CM-6 Configuration Settings
Configuration Management family. 26 Control Correlation Identifiers map to this control, and 525 STIG rules implement those CCIs.
The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.
It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.
Where these rules come from
| STIG benchmark | Version | Rules mapped to CM-6 |
|---|---|---|
| Red Hat Enterprise Linux 9 | V2 | 148 |
| Red Hat Enterprise Linux 8 | V2 | 114 |
| Microsoft Windows 10 | V3 | 67 |
| Microsoft Windows Server 2019 | V3 | 57 |
| Microsoft Windows 11 | V2 | 57 |
| Microsoft Windows Server 2022 | V2 | 56 |
| Kubernetes | V2 | 25 |
| Google Chrome Current Windows | V2 | 1 |
Control Correlation Identifiers mapped to CM-6
| CCI | Definition | Rev |
|---|---|---|
| CCI-000363 | The organization defines security configuration checklists to be used to establish and document configuration settings for the information system technology products employed. | 4 |
| CCI-000364 | The organization establishes configuration settings for information technology products employed within the information system using organization-defined security configuration checklists. | 4 |
| CCI-000365 | The organization documents configuration settings for information technology products employed within the information system using organization-defined security configuration checklists that reflect the most restrictive mode consistent with operational requirements. | 4 |
| CCI-000366 | Implement the security configuration settings. | 5, 4 |
| CCI-000367 | Identify any deviations from the established configuration settings for organization-defined system components based on organization-defined operational requirements. | 5, 4 |
| CCI-000368 | Document any deviations from the established configuration settings for organization-defined system components based on organization-defined operational requirements. | 5, 4 |
| CCI-000369 | Approve any deviations from the established configuration settings for organization-defined system components based on organization-defined operational requirements. | 5, 4 |
| CCI-000370 | Manage configuration settings for organization-defined system components using organization-defined automated mechanisms. | 5, 4 |
| CCI-000371 | Apply configuration settings for organization-defined system components using organization-defined automated mechanisms. | 5, 4 |
| CCI-000372 | Verify configuration settings for organization-defined system components using organization-defined automated mechanisms. | 5, 4 |
| CCI-001502 | The organization monitors changes to the configuration settings in accordance with organizational policies and procedures. | 4 |
| CCI-001503 | The organization controls changes to the configuration settings in accordance with organizational policies and procedures. | 4 |
| CCI-001588 | The organization-defined security configuration checklists reflect the most restrictive mode consistent with operational requirements. | 4 |
| CCI-001755 | Defines the system components for which any deviation from the established configuration settings are to be identified, documented, and approved. | 5, 4 |
| CCI-001756 | Defines the operational requirements on which the configuration settings for the organization-defined system components are to be based. | 5, 4 |
| CCI-001757 | Defines the actions to employ when responding to unauthorized changes to the organization-defined configuration settings. | 5, 4 |
| CCI-001758 | Defines the configuration settings for which to employ organization-defined actions in response to unauthorized changes. | 5, 4 |
| CCI-001759 | Take organization-defined actions in response to unauthorized changes to organization-defined configuration settings. | 5, 4 |
| CCI-002059 | Defines the system components for which the organization will employ automated mechanisms to centrally manage, apply, and verify configuration settings. | 5, 4 |
| CCI-003941 | Establish and document configuration settings for components employed within the system that reflect the most restrictive mode consistent with operational requirements using organization-defined common secure configurations. | 5 |
| CCI-003942 | Defines the common secure configurations for establishing and documenting configuration settings within the system, that reflect the most restrictive mode consistent with operational requirements. | 5 |
| CCI-003943 | Monitor changes to the configuration settings in accordance with organizational policies. | 5 |
| CCI-003944 | Monitor changes to the configuration settings in accordance with organizational procedures. | 5 |
| CCI-003945 | Control changes to the configuration settings in accordance with organizational policies. | 5 |
| CCI-003946 | Control changes to the configuration settings in accordance with organizational procedures. | 5 |
| CCI-003947 | Defines the automated mechanisms for managing, applying, and verifying configuration settings. | 5 |
STIG rules that implement CM-6
Showing the first 300 of 525. The complete set is available from the API endpoint linked below.
| Rule | STIG ID | Severity | Requirement |
|---|---|---|---|
| V-205728 | WN19-00-000290 | medium | Windows Server 2019 must employ automated mechanisms to determine the state of system components with regard to flaw remediation using the following frequency: continuously, where Endpoint Security Solution (ESS) is used; 30 days, for any additional internal network scans not covered by ESS; and annually, for external scans by Computer Network Defense Service Provider (CNDSP). |
| V-205838 | WN19-AU-000180 | medium | Windows Server 2019 must be configured to audit logoff successes. |
| V-205844 | WN19-00-000010 | high | Windows Server 2019 users with Administrative privileges must have separate accounts for administrative duties and normal operational tasks. |
| V-205845 | WN19-00-000030 | high | Windows Server 2019 administrative accounts must not be used with applications that access the Internet, such as web browsers, or with potential Internet sources, such as email. |
| V-205846 | WN19-00-000040 | medium | Windows Server 2019 members of the Backup Operators group must have separate accounts for backup duties and normal operational tasks. |
| V-205847 | WN19-00-000060 | medium | Windows Server 2019 manually managed application account passwords must be changed at least annually or when a system administrator with knowledge of the password leaves the organization. |
| V-205848 | WN19-00-000090 | medium | Windows Server 2019 domain-joined systems must have a Trusted Platform Module (TPM) enabled and ready for use. |
| V-205849 | WN19-00-000100 | high | Windows Server 2019 must be maintained at a supported servicing level. |
| V-205850 | WN19-00-000110 | high | Windows Server 2019 must use an anti-virus program. |
| V-205851 | WN19-00-000120 | medium | Windows Server 2019 must have a host-based intrusion detection or prevention system. |
| V-205852 | WN19-00-000240 | medium | Windows Server 2019 must have software certificate installation files removed. |
| V-205853 | WN19-00-000420 | medium | Windows Server 2019 FTP servers must be configured to prevent anonymous logons. |
| V-205854 | WN19-00-000430 | medium | Windows Server 2019 FTP servers must be configured to prevent access to the system drive. |
| V-205855 | WN19-00-000450 | medium | Windows Server 2019 must have orphaned security identifiers (SIDs) removed from user rights. |
| V-205856 | WN19-00-000460 | low | Windows Server 2019 systems must have Unified Extensible Firmware Interface (UEFI) firmware and be configured to run in UEFI mode, not Legacy BIOS. |
| V-205857 | WN19-00-000470 | low | Windows Server 2019 must have Secure Boot enabled. |
| V-205858 | WN19-CC-000030 | low | Windows Server 2019 Internet Protocol version 6 (IPv6) source routing must be configured to the highest protection level to prevent IP source routing. |
| V-205859 | WN19-CC-000040 | low | Windows Server 2019 source routing must be configured to the highest protection level to prevent Internet Protocol (IP) source routing. |
| V-205860 | WN19-CC-000050 | low | Windows Server 2019 must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF)-generated routes. |
| V-205861 | WN19-CC-000070 | medium | Windows Server 2019 insecure logons to an SMB server must be disabled. |
| V-205862 | WN19-CC-000080 | medium | Windows Server 2019 hardened Universal Naming Convention (UNC) paths must be defined to require mutual authentication and integrity for at least the \\*\SYSVOL and \\*\NETLOGON shares. |
| V-205863 | WN19-CC-000100 | medium | Windows Server 2019 must be configured to enable Remote host allows delegation of non-exportable credentials. |
| V-205864 | WN19-CC-000110 | medium | Windows Server 2019 virtualization-based security must be enabled with the platform security level configured to Secure Boot or Secure Boot with DMA Protection. |
| V-205865 | WN19-CC-000130 | medium | Windows Server 2019 Early Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers identified as bad. |
| V-205866 | WN19-CC-000140 | medium | Windows Server 2019 group policy objects must be reprocessed even if they have not changed. |
| V-205867 | WN19-CC-000180 | medium | Windows Server 2019 users must be prompted to authenticate when the system wakes from sleep (on battery). |
| V-205868 | WN19-CC-000190 | medium | Windows Server 2019 users must be prompted to authenticate when the system wakes from sleep (plugged in). |
| V-205869 | WN19-CC-000250 | medium | Windows Server 2019 Telemetry must be configured to Security or Basic. |
| V-205870 | WN19-CC-000260 | low | Windows Server 2019 Windows Update must not obtain updates from other PCs on the Internet. |
| V-205871 | WN19-CC-000320 | low | Windows Server 2019 Turning off File Explorer heap termination on corruption must be disabled. |
| V-205872 | WN19-CC-000330 | medium | Windows Server 2019 File Explorer shell protocol must run in protected mode. |
| V-205873 | WN19-CC-000390 | medium | Windows Server 2019 must prevent attachments from being downloaded from RSS feeds. |
| V-205874 | WN19-CC-000440 | medium | Windows Server 2019 users must be notified if a web-based program attempts to install software. |
| V-205875 | WN19-DC-000150 | high | Windows Server 2019 directory data (outside the root DSE) of a non-public directory must be configured to prevent anonymous access. |
| V-205876 | WN19-DC-000330 | medium | Windows Server 2019 domain controllers must be configured to allow reset of machine account passwords. |
| V-205877 | WN19-DC-000430 | medium | The password for the krbtgt account on a domain must be reset at least every 180 days. |
| V-205906 | WN19-MS-000050 | medium | Windows Server 2019 must limit the caching of logon credentials to four or less on domain-joined member servers. |
| V-205907 | WN19-MS-000140 | high | Windows Server 2019 must be running Credential Guard on domain-joined member servers. |
| V-205908 | WN19-SO-000020 | high | Windows Server 2019 must prevent local accounts with blank passwords from being used from the network. |
| V-205909 | WN19-SO-000030 | medium | Windows Server 2019 built-in administrator account must be renamed. |
| V-205910 | WN19-SO-000040 | medium | Windows Server 2019 built-in guest account must be renamed. |
| V-205911 | WN19-SO-000100 | medium | Windows Server 2019 maximum age for machine account passwords must be configured to 30 days or less. |
| V-205912 | WN19-SO-000150 | medium | Windows Server 2019 Smart Card removal option must be configured to Force Logoff or Lock Workstation. |
| V-205913 | WN19-SO-000210 | high | Windows Server 2019 must not allow anonymous SID/Name translation. |
| V-205914 | WN19-SO-000220 | high | Windows Server 2019 must not allow anonymous enumeration of Security Account Manager (SAM) accounts. |
| V-205915 | WN19-SO-000240 | medium | Windows Server 2019 must be configured to prevent anonymous users from having the same permissions as the Everyone group. |
| V-205916 | WN19-SO-000260 | medium | Windows Server 2019 services using Local System that use Negotiate when reverting to NTLM authentication must use the computer identity instead of authenticating anonymously. |
| V-205917 | WN19-SO-000270 | medium | Windows Server 2019 must prevent NTLM from falling back to a Null session. |
| V-205918 | WN19-SO-000280 | medium | Windows Server 2019 must prevent PKU2U authentication using online identities. |
| V-205919 | WN19-SO-000310 | high | Windows Server 2019 LAN Manager authentication level must be configured to send NTLMv2 response only and to refuse LM and NTLM. |
| V-205920 | WN19-SO-000320 | medium | Windows Server 2019 must be configured to at least negotiate signing for LDAP client signing. |
| V-205921 | WN19-SO-000330 | medium | Windows Server 2019 session security for NTLM SSP-based clients must be configured to require NTLMv2 session security and 128-bit encryption. |
| V-205922 | WN19-SO-000340 | medium | Windows Server 2019 session security for NTLM SSP-based servers must be configured to require NTLMv2 session security and 128-bit encryption. |
| V-205923 | WN19-SO-000370 | low | Windows Server 2019 default permissions of global system objects must be strengthened. |
| V-205924 | WN19-UC-000010 | medium | Windows Server 2019 must preserve zone information when saving attachments. |
| V-205925 | WN19-CC-000450 | medium | Windows Server 2019 must disable automatically signing in the last interactive user after a system-initiated restart. |
| V-214936 | WN19-00-000280 | medium | Windows Server 2019 must have a host-based firewall installed and enabled. |
| V-220697 | WN10-00-000005 | medium | Domain-joined systems must use Windows 10 Enterprise Edition 64-bit version. |
| V-220698 | WN10-00-000010 | medium | Windows 10 domain-joined systems must have a Trusted Platform Module (TPM) enabled and ready for use. |
| V-220699 | WN10-00-000015 | medium | Windows 10 systems must have Unified Extensible Firmware Interface (UEFI) firmware and be configured to run in UEFI mode, not Legacy BIOS. |
| V-220700 | WN10-00-000020 | low | Secure Boot must be enabled on Windows 10 systems. |
| V-220701 | WN10-00-000025 | medium | Windows 10 must employ automated mechanisms to determine the state of system components with regard to flaw remediation using the following frequency: Continuously, where ESS is used; 30 days, for any additional internal network scans not covered by ESS; and annually, for external scans by Computer Network Defense Service Provider (CNDSP). |
| V-220706 | WN10-00-000040 | high | Windows 10 systems must be maintained at a supported servicing level. |
| V-220707 | WN10-00-000045 | high | The Windows 10 system must use an anti-virus program. |
| V-220709 | WN10-00-000055 | medium | Alternate operating systems must not be permitted on the same system. |
| V-220713 | WN10-00-000075 | medium | Only accounts responsible for the backup operations must be members of the Backup Operators group. |
| V-220715 | WN10-00-000085 | low | Standard local user accounts must not exist on a system in a domain. |
| V-220723 | WN10-00-000130 | medium | Software certificate installation files must be removed from Windows 10. |
| V-220724 | WN10-00-000135 | medium | A host-based firewall must be installed and enabled on the system. |
| V-220725 | WN10-00-000140 | medium | Inbound exceptions to the firewall on Windows 10 domain workstations must only allow authorized remote management hosts. |
| V-220733 | WN10-00-000190 | medium | Orphaned security identifiers (SIDs) must be removed from user rights on Windows 10. |
| V-220736 | WN10-00-000230 | medium | The system must notify the user when a Bluetooth device attempts to connect. |
| V-220737 | WN10-00-000240 | high | Administrative accounts must not be used with applications that access the Internet, such as web browsers, or with potential Internet sources, such as email. |
| V-220795 | WN10-CC-000020 | medium | IPv6 source routing must be configured to highest protection. |
| V-220796 | WN10-CC-000025 | medium | The system must be configured to prevent IP source routing. |
| V-220797 | WN10-CC-000030 | low | The system must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF) generated routes. |
| V-220802 | WN10-CC-000040 | medium | Insecure logons to an SMB server must be disabled. |
| V-220806 | WN10-CC-000055 | medium | Simultaneous connections to the internet or a Windows domain must be limited. |
| V-220807 | WN10-CC-000060 | medium | Connections to non-domain networks when connected to a domain authenticated network must be blocked. |
| V-220808 | WN10-CC-000065 | medium | Wi-Fi Sense must be disabled. |
| V-220810 | WN10-CC-000068 | medium | Windows 10 must be configured to enable Remote host allows delegation of non-exportable credentials. |
| V-220811 | WN10-CC-000070 | medium | Virtualization Based Security must be enabled on Windows 10 with the platform security level configured to Secure Boot or Secure Boot with DMA Protection. |
| V-220812 | WN10-CC-000075 | high | Credential Guard must be running on Windows 10 domain-joined systems. |
| V-220813 | WN10-CC-000085 | medium | Early Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers. |
| V-220814 | WN10-CC-000090 | medium | Group Policy objects must be reprocessed even if they have not changed. |
| V-220818 | WN10-CC-000115 | medium | Systems must at least attempt device authentication using certificates. |
| V-220825 | WN10-CC-000170 | low | The setting to allow Microsoft accounts to be optional for modern style apps must be enabled. |
| V-220830 | WN10-CC-000195 | medium | Enhanced anti-spoofing for facial recognition must be enabled on Window 10. |
| V-220833 | WN10-CC-000204 | medium | If Enhanced diagnostic data is enabled it must be limited to the minimum required to support Windows Analytics. |
| V-220834 | WN10-CC-000205 | medium | Windows Telemetry must not be configured to Full. |
| V-220835 | WN10-CC-000206 | low | Windows Update must not obtain updates from other PCs on the internet. |
| V-220839 | WN10-CC-000225 | medium | File Explorer shell protocol must run in protected mode. |
| V-220840 | WN10-CC-000230 | medium | Users must not be allowed to ignore Windows Defender SmartScreen filter warnings for malicious websites in Microsoft Edge. |
| V-220841 | WN10-CC-000235 | medium | Users must not be allowed to ignore Windows Defender SmartScreen filter warnings for unverified files in Microsoft Edge. |
| V-220842 | WN10-CC-000238 | medium | Windows 10 must be configured to prevent certificate error overrides in Microsoft Edge. |
| V-220843 | WN10-CC-000245 | medium | The password manager function in the Edge browser must be disabled. |
| V-220844 | WN10-CC-000250 | medium | The Windows Defender SmartScreen filter for Microsoft Edge must be enabled. |
| V-220846 | WN10-CC-000255 | medium | The use of a hardware security device with Windows Hello for Business must be enabled. |
| V-220847 | WN10-CC-000260 | medium | Windows 10 must be configured to require a minimum pin length of six characters or greater. |
| V-220853 | WN10-CC-000295 | medium | Attachments must be prevented from being downloaded from RSS feeds. |
| V-220858 | WN10-CC-000320 | medium | Users must be notified if a web-based program attempts to install software. |
| V-220859 | WN10-CC-000325 | medium | Automatically signing in the last interactive user after a system-initiated restart must be disabled. |
| V-220910 | WN10-SO-000015 | medium | Local accounts with blank passwords must be restricted to prevent access from the network. |
| V-220911 | WN10-SO-000020 | medium | The built-in administrator account must be renamed. |
| V-220912 | WN10-SO-000025 | medium | The built-in guest account must be renamed. |
| V-220917 | WN10-SO-000050 | low | The computer account password must not be prevented from being reset. |
| V-220918 | WN10-SO-000055 | low | The maximum age for machine account passwords must be configured to 30 days or less. |
| V-220923 | WN10-SO-000085 | low | Caching of logon credentials must be limited. |
| V-220924 | WN10-SO-000095 | medium | The Smart Card removal option must be configured to Force Logoff or Lock Workstation. |
| V-220928 | WN10-SO-000140 | high | Anonymous SID/Name translation must not be allowed. |
| V-220929 | WN10-SO-000145 | high | Anonymous enumeration of SAM accounts must not be allowed. |
| V-220931 | WN10-SO-000160 | medium | The system must be configured to prevent anonymous users from having the same rights as the Everyone group. |
| V-220934 | WN10-SO-000180 | medium | NTLM must be prevented from falling back to a Null session. |
| V-220935 | WN10-SO-000185 | medium | PKU2U authentication using online identities must be prevented. |
| V-220938 | WN10-SO-000205 | high | The LanMan authentication level must be set to send NTLMv2 response only, and to refuse LM and NTLM. |
| V-220939 | WN10-SO-000210 | medium | The system must be configured to the required LDAP client signing level. |
| V-220940 | WN10-SO-000215 | medium | The system must be configured to meet the minimum session security requirement for NTLM SSP based clients. |
| V-220941 | WN10-SO-000220 | medium | The system must be configured to meet the minimum session security requirement for NTLM SSP based servers. |
| V-220943 | WN10-SO-000240 | low | The default permissions of global system objects must be increased. |
| V-220955 | WN10-UC-000020 | medium | Zone information must be preserved when saving attachments. |
| V-221574 | DTBC-0025 | medium | Network prediction must be disabled. |
| V-230221 | RHEL-08-010000 | high | RHEL 8 must be a vendor-supported release. |
| V-230222 | RHEL-08-010010 | medium | RHEL 8 vendor packaged system security patches and updates must be installed and up to date. |
| V-230253 | RHEL-08-010292 | low | RHEL 8 must ensure the SSH server uses strong entropy. |
| V-230283 | RHEL-08-010460 | high | There must be no shosts.equiv files on the RHEL 8 operating system. |
| V-230284 | RHEL-08-010470 | high | There must be no .shosts files on the RHEL 8 operating system. |
| V-230285 | RHEL-08-010471 | low | RHEL 8 must enable the hardware random number generator entropy gatherer service. |
| V-230286 | RHEL-08-010480 | medium | The RHEL 8 SSH public host key files must have mode 0644 or less permissive. |
| V-230287 | RHEL-08-010490 | medium | The RHEL 8 SSH private host key files must have mode 0640 or less permissive. |
| V-230288 | RHEL-08-010500 | medium | The RHEL 8 SSH daemon must perform strict mode checking of home directory configuration files. |
| V-230290 | RHEL-08-010520 | medium | The RHEL 8 SSH daemon must not allow authentication using known host’s authentication. |
| V-230291 | RHEL-08-010521 | medium | The RHEL 8 SSH daemon must not allow Kerberos authentication, except to fulfill documented and validated mission requirements. |
| V-230292 | RHEL-08-010540 | low | RHEL 8 must use a separate file system for /var. |
| V-230293 | RHEL-08-010541 | low | RHEL 8 must use a separate file system for /var/log. |
| V-230294 | RHEL-08-010542 | low | RHEL 8 must use a separate file system for the system audit data path. |
| V-230295 | RHEL-08-010543 | medium | A separate RHEL 8 filesystem must be used for the /tmp directory. |
| V-230298 | RHEL-08-010561 | medium | The rsyslog service must be running in RHEL 8. |
| V-230299 | RHEL-08-010570 | medium | RHEL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories. |
| V-230300 | RHEL-08-010571 | medium | RHEL 8 must prevent files with the setuid and setgid bit set from being executed on the /boot directory. |
| V-230301 | RHEL-08-010580 | medium | RHEL 8 must prevent special devices on non-root local partitions. |
| V-230302 | RHEL-08-010590 | medium | RHEL 8 must prevent code from being executed on file systems that contain user home directories. |
| V-230303 | RHEL-08-010600 | medium | RHEL 8 must prevent special devices on file systems that are used with removable media. |
| V-230304 | RHEL-08-010610 | medium | RHEL 8 must prevent code from being executed on file systems that are used with removable media. |
| V-230305 | RHEL-08-010620 | medium | RHEL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that are used with removable media. |
| V-230306 | RHEL-08-010630 | medium | RHEL 8 must prevent code from being executed on file systems that are imported via Network File System (NFS). |
| V-230307 | RHEL-08-010640 | medium | RHEL 8 must prevent special devices on file systems that are imported via Network File System (NFS). |
| V-230308 | RHEL-08-010650 | medium | RHEL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that are imported via Network File System (NFS). |
| V-230309 | RHEL-08-010660 | medium | Local RHEL 8 initialization files must not execute world-writable programs. |
| V-230310 | RHEL-08-010670 | medium | RHEL 8 must disable kernel dumps unless needed. |
| V-230311 | RHEL-08-010671 | medium | RHEL 8 must disable the kernel.core_pattern. |
| V-230312 | RHEL-08-010672 | medium | RHEL 8 must disable acquiring, saving, and processing core dumps. |
| V-230313 | RHEL-08-010673 | medium | RHEL 8 must disable core dumps for all users. |
| V-230314 | RHEL-08-010674 | medium | RHEL 8 must disable storing core dumps. |
| V-230315 | RHEL-08-010675 | medium | RHEL 8 must disable core dump backtraces. |
| V-230316 | RHEL-08-010680 | medium | For RHEL 8 systems using Domain Name Servers (DNS) resolution, at least two name servers must be configured. |
| V-230317 | RHEL-08-010690 | medium | Executable search paths within the initialization files of all local interactive RHEL 8 users must only contain paths that resolve to the system default or the users home directory. |
| V-230318 | RHEL-08-010700 | medium | All RHEL 8 world-writable directories must be owned by root, sys, bin, or an application user. |
| V-230319 | RHEL-08-010710 | medium | All RHEL 8 world-writable directories must be group-owned by root, sys, bin, or an application group. |
| V-230320 | RHEL-08-010720 | medium | All RHEL 8 local interactive users must have a home directory assigned in the /etc/passwd file. |
| V-230321 | RHEL-08-010730 | medium | All RHEL 8 local interactive user home directories must have mode 0750 or less permissive. |
| V-230322 | RHEL-08-010740 | medium | All RHEL 8 local interactive user home directories must be group-owned by the home directory owner’s primary group. |
| V-230323 | RHEL-08-010750 | medium | All RHEL 8 local interactive user home directories defined in the /etc/passwd file must exist. |
| V-230324 | RHEL-08-010760 | medium | All RHEL 8 local interactive user accounts must be assigned a home directory upon creation. |
| V-230325 | RHEL-08-010770 | medium | All RHEL 8 local initialization files must have mode 0740 or less permissive. |
| V-230326 | RHEL-08-010780 | medium | All RHEL 8 local files and directories must have a valid owner. |
| V-230327 | RHEL-08-010790 | medium | All RHEL 8 local files and directories must have a valid group owner. |
| V-230328 | RHEL-08-010800 | medium | A separate RHEL 8 filesystem must be used for user home directories (such as /home or an equivalent). |
| V-230329 | RHEL-08-010820 | high | Unattended or automatic logon via the RHEL 8 graphical user interface must not be allowed. |
| V-230330 | RHEL-08-010830 | medium | RHEL 8 must not allow users to override SSH environment variables. |
| V-230356 | RHEL-08-020100 | medium | RHEL 8 must ensure the password complexity module is enabled in the password-auth file. |
| V-230377 | RHEL-08-020300 | medium | RHEL 8 must prevent the use of dictionary words for passwords. |
| V-230378 | RHEL-08-020310 | medium | RHEL 8 must enforce a delay of at least four seconds between logon prompts following a failed logon attempt. |
| V-230379 | RHEL-08-020320 | medium | RHEL 8 must not have unnecessary accounts. |
| V-230380 | RHEL-08-020330 | high | RHEL 8 must not allow accounts configured with blank or null passwords. |
| V-230383 | RHEL-08-020351 | medium | RHEL 8 must define default permissions for all authenticated users in such a way that the user can only read and modify their own files. |
| V-230384 | RHEL-08-020352 | medium | RHEL 8 must set the umask value to 077 for all local interactive user accounts. |
| V-230385 | RHEL-08-020353 | medium | RHEL 8 must define default permissions for logon and non-logon shells. |
| V-230387 | RHEL-08-030010 | medium | Cron logging must be implemented in RHEL 8. |
| V-230393 | RHEL-08-030061 | medium | The RHEL 8 audit system must audit local events. |
| V-230395 | RHEL-08-030063 | low | RHEL 8 must resolve audit information before writing to disk. |
| V-230477 | RHEL-08-030670 | medium | RHEL 8 must have the packages required for offloading audit logs installed. |
| V-230478 | RHEL-08-030680 | medium | RHEL 8 must have the packages required for encrypting offloaded audit logs installed. |
| V-230529 | RHEL-08-040170 | high | The x86 Ctrl-Alt-Delete key sequence must be disabled on RHEL 8. |
| V-230530 | RHEL-08-040171 | high | The x86 Ctrl-Alt-Delete key sequence in RHEL 8 must be disabled if a graphical user interface is installed. |
| V-230531 | RHEL-08-040172 | high | The systemd Ctrl-Alt-Delete burst key sequence in RHEL 8 must be disabled. |
| V-230532 | RHEL-08-040180 | medium | The debug-shell systemd service must be disabled on RHEL 8. |
| V-230533 | RHEL-08-040190 | high | The Trivial File Transfer Protocol (TFTP) server package must not be installed if not required for RHEL 8 operational support. |
| V-230534 | RHEL-08-040200 | high | The root account must be the only account having unrestricted access to the RHEL 8 system. |
| V-230535 | RHEL-08-040210 | medium | RHEL 8 must prevent IPv6 Internet Control Message Protocol (ICMP) redirect messages from being accepted. |
| V-230536 | RHEL-08-040220 | medium | RHEL 8 must not send Internet Control Message Protocol (ICMP) redirects. |
| V-230537 | RHEL-08-040230 | medium | RHEL 8 must not respond to Internet Control Message Protocol (ICMP) echoes sent to a broadcast address. |
| V-230538 | RHEL-08-040240 | medium | RHEL 8 must not forward IPv6 source-routed packets. |
| V-230539 | RHEL-08-040250 | medium | RHEL 8 must not forward IPv6 source-routed packets by default. |
| V-230540 | RHEL-08-040260 | medium | RHEL 8 must not enable IPv6 packet forwarding unless the system is a router. |
| V-230541 | RHEL-08-040261 | medium | RHEL 8 must not accept router advertisements on all IPv6 interfaces. |
| V-230542 | RHEL-08-040262 | medium | RHEL 8 must not accept router advertisements on all IPv6 interfaces by default. |
| V-230543 | RHEL-08-040270 | medium | RHEL 8 must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default. |
| V-230544 | RHEL-08-040280 | medium | RHEL 8 must ignore IPv6 Internet Control Message Protocol (ICMP) redirect messages. |
| V-230545 | RHEL-08-040281 | medium | RHEL 8 must disable access to network bpf syscall from unprivileged processes. |
| V-230546 | RHEL-08-040282 | medium | RHEL 8 must restrict usage of ptrace to descendant processes. |
| V-230547 | RHEL-08-040283 | medium | RHEL 8 must restrict exposed kernel pointer addresses access. |
| V-230548 | RHEL-08-040284 | medium | RHEL 8 must disable the use of user namespaces. |
| V-230549 | RHEL-08-040285 | medium | RHEL 8 must use reverse path filtering on all IPv4 interfaces. |
| V-230550 | RHEL-08-040290 | medium | RHEL 8 must be configured to prevent unrestricted mail relaying. |
| V-230551 | RHEL-08-040300 | low | The RHEL 8 file integrity tool must be configured to verify extended attributes. |
| V-230552 | RHEL-08-040310 | low | The RHEL 8 file integrity tool must be configured to verify Access Control Lists (ACLs). |
| V-230553 | RHEL-08-040320 | medium | The graphical display manager must not be installed on RHEL 8 unless approved. |
| V-230554 | RHEL-08-040330 | medium | RHEL 8 network interfaces must not be in promiscuous mode. |
| V-230555 | RHEL-08-040340 | medium | RHEL 8 remote X connections for interactive users must be disabled unless to fulfill documented and validated mission requirements. |
| V-230556 | RHEL-08-040341 | medium | The RHEL 8 SSH daemon must prevent remote hosts from connecting to the proxy display. |
| V-230557 | RHEL-08-040350 | medium | If the Trivial File Transfer Protocol (TFTP) server is required, the RHEL 8 TFTP daemon must be configured to operate in secure mode. |
| V-230558 | RHEL-08-040360 | high | A File Transfer Protocol (FTP) server package must not be installed unless mission essential on RHEL 8. |
| V-230560 | RHEL-08-040380 | medium | The iprutils package must not be installed unless mission essential on RHEL 8. |
| V-230561 | RHEL-08-040390 | medium | The tuned package must not be installed unless mission essential on RHEL 8. |
| V-237641 | RHEL-08-010382 | medium | RHEL 8 must restrict privilege elevation to authorized personnel. |
| V-242383 | CNTR-K8-000290 | high | User-managed resources must be created in dedicated namespaces. |
| V-242408 | CNTR-K8-000900 | medium | The Kubernetes manifest files must have least privileges. |
| V-242444 | CNTR-K8-003110 | medium | The Kubernetes component manifests must be owned by root. |
| V-242445 | CNTR-K8-003120 | medium | The Kubernetes component etcd must be owned by etcd. |
| V-242446 | CNTR-K8-003130 | medium | The Kubernetes conf files must be owned by root. |
| V-242447 | CNTR-K8-003140 | medium | The Kubernetes Kube Proxy kubeconfig must have file permissions set to 644 or more restrictive. |
| V-242448 | CNTR-K8-003150 | medium | The Kubernetes Kube Proxy kubeconfig must be owned by root. |
| V-242449 | CNTR-K8-003160 | medium | The Kubernetes Kubelet certificate authority file must have file permissions set to 644 or more restrictive. |
| V-242450 | CNTR-K8-003170 | medium | The Kubernetes Kubelet certificate authority must be owned by root. |
| V-242451 | CNTR-K8-003180 | medium | The Kubernetes component PKI must be owned by root. |
| V-242452 | CNTR-K8-003190 | medium | The Kubernetes kubelet KubeConfig must have file permissions set to 644 or more restrictive. |
| V-242453 | CNTR-K8-003200 | medium | The Kubernetes kubelet KubeConfig file must be owned by root. |
| V-242454 | CNTR-K8-003210 | medium | The Kubernetes kubeadm.conf must be owned by root. |
| V-242455 | CNTR-K8-003220 | medium | The Kubernetes kubeadm.conf must have file permissions set to 644 or more restrictive. |
| V-242456 | CNTR-K8-003230 | medium | The Kubernetes kubelet config must have file permissions set to 644 or more restrictive. |
| V-242457 | CNTR-K8-003240 | medium | The Kubernetes kubelet config must be owned by root. |
| V-242459 | CNTR-K8-003260 | medium | The Kubernetes etcd must have file permissions set to 644 or more restrictive. |
| V-242460 | CNTR-K8-003270 | medium | The Kubernetes admin kubeconfig must have file permissions set to 644 or more restrictive. |
| V-242461 | CNTR-K8-003280 | medium | Kubernetes API Server audit logs must be enabled. |
| V-242462 | CNTR-K8-003290 | medium | The Kubernetes API Server must be set to audit log max size. |
| V-242463 | CNTR-K8-003300 | medium | The Kubernetes API Server must be set to audit log maximum backup. |
| V-242464 | CNTR-K8-003310 | medium | The Kubernetes API Server audit log retention must be set. |
| V-242465 | CNTR-K8-003320 | medium | The Kubernetes API Server audit log path must be set. |
| V-242466 | CNTR-K8-003330 | medium | The Kubernetes PKI CRT must have file permissions set to 644 or more restrictive. |
| V-242467 | CNTR-K8-003340 | medium | The Kubernetes PKI keys must have file permissions set to 600 or more restrictive. |
| V-244527 | RHEL-08-010472 | low | RHEL 8 must have the packages required to use the hardware random number generator entropy gatherer service. |
| V-244528 | RHEL-08-010522 | medium | The RHEL 8 SSH daemon must not allow GSSAPI authentication, except to fulfill documented and validated mission requirements. |
| V-244529 | RHEL-08-010544 | medium | RHEL 8 must use a separate file system for /var/tmp. |
| V-244530 | RHEL-08-010572 | medium | RHEL 8 must prevent files with the setuid and setgid bit set from being executed on the /boot/efi directory. |
| V-244531 | RHEL-08-010731 | medium | All RHEL 8 local interactive user home directory files must have mode 0750 or less permissive. |
| V-244532 | RHEL-08-010741 | medium | RHEL 8 must be configured so that all files and directories contained in local interactive user home directories are group-owned by a group of which the home directory owner is a member. |
| V-244536 | RHEL-08-020032 | medium | RHEL 8 must disable the user list at logon for graphical user interfaces. |
| V-244541 | RHEL-08-020332 | high | RHEL 8 must not allow blank or null passwords in the password-auth file. |
| V-244550 | RHEL-08-040209 | medium | RHEL 8 must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted. |
| V-244551 | RHEL-08-040239 | medium | RHEL 8 must not forward IPv4 source-routed packets. |
| V-244552 | RHEL-08-040249 | medium | RHEL 8 must not forward IPv4 source-routed packets by default. |
| V-244553 | RHEL-08-040279 | medium | RHEL 8 must ignore IPv4 Internet Control Message Protocol (ICMP) redirect messages. |
| V-244554 | RHEL-08-040286 | medium | RHEL 8 must enable hardening for the Berkeley Packet Filter Just-in-time compiler. |
| V-250317 | RHEL-08-040259 | medium | RHEL 8 must not enable IPv4 packet forwarding unless the system is a router. |
| V-250319 | WN10-CC-000050 | medium | Hardened UNC paths must be defined to require mutual authentication and integrity for at least the \\*\SYSVOL and \\*\NETLOGON shares. |
| V-251706 | RHEL-08-010121 | high | The RHEL 8 operating system must not have accounts configured with blank or null passwords. |
| V-251711 | RHEL-08-010379 | medium | RHEL 8 must specify the default "include" directory for the /etc/sudoers file. |
| V-251713 | RHEL-08-020101 | medium | RHEL 8 must ensure the password complexity module is enabled in the system-auth file. |
| V-251716 | RHEL-08-020104 | medium | RHEL 8 systems, version 8.4 and above, must ensure the password complexity module is configured for three retries or less. |
| V-251718 | RHEL-08-040321 | medium | The graphical display manager must not be the default target on RHEL 8 unless approved. |
| V-252903 | WN10-CC-000080 | low | Virtualization-based protection of code integrity must be enabled. |
| V-253254 | WN11-00-000005 | medium | Domain-joined systems must use Windows 11 Enterprise Edition 64-bit version. |
| V-253258 | WN11-00-000025 | medium | Windows 11 must employ automated mechanisms to determine the state of system components with regard to flaw remediation using the following frequency: Continuously, where ESS is used; 30 days, for any additional internal network scans not covered by ESS; and annually, for external scans by Computer Network Defense Service Provider (CNDSP). |
| V-253263 | WN11-00-000040 | high | Windows 11 systems must be maintained at a supported servicing level. |
| V-253264 | WN11-00-000045 | high | The Windows 11 system must use an antivirus program. |
| V-253266 | WN11-00-000055 | medium | Alternate operating systems must not be permitted on the same system. |
| V-253270 | WN11-00-000075 | medium | Only accounts responsible for the backup operations must be members of the Backup Operators group. |
| V-253272 | WN11-00-000085 | low | Standard local user accounts must not exist on a system in a domain. |
| V-253280 | WN11-00-000130 | medium | Software certificate installation files must be removed from Windows 11. |
| V-253281 | WN11-00-000135 | medium | A host-based firewall must be installed and enabled on the system. |
| V-253282 | WN11-00-000140 | medium | Inbound exceptions to the firewall on Windows 11 domain workstations must only allow authorized remote management hosts. |
| V-253290 | WN11-00-000190 | medium | Orphaned security identifiers (SIDs) must be removed from user rights on Windows 11. |
| V-253293 | WN11-00-000230 | medium | The system must notify the user when a Bluetooth device attempts to connect. |
| V-253294 | WN11-00-000240 | high | Administrative accounts must not be used with applications that access the internet, such as web browsers, or with potential internet sources, such as email. |
| V-253353 | WN11-CC-000020 | medium | IPv6 source routing must be configured to highest protection. |
| V-253354 | WN11-CC-000025 | medium | The system must be configured to prevent IP source routing. |
| V-253355 | WN11-CC-000030 | low | The system must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF) generated routes. |
| V-253360 | WN11-CC-000040 | medium | Insecure logons to an SMB server must be disabled. |
| V-253362 | WN11-CC-000050 | medium | Hardened UNC Paths must be defined to require mutual authentication and integrity for at least the \\*\SYSVOL and \\*\NETLOGON shares. |
| V-253365 | WN11-CC-000060 | medium | Connections to non-domain networks when connected to a domain authenticated network must be blocked. |
| V-253366 | WN11-CC-000065 | medium | Wi-Fi Sense must be disabled. |
| V-253368 | WN11-CC-000068 | medium | Windows 11 must be configured to enable Remote host allows delegation of non-exportable credentials. |
| V-253369 | WN11-CC-000070 | medium | Virtualization-based Security must be enabled on Windows 11 with the platform security level configured to Secure Boot or Secure Boot with DMA Protection. |
| V-253370 | WN11-CC-000075 | high | Credential Guard must be running on Windows 11 domain-joined systems. |
| V-253371 | WN11-CC-000080 | medium | Virtualization-based protection of code integrity must be enabled. |
| V-253372 | WN11-CC-000085 | medium | Early Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers. |
| V-253373 | WN11-CC-000090 | medium | Group Policy objects must be reprocessed even if they have not changed. |
| V-253377 | WN11-CC-000115 | medium | Systems must at least attempt device authentication using certificates. |
| V-253384 | WN11-CC-000170 | low | The setting to allow Microsoft accounts to be optional for modern style apps must be enabled. |
| V-253389 | WN11-CC-000195 | medium | Enhanced anti-spoofing for facial recognition must be enabled on Windows 11. |
| V-253392 | WN11-CC-000204 | medium | Enhanced diagnostic data must be limited to the minimum required to support Windows Analytics. |
| V-253394 | WN11-CC-000206 | low | Windows Update must not obtain updates from other PCs on the internet. |
| V-253398 | WN11-CC-000225 | medium | File Explorer shell protocol must run in protected mode. |
| V-253400 | WN11-CC-000255 | medium | The use of a hardware security device with Windows Hello for Business must be enabled. |
| V-253401 | WN11-CC-000260 | medium | Windows 11 must be configured to require a minimum pin length of six characters or greater. |
| V-253407 | WN11-CC-000295 | medium | Attachments must be prevented from being downloaded from RSS feeds. |
| V-253412 | WN11-CC-000320 | medium | Users must be notified if a web-based program attempts to install software. |
| V-253413 | WN11-CC-000325 | medium | Automatically signing in the last interactive user after a system-initiated restart must be disabled. |
| V-253434 | WN11-SO-000015 | medium | Local accounts with blank passwords must be restricted to prevent access from the network. |
| V-253435 | WN11-SO-000020 | medium | The built-in administrator account must be renamed. |
Get this as data
The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/CM-6. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.