Skip to content

Commit 8619c26

Browse files
committed
Add initial mappings for IR and RA families
First mappings for Incident Response (IR) and Risk Assessment (RA) families across rhel8, rhel9, and rhel10. These families were previously at 0% coverage. Focused on incident handling, monitoring, and vulnerability scanning capabilities. IR (Incident Response) family: IR-4 (Incident Handling): - Added audit log forwarding: auditd_audispd_configure_remote_server, auditd_offload_logs - Added mail service for notifications: service_postfix_enabled Total: 3 rules (all new) IR-5 (Incident Monitoring and Reporting): - Added file deletion monitoring audit rules: audit_rules_file_deletion_events, audit_rules_file_deletion_events_rename, audit_rules_file_deletion_events_renameat, audit_rules_file_deletion_events_rmdir, audit_rules_file_deletion_events_unlink, audit_rules_file_deletion_events_unlinkat Total: 6 rules (all new) RA (Risk Assessment) family: RA-5 (Vulnerability Monitoring and Scanning): - Added insecure protocol kernel modules: kernel_module_dccp_disabled, kernel_module_rds_disabled, kernel_module_sctp_disabled, kernel_module_tipc_disabled - Added insecure filesystem kernel modules: kernel_module_cramfs_disabled, kernel_module_freevxfs_disabled, kernel_module_hfs_disabled, kernel_module_hfsplus_disabled, kernel_module_jffs2_disabled Total: 9 rules (all new) Coverage improvement: - IR: 0% → 4.8% (2/42 controls) - RA: 0% → 3.8% (1/26 controls) Total new mappings: 54 (across 3 products × 18 unique rules)
1 parent 87192a9 commit 8619c26

6 files changed

Lines changed: 72 additions & 18 deletions

File tree

products/rhel10/controls/nist_800_53/ir.yml

Lines changed: 13 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -60,8 +60,11 @@ controls:
6060
- low
6161
- moderate
6262
- high
63-
rules: []
64-
status: pending
63+
rules:
64+
- auditd_audispd_configure_remote_server
65+
- auditd_offload_logs
66+
- service_postfix_enabled
67+
status: automated
6568
- id: ir-4.1
6669
title: Automated Incident Handling Processes
6770
levels:
@@ -135,8 +138,14 @@ controls:
135138
- low
136139
- moderate
137140
- high
138-
rules: []
139-
status: pending
141+
rules:
142+
- audit_rules_file_deletion_events
143+
- audit_rules_file_deletion_events_rename
144+
- audit_rules_file_deletion_events_renameat
145+
- audit_rules_file_deletion_events_rmdir
146+
- audit_rules_file_deletion_events_unlink
147+
- audit_rules_file_deletion_events_unlinkat
148+
status: automated
140149
- id: ir-5.1
141150
title: Automated Tracking, Data Collection, and Analysis
142151
levels:

products/rhel10/controls/nist_800_53/ra.yml

Lines changed: 11 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -58,8 +58,17 @@ controls:
5858
- low
5959
- moderate
6060
- high
61-
rules: []
62-
status: pending
61+
rules:
62+
- kernel_module_cramfs_disabled
63+
- kernel_module_dccp_disabled
64+
- kernel_module_freevxfs_disabled
65+
- kernel_module_hfs_disabled
66+
- kernel_module_hfsplus_disabled
67+
- kernel_module_jffs2_disabled
68+
- kernel_module_rds_disabled
69+
- kernel_module_sctp_disabled
70+
- kernel_module_tipc_disabled
71+
status: automated
6372
- id: ra-5.1
6473
title: Update Tool Capability
6574
rules: []

products/rhel8/controls/nist_800_53/ir.yml

Lines changed: 13 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -60,8 +60,11 @@ controls:
6060
- low
6161
- moderate
6262
- high
63-
rules: []
64-
status: pending
63+
rules:
64+
- auditd_audispd_configure_remote_server
65+
- auditd_offload_logs
66+
- service_postfix_enabled
67+
status: automated
6568
- id: ir-4.1
6669
title: Automated Incident Handling Processes
6770
levels:
@@ -135,8 +138,14 @@ controls:
135138
- low
136139
- moderate
137140
- high
138-
rules: []
139-
status: pending
141+
rules:
142+
- audit_rules_file_deletion_events
143+
- audit_rules_file_deletion_events_rename
144+
- audit_rules_file_deletion_events_renameat
145+
- audit_rules_file_deletion_events_rmdir
146+
- audit_rules_file_deletion_events_unlink
147+
- audit_rules_file_deletion_events_unlinkat
148+
status: automated
140149
- id: ir-5.1
141150
title: Automated Tracking, Data Collection, and Analysis
142151
levels:

products/rhel8/controls/nist_800_53/ra.yml

Lines changed: 11 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -58,8 +58,17 @@ controls:
5858
- low
5959
- moderate
6060
- high
61-
rules: []
62-
status: pending
61+
rules:
62+
- kernel_module_cramfs_disabled
63+
- kernel_module_dccp_disabled
64+
- kernel_module_freevxfs_disabled
65+
- kernel_module_hfs_disabled
66+
- kernel_module_hfsplus_disabled
67+
- kernel_module_jffs2_disabled
68+
- kernel_module_rds_disabled
69+
- kernel_module_sctp_disabled
70+
- kernel_module_tipc_disabled
71+
status: automated
6372
- id: ra-5.1
6473
title: Update Tool Capability
6574
rules: []

products/rhel9/controls/nist_800_53/ir.yml

Lines changed: 13 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -60,8 +60,11 @@ controls:
6060
- low
6161
- moderate
6262
- high
63-
rules: []
64-
status: pending
63+
rules:
64+
- auditd_audispd_configure_remote_server
65+
- auditd_offload_logs
66+
- service_postfix_enabled
67+
status: automated
6568
- id: ir-4.1
6669
title: Automated Incident Handling Processes
6770
levels:
@@ -135,8 +138,14 @@ controls:
135138
- low
136139
- moderate
137140
- high
138-
rules: []
139-
status: pending
141+
rules:
142+
- audit_rules_file_deletion_events
143+
- audit_rules_file_deletion_events_rename
144+
- audit_rules_file_deletion_events_renameat
145+
- audit_rules_file_deletion_events_rmdir
146+
- audit_rules_file_deletion_events_unlink
147+
- audit_rules_file_deletion_events_unlinkat
148+
status: automated
140149
- id: ir-5.1
141150
title: Automated Tracking, Data Collection, and Analysis
142151
levels:

products/rhel9/controls/nist_800_53/ra.yml

Lines changed: 11 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -58,8 +58,17 @@ controls:
5858
- low
5959
- moderate
6060
- high
61-
rules: []
62-
status: pending
61+
rules:
62+
- kernel_module_cramfs_disabled
63+
- kernel_module_dccp_disabled
64+
- kernel_module_freevxfs_disabled
65+
- kernel_module_hfs_disabled
66+
- kernel_module_hfsplus_disabled
67+
- kernel_module_jffs2_disabled
68+
- kernel_module_rds_disabled
69+
- kernel_module_sctp_disabled
70+
- kernel_module_tipc_disabled
71+
status: automated
6372
- id: ra-5.1
6473
title: Update Tool Capability
6574
rules: []

0 commit comments

Comments
 (0)