Skip to content

Commit a17c1cb

Browse files
committed
Add initial mappings for IR and RA families
First mappings for Incident Response (IR) and Risk Assessment (RA) families across rhel8, rhel9, and rhel10. These families were previously at 0% coverage. Focused on incident handling, monitoring, and vulnerability scanning capabilities. IR (Incident Response) family: IR-4 (Incident Handling): - Added audit log forwarding: auditd_audispd_configure_remote_server, auditd_offload_logs - Added mail service for notifications: service_postfix_enabled Total: 3 rules (all new) IR-5 (Incident Monitoring and Reporting): - Added file deletion monitoring audit rules: audit_rules_file_deletion_events, audit_rules_file_deletion_events_rename, audit_rules_file_deletion_events_renameat, audit_rules_file_deletion_events_rmdir, audit_rules_file_deletion_events_unlink, audit_rules_file_deletion_events_unlinkat Total: 6 rules (all new) RA (Risk Assessment) family: RA-5 (Vulnerability Monitoring and Scanning): - Added insecure protocol kernel modules: kernel_module_dccp_disabled, kernel_module_rds_disabled, kernel_module_sctp_disabled, kernel_module_tipc_disabled - Added insecure filesystem kernel modules: kernel_module_cramfs_disabled, kernel_module_freevxfs_disabled, kernel_module_hfs_disabled, kernel_module_hfsplus_disabled, kernel_module_jffs2_disabled Total: 9 rules (all new) Coverage improvement: - IR: 0% → 4.8% (2/42 controls) - RA: 0% → 3.8% (1/26 controls) Total new mappings: 54 (across 3 products × 18 unique rules)
1 parent a985945 commit a17c1cb

6 files changed

Lines changed: 72 additions & 18 deletions

File tree

products/rhel10/controls/nist_800_53/ir.yml

Lines changed: 13 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -52,8 +52,11 @@ controls:
5252
title: Incident Handling
5353
levels:
5454
- low
55-
rules: []
56-
status: pending
55+
rules:
56+
- auditd_audispd_configure_remote_server
57+
- auditd_offload_logs
58+
- service_postfix_enabled
59+
status: automated
5760
- id: ir-4.1
5861
title: Automated Incident Handling Processes
5962
levels:
@@ -124,8 +127,14 @@ controls:
124127
title: Incident Monitoring
125128
levels:
126129
- low
127-
rules: []
128-
status: pending
130+
rules:
131+
- audit_rules_file_deletion_events
132+
- audit_rules_file_deletion_events_rename
133+
- audit_rules_file_deletion_events_renameat
134+
- audit_rules_file_deletion_events_rmdir
135+
- audit_rules_file_deletion_events_unlink
136+
- audit_rules_file_deletion_events_unlinkat
137+
status: automated
129138
- id: ir-5.1
130139
title: Automated Tracking, Data Collection, and Analysis
131140
levels:

products/rhel10/controls/nist_800_53/ra.yml

Lines changed: 11 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -48,8 +48,17 @@ controls:
4848
title: Vulnerability Monitoring and Scanning
4949
levels:
5050
- low
51-
rules: []
52-
status: pending
51+
rules:
52+
- kernel_module_cramfs_disabled
53+
- kernel_module_dccp_disabled
54+
- kernel_module_freevxfs_disabled
55+
- kernel_module_hfs_disabled
56+
- kernel_module_hfsplus_disabled
57+
- kernel_module_jffs2_disabled
58+
- kernel_module_rds_disabled
59+
- kernel_module_sctp_disabled
60+
- kernel_module_tipc_disabled
61+
status: automated
5362
- id: ra-5.1
5463
title: Update Tool Capability
5564
rules: []

products/rhel8/controls/nist_800_53/ir.yml

Lines changed: 13 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -52,8 +52,11 @@ controls:
5252
title: Incident Handling
5353
levels:
5454
- low
55-
rules: []
56-
status: pending
55+
rules:
56+
- auditd_audispd_configure_remote_server
57+
- auditd_offload_logs
58+
- service_postfix_enabled
59+
status: automated
5760
- id: ir-4.1
5861
title: Automated Incident Handling Processes
5962
levels:
@@ -124,8 +127,14 @@ controls:
124127
title: Incident Monitoring
125128
levels:
126129
- low
127-
rules: []
128-
status: pending
130+
rules:
131+
- audit_rules_file_deletion_events
132+
- audit_rules_file_deletion_events_rename
133+
- audit_rules_file_deletion_events_renameat
134+
- audit_rules_file_deletion_events_rmdir
135+
- audit_rules_file_deletion_events_unlink
136+
- audit_rules_file_deletion_events_unlinkat
137+
status: automated
129138
- id: ir-5.1
130139
title: Automated Tracking, Data Collection, and Analysis
131140
levels:

products/rhel8/controls/nist_800_53/ra.yml

Lines changed: 11 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -48,8 +48,17 @@ controls:
4848
title: Vulnerability Monitoring and Scanning
4949
levels:
5050
- low
51-
rules: []
52-
status: pending
51+
rules:
52+
- kernel_module_cramfs_disabled
53+
- kernel_module_dccp_disabled
54+
- kernel_module_freevxfs_disabled
55+
- kernel_module_hfs_disabled
56+
- kernel_module_hfsplus_disabled
57+
- kernel_module_jffs2_disabled
58+
- kernel_module_rds_disabled
59+
- kernel_module_sctp_disabled
60+
- kernel_module_tipc_disabled
61+
status: automated
5362
- id: ra-5.1
5463
title: Update Tool Capability
5564
rules: []

products/rhel9/controls/nist_800_53/ir.yml

Lines changed: 13 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -52,8 +52,11 @@ controls:
5252
title: Incident Handling
5353
levels:
5454
- low
55-
rules: []
56-
status: pending
55+
rules:
56+
- auditd_audispd_configure_remote_server
57+
- auditd_offload_logs
58+
- service_postfix_enabled
59+
status: automated
5760
- id: ir-4.1
5861
title: Automated Incident Handling Processes
5962
levels:
@@ -124,8 +127,14 @@ controls:
124127
title: Incident Monitoring
125128
levels:
126129
- low
127-
rules: []
128-
status: pending
130+
rules:
131+
- audit_rules_file_deletion_events
132+
- audit_rules_file_deletion_events_rename
133+
- audit_rules_file_deletion_events_renameat
134+
- audit_rules_file_deletion_events_rmdir
135+
- audit_rules_file_deletion_events_unlink
136+
- audit_rules_file_deletion_events_unlinkat
137+
status: automated
129138
- id: ir-5.1
130139
title: Automated Tracking, Data Collection, and Analysis
131140
levels:

products/rhel9/controls/nist_800_53/ra.yml

Lines changed: 11 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -48,8 +48,17 @@ controls:
4848
title: Vulnerability Monitoring and Scanning
4949
levels:
5050
- low
51-
rules: []
52-
status: pending
51+
rules:
52+
- kernel_module_cramfs_disabled
53+
- kernel_module_dccp_disabled
54+
- kernel_module_freevxfs_disabled
55+
- kernel_module_hfs_disabled
56+
- kernel_module_hfsplus_disabled
57+
- kernel_module_jffs2_disabled
58+
- kernel_module_rds_disabled
59+
- kernel_module_sctp_disabled
60+
- kernel_module_tipc_disabled
61+
status: automated
5362
- id: ra-5.1
5463
title: Update Tool Capability
5564
rules: []

0 commit comments

Comments
 (0)