File tree Expand file tree Collapse file tree
tests/data/profile_stability/rhel9 Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -3501,6 +3501,16 @@ controls:
35013501 - audit_rules_privileged_commands_crontab
35023502 status : automated
35033503
3504+ - id : RHEL-09-654097
3505+ levels :
3506+ - medium
3507+ title : RHEL 9 must audit any script or executable called by cron as root or by any privileged user.
3508+ rules :
3509+ - audit_rules_etc_cron_d
3510+ - audit_rules_var_spool_cron
3511+ status : automated
3512+
3513+
35043514 - id : RHEL-09-654100
35053515 levels :
35063516 - medium
Original file line number Diff line number Diff line change @@ -71,6 +71,7 @@ audit_rules_dac_modification_removexattr
7171audit_rules_dac_modification_setxattr
7272audit_rules_dac_modification_umount
7373audit_rules_dac_modification_umount2
74+ audit_rules_etc_cron_d
7475audit_rules_execution_chacl
7576audit_rules_execution_chcon
7677audit_rules_execution_semanage
@@ -124,6 +125,7 @@ audit_rules_usergroup_modification_gshadow
124125audit_rules_usergroup_modification_opasswd
125126audit_rules_usergroup_modification_passwd
126127audit_rules_usergroup_modification_shadow
128+ audit_rules_var_spool_cron
127129auditd_audispd_configure_sufficiently_large_partition
128130auditd_data_disk_error_action_stig
129131auditd_data_disk_full_action_stig
Original file line number Diff line number Diff line change @@ -71,6 +71,7 @@ audit_rules_dac_modification_removexattr
7171audit_rules_dac_modification_setxattr
7272audit_rules_dac_modification_umount
7373audit_rules_dac_modification_umount2
74+ audit_rules_etc_cron_d
7475audit_rules_execution_chacl
7576audit_rules_execution_chcon
7677audit_rules_execution_semanage
@@ -124,6 +125,7 @@ audit_rules_usergroup_modification_gshadow
124125audit_rules_usergroup_modification_opasswd
125126audit_rules_usergroup_modification_passwd
126127audit_rules_usergroup_modification_shadow
128+ audit_rules_var_spool_cron
127129auditd_audispd_configure_sufficiently_large_partition
128130auditd_data_disk_error_action_stig
129131auditd_data_disk_full_action_stig
You can’t perform that action at this time.
0 commit comments