browsers, or with potential Internet sources, such as email.
V-220795WN10-CC-000020mediumIPv6 source routing must be configured to highest protection.
V-220796WN10-CC-000025mediumThe system must be configured to prevent IP source routing.
V-220797WN10-CC-000030lowThe system must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF) generated routes.
V-220802WN10-CC-000040mediumInsecure logons to an SMB server must be disabled.
V-220806WN10-CC-000055mediumSimultaneous connections to the internet or a Windows domain must be limited.
V-220807WN10-CC-000060mediumConnections to non-domain networks when connected to a domain authenticated network must be blocked.
V-220808WN10-CC-000065mediumWi-Fi Sense must be disabled.
V-220810WN10-CC-000068mediumWindows 10 must be configured to enable Remote host allows delegation of non-exportable credentials.
V-220811WN10-CC-000070mediumVirtualization Based Security must be enabled on Windows 10 with the platform security level configured to Secure Boot or Secure Boot with DMA Protection.
V-220812WN10-CC-000075highCredential Guard must be running on Windows 10 domain-joined systems.
V-220813WN10-CC-000085mediumEarly Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers.
V-220814WN10-CC-000090mediumGroup Policy objects must be reprocessed even if they have not changed.
V-220818WN10-CC-000115mediumSystems must at least attempt device authentication using certificates.
V-220825WN10-CC-000170lowThe setting to allow Microsoft accounts to be optional for modern style apps must be enabled.
V-220830WN10-CC-000195mediumEnhanced anti-spoofing for facial recognition must be enabled on Window 10.
V-220833WN10-CC-000204mediumIf Enhanced diagnostic data is enabled it must be limited to the minimum required to support Windows Analytics.
V-220834WN10-CC-000205mediumWindows Telemetry must not be configured to Full.
V-220835WN10-CC-000206lowWindows Update must not obtain updates from other PCs on the internet.
V-220839WN10-CC-000225mediumFile Explorer shell protocol must run in protected mode.
V-220840WN10-CC-000230mediumUsers must not be allowed to ignore Windows Defender SmartScreen filter warnings for malicious websites in Microsoft Edge.
V-220841WN10-CC-000235mediumUsers must not be allowed to ignore Windows Defender SmartScreen filter warnings for unverified files in Microsoft Edge.
V-220842WN10-CC-000238mediumWindows 10 must be configured to prevent certificate error overrides in Microsoft Edge.
V-220843WN10-CC-000245mediumThe password manager function in the Edge browser must be disabled.
V-220844WN10-CC-000250mediumThe Windows Defender SmartScreen filter for Microsoft Edge must be enabled.
V-220846WN10-CC-000255mediumThe use of a hardware security device with Windows Hello for Business must be enabled.
V-220847WN10-CC-000260mediumWindows 10 must be configured to require a minimum pin length of six characters or greater.
V-220853WN10-CC-000295mediumAttachments must be prevented from being downloaded from RSS feeds.
V-220858WN10-CC-000320mediumUsers must be notified if a web-based program attempts to install software.
V-220859WN10-CC-000325mediumAutomatically signing in the last interactive user after a system-initiated restart must be disabled.
V-220910WN10-SO-000015mediumLocal accounts with blank passwords must be restricted to prevent access from the network.
V-220911WN10-SO-000020mediumThe built-in administrator account must be renamed.
V-220912WN10-SO-000025mediumThe built-in guest account must be renamed.
V-220917WN10-SO-000050lowThe computer account password must not be prevented from being reset.
V-220918WN10-SO-000055lowThe maximum age for machine account passwords must be configured to 30 days or less.
V-220923WN10-SO-000085lowCaching of logon credentials must be limited.
V-220924WN10-SO-000095mediumThe Smart Card removal option must be configured to Force Logoff or Lock Workstation.
V-220928WN10-SO-000140highAnonymous SID/Name translation must not be allowed.
V-220929WN10-SO-000145highAnonymous enumeration of SAM accounts must not be allowed.
V-220931WN10-SO-000160mediumThe system must be configured to prevent anonymous users from having the same rights as the Everyone group.
V-220934WN10-SO-000180mediumNTLM must be prevented from falling back to a Null session.
V-220935WN10-SO-000185mediumPKU2U authentication using online identities must be prevented.
V-220938WN10-SO-000205highThe LanMan authentication level must be set to send NTLMv2 response only, and to refuse LM and NTLM.
V-220939WN10-SO-000210mediumThe system must be configured to the required LDAP client signing level.
V-220940WN10-SO-000215mediumThe system must be configured to meet the minimum session security requirement for NTLM SSP based clients.
V-220941WN10-SO-000220mediumThe system must be configured to meet the minimum session security requirement for NTLM SSP based servers.
V-220943WN10-SO-000240lowThe default permissions of global system objects must be increased.
V-220955WN10-UC-000020mediumZone information must be preserved when saving attachments.
V-221574DTBC-0025mediumNetwork prediction must be disabled.
V-230221RHEL-08-010000highRHEL 8 must be a vendor-supported release.
V-230222RHEL-08-010010mediumRHEL 8 vendor packaged system security patches and updates must be installed and up to date.
V-230253RHEL-08-010292lowRHEL 8 must ensure the SSH server uses strong entropy.
V-230283RHEL-08-010460highThere must be no shosts.equiv files on the RHEL 8 operating system.
V-230284RHEL-08-010470highThere must be no .shosts files on the RHEL 8 operating system.
V-230285RHEL-08-010471lowRHEL 8 must enable the hardware random number generator entropy gatherer service.
V-230286RHEL-08-010480mediumThe RHEL 8 SSH public host key files must have mode 0644 or less permissive.
V-230287RHEL-08-010490mediumThe RHEL 8 SSH private host key files must have mode 0640 or less permissive.
V-230288RHEL-08-010500mediumThe RHEL 8 SSH daemon must perform strict mode checking of home directory configuration files.
V-230290RHEL-08-010520mediumThe RHEL 8 SSH daemon must not allow authentication using known host’s authentication.
V-230291RHEL-08-010521mediumThe RHEL 8 SSH daemon must not allow Kerberos authentication, except to fulfill documented and validated mission requirements.
V-230292RHEL-08-010540lowRHEL 8 must use a separate file system for /var.
V-230293RHEL-08-010541lowRHEL 8 must use a separate file system for /var/log.
V-230294RHEL-08-010542lowRHEL 8 must use a separate file system for the system audit data path.
V-230295RHEL-08-010543mediumA separate RHEL 8 filesystem must be used for the /tmp directory.
V-230298RHEL-08-010561mediumThe rsyslog service must be running in RHEL 8.
V-230299RHEL-08-010570mediumRHEL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories.
V-230300RHEL-08-010571mediumRHEL 8 must prevent files with the setuid and setgid bit set from being executed on the /boot directory.
V-230301RHEL-08-010580mediumRHEL 8 must prevent special devices on non-root local partitions.
V-230302RHEL-08-010590mediumRHEL 8 must prevent code from being executed on file systems that contain user home directories.
V-230303RHEL-08-010600mediumRHEL 8 must prevent special devices on file systems that are used with removable media.
V-230304RHEL-08-010610mediumRHEL 8 must prevent code from being executed on file systems that are used with removable media.
V-230305RHEL-08-010620mediumRHEL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that are used with removable media.
V-230306RHEL-08-010630mediumRHEL 8 must prevent code from being executed on file systems that are imported via Network File System (NFS).
V-230307RHEL-08-010640mediumRHEL 8 must prevent special devices on file systems that are imported via Network File System (NFS).
V-230308RHEL-08-010650mediumRHEL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that are imported via Network File System (NFS).
V-230309RHEL-08-010660mediumLocal RHEL 8 initialization files must not execute world-writable programs.
V-230310RHEL-08-010670mediumRHEL 8 must disable kernel dumps unless needed.
V-230311RHEL-08-010671mediumRHEL 8 must disable the kernel.core_pattern.
V-230312RHEL-08-010672mediumRHEL 8 must disable acquiring, saving, and processing core dumps.
V-230313RHEL-08-010673mediumRHEL 8 must disable core dumps for all users.
V-230314RHEL-08-010674mediumRHEL 8 must disable storing core dumps.
V-230315RHEL-08-010675mediumRHEL 8 must disable core dump backtraces.
V-230316RHEL-08-010680mediumFor RHEL 8 systems using Domain Name Servers (DNS) resolution, at least two name servers must be configured.
V-230317RHEL-08-010690mediumExecutable search paths within the initialization files of all local interactive RHEL 8 users must only contain paths that resolve to the system default or the users home directory.
V-230318RHEL-08-010700mediumAll RHEL 8 world-writable directories must be owned by root, sys, bin, or an application user.
V-230319RHEL-08-010710mediumAll RHEL 8 world-writable directories must be group-owned by root, sys, bin, or an application group.
V-230320RHEL-08-010720mediumAll RHEL 8 local interactive users must have a home directory assigned in the /etc/passwd file.
V-230321RHEL-08-010730mediumAll RHEL 8 local interactive user home directories must have mode 0750 or less permissive.
V-230322RHEL-08-010740mediumAll RHEL 8 local interactive user home directories must be group-owned by the home directory owner’s primary group.
V-230323RHEL-08-010750mediumAll RHEL 8 local interactive user home directories defined in the /etc/passwd file must exist.
V-230324RHEL-08-010760mediumAll RHEL 8 local interactive user accounts must be assigned a home directory upon creation.
V-230325RHEL-08-010770mediumAll RHEL 8 local initialization files must have mode 0740 or less permissive.
V-230326RHEL-08-010780mediumAll RHEL 8 local files and directories must have a valid owner.
V-230327RHEL-08-010790mediumAll RHEL 8 local files and directories must have a valid group owner.
V-230328RHEL-08-010800mediumA separate RHEL 8 filesystem must be used for user home directories (such as /home or an equivalent).
V-230329RHEL-08-010820highUnattended or automatic logon via the RHEL 8 graphical user interface must not be allowed.
V-230330RHEL-08-010830mediumRHEL 8 must not allow users to override SSH environment variables.
V-230356RHEL-08-020100mediumRHEL 8 must ensure the password complexity module is enabled in the password-auth file.
V-230377RHEL-08-020300mediumRHEL 8 must prevent the use of dictionary words for passwords.
V-230378RHEL-08-020310mediumRHEL 8 must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
V-230379RHEL-08-020320mediumRHEL 8 must not have unnecessary accounts.
V-230380RHEL-08-020330highRHEL 8 must not allow accounts configured with blank or null passwords.
V-230383RHEL-08-020351mediumRHEL 8 must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.
V-230384RHEL-08-020352mediumRHEL 8 must set the umask value to 077 for all local interactive user accounts.
V-230385RHEL-08-020353mediumRHEL 8 must define default permissions for logon and non-logon shells.
V-230387RHEL-08-030010mediumCron logging must be implemented in RHEL 8.
V-230393RHEL-08-030061mediumThe RHEL 8 audit system must audit local events.
V-230395RHEL-08-030063lowRHEL 8 must resolve audit information before writing to disk.
V-230477RHEL-08-030670mediumRHEL 8 must have the packages required for offloading audit logs installed.
V-230478RHEL-08-030680mediumRHEL 8 must have the packages required for encrypting offloaded audit logs installed.
V-230529RHEL-08-040170highThe x86 Ctrl-Alt-Delete key sequence must be disabled on RHEL 8.
V-230530RHEL-08-040171highThe x86 Ctrl-Alt-Delete key sequence in RHEL 8 must be disabled if a graphical user interface is installed.
V-230531RHEL-08-040172highThe systemd Ctrl-Alt-Delete burst key sequence in RHEL 8 must be disabled.
V-230532RHEL-08-040180mediumThe debug-shell systemd service must be disabled on RHEL 8.
V-230533RHEL-08-040190highThe Trivial File Transfer Protocol (TFTP) server package must not be installed if not required for RHEL 8 operational support.
V-230534RHEL-08-040200highThe root account must be the only account having unrestricted access to the RHEL 8 system.
V-230535RHEL-08-040210mediumRHEL 8 must prevent IPv6 Internet Control Message Protocol (ICMP) redirect messages from being accepted.
V-230536RHEL-08-040220mediumRHEL 8 must not send Internet Control Message Protocol (ICMP) redirects.
V-230537RHEL-08-040230mediumRHEL 8 must not respond to Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.
V-230538RHEL-08-040240mediumRHEL 8 must not forward IPv6 source-routed packets.
V-230539RHEL-08-040250mediumRHEL 8 must not forward IPv6 source-routed packets by default.
V-230540RHEL-08-040260mediumRHEL 8 must not enable IPv6 packet forwarding unless the system is a router.
V-230541RHEL-08-040261mediumRHEL 8 must not accept router advertisements on all IPv6 interfaces.
V-230542RHEL-08-040262mediumRHEL 8 must not accept router advertisements on all IPv6 interfaces by default.
V-230543RHEL-08-040270mediumRHEL 8 must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default.
V-230544RHEL-08-040280mediumRHEL 8 must ignore IPv6 Internet Control Message Protocol (ICMP) redirect messages.
V-230545RHEL-08-040281mediumRHEL 8 must disable access to network bpf syscall from unprivileged processes.
V-230546RHEL-08-040282mediumRHEL 8 must restrict usage of ptrace to descendant processes.
V-230547RHEL-08-040283mediumRHEL 8 must restrict exposed kernel pointer addresses access.
V-230548RHEL-08-040284mediumRHEL 8 must disable the use of user namespaces.
V-230549RHEL-08-040285mediumRHEL 8 must use reverse path filtering on all IPv4 interfaces.
V-230550RHEL-08-040290mediumRHEL 8 must be configured to prevent unrestricted mail relaying.
V-230551RHEL-08-040300lowThe RHEL 8 file integrity tool must be configured to verify extended attributes.
V-230552RHEL-08-040310lowThe RHEL 8 file integrity tool must be configured to verify Access Control Lists (ACLs).
V-230553RHEL-08-040320mediumThe graphical display manager must not be installed on RHEL 8 unless approved.
V-230554RHEL-08-040330mediumRHEL 8 network interfaces must not be in promiscuous mode.
V-230555RHEL-08-040340mediumRHEL 8 remote X connections for interactive users must be disabled unless to fulfill documented and validated mission requirements.
V-230556RHEL-08-040341mediumThe RHEL 8 SSH daemon must prevent remote hosts from connecting to the proxy display.
V-230557RHEL-08-040350mediumIf the Trivial File Transfer Protocol (TFTP) server is required, the RHEL 8 TFTP daemon must be configured to operate in secure mode.
V-230558RHEL-08-040360highA File Transfer Protocol (FTP) server package must not be installed unless mission essential on RHEL 8.
V-230560RHEL-08-040380mediumThe iprutils package must not be installed unless mission essential on RHEL 8.
V-230561RHEL-08-040390mediumThe tuned package must not be installed unless mission essential on RHEL 8.
V-237641RHEL-08-010382mediumRHEL 8 must restrict privilege elevation to authorized personnel.
V-242383CNTR-K8-000290highUser-managed resources must be created in dedicated namespaces.
V-242408CNTR-K8-000900mediumThe Kubernetes manifest files must have least privileges.
V-242444CNTR-K8-003110mediumThe Kubernetes component manifests must be owned by root.
V-242445CNTR-K8-003120mediumThe Kubernetes component etcd must be owned by etcd.
V-242446CNTR-K8-003130mediumThe Kubernetes conf files must be owned by root.
V-242447CNTR-K8-003140mediumThe Kubernetes Kube Proxy kubeconfig must have file permissions set to 644 or more restrictive.
V-242448CNTR-K8-003150mediumThe Kubernetes Kube Proxy kubeconfig must be owned by root.
V-242449CNTR-K8-003160mediumThe Kubernetes Kubelet certificate authority file must have file permissions set to 644 or more restrictive.
V-242450CNTR-K8-003170mediumThe Kubernetes Kubelet certificate authority must be owned by root.
V-242451CNTR-K8-003180mediumThe Kubernetes component PKI must be owned by root.
V-242452CNTR-K8-003190mediumThe Kubernetes kubelet KubeConfig must have file permissions set to 644 or more restrictive.
V-242453CNTR-K8-003200mediumThe Kubernetes kubelet KubeConfig file must be owned by root.
V-242454CNTR-K8-003210mediumThe Kubernetes kubeadm.conf must be owned by root.
V-242455CNTR-K8-003220mediumThe Kubernetes kubeadm.conf must have file permissions set to 644 or more restrictive.
V-242456CNTR-K8-003230mediumThe Kubernetes kubelet config must have file permissions set to 644 or more restrictive.
V-242457CNTR-K8-003240mediumThe Kubernetes kubelet config must be owned by root.
V-242459CNTR-K8-003260mediumThe Kubernetes etcd must have file permissions set to 644 or more restrictive.
V-242460CNTR-K8-003270mediumThe Kubernetes admin kubeconfig must have file permissions set to 644 or more restrictive.
V-242461CNTR-K8-003280mediumKubernetes API Server audit logs must be enabled.
V-242462CNTR-K8-003290mediumThe Kubernetes API Server must be set to audit log max size.
V-242463CNTR-K8-003300mediumThe Kubernetes API Server must be set to audit log maximum backup.
V-242464CNTR-K8-003310mediumThe Kubernetes API Server audit log retention must be set.
V-242465CNTR-K8-003320mediumThe Kubernetes API Server audit log path must be set.
V-242466CNTR-K8-003330mediumThe Kubernetes PKI CRT must have file permissions set to 644 or more restrictive.
V-242467CNTR-K8-003340mediumThe Kubernetes PKI keys must have file permissions set to 600 or more restrictive.
V-244527RHEL-08-010472lowRHEL 8 must have the packages required to use the hardware random number generator entropy gatherer service.
V-244528RHEL-08-010522mediumThe RHEL 8 SSH daemon must not allow GSSAPI authentication, except to fulfill documented and validated mission requirements.
V-244529RHEL-08-010544mediumRHEL 8 must use a separate file system for /var/tmp.
V-244530RHEL-08-010572mediumRHEL 8 must prevent files with the setuid and setgid bit set from being executed on the /boot/efi directory.
V-244531RHEL-08-010731mediumAll RHEL 8 local interactive user home directory files must have mode 0750 or less permissive.
V-244532RHEL-08-010741mediumRHEL 8 must be configured so that all files and directories contained in local interactive user home directories are group-owned by a group of which the home directory owner is a member.
V-244536RHEL-08-020032mediumRHEL 8 must disable the user list at logon for graphical user interfaces.
V-244541RHEL-08-020332highRHEL 8 must not allow blank or null passwords in the password-auth file.
V-244550RHEL-08-040209mediumRHEL 8 must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted.
V-244551RHEL-08-040239mediumRHEL 8 must not forward IPv4 source-routed packets.
V-244552RHEL-08-040249mediumRHEL 8 must not forward IPv4 source-routed packets by default.
V-244553RHEL-08-040279mediumRHEL 8 must ignore IPv4 Internet Control Message Protocol (ICMP) redirect messages.
V-244554RHEL-08-040286mediumRHEL 8 must enable hardening for the Berkeley Packet Filter Just-in-time compiler.
V-250317RHEL-08-040259mediumRHEL 8 must not enable IPv4 packet forwarding unless the system is a router.
V-250319WN10-CC-000050mediumHardened UNC paths must be defined to require mutual authentication and integrity for at least the \\*\SYSVOL and \\*\NETLOGON shares.
V-251706RHEL-08-010121highThe RHEL 8 operating system must not have accounts configured with blank or null passwords.
V-251711RHEL-08-010379mediumRHEL 8 must specify the default "include" directory for the /etc/sudoers file.
V-251713RHEL-08-020101mediumRHEL 8 must ensure the password complexity module is enabled in the system-auth file.
V-251716RHEL-08-020104mediumRHEL 8 systems, version 8.4 and above, must ensure the password complexity module is configured for three retries or less.
V-251718RHEL-08-040321mediumThe graphical display manager must not be the default target on RHEL 8 unless approved.
V-252903WN10-CC-000080lowVirtualization-based protection of code integrity must be enabled.
V-253254WN11-00-000005mediumDomain-joined systems must use Windows 11 Enterprise Edition 64-bit version.
V-253258WN11-00-000025mediumWindows 11 must employ automated mechanisms to determine the state of system components with regard to flaw remediation using the following frequency: Continuously, where ESS is used; 30 days, for any additional internal network scans not covered by ESS; and annually, for external scans by Computer Network Defense Service Provider (CNDSP).
V-253263WN11-00-000040highWindows 11 systems must be maintained at a supported servicing level.
V-253264WN11-00-000045highThe Windows 11 system must use an antivirus program.
V-253266WN11-00-000055mediumAlternate operating systems must not be permitted on the same system.
V-253270WN11-00-000075mediumOnly accounts responsible for the backup operations must be members of the Backup Operators group.
V-253272WN11-00-000085lowStandard local user accounts must not exist on a system in a domain.
V-253280WN11-00-000130mediumSoftware certificate installation files must be removed from Windows 11.
V-253281WN11-00-000135mediumA host-based firewall must be installed and enabled on the system.
V-253282WN11-00-000140mediumInbound exceptions to the firewall on Windows 11 domain workstations must only allow authorized remote management hosts.
V-253290WN11-00-000190mediumOrphaned security identifiers (SIDs) must be removed from user rights on Windows 11.
V-253293WN11-00-000230mediumThe system must notify the user when a Bluetooth device attempts to connect.
V-253294WN11-00-000240highAdministrative accounts must not be used with applications that access the internet, such as web browsers, or with potential internet sources, such as email.
V-253353WN11-CC-000020mediumIPv6 source routing must be configured to highest protection.
V-253354WN11-CC-000025mediumThe system must be configured to prevent IP source routing.
V-253355WN11-CC-000030lowThe system must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF) generated routes.
V-253360WN11-CC-000040mediumInsecure logons to an SMB server must be disabled.
V-253362WN11-CC-000050mediumHardened UNC Paths must be defined to require mutual authentication and integrity for at least the \\*\SYSVOL and \\*\NETLOGON shares.
V-253365WN11-CC-000060mediumConnections to non-domain networks when connected to a domain authenticated network must be blocked.
V-253366WN11-CC-000065mediumWi-Fi Sense must be disabled.
V-253368WN11-CC-000068mediumWindows 11 must be configured to enable Remote host allows delegation of non-exportable credentials.
V-253369WN11-CC-000070mediumVirtualization-based Security must be enabled on Windows 11 with the platform security level configured to Secure Boot or Secure Boot with DMA Protection.
V-253370WN11-CC-000075highCredential Guard must be running on Windows 11 domain-joined systems.
V-253371WN11-CC-000080mediumVirtualization-based protection of code integrity must be enabled.
V-253372WN11-CC-000085mediumEarly Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers.
V-253373WN11-CC-000090mediumGroup Policy objects must be reprocessed even if they have not changed.
V-253377WN11-CC-000115mediumSystems must at least attempt device authentication using certificates.
V-253384WN11-CC-000170lowThe setting to allow Microsoft accounts to be optional for modern style apps must be enabled.
V-253389WN11-CC-000195mediumEnhanced anti-spoofing for facial recognition must be enabled on Windows 11.
V-253392WN11-CC-000204mediumEnhanced diagnostic data must be limited to the minimum required to support Windows Analytics.
V-253394WN11-CC-000206lowWindows Update must not obtain updates from other PCs on the internet.
V-253398WN11-CC-000225mediumFile Explorer shell protocol must run in protected mode.
V-253400WN11-CC-000255mediumThe use of a hardware security device with Windows Hello for Business must be enabled.
V-253401WN11-CC-000260mediumWindows 11 must be configured to require a minimum pin length of six characters or greater.
V-253407WN11-CC-000295mediumAttachments must be prevented from being downloaded from RSS feeds.
V-253412WN11-CC-000320mediumUsers must be notified if a web-based program attempts to install software.
V-253413WN11-CC-000325mediumAutomatically signing in the last interactive user after a system-initiated restart must be disabled.
V-253434WN11-SO-000015mediumLocal accounts with blank passwords must be restricted to prevent access from the network.
V-253435WN11-SO-000020mediumThe built-in administrator account must be renamed.

Get this as data

The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/CM-6. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.