content
content copied to clipboard
RHEL9 ISM O - Rules missing `ism` reference
Description of problem:
A lot of ISM O rules doesn't have ism reference. The list of affected rules:
- rpm_verify_hashes
- dir_perms_world_writable_sticky_bits
- sysctl_kernel_kptr_restrict
- service_telnet_disabled
- network_sniffer_disabled
- package_firewalld_installed
- audit_rules_execution_setfiles
- file_ownership_binary_dirs
- audit_rules_execution_setsebool
- configure_ssh_crypto_policy
- sshd_enable_warning_banner
- package_telnet-server_removed
- ensure_gpgcheck_globally_activated
- package_quagga_removed
- sysctl_kernel_kexec_load_disabled
- file_permissions_sshd_private_key
- auditd_log_format
- package_talk-server_removed
- sshd_disable_root_login
- package_fapolicyd_installed
- package_rsh_removed
- audit_rules_time_adjtimex
- audit_rules_login_events
- sysctl_kernel_dmesg_restrict
- usbguard_allow_hid_and_hub
- file_ownership_library_dirs
- mount_option_dev_shm_nosuid
- package_rear_installed
- auditd_data_retention_flush
- audit_rules_dac_modification_chmod
- sshd_disable_rhosts
- file_permissions_library_dirs
- sshd_print_last_log
- auditd_freq
- audit_rules_time_clock_settime
- audit_rules_execution_semanage
- package_rsyslog_installed
- audit_rules_execution_seunshare
- rpm_verify_ownership
- rpm_verify_permissions
- sysctl_kernel_exec_shield
- sshd_set_loglevel_info
- package_talk_removed
- accounts_no_uid_except_zero
- sshd_use_directory_configuration
- auditd_local_events
- package_squid_removed
- ensure_gpgcheck_local_packages
- audit_rules_kernel_module_loading
- audit_rules_login_events_faillock
- auditd_write_logs
- sysctl_kernel_yama_ptrace_scope
- file_permissions_unauthorized_suid
- service_avahi-daemon_disabled
- service_fapolicyd_enabled
- ensure_redhat_gpgkey_installed
- sudo_remove_nopasswd
- sshd_disable_empty_passwords
- audit_rules_execution_chcon
- audit_rules_login_events_tallylog
- audit_rules_usergroup_modification
- sshd_disable_x11_forwarding
- sshd_enable_strictmodes
- audit_rules_execution_restorecon
- auditd_name_format
- file_permissions_unauthorized_world_writable
- audit_rules_time_stime
- package_ypbind_removed
- sysctl_net_core_bpf_jit_harden
- sysctl_kernel_unprivileged_bpf_disabled
- package_rsh-server_removed
- file_permissions_unauthorized_sgid
- selinux_policytype
- security_patches_up_to_date
- audit_rules_dac_modification_chown
- audit_rules_time_settimeofday
- enable_authselect
- sshd_disable_user_known_hosts
- selinux_state
- service_auditd_enabled
- file_permissions_binary_dirs
- service_rsyslog_enabled
- ensure_gpgcheck_never_disabled
- sudo_require_authentication
- audit_rules_login_events_lastlog
- audit_rules_sysadmin_actions
- mount_option_dev_shm_noexec
- service_squid_disabled
- service_firewalld_enabled
- sshd_do_not_permit_user_env
- dnf-automatic_security_updates_only
- package_telnet_removed
- no_empty_passwords
- mount_option_dev_shm_nodev
- audit_rules_time_watch_localtime
- sysctl_kernel_randomize_va_space
- sudo_remove_no_authenticate
- audit_rules_networkconfig_modification
SCAP Security Guide Version:
master
Operating System Version:
RHEL9