Rules In DISA STIG for Red Hat Enterprise Linux 8


Total Missing Implemented Coverage STIG ids missing rule
371 371 0 .00% RHEL-08-010000 RHEL-08-010001 RHEL-08-010010 RHEL-08-010020 RHEL-08-010030 RHEL-08-010040 RHEL-08-010049 RHEL-08-010050 RHEL-08-010060 RHEL-08-010070 RHEL-08-010090 RHEL-08-010100 RHEL-08-010110 RHEL-08-010120 RHEL-08-010121 RHEL-08-010130 RHEL-08-010140 RHEL-08-010141 RHEL-08-010149 RHEL-08-010150 RHEL-08-010151 RHEL-08-010152 RHEL-08-010159 RHEL-08-010160 RHEL-08-010161 RHEL-08-010162 RHEL-08-010163 RHEL-08-010170 RHEL-08-010171 RHEL-08-010190 RHEL-08-010200 RHEL-08-010201 RHEL-08-010210 RHEL-08-010220 RHEL-08-010230 RHEL-08-010240 RHEL-08-010250 RHEL-08-010260 RHEL-08-010287 RHEL-08-010290 RHEL-08-010291 RHEL-08-010292 RHEL-08-010293 RHEL-08-010294 RHEL-08-010295 RHEL-08-010300 RHEL-08-010310 RHEL-08-010320 RHEL-08-010330 RHEL-08-010331 RHEL-08-010340 RHEL-08-010341 RHEL-08-010350 RHEL-08-010351 RHEL-08-010359 RHEL-08-010360 RHEL-08-010370 RHEL-08-010371 RHEL-08-010372 RHEL-08-010373 RHEL-08-010374 RHEL-08-010375 RHEL-08-010376 RHEL-08-010379 RHEL-08-010380 RHEL-08-010381 RHEL-08-010382 RHEL-08-010383 RHEL-08-010384 RHEL-08-010385 RHEL-08-010390 RHEL-08-010400 RHEL-08-010410 RHEL-08-010420 RHEL-08-010421 RHEL-08-010422 RHEL-08-010423 RHEL-08-010430 RHEL-08-010440 RHEL-08-010450 RHEL-08-010460 RHEL-08-010470 RHEL-08-010471 RHEL-08-010472 RHEL-08-010480 RHEL-08-010490 RHEL-08-010500 RHEL-08-010510 RHEL-08-010520 RHEL-08-010521 RHEL-08-010522 RHEL-08-010540 RHEL-08-010541 RHEL-08-010542 RHEL-08-010543 RHEL-08-010544 RHEL-08-010550 RHEL-08-010561 RHEL-08-010570 RHEL-08-010571 RHEL-08-010572 RHEL-08-010580 RHEL-08-010590 RHEL-08-010600 RHEL-08-010610 RHEL-08-010620 RHEL-08-010630 RHEL-08-010640 RHEL-08-010650 RHEL-08-010660 RHEL-08-010670 RHEL-08-010671 RHEL-08-010672 RHEL-08-010673 RHEL-08-010674 RHEL-08-010675 RHEL-08-010680 RHEL-08-010690 RHEL-08-010700 RHEL-08-010710 RHEL-08-010720 RHEL-08-010730 RHEL-08-010731 RHEL-08-010740 RHEL-08-010741 RHEL-08-010750 RHEL-08-010760 RHEL-08-010770 RHEL-08-010780 RHEL-08-010790 RHEL-08-010800 RHEL-08-010820 RHEL-08-010830 RHEL-08-020000 RHEL-08-020010 RHEL-08-020011 RHEL-08-020012 RHEL-08-020013 RHEL-08-020014 RHEL-08-020015 RHEL-08-020016 RHEL-08-020017 RHEL-08-020018 RHEL-08-020019 RHEL-08-020020 RHEL-08-020021 RHEL-08-020022 RHEL-08-020023 RHEL-08-020024 RHEL-08-020025 RHEL-08-020026 RHEL-08-020027 RHEL-08-020028 RHEL-08-020030 RHEL-08-020031 RHEL-08-020032 RHEL-08-020039 RHEL-08-020040 RHEL-08-020041 RHEL-08-020042 RHEL-08-020050 RHEL-08-020060 RHEL-08-020070 RHEL-08-020080 RHEL-08-020081 RHEL-08-020082 RHEL-08-020090 RHEL-08-020100 RHEL-08-020101 RHEL-08-020102 RHEL-08-020103 RHEL-08-020104 RHEL-08-020110 RHEL-08-020120 RHEL-08-020130 RHEL-08-020140 RHEL-08-020150 RHEL-08-020160 RHEL-08-020170 RHEL-08-020180 RHEL-08-020190 RHEL-08-020200 RHEL-08-020210 RHEL-08-020220 RHEL-08-020221 RHEL-08-020230 RHEL-08-020231 RHEL-08-020240 RHEL-08-020250 RHEL-08-020260 RHEL-08-020270 RHEL-08-020280 RHEL-08-020290 RHEL-08-020300 RHEL-08-020310 RHEL-08-020320 RHEL-08-020330 RHEL-08-020331 RHEL-08-020332 RHEL-08-020340 RHEL-08-020350 RHEL-08-020351 RHEL-08-020352 RHEL-08-020353 RHEL-08-030000 RHEL-08-030010 RHEL-08-030020 RHEL-08-030030 RHEL-08-030040 RHEL-08-030060 RHEL-08-030061 RHEL-08-030062 RHEL-08-030063 RHEL-08-030070 RHEL-08-030080 RHEL-08-030090 RHEL-08-030100 RHEL-08-030110 RHEL-08-030120 RHEL-08-030121 RHEL-08-030122 RHEL-08-030130 RHEL-08-030140 RHEL-08-030150 RHEL-08-030160 RHEL-08-030170 RHEL-08-030171 RHEL-08-030172 RHEL-08-030180 RHEL-08-030181 RHEL-08-030190 RHEL-08-030200 RHEL-08-030250 RHEL-08-030260 RHEL-08-030280 RHEL-08-030290 RHEL-08-030300 RHEL-08-030301 RHEL-08-030302 RHEL-08-030310 RHEL-08-030311 RHEL-08-030312 RHEL-08-030313 RHEL-08-030314 RHEL-08-030315 RHEL-08-030316 RHEL-08-030317 RHEL-08-030320 RHEL-08-030330 RHEL-08-030340 RHEL-08-030350 RHEL-08-030360 RHEL-08-030361 RHEL-08-030370 RHEL-08-030390 RHEL-08-030400 RHEL-08-030410 RHEL-08-030420 RHEL-08-030480 RHEL-08-030490 RHEL-08-030550 RHEL-08-030560 RHEL-08-030570 RHEL-08-030580 RHEL-08-030590 RHEL-08-030600 RHEL-08-030601 RHEL-08-030602 RHEL-08-030603 RHEL-08-030610 RHEL-08-030620 RHEL-08-030630 RHEL-08-030640 RHEL-08-030650 RHEL-08-030660 RHEL-08-030670 RHEL-08-030680 RHEL-08-030690 RHEL-08-030700 RHEL-08-030710 RHEL-08-030720 RHEL-08-030730 RHEL-08-030731 RHEL-08-030740 RHEL-08-030741 RHEL-08-030742 RHEL-08-040000 RHEL-08-040001 RHEL-08-040002 RHEL-08-040004 RHEL-08-040010 RHEL-08-040020 RHEL-08-040021 RHEL-08-040022 RHEL-08-040023 RHEL-08-040024 RHEL-08-040025 RHEL-08-040026 RHEL-08-040030 RHEL-08-040070 RHEL-08-040080 RHEL-08-040090 RHEL-08-040100 RHEL-08-040101 RHEL-08-040110 RHEL-08-040111 RHEL-08-040120 RHEL-08-040121 RHEL-08-040122 RHEL-08-040123 RHEL-08-040124 RHEL-08-040125 RHEL-08-040126 RHEL-08-040127 RHEL-08-040128 RHEL-08-040129 RHEL-08-040130 RHEL-08-040131 RHEL-08-040132 RHEL-08-040133 RHEL-08-040134 RHEL-08-040135 RHEL-08-040136 RHEL-08-040137 RHEL-08-040139 RHEL-08-040140 RHEL-08-040141 RHEL-08-040150 RHEL-08-040159 RHEL-08-040160 RHEL-08-040161 RHEL-08-040170 RHEL-08-040171 RHEL-08-040172 RHEL-08-040180 RHEL-08-040190 RHEL-08-040200 RHEL-08-040209 RHEL-08-040210 RHEL-08-040220 RHEL-08-040230 RHEL-08-040239 RHEL-08-040240 RHEL-08-040249 RHEL-08-040250 RHEL-08-040259 RHEL-08-040260 RHEL-08-040261 RHEL-08-040262 RHEL-08-040270 RHEL-08-040279 RHEL-08-040280 RHEL-08-040281 RHEL-08-040282 RHEL-08-040283 RHEL-08-040284 RHEL-08-040285 RHEL-08-040286 RHEL-08-040290 RHEL-08-040300 RHEL-08-040310 RHEL-08-040320 RHEL-08-040321 RHEL-08-040330 RHEL-08-040340 RHEL-08-040341 RHEL-08-040350 RHEL-08-040360 RHEL-08-040370 RHEL-08-040380 RHEL-08-040390
V-ID CCI CAT Title Description Check Procedures Fixtext Version Mapped Rule
V-230221 high RHEL 8 must be a vendor-supported release. RHEL-08-010000 Missing Rule
V-245540 medium The RHEL 8 operating system must implement the Endpoint Security for Linux Threat Prevention tool. RHEL-08-010001 Missing Rule
V-230222 medium RHEL 8 vendor packaged system security patches and updates must be installed and up to date. RHEL-08-010010 Missing Rule
V-230223 high RHEL 8 must implement NIST FIPS-validated cryptography for the following: to provision digital signatures, to generate cryptographic hashes, and to protect data requiring data-at-rest protections in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards. RHEL-08-010020 Missing Rule
V-230224 medium All RHEL 8 local disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at rest protection. RHEL-08-010030 Missing Rule
V-230225 medium RHEL 8 must display the Standard Mandatory DoD Notice and Consent Banner before granting local or remote access to the system via a ssh logon. RHEL-08-010040 Missing Rule
V-244519 medium RHEL 8 must display a banner before granting local or remote access to the system via a graphical user logon. RHEL-08-010049 Missing Rule
V-230226 medium RHEL 8 must display the Standard Mandatory DoD Notice and Consent Banner before granting local or remote access to the system via a graphical user logon. RHEL-08-010050 Missing Rule
V-230227 medium RHEL 8 must display the Standard Mandatory DoD Notice and Consent Banner before granting local or remote access to the system via a command line user logon. RHEL-08-010060 Missing Rule
V-230228 medium All RHEL 8 remote access methods must be monitored. RHEL-08-010070 Missing Rule
V-230229 medium RHEL 8, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor. RHEL-08-010090 Missing Rule
V-230230 medium RHEL 8, for certificate-based authentication, must enforce authorized access to the corresponding private key. RHEL-08-010100 Missing Rule
V-230231 medium RHEL 8 must encrypt all stored passwords with a FIPS 140-2 approved cryptographic hashing algorithm. RHEL-08-010110 Missing Rule
V-230232 medium RHEL 8 must employ FIPS 140-2 approved cryptographic hashing algorithms for all stored passwords. RHEL-08-010120 Missing Rule
V-251706 high The RHEL 8 operating system must not have accounts configured with blank or null passwords. RHEL-08-010121 Missing Rule
V-230233 medium The RHEL 8 shadow password suite must be configured to use a sufficient number of hashing rounds. RHEL-08-010130 Missing Rule
V-230234 high RHEL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must require authentication upon booting into single-user mode and maintenance. RHEL-08-010140 Missing Rule
V-244521 medium RHEL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must require a unique superusers name upon booting into single-user mode and maintenance. RHEL-08-010141 Missing Rule
V-244522 medium RHEL 8 operating systems booted with a BIOS must require a unique superusers name upon booting into single-user and maintenance modes. RHEL-08-010149 Missing Rule
V-230235 high RHEL 8 operating systems booted with a BIOS must require authentication upon booting into single-user and maintenance modes. RHEL-08-010150 Missing Rule
V-230236 medium RHEL 8 operating systems must require authentication upon booting into rescue mode. RHEL-08-010151 Missing Rule
V-244523 medium RHEL 8 operating systems must require authentication upon booting into emergency mode. RHEL-08-010152 Missing Rule
V-244524 medium The RHEL 8 pam_unix.so module must be configured in the system-auth file to use a FIPS 140-2 approved cryptographic hashing algorithm for system authentication. RHEL-08-010159 Missing Rule
V-230237 medium The RHEL 8 pam_unix.so module must be configured in the password-auth file to use a FIPS 140-2 approved cryptographic hashing algorithm for system authentication. RHEL-08-010160 Missing Rule
V-230238 medium RHEL 8 must prevent system daemons from using Kerberos for authentication. RHEL-08-010161 Missing Rule
V-230239 medium The krb5-workstation package must not be installed on RHEL 8. RHEL-08-010162 Missing Rule
V-237640 medium The krb5-server package must not be installed on RHEL 8. RHEL-08-010163 Missing Rule
V-230240 medium RHEL 8 must use a Linux Security Module configured to enforce limits on system services. RHEL-08-010170 Missing Rule
V-230241 low RHEL 8 must have policycoreutils package installed. RHEL-08-010171 Missing Rule
V-230243 medium A sticky bit must be set on all RHEL 8 public directories to prevent unauthorized and unintended information transferred via shared system resources. RHEL-08-010190 Missing Rule
V-230244 medium RHEL 8 must be configured so that all network connections associated with SSH traffic are terminated at the end of the session or after 10 minutes of inactivity, except to fulfill documented and validated mission requirements. RHEL-08-010200 Missing Rule
V-244525 medium The RHEL 8 SSH daemon must be configured with a timeout interval. RHEL-08-010201 Missing Rule
V-230245 medium The RHEL 8 /var/log/messages file must have mode 0640 or less permissive. RHEL-08-010210 Missing Rule
V-230246 medium The RHEL 8 /var/log/messages file must be owned by root. RHEL-08-010220 Missing Rule
V-230247 medium The RHEL 8 /var/log/messages file must be group-owned by root. RHEL-08-010230 Missing Rule
V-230248 medium The RHEL 8 /var/log directory must have mode 0755 or less permissive. RHEL-08-010240 Missing Rule
V-230249 medium The RHEL 8 /var/log directory must be owned by root. RHEL-08-010250 Missing Rule
V-230250 medium The RHEL 8 /var/log directory must be group-owned by root. RHEL-08-010260 Missing Rule
V-244526 medium The RHEL 8 SSH daemon must be configured to use system-wide crypto policies. RHEL-08-010287 Missing Rule
V-230251 medium The RHEL 8 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-2 validated cryptographic hash algorithms. RHEL-08-010290 Missing Rule
V-230252 medium The RHEL 8 operating system must implement DoD-approved encryption to protect the confidentiality of SSH server connections. RHEL-08-010291 Missing Rule
V-230253 low RHEL 8 must ensure the SSH server uses strong entropy. RHEL-08-010292 Missing Rule
V-230254 medium The RHEL 8 operating system must implement DoD-approved encryption in the OpenSSL package. RHEL-08-010293 Missing Rule
V-230255 medium The RHEL 8 operating system must implement DoD-approved TLS encryption in the OpenSSL package. RHEL-08-010294 Missing Rule
V-230256 medium The RHEL 8 operating system must implement DoD-approved TLS encryption in the GnuTLS package. RHEL-08-010295 Missing Rule
V-230257 medium RHEL 8 system commands must have mode 755 or less permissive. RHEL-08-010300 Missing Rule
V-230258 medium RHEL 8 system commands must be owned by root. RHEL-08-010310 Missing Rule
V-230259 medium RHEL 8 system commands must be group-owned by root or a system account. RHEL-08-010320 Missing Rule
V-230260 medium RHEL 8 library files must have mode 755 or less permissive. RHEL-08-010330 Missing Rule
V-251707 medium RHEL 8 library directories must have mode 755 or less permissive. RHEL-08-010331 Missing Rule
V-230261 medium RHEL 8 library files must be owned by root. RHEL-08-010340 Missing Rule
V-251708 medium RHEL 8 library directories must be owned by root. RHEL-08-010341 Missing Rule
V-230262 medium RHEL 8 library files must be group-owned by root or a system account. RHEL-08-010350 Missing Rule
V-251709 medium RHEL 8 library directories must be group-owned by root or a system account. RHEL-08-010351 Missing Rule
V-251710 medium The RHEL 8 operating system must use a file integrity tool to verify correct operation of all security functions. RHEL-08-010359 Missing Rule
V-230263 medium The RHEL 8 file integrity tool must notify the system administrator when changes to the baseline configuration or anomalies in the operation of any security functions are discovered within an organizationally defined frequency. RHEL-08-010360 Missing Rule
V-230264 high RHEL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components from a repository without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization. RHEL-08-010370 Missing Rule
V-230265 high RHEL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components of local packages without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization. RHEL-08-010371 Missing Rule
V-230266 medium RHEL 8 must prevent the loading of a new kernel for later execution. RHEL-08-010372 Missing Rule
V-230267 medium RHEL 8 must enable kernel parameters to enforce discretionary access control on symlinks. RHEL-08-010373 Missing Rule
V-230268 medium RHEL 8 must enable kernel parameters to enforce discretionary access control on hardlinks. RHEL-08-010374 Missing Rule
V-230269 low RHEL 8 must restrict access to the kernel message buffer. RHEL-08-010375 Missing Rule
V-230270 low RHEL 8 must prevent kernel profiling by unprivileged users. RHEL-08-010376 Missing Rule
V-251711 medium RHEL 8 must specify the default "include" directory for the /etc/sudoers file. RHEL-08-010379 Missing Rule
V-230271 medium RHEL 8 must require users to provide a password for privilege escalation. RHEL-08-010380 Missing Rule
V-230272 medium RHEL 8 must require users to reauthenticate for privilege escalation. RHEL-08-010381 Missing Rule
V-237641 medium RHEL 8 must restrict privilege elevation to authorized personnel. RHEL-08-010382 Missing Rule
V-237642 medium RHEL 8 must use the invoking user's password for privilege escalation when using "sudo". RHEL-08-010383 Missing Rule
V-237643 medium RHEL 8 must require re-authentication when using the "sudo" command. RHEL-08-010384 Missing Rule
V-251712 medium The RHEL 8 operating system must not be configured to bypass password requirements for privilege escalation. RHEL-08-010385 Missing Rule
V-230273 medium RHEL 8 must have the packages required for multifactor authentication installed. RHEL-08-010390 Missing Rule
V-230274 medium RHEL 8 must implement certificate status checking for multifactor authentication. RHEL-08-010400 Missing Rule
V-230275 medium RHEL 8 must accept Personal Identity Verification (PIV) credentials. RHEL-08-010410 Missing Rule
V-230276 medium RHEL 8 must implement non-executable data to protect its memory from unauthorized code execution. RHEL-08-010420 Missing Rule
V-230277 medium RHEL 8 must clear the page allocator to prevent use-after-free attacks. RHEL-08-010421 Missing Rule
V-230278 medium RHEL 8 must disable virtual syscalls. RHEL-08-010422 Missing Rule
V-230279 medium RHEL 8 must clear SLUB/SLAB objects to prevent use-after-free attacks. RHEL-08-010423 Missing Rule
V-230280 medium RHEL 8 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution. RHEL-08-010430 Missing Rule
V-230281 low YUM must remove all software components after updated versions have been installed on RHEL 8. RHEL-08-010440 Missing Rule
V-230282 medium RHEL 8 must enable the SELinux targeted policy. RHEL-08-010450 Missing Rule
V-230283 high There must be no shosts.equiv files on the RHEL 8 operating system. RHEL-08-010460 Missing Rule
V-230284 high There must be no .shosts files on the RHEL 8 operating system. RHEL-08-010470 Missing Rule
V-230285 low RHEL 8 must enable the hardware random number generator entropy gatherer service. RHEL-08-010471 Missing Rule
V-244527 low RHEL 8 must have the packages required to use the hardware random number generator entropy gatherer service. RHEL-08-010472 Missing Rule
V-230286 medium The RHEL 8 SSH public host key files must have mode 0644 or less permissive. RHEL-08-010480 Missing Rule
V-230287 medium The RHEL 8 SSH private host key files must have mode 0600 or less permissive. RHEL-08-010490 Missing Rule
V-230288 medium The RHEL 8 SSH daemon must perform strict mode checking of home directory configuration files. RHEL-08-010500 Missing Rule
V-230289 medium The RHEL 8 SSH daemon must not allow compression or must only allow compression after successful authentication. RHEL-08-010510 Missing Rule
V-230290 medium The RHEL 8 SSH daemon must not allow authentication using known host’s authentication. RHEL-08-010520 Missing Rule
V-230291 medium The RHEL 8 SSH daemon must not allow Kerberos authentication, except to fulfill documented and validated mission requirements. RHEL-08-010521 Missing Rule
V-244528 medium The RHEL 8 SSH daemon must not allow GSSAPI authentication, except to fulfill documented and validated mission requirements. RHEL-08-010522 Missing Rule
V-230292 low RHEL 8 must use a separate file system for /var. RHEL-08-010540 Missing Rule
V-230293 low RHEL 8 must use a separate file system for /var/log. RHEL-08-010541 Missing Rule
V-230294 low RHEL 8 must use a separate file system for the system audit data path. RHEL-08-010542 Missing Rule
V-230295 medium A separate RHEL 8 filesystem must be used for the /tmp directory. RHEL-08-010543 Missing Rule
V-244529 medium RHEL 8 must use a separate file system for /var/tmp. RHEL-08-010544 Missing Rule
V-230296 medium RHEL 8 must not permit direct logons to the root account using remote access via SSH. RHEL-08-010550 Missing Rule
V-230298 medium The rsyslog service must be running in RHEL 8. RHEL-08-010561 Missing Rule
V-230299 medium RHEL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories. RHEL-08-010570 Missing Rule
V-230300 medium RHEL 8 must prevent files with the setuid and setgid bit set from being executed on the /boot directory. RHEL-08-010571 Missing Rule
V-244530 medium RHEL 8 must prevent files with the setuid and setgid bit set from being executed on the /boot/efi directory. RHEL-08-010572 Missing Rule
V-230301 medium RHEL 8 must prevent special devices on non-root local partitions. RHEL-08-010580 Missing Rule
V-230302 medium RHEL 8 must prevent code from being executed on file systems that contain user home directories. RHEL-08-010590 Missing Rule
V-230303 medium RHEL 8 must prevent special devices on file systems that are used with removable media. RHEL-08-010600 Missing Rule
V-230304 medium RHEL 8 must prevent code from being executed on file systems that are used with removable media. RHEL-08-010610 Missing Rule
V-230305 medium RHEL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that are used with removable media. RHEL-08-010620 Missing Rule
V-230306 medium RHEL 8 must prevent code from being executed on file systems that are imported via Network File System (NFS). RHEL-08-010630 Missing Rule
V-230307 medium RHEL 8 must prevent special devices on file systems that are imported via Network File System (NFS). RHEL-08-010640 Missing Rule
V-230308 medium RHEL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that are imported via Network File System (NFS). RHEL-08-010650 Missing Rule
V-230309 medium Local RHEL 8 initialization files must not execute world-writable programs. RHEL-08-010660 Missing Rule
V-230310 medium RHEL 8 must disable kernel dumps unless needed. RHEL-08-010670 Missing Rule
V-230311 medium RHEL 8 must disable the kernel.core_pattern. RHEL-08-010671 Missing Rule
V-230312 medium RHEL 8 must disable acquiring, saving, and processing core dumps. RHEL-08-010672 Missing Rule
V-230313 medium RHEL 8 must disable core dumps for all users. RHEL-08-010673 Missing Rule
V-230314 medium RHEL 8 must disable storing core dumps. RHEL-08-010674 Missing Rule
V-230315 medium RHEL 8 must disable core dump backtraces. RHEL-08-010675 Missing Rule
V-230316 medium For RHEL 8 systems using Domain Name Servers (DNS) resolution, at least two name servers must be configured. RHEL-08-010680 Missing Rule
V-230317 medium Executable search paths within the initialization files of all local interactive RHEL 8 users must only contain paths that resolve to the system default or the users home directory. RHEL-08-010690 Missing Rule
V-230318 medium All RHEL 8 world-writable directories must be owned by root, sys, bin, or an application user. RHEL-08-010700 Missing Rule
V-230319 medium All RHEL 8 world-writable directories must be group-owned by root, sys, bin, or an application group. RHEL-08-010710 Missing Rule
V-230320 medium All RHEL 8 local interactive users must have a home directory assigned in the /etc/passwd file. RHEL-08-010720 Missing Rule
V-230321 medium All RHEL 8 local interactive user home directories must have mode 0750 or less permissive. RHEL-08-010730 Missing Rule
V-244531 medium All RHEL 8 local interactive user home directory files must have mode 0750 or less permissive. RHEL-08-010731 Missing Rule
V-230322 medium All RHEL 8 local interactive user home directories must be group-owned by the home directory owner’s primary group. RHEL-08-010740 Missing Rule
V-244532 medium RHEL 8 must be configured so that all files and directories contained in local interactive user home directories are group-owned by a group of which the home directory owner is a member. RHEL-08-010741 Missing Rule
V-230323 medium All RHEL 8 local interactive user home directories defined in the /etc/passwd file must exist. RHEL-08-010750 Missing Rule
V-230324 medium All RHEL 8 local interactive user accounts must be assigned a home directory upon creation. RHEL-08-010760 Missing Rule
V-230325 medium All RHEL 8 local initialization files must have mode 0740 or less permissive. RHEL-08-010770 Missing Rule
V-230326 medium All RHEL 8 local files and directories must have a valid owner. RHEL-08-010780 Missing Rule
V-230327 medium All RHEL 8 local files and directories must have a valid group owner. RHEL-08-010790 Missing Rule
V-230328 medium A separate RHEL 8 filesystem must be used for user home directories (such as /home or an equivalent). RHEL-08-010800 Missing Rule
V-230329 high Unattended or automatic logon via the RHEL 8 graphical user interface must not be allowed. RHEL-08-010820 Missing Rule
V-230330 medium RHEL 8 must not allow users to override SSH environment variables. RHEL-08-010830 Missing Rule
V-230331 medium RHEL 8 temporary user accounts must be provisioned with an expiration time of 72 hours or less. RHEL-08-020000 Missing Rule
V-230332 medium RHEL 8 must automatically lock an account when three unsuccessful logon attempts occur. RHEL-08-020010 Missing Rule
V-230333 medium RHEL 8 must automatically lock an account when three unsuccessful logon attempts occur. RHEL-08-020011 Missing Rule
V-230334 medium RHEL 8 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period. RHEL-08-020012 Missing Rule
V-230335 medium RHEL 8 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period. RHEL-08-020013 Missing Rule
V-230336 medium RHEL 8 must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period. RHEL-08-020014 Missing Rule
V-230337 medium RHEL 8 must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period. RHEL-08-020015 Missing Rule
V-230338 medium RHEL 8 must ensure account lockouts persist. RHEL-08-020016 Missing Rule
V-230339 medium RHEL 8 must ensure account lockouts persist. RHEL-08-020017 Missing Rule
V-230340 medium RHEL 8 must prevent system messages from being presented when three unsuccessful logon attempts occur. RHEL-08-020018 Missing Rule
V-230341 medium RHEL 8 must prevent system messages from being presented when three unsuccessful logon attempts occur. RHEL-08-020019 Missing Rule
V-230342 medium RHEL 8 must log user name information when unsuccessful logon attempts occur. RHEL-08-020020 Missing Rule
V-230343 medium RHEL 8 must log user name information when unsuccessful logon attempts occur. RHEL-08-020021 Missing Rule
V-230344 medium RHEL 8 must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period. RHEL-08-020022 Missing Rule
V-230345 medium RHEL 8 must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period. RHEL-08-020023 Missing Rule
V-230346 low RHEL 8 must limit the number of concurrent sessions to ten for all accounts and/or account types. RHEL-08-020024 Missing Rule
V-244533 medium RHEL 8 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file. RHEL-08-020025 Missing Rule
V-244534 medium RHEL 8 must configure the use of the pam_faillock.so module in the /etc/pam.d/password-auth file. RHEL-08-020026 Missing Rule
V-250315 medium RHEL 8 systems, versions 8.2 and above, must configure SELinux context type to allow the use of a non-default faillock tally directory. RHEL-08-020027 Missing Rule
V-250316 medium RHEL 8 systems below version 8.2 must configure SELinux context type to allow the use of a non-default faillock tally directory. RHEL-08-020028 Missing Rule
V-230347 medium RHEL 8 must enable a user session lock until that user re-establishes access using established identification and authentication procedures for graphical user sessions. RHEL-08-020030 Missing Rule
V-244535 medium RHEL 8 must initiate a session lock for graphical user interfaces when the screensaver is activated. RHEL-08-020031 Missing Rule
V-244536 medium RHEL 8 must disable the user list at logon for graphical user interfaces. RHEL-08-020032 Missing Rule
V-244537 medium RHEL 8 must have the tmux package installed. RHEL-08-020039 Missing Rule
V-230348 medium RHEL 8 must enable a user session lock until that user re-establishes access using established identification and authentication procedures for command line sessions. RHEL-08-020040 Missing Rule
V-230349 medium RHEL 8 must ensure session control is automatically started at shell initialization. RHEL-08-020041 Missing Rule
V-230350 low RHEL 8 must prevent users from disabling session control mechanisms. RHEL-08-020042 Missing Rule
V-230351 medium RHEL 8 must be able to initiate directly a session lock for all connection types using smartcard when the smartcard is removed. RHEL-08-020050 Missing Rule
V-230352 medium RHEL 8 must automatically lock graphical user sessions after 15 minutes of inactivity. RHEL-08-020060 Missing Rule
V-230353 medium RHEL 8 must automatically lock command line user sessions after 15 minutes of inactivity. RHEL-08-020070 Missing Rule
V-230354 medium RHEL 8 must prevent a user from overriding the session lock-delay setting for the graphical user interface. RHEL-08-020080 Missing Rule
V-244538 medium RHEL 8 must prevent a user from overriding the session idle-delay setting for the graphical user interface. RHEL-08-020081 Missing Rule
V-244539 medium RHEL 8 must prevent a user from overriding the screensaver lock-enabled setting for the graphical user interface. RHEL-08-020082 Missing Rule
V-230355 medium RHEL 8 must map the authenticated identity to the user or group account for PKI-based authentication. RHEL-08-020090 Missing Rule
V-230356 medium RHEL 8 must ensure the password complexity module is enabled in the password-auth file. RHEL-08-020100 Missing Rule
V-251713 medium RHEL 8 must ensure the password complexity module is enabled in the system-auth file. RHEL-08-020101 Missing Rule
V-251714 medium RHEL 8 systems below version 8.4 must ensure the password complexity module in the system-auth file is configured for three retries or less. RHEL-08-020102 Missing Rule
V-251715 medium RHEL 8 systems below version 8.4 must ensure the password complexity module in the password-auth file is configured for three retries or less. RHEL-08-020103 Missing Rule
V-251716 medium RHEL 8 systems, version 8.4 and above, must ensure the password complexity module is configured for three retries or less. RHEL-08-020104 Missing Rule
V-230357 medium RHEL 8 must enforce password complexity by requiring that at least one uppercase character be used. RHEL-08-020110 Missing Rule
V-230358 medium RHEL 8 must enforce password complexity by requiring that at least one lower-case character be used. RHEL-08-020120 Missing Rule
V-230359 medium RHEL 8 must enforce password complexity by requiring that at least one numeric character be used. RHEL-08-020130 Missing Rule
V-230360 medium RHEL 8 must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed. RHEL-08-020140 Missing Rule
V-230361 medium RHEL 8 must require the maximum number of repeating characters be limited to three when passwords are changed. RHEL-08-020150 Missing Rule
V-230362 medium RHEL 8 must require the change of at least four character classes when passwords are changed. RHEL-08-020160 Missing Rule
V-230363 medium RHEL 8 must require the change of at least 8 characters when passwords are changed. RHEL-08-020170 Missing Rule
V-230364 medium RHEL 8 passwords must have a 24 hours/1 day minimum password lifetime restriction in /etc/shadow. RHEL-08-020180 Missing Rule
V-230365 medium RHEL 8 passwords for new users or password changes must have a 24 hours/1 day minimum password lifetime restriction in /etc/logins.def. RHEL-08-020190 Missing Rule
V-230366 medium RHEL 8 user account passwords must have a 60-day maximum password lifetime restriction. RHEL-08-020200 Missing Rule
V-230367 medium RHEL 8 user account passwords must be configured so that existing passwords are restricted to a 60-day maximum lifetime. RHEL-08-020210 Missing Rule
V-230368 medium RHEL 8 must be configured in the password-auth file to prohibit password reuse for a minimum of five generations. RHEL-08-020220 Missing Rule
V-251717 medium RHEL 8 must be configured in the system-auth file to prohibit password reuse for a minimum of five generations. RHEL-08-020221 Missing Rule
V-230369 medium RHEL 8 passwords must have a minimum of 15 characters. RHEL-08-020230 Missing Rule
V-230370 medium RHEL 8 passwords for new users must have a minimum of 15 characters. RHEL-08-020231 Missing Rule
V-230371 medium RHEL 8 duplicate User IDs (UIDs) must not exist for interactive users. RHEL-08-020240 Missing Rule
V-230372 medium RHEL 8 must implement smart card logon for multifactor authentication for access to interactive accounts. RHEL-08-020250 Missing Rule
V-230373 medium RHEL 8 account identifiers (individuals, groups, roles, and devices) must be disabled after 35 days of inactivity. RHEL-08-020260 Missing Rule
V-230374 medium RHEL 8 emergency accounts must be automatically removed or disabled after the crisis is resolved or within 72 hours. RHEL-08-020270 Missing Rule
V-230375 medium All RHEL 8 passwords must contain at least one special character. RHEL-08-020280 Missing Rule
V-230376 medium RHEL 8 must prohibit the use of cached authentications after one day. RHEL-08-020290 Missing Rule
V-230377 medium RHEL 8 must prevent the use of dictionary words for passwords. RHEL-08-020300 Missing Rule
V-230378 medium RHEL 8 must enforce a delay of at least four seconds between logon prompts following a failed logon attempt. RHEL-08-020310 Missing Rule
V-230379 medium RHEL 8 must not have unnecessary accounts. RHEL-08-020320 Missing Rule
V-230380 high RHEL 8 must not allow accounts configured with blank or null passwords. RHEL-08-020330 Missing Rule
V-244540 high RHEL 8 must not allow blank or null passwords in the system-auth file. RHEL-08-020331 Missing Rule
V-244541 high RHEL 8 must not allow blank or null passwords in the password-auth file. RHEL-08-020332 Missing Rule
V-230381 low RHEL 8 must display the date and time of the last successful account logon upon logon. RHEL-08-020340 Missing Rule
V-230382 medium RHEL 8 must display the date and time of the last successful account logon upon an SSH logon. RHEL-08-020350 Missing Rule
V-230383 medium RHEL 8 must define default permissions for all authenticated users in such a way that the user can only read and modify their own files. RHEL-08-020351 Missing Rule
V-230384 medium RHEL 8 must set the umask value to 077 for all local interactive user accounts. RHEL-08-020352 Missing Rule
V-230385 medium RHEL 8 must define default permissions for logon and non-logon shells. RHEL-08-020353 Missing Rule
V-230386 medium The RHEL 8 audit system must be configured to audit the execution of privileged functions and prevent all software from executing at higher privilege levels than users executing the software. RHEL-08-030000 Missing Rule
V-230387 medium Cron logging must be implemented in RHEL 8. RHEL-08-030010 Missing Rule
V-230388 medium The RHEL 8 System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) must be alerted of an audit processing failure event. RHEL-08-030020 Missing Rule
V-230389 medium The RHEL 8 Information System Security Officer (ISSO) and System Administrator (SA) (at a minimum) must have mail aliases to be notified of an audit processing failure. RHEL-08-030030 Missing Rule
V-230390 medium The RHEL 8 System must take appropriate action when an audit processing failure occurs. RHEL-08-030040 Missing Rule
V-230392 medium The RHEL 8 audit system must take appropriate action when the audit storage volume is full. RHEL-08-030060 Missing Rule
V-230393 medium The RHEL 8 audit system must audit local events. RHEL-08-030061 Missing Rule
V-230394 medium RHEL 8 must label all off-loaded audit logs before sending them to the central log server. RHEL-08-030062 Missing Rule
V-230395 low RHEL 8 must resolve audit information before writing to disk. RHEL-08-030063 Missing Rule
V-230396 medium RHEL 8 audit logs must have a mode of 0600 or less permissive to prevent unauthorized read access. RHEL-08-030070 Missing Rule
V-230397 medium RHEL 8 audit logs must be owned by root to prevent unauthorized read access. RHEL-08-030080 Missing Rule
V-230398 medium RHEL 8 audit logs must be group-owned by root to prevent unauthorized read access. RHEL-08-030090 Missing Rule
V-230399 medium RHEL 8 audit log directory must be owned by root to prevent unauthorized read access. RHEL-08-030100 Missing Rule
V-230400 medium RHEL 8 audit log directory must be group-owned by root to prevent unauthorized read access. RHEL-08-030110 Missing Rule
V-230401 medium RHEL 8 audit log directory must have a mode of 0700 or less permissive to prevent unauthorized read access. RHEL-08-030120 Missing Rule
V-230402 medium RHEL 8 audit system must protect auditing rules from unauthorized change. RHEL-08-030121 Missing Rule
V-230403 medium RHEL 8 audit system must protect logon UIDs from unauthorized change. RHEL-08-030122 Missing Rule
V-230404 medium RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow. RHEL-08-030130 Missing Rule
V-230405 medium RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd. RHEL-08-030140 Missing Rule
V-230406 medium RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd. RHEL-08-030150 Missing Rule
V-230407 medium RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow. RHEL-08-030160 Missing Rule
V-230408 medium RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group. RHEL-08-030170 Missing Rule
V-230409 medium RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers. RHEL-08-030171 Missing Rule
V-230410 medium RHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/. RHEL-08-030172 Missing Rule
V-230411 medium The RHEL 8 audit package must be installed. RHEL-08-030180 Missing Rule
V-244542 medium RHEL 8 audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events. RHEL-08-030181 Missing Rule
V-230412 medium Successful/unsuccessful uses of the su command in RHEL 8 must generate an audit record. RHEL-08-030190 Missing Rule
V-230413 medium The RHEL 8 audit system must be configured to audit any usage of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls. RHEL-08-030200 Missing Rule
V-230418 medium Successful/unsuccessful uses of the chage command in RHEL 8 must generate an audit record. RHEL-08-030250 Missing Rule
V-230419 medium Successful/unsuccessful uses of the chcon command in RHEL 8 must generate an audit record. RHEL-08-030260 Missing Rule
V-230421 medium Successful/unsuccessful uses of the ssh-agent in RHEL 8 must generate an audit record. RHEL-08-030280 Missing Rule
V-230422 medium Successful/unsuccessful uses of the passwd command in RHEL 8 must generate an audit record. RHEL-08-030290 Missing Rule
V-230423 medium Successful/unsuccessful uses of the mount command in RHEL 8 must generate an audit record. RHEL-08-030300 Missing Rule
V-230424 medium Successful/unsuccessful uses of the umount command in RHEL 8 must generate an audit record. RHEL-08-030301 Missing Rule
V-230425 medium Successful/unsuccessful uses of the mount syscall in RHEL 8 must generate an audit record. RHEL-08-030302 Missing Rule
V-230426 medium Successful/unsuccessful uses of the unix_update in RHEL 8 must generate an audit record. RHEL-08-030310 Missing Rule
V-230427 medium Successful/unsuccessful uses of postdrop in RHEL 8 must generate an audit record. RHEL-08-030311 Missing Rule
V-230428 medium Successful/unsuccessful uses of postqueue in RHEL 8 must generate an audit record. RHEL-08-030312 Missing Rule
V-230429 medium Successful/unsuccessful uses of semanage in RHEL 8 must generate an audit record. RHEL-08-030313 Missing Rule
V-230430 medium Successful/unsuccessful uses of setfiles in RHEL 8 must generate an audit record. RHEL-08-030314 Missing Rule
V-230431 medium Successful/unsuccessful uses of userhelper in RHEL 8 must generate an audit record. RHEL-08-030315 Missing Rule
V-230432 medium Successful/unsuccessful uses of setsebool in RHEL 8 must generate an audit record. RHEL-08-030316 Missing Rule
V-230433 medium Successful/unsuccessful uses of unix_chkpwd in RHEL 8 must generate an audit record. RHEL-08-030317 Missing Rule
V-230434 medium Successful/unsuccessful uses of the ssh-keysign in RHEL 8 must generate an audit record. RHEL-08-030320 Missing Rule
V-230435 medium Successful/unsuccessful uses of the setfacl command in RHEL 8 must generate an audit record. RHEL-08-030330 Missing Rule
V-230436 medium Successful/unsuccessful uses of the pam_timestamp_check command in RHEL 8 must generate an audit record. RHEL-08-030340 Missing Rule
V-230437 medium Successful/unsuccessful uses of the newgrp command in RHEL 8 must generate an audit record. RHEL-08-030350 Missing Rule
V-230438 medium Successful/unsuccessful uses of the init_module and finit_module system calls in RHEL 8 must generate an audit record. RHEL-08-030360 Missing Rule
V-230439 medium Successful/unsuccessful uses of the rename, unlink, rmdir, renameat, and unlinkat system calls in RHEL 8 must generate an audit record. RHEL-08-030361 Missing Rule
V-230444 medium Successful/unsuccessful uses of the gpasswd command in RHEL 8 must generate an audit record. RHEL-08-030370 Missing Rule
V-230446 medium Successful/unsuccessful uses of the delete_module command in RHEL 8 must generate an audit record. RHEL-08-030390 Missing Rule
V-230447 medium Successful/unsuccessful uses of the crontab command in RHEL 8 must generate an audit record. RHEL-08-030400 Missing Rule
V-230448 medium Successful/unsuccessful uses of the chsh command in RHEL 8 must generate an audit record. RHEL-08-030410 Missing Rule
V-230449 medium Successful/unsuccessful uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls in RHEL 8 must generate an audit record. RHEL-08-030420 Missing Rule
V-230455 medium Successful/unsuccessful uses of the chown, fchown, fchownat, and lchown system calls in RHEL 8 must generate an audit record. RHEL-08-030480 Missing Rule
V-230456 medium Successful/unsuccessful uses of the chmod, fchmod, and fchmodat system calls in RHEL 8 must generate an audit record. RHEL-08-030490 Missing Rule
V-230462 medium Successful/unsuccessful uses of the sudo command in RHEL 8 must generate an audit record. RHEL-08-030550 Missing Rule
V-230463 medium Successful/unsuccessful uses of the usermod command in RHEL 8 must generate an audit record. RHEL-08-030560 Missing Rule
V-230464 medium Successful/unsuccessful uses of the chacl command in RHEL 8 must generate an audit record. RHEL-08-030570 Missing Rule
V-230465 medium Successful/unsuccessful uses of the kmod command in RHEL 8 must generate an audit record. RHEL-08-030580 Missing Rule
V-230466 medium Successful/unsuccessful modifications to the faillock log file in RHEL 8 must generate an audit record. RHEL-08-030590 Missing Rule
V-230467 medium Successful/unsuccessful modifications to the lastlog file in RHEL 8 must generate an audit record. RHEL-08-030600 Missing Rule
V-230468 low RHEL 8 must enable auditing of processes that start prior to the audit daemon. RHEL-08-030601 Missing Rule
V-230469 low RHEL 8 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon. RHEL-08-030602 Missing Rule
V-230470 low RHEL 8 must enable Linux audit logging for the USBGuard daemon. RHEL-08-030603 Missing Rule
V-230471 medium RHEL 8 must allow only the Information System Security Manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited. RHEL-08-030610 Missing Rule
V-230472 medium RHEL 8 audit tools must have a mode of 0755 or less permissive. RHEL-08-030620 Missing Rule
V-230473 medium RHEL 8 audit tools must be owned by root. RHEL-08-030630 Missing Rule
V-230474 medium RHEL 8 audit tools must be group-owned by root. RHEL-08-030640 Missing Rule
V-230475 medium RHEL 8 must use cryptographic mechanisms to protect the integrity of audit tools. RHEL-08-030650 Missing Rule
V-230476 medium RHEL 8 must allocate audit record storage capacity to store at least one week of audit records, when audit records are not immediately sent to a central audit record storage facility. RHEL-08-030660 Missing Rule
V-230477 medium RHEL 8 must have the packages required for offloading audit logs installed. RHEL-08-030670 Missing Rule
V-230478 medium RHEL 8 must have the packages required for encrypting offloaded audit logs installed. RHEL-08-030680 Missing Rule
V-230479 medium The RHEL 8 audit records must be off-loaded onto a different system or storage media from the system being audited. RHEL-08-030690 Missing Rule
V-230480 medium RHEL 8 must take appropriate action when the internal event queue is full. RHEL-08-030700 Missing Rule
V-230481 medium RHEL 8 must encrypt the transfer of audit records off-loaded onto a different system or media from the system being audited. RHEL-08-030710 Missing Rule
V-230482 medium RHEL 8 must authenticate the remote logging server for off-loading audit logs. RHEL-08-030720 Missing Rule
V-230483 medium RHEL 8 must take action when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity. RHEL-08-030730 Missing Rule
V-244543 medium RHEL 8 must notify the System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) when allocated audit record storage volume 75 percent utilization. RHEL-08-030731 Missing Rule
V-230484 medium RHEL 8 must securely compare internal information system clocks at least every 24 hours with a server synchronized to an authoritative time source, such as the United States Naval Observatory (USNO) time servers, or a time server designated for the appropriate DoD network (NIPRNet/SIPRNet), and/or the Global Positioning System (GPS). RHEL-08-030740 Missing Rule
V-230485 low RHEL 8 must disable the chrony daemon from acting as a server. RHEL-08-030741 Missing Rule
V-230486 low RHEL 8 must disable network management of the chrony daemon. RHEL-08-030742 Missing Rule
V-230487 high RHEL 8 must not have the telnet-server package installed. RHEL-08-040000 Missing Rule
V-230488 medium RHEL 8 must not have any automated bug reporting tools installed. RHEL-08-040001 Missing Rule
V-230489 medium RHEL 8 must not have the sendmail package installed. RHEL-08-040002 Missing Rule
V-230491 low RHEL 8 must enable mitigations against processor-based vulnerabilities. RHEL-08-040004 Missing Rule
V-230492 high RHEL 8 must not have the rsh-server package installed. RHEL-08-040010 Missing Rule
V-230493 medium RHEL 8 must cover or disable the built-in or attached camera when not in use. RHEL-08-040020 Missing Rule
V-230494 low RHEL 8 must disable the asynchronous transfer mode (ATM) protocol. RHEL-08-040021 Missing Rule
V-230495 low RHEL 8 must disable the controller area network (CAN) protocol. RHEL-08-040022 Missing Rule
V-230496 low RHEL 8 must disable the stream control transmission protocol (SCTP). RHEL-08-040023 Missing Rule
V-230497 low RHEL 8 must disable the transparent inter-process communication (TIPC) protocol. RHEL-08-040024 Missing Rule
V-230498 low RHEL 8 must disable mounting of cramfs. RHEL-08-040025 Missing Rule
V-230499 low RHEL 8 must disable IEEE 1394 (FireWire) Support. RHEL-08-040026 Missing Rule
V-230500 medium RHEL 8 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments. RHEL-08-040030 Missing Rule
V-230502 medium The RHEL 8 file system automounter must be disabled unless required. RHEL-08-040070 Missing Rule
V-230503 medium RHEL 8 must be configured to disable USB mass storage. RHEL-08-040080 Missing Rule
V-230504 medium A RHEL 8 firewall must employ a deny-all, allow-by-exception policy for allowing connections to other systems. RHEL-08-040090 Missing Rule
V-230505 medium A firewall must be installed on RHEL 8. RHEL-08-040100 Missing Rule
V-244544 medium A firewall must be active on RHEL 8. RHEL-08-040101 Missing Rule
V-230506 medium RHEL 8 wireless network adapters must be disabled. RHEL-08-040110 Missing Rule
V-230507 medium RHEL 8 Bluetooth must be disabled. RHEL-08-040111 Missing Rule
V-230508 medium RHEL 8 must mount /dev/shm with the nodev option. RHEL-08-040120 Missing Rule
V-230509 medium RHEL 8 must mount /dev/shm with the nosuid option. RHEL-08-040121 Missing Rule
V-230510 medium RHEL 8 must mount /dev/shm with the noexec option. RHEL-08-040122 Missing Rule
V-230511 medium RHEL 8 must mount /tmp with the nodev option. RHEL-08-040123 Missing Rule
V-230512 medium RHEL 8 must mount /tmp with the nosuid option. RHEL-08-040124 Missing Rule
V-230513 medium RHEL 8 must mount /tmp with the noexec option. RHEL-08-040125 Missing Rule
V-230514 medium RHEL 8 must mount /var/log with the nodev option. RHEL-08-040126 Missing Rule
V-230515 medium RHEL 8 must mount /var/log with the nosuid option. RHEL-08-040127 Missing Rule
V-230516 medium RHEL 8 must mount /var/log with the noexec option. RHEL-08-040128 Missing Rule
V-230517 medium RHEL 8 must mount /var/log/audit with the nodev option. RHEL-08-040129 Missing Rule
V-230518 medium RHEL 8 must mount /var/log/audit with the nosuid option. RHEL-08-040130 Missing Rule
V-230519 medium RHEL 8 must mount /var/log/audit with the noexec option. RHEL-08-040131 Missing Rule
V-230520 medium RHEL 8 must mount /var/tmp with the nodev option. RHEL-08-040132 Missing Rule
V-230521 medium RHEL 8 must mount /var/tmp with the nosuid option. RHEL-08-040133 Missing Rule
V-230522 medium RHEL 8 must mount /var/tmp with the noexec option. RHEL-08-040134 Missing Rule
V-230523 medium The RHEL 8 fapolicy module must be installed. RHEL-08-040135 Missing Rule
V-244545 medium The RHEL 8 fapolicy module must be enabled. RHEL-08-040136 Missing Rule
V-244546 medium The RHEL 8 fapolicy module must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs. RHEL-08-040137 Missing Rule
V-244547 medium RHEL 8 must have the USBGuard installed. RHEL-08-040139 Missing Rule
V-230524 medium RHEL 8 must block unauthorized peripherals before establishing a connection. RHEL-08-040140 Missing Rule
V-244548 medium RHEL 8 must enable the USBGuard. RHEL-08-040141 Missing Rule
V-230525 medium A firewall must be able to protect against or limit the effects of Denial of Service (DoS) attacks by ensuring RHEL 8 can implement rate-limiting measures on impacted network interfaces. RHEL-08-040150 Missing Rule
V-244549 medium All RHEL 8 networked systems must have SSH installed. RHEL-08-040159 Missing Rule
V-230526 medium All RHEL 8 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission. RHEL-08-040160 Missing Rule
V-230527 medium RHEL 8 must force a frequent session key renegotiation for SSH connections to the server. RHEL-08-040161 Missing Rule
V-230529 high The x86 Ctrl-Alt-Delete key sequence must be disabled on RHEL 8. RHEL-08-040170 Missing Rule
V-230530 high The x86 Ctrl-Alt-Delete key sequence in RHEL 8 must be disabled if a graphical user interface is installed. RHEL-08-040171 Missing Rule
V-230531 high The systemd Ctrl-Alt-Delete burst key sequence in RHEL 8 must be disabled. RHEL-08-040172 Missing Rule
V-230532 medium The debug-shell systemd service must be disabled on RHEL 8. RHEL-08-040180 Missing Rule
V-230533 high The Trivial File Transfer Protocol (TFTP) server package must not be installed if not required for RHEL 8 operational support. RHEL-08-040190 Missing Rule
V-230534 high The root account must be the only account having unrestricted access to the RHEL 8 system. RHEL-08-040200 Missing Rule
V-244550 medium RHEL 8 must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted. RHEL-08-040209 Missing Rule
V-230535 medium RHEL 8 must prevent IPv6 Internet Control Message Protocol (ICMP) redirect messages from being accepted. RHEL-08-040210 Missing Rule
V-230536 medium RHEL 8 must not send Internet Control Message Protocol (ICMP) redirects. RHEL-08-040220 Missing Rule
V-230537 medium RHEL 8 must not respond to Internet Control Message Protocol (ICMP) echoes sent to a broadcast address. RHEL-08-040230 Missing Rule
V-244551 medium RHEL 8 must not forward IPv4 source-routed packets. RHEL-08-040239 Missing Rule
V-230538 medium RHEL 8 must not forward IPv6 source-routed packets. RHEL-08-040240 Missing Rule
V-244552 medium RHEL 8 must not forward IPv4 source-routed packets by default. RHEL-08-040249 Missing Rule
V-230539 medium RHEL 8 must not forward IPv6 source-routed packets by default. RHEL-08-040250 Missing Rule
V-250317 medium RHEL 8 must not enable IPv4 packet forwarding unless the system is a router. RHEL-08-040259 Missing Rule
V-230540 medium RHEL 8 must not enable IPv6 packet forwarding unless the system is a router. RHEL-08-040260 Missing Rule
V-230541 medium RHEL 8 must not accept router advertisements on all IPv6 interfaces. RHEL-08-040261 Missing Rule
V-230542 medium RHEL 8 must not accept router advertisements on all IPv6 interfaces by default. RHEL-08-040262 Missing Rule
V-230543 medium RHEL 8 must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default. RHEL-08-040270 Missing Rule
V-244553 medium RHEL 8 must ignore IPv4 Internet Control Message Protocol (ICMP) redirect messages. RHEL-08-040279 Missing Rule
V-230544 medium RHEL 8 must ignore IPv6 Internet Control Message Protocol (ICMP) redirect messages. RHEL-08-040280 Missing Rule
V-230545 medium RHEL 8 must disable access to network bpf syscall from unprivileged processes. RHEL-08-040281 Missing Rule
V-230546 medium RHEL 8 must restrict usage of ptrace to descendant processes. RHEL-08-040282 Missing Rule
V-230547 medium RHEL 8 must restrict exposed kernel pointer addresses access. RHEL-08-040283 Missing Rule
V-230548 medium RHEL 8 must disable the use of user namespaces. RHEL-08-040284 Missing Rule
V-230549 medium RHEL 8 must use reverse path filtering on all IPv4 interfaces. RHEL-08-040285 Missing Rule
V-244554 medium RHEL 8 must enable hardening for the Berkeley Packet Filter Just-in-time compiler. RHEL-08-040286 Missing Rule
V-230550 medium RHEL 8 must be configured to prevent unrestricted mail relaying. RHEL-08-040290 Missing Rule
V-230551 low The RHEL 8 file integrity tool must be configured to verify extended attributes. RHEL-08-040300 Missing Rule
V-230552 low The RHEL 8 file integrity tool must be configured to verify Access Control Lists (ACLs). RHEL-08-040310 Missing Rule
V-230553 medium The graphical display manager must not be installed on RHEL 8 unless approved. RHEL-08-040320 Missing Rule
V-251718 medium The graphical display manager must not be the default target on RHEL 8 unless approved. RHEL-08-040321 Missing Rule
V-230554 medium RHEL 8 network interfaces must not be in promiscuous mode. RHEL-08-040330 Missing Rule
V-230555 medium RHEL 8 remote X connections for interactive users must be disabled unless to fulfill documented and validated mission requirements. RHEL-08-040340 Missing Rule
V-230556 medium The RHEL 8 SSH daemon must prevent remote hosts from connecting to the proxy display. RHEL-08-040341 Missing Rule
V-230557 medium If the Trivial File Transfer Protocol (TFTP) server is required, the RHEL 8 TFTP daemon must be configured to operate in secure mode. RHEL-08-040350 Missing Rule
V-230558 high A File Transfer Protocol (FTP) server package must not be installed unless mission essential on RHEL 8. RHEL-08-040360 Missing Rule
V-230559 medium The gssproxy package must not be installed unless mission essential on RHEL 8. RHEL-08-040370 Missing Rule
V-230560 medium The iprutils package must not be installed unless mission essential on RHEL 8. RHEL-08-040380 Missing Rule
V-230561 medium The tuned package must not be installed unless mission essential on RHEL 8. RHEL-08-040390 Missing Rule