San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active

CM-7 Least Functionality

Configuration Management family. 40 Control Correlation Identifiers map to this control, and 234 STIG rules implement those CCIs.

17CAT I (high)
194CAT II (medium)
23CAT III (low)
40CCIs
What this page is built from, and what it is not.

The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.

It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.

Where these rules come from

STIG benchmarkVersionRules mapped to CM-7
Red Hat Enterprise Linux 9V250
Microsoft Windows 10V340
Microsoft Windows 11V238
Red Hat Enterprise Linux 8V234
Microsoft Windows Server 2019V326
Microsoft Windows Server 2022V226
Google Chrome Current WindowsV214
KubernetesV26

Control Correlation Identifiers mapped to CM-7

CCIDefinitionRev
CCI-000380Defines prohibited or restricted functions, system ports, protocols, software and/or services for the system.5, 4
CCI-000381Configure the system to provide only organization-defined mission essential capabilities.5, 4
CCI-000382Configure the system to prohibit or restrict the use of organization-defined prohibited or restricted functions, system ports, protocols, software, and/or services.5, 4
CCI-000384Review the system per organization-defined frequency to identify unnecessary and nonsecure functions, ports, protocols, software, and services.5, 4
CCI-000387Defines registration requirements for functions, ports, protocols, and services.5, 4
CCI-000388Ensure compliance with organization-defined registration requirements for functions, ports, protocols, and services.5, 4
CCI-001592Defines the rules authorizing the terms and conditions of software program usage on the system.5, 4
CCI-001760Defines the frequency of system reviews to identify unnecessary and/or nonsecure functions, ports, protocols, software, and services.5, 4
CCI-001761Defines the functions, ports, protocols, software, and services within the information system that are to be disabled or removed when deemed unnecessary and/or nonsecure.5, 4
CCI-001762Disable or remove organization-defined functions, ports, protocols, software, and services within the system deemed to be unnecessary and/or nonsecure.5, 4
CCI-001763Defines the policies regarding software program usage and restrictions.5, 4
CCI-001764Prevent program execution in accordance with organization-defined policies, rules of behavior, and/or access agreements regarding software program usage and restrictions; rules authorizing the terms and conditions of software program usage.5, 4
CCI-001765Defines the software programs not authorized to execute on the system.5, 4
CCI-001766Identify the organization-defined software programs not authorized to execute on the system.5, 4
CCI-001767Employ an allow-all, deny-by-exception policy to prohibit the execution of unauthorized software programs on the system.5, 4
CCI-001768Defines the frequency on which the list of unauthorized software programs will be reviewed and updated.5, 4
CCI-001769The organization defines the frequency on which it will update the list of unauthorized software programs.4
CCI-001770Review and update the list of unauthorized software programs per organization-defined frequency.5, 4
CCI-001771The organization updates the list of unauthorized software programs per organization-defined frequency.4
CCI-001772Defines the software programs authorized to execute on the system.5, 4
CCI-001773Identify the organization-defined software programs authorized to execute on the system.5, 4
CCI-001774Employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs on the system.5, 4
CCI-001775Defines the frequency on which the list of authorized software programs will be reviewed and updated.5, 4
CCI-001776The organization defines the frequency on which it will update the list of authorized software programs.4
CCI-001777Review and update the list of authorized software programs per organization-defined frequency.5, 4
CCI-001778The organization updates the list of authorized software programs per organization-defined frequency.4
CCI-003948Defines the mission essential capabilities for configuring the system.5
CCI-003949Require that organization-defined user-installed software in a confined physical or virtual machine environment with limited privileges.5
CCI-003950Defines the user-installed software required for executing in a confined physical or virtual machine environment with limited privileges.5
CCI-003951Allow execution of binary or machine-executable code only in confined physical or virtual machine environments and with the explicit approval of organization-defined personnel or roles when such code is obtained from sources with limited or no warranty.5
CCI-003952Defines the personnel or roles who allow execution of binary or machine-executable code only in confined physical or virtual machine environments when such code is obtained from sources with limited or no warranty.5
CCI-003953Allow execution of binary or machine-executable code only in confined physical or virtual machine environments and with the explicit approval of organization-defined personnel or roles when such code is without the provision of source code.5
CCI-003954Defines the personnel or roles who allow execution of binary or machine-executable code only in confined physical or virtual machine environments when such code is without the provision of source code.5
CCI-003955Prohibit the use of binary or machine-executable code from sources with limited or no warranty or without the provision of source code.5
CCI-003956Allow exceptions only for compelling mission or operational requirements and with the approval of the authorizing official.5
CCI-003957Identify organization-defined hardware components authorized for system use.5
CCI-003958Defines the hardware components to be identified for authorized system use.5
CCI-003959Prohibit the use or connection of unauthorized hardware components.5
CCI-003960Review and update the list of authorized hardware components on an organization-defined frequency.5
CCI-003961Defines the frequency the hardware components are reviewed and updated.5

STIG rules that implement CM-7

RuleSTIG IDSeverityRequirement
V-205677WN19-00-000270mediumWindows Server 2019 must have the roles and features required by the system documented.
V-205678WN19-00-000320mediumWindows Server 2019 must not have the Fax Server role installed.
V-205679WN19-00-000340mediumWindows Server 2019 must not have the Peer Name Resolution Protocol installed.
V-205680WN19-00-000350mediumWindows Server 2019 must not have Simple TCP/IP Services installed.
V-205681WN19-00-000370mediumWindows Server 2019 must not have the TFTP Client installed.
V-205682WN19-00-000380mediumWindows Server 2019 must not have the Server Message Block (SMB) v1 protocol installed.
V-205683WN19-00-000390mediumWindows Server 2019 must have the Server Message Block (SMB) v1 protocol disabled on the SMB server.
V-205684WN19-00-000400mediumWindows Server 2019 must have the Server Message Block (SMB) v1 protocol disabled on the SMB client.
V-205685WN19-00-000410mediumWindows Server 2019 must not have Windows PowerShell 2.0 installed.
V-205686WN19-CC-000010mediumWindows Server 2019 must prevent the display of slide shows on the lock screen.
V-205687WN19-CC-000020mediumWindows Server 2019 must have WDigest Authentication disabled.
V-205688WN19-CC-000150mediumWindows Server 2019 downloading print driver packages over HTTP must be turned off.
V-205689WN19-CC-000160mediumWindows Server 2019 printing over HTTP must be turned off.
V-205690WN19-CC-000170mediumWindows Server 2019 network selection user interface (UI) must not be displayed on the logon screen.
V-205691WN19-CC-000200lowWindows Server 2019 Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft.
V-205692WN19-CC-000300mediumWindows Server 2019 Windows Defender SmartScreen must be enabled.
V-205693WN19-CC-000400mediumWindows Server 2019 must disable Basic authentication for RSS feeds over HTTP.
V-205694WN19-CC-000410mediumWindows Server 2019 must prevent Indexing of encrypted files.
V-205695WN19-DC-000130mediumWindows Server 2019 domain controllers must run on a machine dedicated to that function.
V-205696WN19-MS-000030mediumWindows Server 2019 local users on domain-joined member servers must not be enumerated.
V-205697WN19-00-000330mediumWindows Server 2019 must not have the Microsoft FTP service installed unless required by the organization.
V-205698WN19-00-000360mediumWindows Server 2019 must not have the Telnet Client installed.
V-205804WN19-CC-000210highWindows Server 2019 Autoplay must be turned off for non-volume devices.
V-205805WN19-CC-000220highWindows Server 2019 default AutoRun behavior must be configured to prevent AutoRun commands.
V-205806WN19-CC-000230highWindows Server 2019 AutoPlay must be disabled for all drives.
V-205807WN19-00-000080mediumWindows Server 2019 must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
V-220705WN10-00-000035mediumThe operating system must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
V-220714WN10-00-000080mediumOnly authorized user accounts must be allowed to create or run virtual machines on Windows 10 systems.
V-220718WN10-00-000100highInternet Information System (IIS) or its subcomponents must not be installed on a workstation.
V-220719WN10-00-000105mediumSimple Network Management Protocol (SNMP) must not be installed on the system.
V-220720WN10-00-000110mediumSimple TCP/IP Services must not be installed on the system.
V-220721WN10-00-000115mediumThe Telnet Client must not be installed on the system.
V-220722WN10-00-000120mediumThe TFTP Client must not be installed on the system.
V-220728WN10-00-000155mediumThe Windows PowerShell 2.0 feature must be disabled on the system.
V-220729WN10-00-000160mediumThe Server Message Block (SMB) v1 protocol must be disabled on the system.
V-220730WN10-00-000165mediumThe Server Message Block (SMB) v1 protocol must be disabled on the SMB server.
V-220731WN10-00-000170mediumThe Server Message Block (SMB) v1 protocol must be disabled on the SMB client.
V-220732WN10-00-000175mediumThe Secondary Logon service must be disabled on Windows 10.
V-220734WN10-00-000210mediumBluetooth must be turned off unless approved by the organization.
V-220735WN10-00-000220mediumBluetooth must be turned off when not in use.
V-220792WN10-CC-000005mediumCamera access from the lock screen must be disabled.
V-220793WN10-CC-000007mediumWindows 10 must cover or disable the built-in or attached camera when not in use.
V-220794WN10-CC-000010mediumThe display of slide shows on the lock screen must be disabled.
V-220800WN10-CC-000038mediumWDigest Authentication must be disabled.
V-220801WN10-CC-000039mediumRun as different user must be removed from context menus.
V-220803WN10-CC-000044mediumInternet connection sharing must be disabled.
V-220815WN10-CC-000100mediumDownloading print driver packages over HTTP must be prevented.
V-220816WN10-CC-000105mediumWeb publishing and online ordering wizards must be prevented from downloading a list of providers.
V-220817WN10-CC-000110mediumPrinting over HTTP must be prevented.
V-220819WN10-CC-000120mediumThe network selection user interface (UI) must not be displayed on the logon screen.
V-220820WN10-CC-000130mediumLocal users on domain-joined computers must not be enumerated.
V-220826WN10-CC-000175lowThe Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft.
V-220827WN10-CC-000180highAutoplay must be turned off for non-volume devices.
V-220828WN10-CC-000185highThe default autorun behavior must be configured to prevent autorun commands.
V-220829WN10-CC-000190highAutoplay must be disabled for all drives.
V-220831WN10-CC-000197lowMicrosoft consumer experiences must be turned off.
V-220836WN10-CC-000210mediumThe Windows Defender SmartScreen for Explorer must be enabled.
V-220845WN10-CC-000252mediumWindows 10 must be configured to disable Windows Game Recording and Broadcasting.
V-220854WN10-CC-000300mediumBasic authentication for RSS feeds over HTTP must not be used.
V-220855WN10-CC-000305mediumIndexing of encrypted files must be turned off.
V-220870WN10-CC-000370mediumThe convenience PIN for Windows 10 must be disabled.
V-220871WN10-CC-000385mediumWindows Ink Workspace must be configured to disallow access above the lock.
V-220872WN10-CC-000390lowWindows 10 should be configured to prevent users from receiving suggestions for third-party or additional applications.
V-220954WN10-UC-000015lowToast notifications to the lock screen must be turned off.
V-221561DTBC-0004mediumSites ability to show pop-ups must be disabled.
V-221564DTBC-0007mediumThe default search providers name must be set.
V-221565DTBC-0008mediumThe default search provider URL must be set to perform encrypted searches.
V-221566DTBC-0009mediumDefault search provider must be enabled.
V-221567DTBC-0011mediumThe Password Manager must be disabled.
V-221572DTBC-0021mediumThe URL protocol schema javascript must be disabled.
V-221575DTBC-0026mediumMetrics reporting to Google must be disabled.
V-221576DTBC-0027mediumSearch suggestions must be disabled.
V-221577DTBC-0029mediumImporting of saved passwords must be disabled.
V-221591DTBC-0058mediumWebUSB must be disabled.
V-221594DTBC-0063mediumGoogle Cast must be disabled.
V-221595DTBC-0064mediumAutoplay must be disabled.
V-230485RHEL-08-030741lowRHEL 8 must disable the chrony daemon from acting as a server.
V-230486RHEL-08-030742lowRHEL 8 must disable network management of the chrony daemon.
V-230487RHEL-08-040000highRHEL 8 must not have the telnet-server package installed.
V-230488RHEL-08-040001mediumRHEL 8 must not have any automated bug reporting tools installed.
V-230489RHEL-08-040002mediumRHEL 8 must not have the sendmail package installed.
V-230491RHEL-08-040004lowRHEL 8 must enable mitigations against processor-based vulnerabilities.
V-230492RHEL-08-040010highRHEL 8 must not have the rsh-server package installed.
V-230493RHEL-08-040020mediumRHEL 8 must cover or disable the built-in or attached camera when not in use.
V-230494RHEL-08-040021lowRHEL 8 must disable the asynchronous transfer mode (ATM) protocol.
V-230495RHEL-08-040022lowRHEL 8 must disable the controller area network (CAN) protocol.
V-230496RHEL-08-040023lowRHEL 8 must disable the stream control transmission protocol (SCTP).
V-230497RHEL-08-040024lowRHEL 8 must disable the transparent inter-process communication (TIPC) protocol.
V-230498RHEL-08-040025lowRHEL 8 must disable mounting of cramfs.
V-230499RHEL-08-040026lowRHEL 8 must disable IEEE 1394 (FireWire) Support.
V-230500RHEL-08-040030mediumRHEL 8 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.
V-230508RHEL-08-040120mediumRHEL 8 must mount /dev/shm with the nodev option.
V-230509RHEL-08-040121mediumRHEL 8 must mount /dev/shm with the nosuid option.
V-230510RHEL-08-040122mediumRHEL 8 must mount /dev/shm with the noexec option.
V-230511RHEL-08-040123mediumRHEL 8 must mount /tmp with the nodev option.
V-230512RHEL-08-040124mediumRHEL 8 must mount /tmp with the nosuid option.
V-230513RHEL-08-040125mediumRHEL 8 must mount /tmp with the noexec option.
V-230514RHEL-08-040126mediumRHEL 8 must mount /var/log with the nodev option.
V-230515RHEL-08-040127mediumRHEL 8 must mount /var/log with the nosuid option.
V-230516RHEL-08-040128mediumRHEL 8 must mount /var/log with the noexec option.
V-230517RHEL-08-040129mediumRHEL 8 must mount /var/log/audit with the nodev option.
V-230518RHEL-08-040130mediumRHEL 8 must mount /var/log/audit with the nosuid option.
V-230519RHEL-08-040131mediumRHEL 8 must mount /var/log/audit with the noexec option.
V-230520RHEL-08-040132mediumRHEL 8 must mount /var/tmp with the nodev option.
V-230521RHEL-08-040133mediumRHEL 8 must mount /var/tmp with the nosuid option.
V-230522RHEL-08-040134mediumRHEL 8 must mount /var/tmp with the noexec option.
V-230523RHEL-08-040135mediumThe RHEL 8 fapolicy module must be installed.
V-230559RHEL-08-040370mediumThe gssproxy package must not be installed unless mission essential on RHEL 8.
V-241787DTBC-0073mediumWeb Bluetooth API must be disabled.
V-242409CNTR-K8-000910mediumKubernetes Controller Manager must disable profiling.
V-242410CNTR-K8-000920mediumThe Kubernetes API Server must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL).
V-242411CNTR-K8-000930mediumThe Kubernetes Scheduler must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL).
V-242412CNTR-K8-000940mediumThe Kubernetes Controllers must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL).
V-242413CNTR-K8-000950mediumThe Kubernetes etcd must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL).
V-242414CNTR-K8-000960mediumThe Kubernetes cluster must use non-privileged host ports for user pods.
V-244545RHEL-08-040136mediumThe RHEL 8 fapolicy module must be enabled.
V-244546RHEL-08-040137mediumThe RHEL 8 fapolicy module must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
V-245538DTBC-0074mediumUse of the QUIC protocol must be disabled.
V-253262WN11-00-000035mediumThe operating system must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
V-253275WN11-00-000100highInternet Information System (IIS) or its subcomponents must not be installed on a workstation.
V-253276WN11-00-000105mediumSimple Network Management Protocol (SNMP) must not be installed on the system.
V-253277WN11-00-000110mediumSimple TCP/IP Services must not be installed on the system.
V-253278WN11-00-000115mediumThe Telnet Client must not be installed on the system.
V-253279WN11-00-000120mediumThe TFTP Client must not be installed on the system.
V-253285WN11-00-000155mediumThe Windows PowerShell 2.0 feature must be disabled on the system.
V-253286WN11-00-000160mediumThe Server Message Block (SMB) v1 protocol must be disabled on the system.
V-253287WN11-00-000165mediumThe Server Message Block (SMB) v1 protocol must be disabled on the SMB server.
V-253288WN11-00-000170mediumThe Server Message Block (SMB) v1 protocol must be disabled on the SMB client.
V-253289WN11-00-000175mediumThe Secondary Logon service must be disabled on Windows 11.
V-253291WN11-00-000210mediumBluetooth must be turned off unless approved by the organization.
V-253292WN11-00-000220mediumBluetooth must be turned off when not in use.
V-253350WN11-CC-000005mediumCamera access from the lock screen must be disabled.
V-253351WN11-CC-000007mediumWindows 11 must cover or disable the built-in or attached camera when not in use.
V-253352WN11-CC-000010mediumThe display of slide shows on the lock screen must be disabled.
V-253358WN11-CC-000038mediumWDigest Authentication must be disabled.
V-253359WN11-CC-000039mediumRun as different user must be removed from context menus.
V-253361WN11-CC-000044mediumInternet connection sharing must be disabled.
V-253374WN11-CC-000100mediumDownloading print driver packages over HTTP must be prevented.
V-253375WN11-CC-000105mediumWeb publishing and online ordering wizards must be prevented from downloading a list of providers.
V-253376WN11-CC-000110mediumPrinting over HTTP must be prevented.
V-253378WN11-CC-000120mediumThe network selection user interface (UI) must not be displayed on the logon screen.
V-253379WN11-CC-000130mediumLocal users on domain-joined computers must not be enumerated.
V-253385WN11-CC-000175lowThe Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft.
V-253386WN11-CC-000180highAutoplay must be turned off for non-volume devices.
V-253387WN11-CC-000185highThe default autorun behavior must be configured to prevent autorun commands.
V-253388WN11-CC-000190highAutoplay must be disabled for all drives.
V-253390WN11-CC-000197lowMicrosoft consumer experiences must be turned off.
V-253395WN11-CC-000210mediumThe Microsoft Defender SmartScreen for Explorer must be enabled.
V-253399WN11-CC-000252mediumWindows 11 must be configured to disable Windows Game Recording and Broadcasting.
V-253408WN11-CC-000300mediumBasic authentication for RSS feeds over HTTP must not be used.
V-253409WN11-CC-000305mediumIndexing of encrypted files must be turned off.
V-253423WN11-CC-000370mediumThe convenience PIN for Windows 11 must be disabled.
V-253425WN11-CC-000390lowWindows 11 must be configured to prevent users from receiving suggestions for third-party or additional applications.
V-253477WN11-UC-000015lowToast notifications to the lock screen must be turned off.
V-254245WN22-00-000080mediumWindows Server 2022 must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
V-254264WN22-00-000270mediumWindows Server 2022 must have the roles and features required by the system documented.
V-254269WN22-00-000320mediumWindows Server 2022 must not have the Fax Server role installed.
V-254270WN22-00-000330mediumWindows Server 2022 must not have the Microsoft FTP service installed unless required by the organization.
V-254271WN22-00-000340mediumWindows Server 2022 must not have the Peer Name Resolution Protocol installed.
V-254272WN22-00-000350mediumWindows Server 2022 must not have Simple TCP/IP Services installed.
V-254273WN22-00-000360mediumWindows Server 2022 must not have the Telnet Client installed.
V-254274WN22-00-000370mediumWindows Server 2022 must not have the TFTP Client installed.
V-254275WN22-00-000380mediumWindows Server 2022 must not the Server Message Block (SMB) v1 protocol installed.
V-254276WN22-00-000390mediumWindows Server 2022 must have the Server Message Block (SMB) v1 protocol disabled on the SMB server.
V-254277WN22-00-000400mediumWindows Server 2022 must have the Server Message Block (SMB) v1 protocol disabled on the SMB client.
V-254278WN22-00-000410mediumWindows Server 2022 must not have Windows PowerShell 2.0 installed.
V-254333WN22-CC-000010mediumWindows Server 2022 must prevent the display of slide shows on the lock screen.
V-254334WN22-CC-000020mediumWindows Server 2022 must have WDigest Authentication disabled.
V-254346WN22-CC-000150mediumWindows Server 2022 downloading print driver packages over HTTP must be turned off.
V-254347WN22-CC-000160mediumWindows Server 2022 printing over HTTP must be turned off.
V-254348WN22-CC-000170mediumWindows Server 2022 network selection user interface (UI) must not be displayed on the logon screen.
V-254351WN22-CC-000200lowWindows Server 2022 Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft.
V-254352WN22-CC-000210highWindows Server 2022 Autoplay must be turned off for nonvolume devices.
V-254353WN22-CC-000220highWindows Server 2022 default AutoRun behavior must be configured to prevent AutoRun commands.
V-254354WN22-CC-000230highWindows Server 2022 AutoPlay must be disabled for all drives.
V-254361WN22-CC-000300mediumWindows Server 2022 Microsoft Defender antivirus SmartScreen must be enabled.
V-254371WN22-CC-000400mediumWindows Server 2022 must disable Basic authentication for RSS feeds over HTTP.
V-254372WN22-CC-000410mediumWindows Server 2022 must prevent Indexing of encrypted files.
V-254397WN22-DC-000130mediumWindows Server 2022 domain controllers must run on a machine dedicated to that function.
V-254430WN22-MS-000030mediumWindows Server 2022 local users on domain-joined member servers must not be enumerated.
V-257592WN11-00-000395mediumWindows 11 must not have portproxy enabled or in use.
V-257593WN10-00-000395mediumWindows 10 must not have portproxy enabled or in use.
V-257795RHEL-09-212050lowRHEL 9 must enable mitigations against processor-based vulnerabilities.
V-257804RHEL-09-213045mediumRHEL 9 must be configured to disable the Asynchronous Transfer Mode kernel module.
V-257805RHEL-09-213050mediumRHEL 9 must be configured to disable the Controller Area Network kernel module.
V-257806RHEL-09-213055mediumRHEL 9 must be configured to disable the FireWire kernel module.
V-257807RHEL-09-213060mediumRHEL 9 must disable the Stream Control Transmission Protocol (SCTP) kernel module.
V-257808RHEL-09-213065mediumRHEL 9 must disable the Transparent Inter Process Communication (TIPC) kernel module.
V-257826RHEL-09-215015highRHEL 9 must not have a File Transfer Protocol (FTP) server package installed.
V-257827RHEL-09-215020mediumRHEL 9 must not have the sendmail package installed.
V-257828RHEL-09-215025mediumRHEL 9 must not have the nfs-utils package installed.
V-257829RHEL-09-215030mediumRHEL 9 must not have the ypserv package installed.
V-257830RHEL-09-215035mediumRHEL 9 must not have the rsh-server package installed.
V-257831RHEL-09-215040mediumRHEL 9 must not have the telnet-server package installed.
V-257832RHEL-09-215045mediumRHEL 9 must not have the gssproxy package installed.
V-257833RHEL-09-215050mediumRHEL 9 must not have the iprutils package installed.
V-257834RHEL-09-215055mediumRHEL 9 must not have the tuned package installed.
V-257850RHEL-09-231045mediumRHEL 9 must prevent device files from being interpreted on file systems that contain user home directories.
V-257851RHEL-09-231050mediumRHEL 9 must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories.
V-257860RHEL-09-231095mediumRHEL 9 must mount /boot with the nodev option.
V-257861RHEL-09-231100mediumRHEL 9 must prevent files with the setuid and setgid bit set from being executed on the /boot directory.
V-257862RHEL-09-231105mediumRHEL 9 must prevent files with the setuid and setgid bit set from being executed on the /boot/efi directory.
V-257863RHEL-09-231110mediumRHEL 9 must mount /dev/shm with the nodev option.
V-257864RHEL-09-231115mediumRHEL 9 must mount /dev/shm with the noexec option.
V-257865RHEL-09-231120mediumRHEL 9 must mount /dev/shm with the nosuid option.
V-257866RHEL-09-231125mediumRHEL 9 must mount /tmp with the nodev option.
V-257867RHEL-09-231130mediumRHEL 9 must mount /tmp with the noexec option.
V-257868RHEL-09-231135mediumRHEL 9 must mount /tmp with the nosuid option.
V-257869RHEL-09-231140mediumRHEL 9 must mount /var with the nodev option.
V-257870RHEL-09-231145mediumRHEL 9 must mount /var/log with the nodev option.
V-257871RHEL-09-231150mediumRHEL 9 must mount /var/log with the noexec option.
V-257872RHEL-09-231155mediumRHEL 9 must mount /var/log with the nosuid option.
V-257873RHEL-09-231160mediumRHEL 9 must mount /var/log/audit with the nodev option.
V-257874RHEL-09-231165mediumRHEL 9 must mount /var/log/audit with the noexec option.
V-257875RHEL-09-231170mediumRHEL 9 must mount /var/log/audit with the nosuid option.
V-257876RHEL-09-231175mediumRHEL 9 must mount /var/tmp with the nodev option.
V-257877RHEL-09-231180mediumRHEL 9 must mount /var/tmp with the noexec option.
V-257878RHEL-09-231185mediumRHEL 9 must mount /var/tmp with the nosuid option.
V-257880RHEL-09-231195lowRHEL 9 must disable mounting of cramfs.
V-257935RHEL-09-251010mediumRHEL 9 must have the firewalld package installed.
V-257936RHEL-09-251015mediumThe firewalld service on RHEL 9 must be active.
V-257940RHEL-09-251035mediumRHEL 9 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.
V-257946RHEL-09-252025lowRHEL 9 must disable the chrony daemon from acting as a server.
V-257947RHEL-09-252030lowRHEL 9 must disable network management of the chrony daemon.
V-258016RHEL-09-271030mediumRHEL 9 must disable the graphical user interface autorun function unless required.
V-258034RHEL-09-291010mediumRHEL 9 must be configured to disable USB mass storage.
V-258035RHEL-09-291015mediumRHEL 9 must have the USBGuard package installed.
V-258036RHEL-09-291020mediumRHEL 9 must have the USBGuard package enabled.
V-258039RHEL-09-291035mediumRHEL 9 Bluetooth must be disabled.
V-258089RHEL-09-433010mediumRHEL 9 fapolicy module must be installed.
V-258090RHEL-09-433015mediumRHEL 9 fapolicy module must be enabled.
V-268315WN10-00-000107mediumCopilot in Windows must be disabled for Windows 10.
V-268317WN11-00-000125mediumCopilot in Windows must be disabled for Windows 11
V-270180RHEL-09-433016mediumThe RHEL 9 fapolicy module must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.

Get this as data

The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/CM-7. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.