STIG Rules List - 2
- Column 1:
CCE Number
- Column 2:
Rule Name
- Column 3:
Control Group
- Column 4:
Default Status
- Column 5:
Passed/Exception
- Column 1:
CCE-82197-5
- Column 2:
Ensure Users Re-Authenticate for Privilege Escalation - sudo NOPASSWD
- Column 3:
N/A
- Column 4:
disabled
- Column 5:
Exception
- Column 1:
N/A
- Column 2:
The operating system must require Re-Authentication when using the sudo command. Ensure sudo timestamp_timeout is appropriate - sudo timestamp_timeout
- Column 3:
N/A
- Column 4:
disabled
- Column 5:
Exception
- Column 1:
CCE-83425-9
- Column 2:
The operating system must restrict privilege elevation to authorized personnel
- Column 3:
N/A
- Column 4:
enabled
- Column 5:
Passed
- Column 1:
CCE-86377-9
- Column 2:
Ensure sudo only includes the default configuration directory
- Column 3:
N/A
- Column 4:
enabled
- Column 5:
Passed
- Column 1:
CCE-83422-6
- Column 2:
Ensure invoking users password for privilege escalation when using sudo
- Column 3:
N/A
- Column 4:
N/A
- Column 5:
Exception
- Column 1:
CCE-82943-2
- Column 2:
Uninstall gssproxy Package
- Column 3:
N/A
- Column 4:
N/A
- Column 5:
Exception
- Column 1:
CCE-82946-5
- Column 2:
Uninstall iprutils Package
- Column 3:
N/A
- Column 4:
N/A
- Column 5:
Exception
- Column 1:
CCE-82931-7
- Column 2:
Uninstall krb5-workstation Package
- Column 3:
N/A
- Column 4:
N/A
- Column 5:
N/A
- Column 1:
CCE-82904-4
- Column 2:
Uninstall tuned Package
- Column 3:
N/A
- Column 4:
N/A
- Column 5:
Exception
- Column 1:
CCE-80865-9
- Column 2:
Ensure Software Patches Installed
- Column 3:
N/A
- Column 4:
enabled
- Column 5:
Passed
- Column 1:
CCE-80768-5
- Column 2:
Enable GNOME3 Login Warning Banner
- Column 3:
N/A
- Column 4:
N/A
- Column 5:
N/A
- Column 1:
CCE-80770-1
- Column 2:
Set the GNOME3 Login Warning Banner Text
- Column 3:
N/A
- Column 4:
N/A
- Column 5:
N/A
- Column 1:
CCE-80763-6
- Column 2:
Modify the System Login Banner
- Column 3:
ssh
- Column 4:
enabled
- Column 5:
EXCEPTION
- Column 1:
CCE-86248-2
- Column 2:
An SELinux Context must be configured for the pam_faillock.so records directory
- Column 3:
auth
- Column 4:
enabled
- Column 5:
Passed
- Column 1:
CCE-83478-8
- Column 2:
Limit Password Reuse: password-auth
- Column 3:
N/A
- Column 4:
N/A
- Column 5:
Exception
- Column 1:
CCE-83480-4
- Column 2:
Limit Password Reuse: system-auth
- Column 3:
N/A
- Column 4:
N/A
- Column 5:
Exception
- Column 1:
CCE-86099-9
- Column 2:
Account Lockouts Must Be Logged
- Column 3:
N/A
- Column 4:
N/A
- Column 5:
Exception
- Column 1:
CCE-80667-9
- Column 2:
Lock Accounts After Failed Password Attempts
- Column 3:
N/A
- Column 4:
N/A
- Column 5:
Exception
- Column 1:
CCE-80668-7
- Column 2:
Configure the root Account for Failed Password Attempts
- Column 3:
N/A
- Column 4:
N/A
- Column 5:
Exception
- Column 1:
CCE-86067-6
- Column 2:
Lock Accounts Must Persist
- Column 3:
N/A
- Column 4:
N/A
- Column 5:
Exception
- Column 1:
CCE-80669-5
- Column 2:
Set Interval For Counting Failed Password Attempts
- Column 3:
N/A
- Column 4:
N/A
- Column 5:
Exception