1+ # NIST 800-53 AU Family: Audit and Accountability
12controls :
23 - id : au-1
34 title : Policy and Procedures
@@ -68,6 +69,7 @@ controls:
6869 - moderate
6970 - high
7071 rules :
72+ - audit_rules_login_events_faillog
7173 - audit_rules_privileged_commands_chfn
7274 - auditd_log_format
7375 - auditd_name_format
@@ -79,6 +81,11 @@ controls:
7981 - moderate
8082 - high
8183 rules :
84+ - audit_rules_etc_cron_d
85+ - audit_rules_networkconfig_modification_etc_hosts
86+ - audit_rules_networkconfig_modification_etc_issue
87+ - audit_rules_networkconfig_modification_etc_issue_net
88+ - audit_rules_networkconfig_modification_etc_networkmanager_system_connections
8289 - audit_rules_privileged_commands_insmod
8390 - audit_rules_privileged_commands_kmod
8491 - audit_rules_privileged_commands_modprobe
@@ -122,6 +129,8 @@ controls:
122129 - moderate
123130 - high
124131 rules :
132+ - audit_rules_continue_loading
133+ - audit_rules_enable_syscall_auditing
125134 - audit_rules_system_shutdown
126135 - postfix_client_configure_mail_alias_postmaster
127136 status : automated
@@ -313,6 +322,9 @@ controls:
313322 - moderate
314323 - high
315324 rules :
325+ - audit_rules_immutable_login_uids
326+ - audit_rules_mac_modification_etc_apparmor
327+ - audit_rules_mac_modification_etc_apparmor_d
316328 - directory_permissions_var_log_audit
317329 - file_audit_tools_group_ownership
318330 - file_audit_tools_ownership
@@ -435,12 +447,19 @@ controls:
435447 - audit_rules_dac_modification_lsetxattr
436448 - audit_rules_dac_modification_removexattr
437449 - audit_rules_dac_modification_setxattr
450+ - audit_rules_dac_modification_umount
451+ - audit_rules_dac_modification_umount2
452+ - audit_rules_execution_chacl
438453 - audit_rules_execution_chcon
454+ - audit_rules_execution_chmod
455+ - audit_rules_execution_rm
456+ - audit_rules_execution_setfacl
439457 - audit_rules_file_deletion_events_rename
440458 - audit_rules_file_deletion_events_renameat
441459 - audit_rules_file_deletion_events_renameat2
442460 - audit_rules_file_deletion_events_unlink
443461 - audit_rules_file_deletion_events_unlinkat
462+ - audit_rules_kernel_module_loading_create
444463 - audit_rules_kernel_module_loading_delete
445464 - audit_rules_kernel_module_loading_finit
446465 - audit_rules_kernel_module_loading_init
0 commit comments