File: rule.yml

package info (click to toggle)
scap-security-guide 0.1.65-1
  • links: PTS, VCS
  • area: main
  • in suites: bookworm
  • size: 71,936 kB
  • sloc: xml: 179,374; sh: 69,771; python: 23,819; makefile: 23
file content (33 lines) | stat: -rw-r--r-- 980 bytes parent folder | download
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
documentation_complete: true

title: 'Ensure the default plugins for the audit dispatcher are Installed'

description: 'The audit-audispd-plugins package should be installed.'

rationale: 'Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Off-loading is a common process in information systems with limited audit storage capacity.'

severity: medium

identifiers:
    cce@rhel9: CCE-89457-6
    cce@sle12: CCE-83033-1
    cce@sle15: CCE-85613-8

ocil_clause: 'the package is not installed'

references:
    disa: CCI-001851
    nist@sle12: AU-4(1)
    pcidss: Req-10.5.3
    srg: SRG-OS-000342-GPOS-00133
    stigid@sle12: SLES-12-020070
    stigid@sle15: SLES-15-030670
    stigid@ubuntu2004: UBTU-20-010216

template:
    name: package_installed
    vars:
        pkgname: audit-audispd-plugins
        pkgname@ubuntu1604: audispd-plugins
        pkgname@ubuntu1804: audispd-plugins
        pkgname@ubuntu2004: audispd-plugins