DISA STIG
The US Department of Defense's Security Technical Implementation Guides, detailed, testable hardening requirements for systems operating on DoD networks. Each finding has a severity (CAT I/II/III) and a fix.
How to read the references
DISA STIG references are rule identifiers, a STIG ID tied to the OS-specific guide, such as UBTU-22-xxxxxx for Ubuntu 22.04 (or a legacy V- vulnerability ID).
Each finding carries a severity category:
- CAT I, high: directly and immediately leads to loss of confidentiality, integrity or availability.
- CAT II, medium.
- CAT III, low.
STIG coverage in Pavois is currently strongest on the Ubuntu systems, for which DISA publishes an OS STIG.
| Ref | Rule | OS | Domain | Sev. | DISA ref |
|---|---|---|---|---|---|
| SOCLE-CLD-IAM-006 | Prevent Login to Accounts With Empty Password | 9 | Accounts | critical | UBTU-22-611060 · UBTU-22-611065 · UBTU-24-300028 · UBTU-24-300027 |
| SOCLE-RUN-AUD-001 | Record Events that Modify the System's Discretionary Access Controls - chmod | 9 | Audit (auditd) | medium | UBTU-22-654155 · UBTU-22-654160 · UBTU-22-654180 · UBTU-24-900150 · UBTU-24-900140 · UBTU-24-900130 |
| SOCLE-RUN-AUD-003 | Ensure auditd Collects Changes to Cron Jobs - /etc/cron.d/ | 7 | Audit (auditd) | medium | UBTU-22-654041 · UBTU-24-200270 |
| SOCLE-RUN-AUD-004 | Record Any Attempts to Run chacl | 9 | Audit (auditd) | medium | UBTU-22-654015 · UBTU-22-654025 · UBTU-22-654085 · UBTU-22-654010 · UBTU-22-654020 · UBTU-22-654030 · UBTU-22-654035 · UBTU-22-654040 · UBTU-22-654050 · UBTU-22-654055 · UBTU-22-654065 · UBTU-22-654070 · UBTU-22-654075 · UBTU-22-654080 · UBTU-22-654090 · UBTU-22-654095 · UBTU-22-654100 · UBTU-22-654105 · UBTU-22-654110 · UBTU-22-654115 · UBTU-22-654120 · UBTU-22-654125 · UBTU-24-900240 · UBTU-24-900210 · UBTU-24-900230 · UBTU-24-900220 · UBTU-24-900300 · UBTU-24-900080 · UBTU-24-900190 · UBTU-24-900320 · UBTU-24-900290 · UBTU-24-900740 · UBTU-24-900090 · UBTU-24-900200 · UBTU-24-900330 · UBTU-24-900270 · UBTU-24-900110 · UBTU-24-900120 · UBTU-24-900070 · UBTU-24-900170 · UBTU-24-900180 · UBTU-24-900100 · UBTU-24-900280 · UBTU-24-900310 |
| SOCLE-RUN-AUD-005 | Ensure auditd Collects File Deletion Events by User - rename | 9 | Audit (auditd) | medium | UBTU-22-654185 · UBTU-24-900540 |
| SOCLE-RUN-AUD-006 | Make the auditd Configuration Immutable | 9 | Audit (auditd) | medium | UBTU-24-909000 |
| SOCLE-RUN-AUD-008 | Record Attempts to Alter Logon and Logout Events - faillock | 9 | Audit (auditd) | medium | UBTU-22-654210 · UBTU-22-654215 · UBTU-24-900250 · UBTU-24-900260 |
| SOCLE-RUN-AUD-013 | Ensure auditd Collects Information on the Use of Privileged Commands - fdisk | 3 | Audit (auditd) | medium | UBTU-22-654170 · UBTU-22-654175 · UBTU-22-654045 · UBTU-22-654060 · UBTU-24-900350 · UBTU-24-900340 · UBTU-24-900750 · UBTU-24-900730 |
| SOCLE-RUN-AUD-015 | Record Attempts to Alter Process and Session Initiation Information | 9 | Audit (auditd) | medium | UBTU-22-654195 · UBTU-22-654205 · UBTU-22-654200 · UBTU-24-900610 · UBTU-24-900600 · UBTU-24-900590 |
| SOCLE-RUN-AUD-018 | Record Events When Privileged Executables Are Run | 7 | Audit (auditd) | medium | UBTU-22-654230 · UBTU-24-200580 |
| SOCLE-RUN-AUD-019 | Ensure auditd Collects System Administrator Actions | 8 | Audit (auditd) | medium | UBTU-24-900510 · UBTU-24-900520 |
| SOCLE-RUN-AUD-022 | Record Unsuccessful Access Attempts to Files - creat | 9 | Audit (auditd) | medium | UBTU-22-654165 · UBTU-24-900160 |
| SOCLE-RUN-AUD-023 | Record Events that Modify User/Group Information - /etc/group | 9 | Audit (auditd) | medium | UBTU-22-654130 · UBTU-22-654135 · UBTU-22-654140 · UBTU-22-654145 · UBTU-22-654150 · UBTU-24-200290 · UBTU-24-200310 · UBTU-24-200320 · UBTU-24-200280 · UBTU-24-200300 |
| SOCLE-RUN-AUD-024 | Ensure auditd Collects records for events that affect "/var/log/journal" | 3 | Audit (auditd) | medium | UBTU-22-654190 · UBTU-24-300029 |
| SOCLE-RUN-AUD-025 | Configure auditd mail_acct Action on Low Disk Space | 9 | Audit (auditd daemon) | medium | UBTU-22-653025 · UBTU-24-900980 |
| SOCLE-RUN-AUD-029 | Configure auditd Disk Full Action when Disk Space Is Full | 9 | Audit (auditd daemon) | medium | UBTU-22-653030 |
| SOCLE-RUN-AUD-036 | Configure auditd space_left Action on Low Disk Space | 9 | Audit (auditd daemon) | medium | UBTU-22-653040 · UBTU-24-900960 |
| SOCLE-RUN-AUD-037 | Configure auditd space_left on Low Disk Space | 7 | Audit (auditd daemon) | medium | UBTU-22-653040 · UBTU-24-900960 |
| SOCLE-CLD-KRN-001 | Enable Auditing for Processes Which Start Prior to the Audit Daemon | 9 | Kernel command line | low | UBTU-22-212015 · UBTU-24-102010 |
| SOCLE-CLD-GEN-004 | Enable GNOME3 Login Warning Banner | 9 | GNOME desktop (dconf) | medium | UBTU-22-271010 · UBTU-24-200650 |
| SOCLE-CLD-GEN-006 | Disable GNOME3 Automount Opening | 9 | GNOME desktop (dconf) | medium | UBTU-24-200040 |
| SOCLE-CLD-GEN-007 | Disable GNOME3 Automount running | 9 | GNOME desktop (dconf) | low | UBTU-24-200041 |
| SOCLE-CLD-GEN-008 | Disable Ctrl-Alt-Del Reboot Key Sequence in GNOME3 | 7 | GNOME desktop (dconf) | high | UBTU-22-271030 · UBTU-24-300025 |
| SOCLE-CLD-GEN-011 | Enable the GNOME3 Screen Locking On Smartcard Removal | 6 | GNOME desktop (dconf) | medium | UBTU-24-200042 |
| SOCLE-CLD-GEN-016 | Set GNOME3 Screensaver Lock Delay After Activation Period | 3 | GNOME desktop (dconf) | medium | UBTU-22-271025 · UBTU-24-200020 |
| SOCLE-CLD-GEN-018 | Set GNOME3 Screensaver Inactivity Timeout | 3 | GNOME desktop (dconf) | medium | UBTU-22-271025 · UBTU-24-200020 |
| SOCLE-CLD-GEN-019 | Enable GNOME3 Screensaver Lock After Idle Period | 9 | GNOME desktop (dconf) | medium | UBTU-22-271020 · UBTU-24-200020 |
| SOCLE-CLD-GEN-021 | Implement Blank Screensaver | 5 | GNOME desktop (dconf) | medium | UBTU-24-200043 |
| SOCLE-CLD-IAM-008 | Lock Accounts After Failed Password Attempts | 9 | Accounts (faillock) | medium | UBTU-22-411045 · UBTU-24-200610 |
| SOCLE-CLD-IAM-009 | Set Lockout Time for Failed Password Attempts | 9 | Accounts (faillock) | medium | UBTU-22-411045 · UBTU-24-200610 |
| SOCLE-CLD-FSP-036 | Verify Groupowner on the journalctl command | 3 | File ownership | medium | UBTU-22-232105 · UBTU-24-700050 |
| SOCLE-CLD-FSP-041 | Verify Group Who Owns /var/log Directory | 7 | File ownership | medium | UBTU-22-232125 · UBTU-24-700100 |
| SOCLE-CLD-FSP-048 | Verify Group Who Owns /var/log/syslog File | 5 | File ownership | medium | UBTU-22-232135 · UBTU-24-700130 |
| SOCLE-CLD-FSP-051 | Verify that audit tools are owned by group root | 9 | File ownership | medium | UBTU-24-901250 |
| SOCLE-CLD-FSP-052 | Audit Configuration Files Must Be Owned By Group root | 9 | File ownership | medium | UBTU-22-653075 · UBTU-24-900060 |
| SOCLE-CLD-FSP-092 | Verify Owner on the journalctl Command | 3 | File ownership | medium | UBTU-22-232100 · UBTU-24-700040 |
| SOCLE-CLD-FSP-097 | Verify User Who Owns /var/log Directory | 7 | File ownership | medium | UBTU-22-232120 · UBTU-24-700110 |
| SOCLE-CLD-FSP-104 | Verify User Who Owns /var/log/syslog File | 5 | File ownership | medium | UBTU-22-232130 · UBTU-24-700140 |
| SOCLE-CLD-FSP-107 | Verify that audit tools are owned by root | 9 | File ownership | medium | UBTU-22-232110 · UBTU-24-901240 |
| SOCLE-CLD-FSP-108 | Audit Configuration Files Must Be Owned By Root | 9 | File ownership | medium | UBTU-22-653070 · UBTU-24-900050 |
| SOCLE-CLD-FSP-114 | Verify that audit tools Have Mode 0755 or less | 9 | File permissions | medium | UBTU-22-232035 · UBTU-24-901230 |
| SOCLE-CLD-FSP-131 | Verify Permissions on /etc/audit/auditd.conf | 9 | File permissions | medium | UBTU-22-653065 · UBTU-24-900040 |
| SOCLE-CLD-FSP-132 | Verify Permissions on /etc/audit/audit.rules | 9 | File permissions | medium | UBTU-22-653065 · UBTU-24-900040 |
| SOCLE-CLD-FSP-133 | Verify Permissions on /etc/audit/rules.d/*.rules | 9 | File permissions | medium | UBTU-22-653065 · UBTU-24-900040 |
| SOCLE-CLD-FSP-155 | Verify Permissions on the journal command | 3 | File permissions | medium | UBTU-22-232140 · UBTU-24-700030 |
| SOCLE-CLD-FSP-156 | Verify that Shared Library Files Have Restrictive Permissions | 7 | File permissions | medium | UBTU-22-232020 · UBTU-24-300006 |
| SOCLE-CLD-FSP-165 | Verify Permissions on /var/log Directory | 7 | File permissions | medium | UBTU-22-232025 · UBTU-24-700120 |
| SOCLE-CLD-FSP-167 | System Audit Logs Must Have Mode 0640 or Less Permissive | 9 | File permissions | medium | UBTU-22-653060 · UBTU-24-901380 |
| SOCLE-CLD-FSP-176 | Verify Permissions on /var/log/syslog File | 5 | File permissions | medium | UBTU-22-232030 · UBTU-24-700150 |
| SOCLE-CLD-FSP-179 | Verify that All World-Writable Directories Have Sticky Bits Set | 9 | Filesystem (scan) | medium | UBTU-22-232145 · UBTU-24-600150 |
| SOCLE-CLD-FSP-181 | Verify the group owning the /var/log directory | 7 | Filesystem (scan) | medium | UBTU-22-232125 · UBTU-24-700100 |
| SOCLE-CLD-FSP-182 | Verify that system commands files are group owned by root or a system account | 8 | Filesystem (scan) | medium | UBTU-22-232055 · UBTU-24-300013 |
| SOCLE-CLD-FSP-184 | Verify the user owning the /var/log directory | 7 | Filesystem (scan) | medium | UBTU-22-232120 · UBTU-24-700110 |
| SOCLE-CLD-FSP-185 | Verify that system executables have root ownership | 9 | Filesystem (scan) | medium | UBTU-22-232050 · UBTU-24-300012 |
| SOCLE-CLD-FSP-192 | Verify permissions of log files | 8 | Filesystem (scan) | medium | UBTU-24-700120 |
| SOCLE-CLD-NET-002 | A host firewall is installed and active | 9 | Firewall | high | UBTU-22-251020 · UBTU-24-100300 |
| SOCLE-CLD-MOD-022 | Disable Modprobe Loading of USB Storage Driver | 9 | Kernel modules | medium | UBTU-22-291010 · UBTU-24-300039 |
| SOCLE-RUN-LOG-004 | A system logging daemon is active | 9 | Logging | medium | UBTU-22-652010 · UBTU-24-100200 |
| SOCLE-CLD-IAM-016 | Set Password Hashing Algorithm in /etc/login.defs | 9 | Accounts (login.defs) | medium | UBTU-22-611070 · UBTU-24-400400 |
| SOCLE-CLD-IAM-018 | Set Password Maximum Age | 9 | Accounts (login.defs) | medium | UBTU-22-411030 · UBTU-24-400310 |