Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion controls/anssi.yml
Original file line number Diff line number Diff line change
Expand Up @@ -1492,7 +1492,9 @@ controls:
- audit_rules_login_events_faillock
- audit_rules_login_events_lastlog

- audit_rules_session_events
- audit_rules_session_events_utmp
- audit_rules_session_events_btmp
- audit_rules_session_events_wtmp

- audit_rules_time_adjtimex
- audit_rules_time_clock_settime
Expand Down
4 changes: 3 additions & 1 deletion controls/ccn_rhel9.yml
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,9 @@ controls:
- advanced
status: automated
rules:
- audit_rules_session_events
- audit_rules_session_events_utmp
- audit_rules_session_events_btmp
- audit_rules_session_events_wtmp
- audit_rules_login_events_faillock
- audit_rules_login_events_lastlog

Expand Down
4 changes: 3 additions & 1 deletion controls/cis_rhel10.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2597,7 +2597,9 @@ controls:
- l2_workstation
status: automated
rules:
- audit_rules_session_events
- audit_rules_session_events_utmp
- audit_rules_session_events_btmp
- audit_rules_session_events_wtmp

- id: 6.3.3.12
title: Ensure login and logout events are collected (Automated)
Expand Down
4 changes: 3 additions & 1 deletion controls/cis_rhel8.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2531,7 +2531,9 @@ controls:
- l2_workstation
status: automated
rules:
- audit_rules_session_events
- audit_rules_session_events_utmp
- audit_rules_session_events_btmp
- audit_rules_session_events_wtmp

- id: 5.2.3.12
title: Ensure login and logout events are collected (Automated)
Expand Down
4 changes: 3 additions & 1 deletion controls/cis_rhel9.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2685,7 +2685,9 @@ controls:
- l2_workstation
status: automated
rules:
- audit_rules_session_events
- audit_rules_session_events_utmp
- audit_rules_session_events_btmp
- audit_rules_session_events_wtmp

- id: 6.3.3.12
title: Ensure login and logout events are collected (Automated)
Expand Down
28 changes: 21 additions & 7 deletions controls/hipaa.yml
Original file line number Diff line number Diff line change
Expand Up @@ -122,7 +122,9 @@ controls:
- audit_rules_mac_modification_usr_share
- audit_rules_media_export
- audit_rules_networkconfig_modification
- audit_rules_session_events
- audit_rules_session_events_utmp
- audit_rules_session_events_btmp
- audit_rules_session_events_wtmp
- audit_rules_sysadmin_actions
- audit_rules_system_shutdown
- audit_rules_usergroup_modification_group
Expand Down Expand Up @@ -283,7 +285,9 @@ controls:
- audit_rules_mac_modification_usr_share
- audit_rules_media_export
- audit_rules_networkconfig_modification
- audit_rules_session_events
- audit_rules_session_events_utmp
- audit_rules_session_events_btmp
- audit_rules_session_events_wtmp
- audit_rules_sysadmin_actions
- audit_rules_system_shutdown
- audit_rules_usergroup_modification_group
Expand Down Expand Up @@ -475,7 +479,9 @@ controls:
- audit_rules_mac_modification_usr_share
- audit_rules_media_export
- audit_rules_networkconfig_modification
- audit_rules_session_events
- audit_rules_session_events_utmp
- audit_rules_session_events_btmp
- audit_rules_session_events_wtmp
- audit_rules_sysadmin_actions
- audit_rules_system_shutdown
- audit_rules_usergroup_modification_group
Expand Down Expand Up @@ -1203,7 +1209,9 @@ controls:
- audit_rules_mac_modification_usr_share
- audit_rules_media_export
- audit_rules_networkconfig_modification
- audit_rules_session_events
- audit_rules_session_events_utmp
- audit_rules_session_events_btmp
- audit_rules_session_events_wtmp
- audit_rules_sysadmin_actions
- audit_rules_system_shutdown
- audit_rules_usergroup_modification_group
Expand Down Expand Up @@ -1339,7 +1347,9 @@ controls:
- audit_rules_mac_modification_usr_share
- audit_rules_media_export
- audit_rules_networkconfig_modification
- audit_rules_session_events
- audit_rules_session_events_utmp
- audit_rules_session_events_btmp
- audit_rules_session_events_wtmp
- audit_rules_sysadmin_actions
- audit_rules_system_shutdown
- audit_rules_usergroup_modification_group
Expand Down Expand Up @@ -1505,7 +1515,9 @@ controls:
- audit_rules_mac_modification_usr_share
- audit_rules_media_export
- audit_rules_networkconfig_modification
- audit_rules_session_events
- audit_rules_session_events_utmp
- audit_rules_session_events_btmp
- audit_rules_session_events_wtmp
- audit_rules_sysadmin_actions
- audit_rules_system_shutdown
- audit_rules_usergroup_modification_group
Expand Down Expand Up @@ -1600,7 +1612,9 @@ controls:
- audit_rules_mac_modification_usr_share
- audit_rules_media_export
- audit_rules_networkconfig_modification
- audit_rules_session_events
- audit_rules_session_events_utmp
- audit_rules_session_events_btmp
- audit_rules_session_events_wtmp
- audit_rules_sysadmin_actions
- audit_rules_system_shutdown
- audit_rules_usergroup_modification_group
Expand Down
8 changes: 6 additions & 2 deletions controls/ism_o.yml
Original file line number Diff line number Diff line change
Expand Up @@ -125,7 +125,9 @@ controls:
- audit_access_success_aarch64
- audit_access_success_ppc64le
- audit_rules_privileged_commands
- audit_rules_session_events
- audit_rules_session_events_utmp
- audit_rules_session_events_btmp
- audit_rules_session_events_wtmp
- audit_rules_unsuccessful_file_modification_creat
- audit_rules_unsuccessful_file_modification_open
- audit_rules_unsuccessful_file_modification_openat
Expand All @@ -149,7 +151,9 @@ controls:
- audit_access_success_aarch64
- audit_access_success_ppc64le
- audit_rules_privileged_commands
- audit_rules_session_events
- audit_rules_session_events_utmp
- audit_rules_session_events_btmp
- audit_rules_session_events_wtmp
- audit_rules_unsuccessful_file_modification_creat
- audit_rules_unsuccessful_file_modification_open
- audit_rules_unsuccessful_file_modification_openat
Expand Down
4 changes: 3 additions & 1 deletion controls/pcidss_4.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2694,7 +2694,9 @@ controls:
- audit_rules_login_events_faillock
- audit_rules_login_events_lastlog
- audit_rules_login_events_tallylog
- audit_rules_session_events
- audit_rules_session_events_utmp
- audit_rules_session_events_btmp
- audit_rules_session_events_wtmp
- audit_sudo_log_events
related_rules:
# This rule incorportes faillock, lastlog and tallylog. It is redundant to keep it.
Expand Down

This file was deleted.

This file was deleted.

Original file line number Diff line number Diff line change
Expand Up @@ -15,11 +15,15 @@ rationale: |-
severity: medium

identifiers:
cce@rhel8: CCE-86196-3
cce@rhel9: CCE-86198-9
cce@rhel10: CCE-86190-6
cce@sle15: CCE-85758-1
cce@slmicro5: CCE-93725-0

references:
disa: CCI-000172
hipaa: 164.308(a)(1)(ii)(D),164.308(a)(3)(ii)(A),164.308(a)(5)(ii)(C),164.312(a)(2)(i),164.312(b),164.312(d),164.312(e)
nist: AU-12(c),AU-12.1(iv)
srg: SRG-OS-000472-GPOS-00217
stigid@sle15: SLES-15-030780
Expand All @@ -36,6 +40,3 @@ template:
vars:
path: /var/log/btmp
key: session
backends:
ansible: "off"
bash: "off"

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ title: 'Record Attempts to Alter Process and Session Initiation Information utmp
description: |-
The audit system already collects process information for all
users and root.
{{{ describe_audit_rules_watch("/run/utmp", "session") }}}
{{{ describe_audit_rules_watch("/var/run/utmp", "session") }}}

rationale: |-
Manual editing of these files may indicate nefarious activity, such
Expand All @@ -15,11 +15,15 @@ rationale: |-
severity: medium

identifiers:
cce@rhel8: CCE-86199-7
cce@rhel9: CCE-86202-9
cce@rhel10: CCE-86193-0
cce@sle15: CCE-85714-4
cce@slmicro5: CCE-93723-5

references:
disa: CCI-000172
hipaa: 164.308(a)(1)(ii)(D),164.308(a)(3)(ii)(A),164.308(a)(5)(ii)(C),164.312(a)(2)(i),164.312(b),164.312(d),164.312(e)
nist: AU-12(c),AU-12.1(iv)
srg: SRG-OS-000472-GPOS-00217
stigid@sle15: SLES-15-030760
Expand All @@ -29,13 +33,10 @@ references:
ocil_clause: 'Audit rule is not present'

ocil: |-
{{{ ocil_audit_rules_watch("/run/utmp", "session") }}}
{{{ ocil_audit_rules_watch("/var/run/utmp", "session") }}}

template:
name: audit_rules_watch
vars:
path: /run/utmp
path: /var/run/utmp
key: session
backends:
ansible: "off"
bash: "off"

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

Original file line number Diff line number Diff line change
Expand Up @@ -15,11 +15,15 @@ rationale: |-
severity: medium

identifiers:
cce@rhel8: CCE-86204-5
cce@rhel9: CCE-86203-7
cce@rhel10: CCE-86206-0
cce@sle15: CCE-85757-3
cce@slmicro5: CCE-93724-3

references:
disa: CCI-000172
hipaa: 164.308(a)(1)(ii)(D),164.308(a)(3)(ii)(A),164.308(a)(5)(ii)(C),164.312(a)(2)(i),164.312(b),164.312(d),164.312(e)
nist: AU-12(c),AU-12.1(iv)
srg: SRG-OS-000472-GPOS-00217
stigid@sle15: SLES-15-030770
Expand All @@ -36,6 +40,4 @@ template:
vars:
path: /var/log/wtmp
key: session
backends:
ansible: "off"
bash: "off"

Loading
Loading