Changeset 140
- Timestamp:
- 12/13/07 16:38:24 (1 year ago)
- Files:
-
- trunk/RHEL5.1/kickstart/clip.ks (modified) (51 diffs)
Legend:
- Unmodified
- Added
- Removed
- Modified
- Copied
- Moved
trunk/RHEL5.1/kickstart/clip.ks
r136 r140 27 27 ## Version .02 Feburary 2007 ## 28 28 ## Version .03 December 2007 ## 29 30 29 31 30 32 #The "install" command tells the system to install a fresh system … … 304 306 # the mounting of each file system (/etc/fstab). 305 307 306 307 308 ## (GEN002420: CAT II) (Previously â G086) The SA will ensure user filesystems, 308 309 ## removable media, and remote filesystems will be mounted with the nosuid … … 406 407 chown root /etc/syslog.conf 407 408 chmod 640 /etc/syslog.conf 408 409 410 ## (GEN005420: CAT II) (Previously â G657) The SA will ensure the group owner 411 ## of the /etc/syslog.conf file is root, sys, or bin. 412 chgrp root /etc/syslog.conf 413 414 ## (GEN004500: CAT II) (Previously â G136) The SA will ensure the critical 415 ## sendmail log file has permissions of 644, or more restrictive. 416 chmod 644 /var/log/maillog 417 418 ## (GEN003180: CAT II) (Previously â G210) The SA will ensure cron logs have 419 ## permissions of 600, or more restrictive. 420 chmod 600 /var/log/cron 421 409 422 ## (GEN001260: CAT II) (Previously â G037) The SA will ensure all system log 410 423 ## files have permissions of 640, or more restrictive. 411 424 ## TODO: Is this correct? 412 425 perl -npe 's%chmod 0664 /var/run/utmp /var/log/wtmp%chmod 0644 /var/run/utmp /var/log/wtmp%g' -i /etc/rc.d/rc.sysinit 413 426 414 427 # 4.B.4.a(6)(c) 415 428 # KickStart Actions: Log rotation to 90 days (12 weeks) and turn compression on. … … 487 500 -a exit,possible -S ftruncate -F success=0 488 501 -a exit,possible -S ftruncate64 -F success=0 489 502 490 503 # GEN002740 491 504 ## Audit for files and programs deleted by user … … 494 507 -a exit,possible -w /bin/rm -F success=0 -F success!=0 495 508 -a exit,possible -S rename -F success!=0 496 509 497 510 # GEN002760 498 511 ## Audit all administrative actions … … 516 529 -a exit,always -S settimeofday -F success!=0 517 530 -a exit,always -S kill -F success=0 -F success!=0 518 531 519 532 #Proc_privilege 520 533 -a exit,always -w /bin/chgrp -F success=0 -F success!=0 … … 524 537 -a exit,always -w /usr/sbin/groupdel -F success=0 -F success!=0 525 538 # Restore imports 526 539 527 540 # TCBCK_delete 528 541 -a exit,possible -w /usr/sbin/useradd -F success=0 -F success!=0 … … 532 545 -a exit,possible -S reboot -F success!=0 533 546 # User_setenv 534 547 535 548 ## 536 549 ## 4.B.4.a(6)(d)(1) … … 543 556 -a exit,possible -S delete_module -F success!=0 544 557 -a exit,possible -w /bin/su -F success!=0 545 558 546 559 # GEN002800 547 560 ## Audit use of privileged commands … … 554 567 # Proc_realgid 555 568 # Proc_setuserids 556 569 557 570 ## ??????????? 558 571 ## Audit application and session initiation … … 560 573 # 561 574 # ???????????? 562 EOF575 EOF 563 576 564 577 # 4.B.4.a(6)(d)(3) … … 569 582 ## informational data is logged. 570 583 echo "auth.notice /var/log/messages" >> /etc/syslog.conf 584 585 ## (GEN000440: CAT II) (Previously â G012) The SA will ensure all logon attempts (both 586 ## successful and unsuccessful) are logged to a system log file. 587 echo " 588 # Log all authentication information 589 auth.* /var/log/authlog" >> /etc/syslog.conf 590 571 591 572 592 # 4.B.4.a(7) … … 622 642 623 643 # Passwd strength 644 ## FIXME: ask_oldauthok=update causes problems on RHEL5.1 (commented out for now) 645 ## FIXME: it is likely this could be split up into stigs or is already covered by stigs 624 646 cat <<-EOF > /etc/pam.d/system-auth 625 647 # %PAM-1.0 … … 646 668 sed -i "s/PASS_MIN_LEN[ \t]*[0-9]*/PASS_MIN_LEN\t8/" /etc/login.defs 647 669 670 ## (GEN000600: CAT II) (Previously â G019) The IAO will ensure passwords include at 671 ## least two alphabetic characters, one of which must be capitalized. 672 sed -i s/minlen\=8/minlen\=9/ /etc/pam.d/system-auth 673 sed -i "s/difok\=3/difok\=3 dcredit\=-2 ucredit\=-2 ocredit\=-2 lcredit\=-2/" /etc/pam.d/system-auth 674 675 676 # Running the authconfig tool WILL clobber these changes! 677 # Taking the executable permissions off of /usr/sbin/authconfig 678 chmod ugo-x /usr/sbin/authconfig 679 648 680 # 4.B.4.a(11)(d) 649 681 # KickStart Actions: None - PROCEDURAL REQUIREMENT … … 665 697 # for non-replication. 666 698 667 touch /etc/security/opasswd 668 chmod 600 /etc/security/opasswd 699 ## (GEN000800: CAT II) (Previously â G606) The SA will ensure passwords will not be 700 ## reused within the last ten changes. 701 sed -i "s/shadow/shadow remember\=10/" /etc/pam.d/system-auth 669 702 670 703 # 4.B.4.a(11)(g) … … 673 706 # integrity. Red Hat encrypts authenticators using the MD5 674 707 # Message Digest. 708 709 # FIXME: Find a stig for this, maybe GEN000800 710 # Make sure rememberd password are safe 711 touch /etc/security/opasswd 712 chmod 600 /etc/security/opasswd 713 714 ## (GEN001380: CAT II) (Previously â G048) The SA will ensure the /etc/passwd 715 ## file has permissions of 644, or more restrictive. 716 chmod 644 /etc/passwd 717 718 ## (GEN001400: CAT I) (Previously â G047) The SA will ensure the owner of the 719 ## /etc/passwd and /etc/shadow files (or equivalent) is root. 720 chown root /etc/passwd 721 chown root /etc/shadow 722 723 ## (GEN001420: CAT II) (Previously â G050) The SA will ensure the /etc/shadow 724 ## file (or equivalent) has permissions of 400. 725 chmod 400 /etc/shadow 726 675 727 676 728 # 4.B.4.a(12) … … 684 736 685 737 perl -npe 's/\#\s+Cipher\s+3des/Ciphers aes256-cbc/' -i /etc/ssh/ssh_config 738 739 ## (GEN005500: CAT I) (Previously â G701) The IAO and SA will ensure SSH 740 ## Protocol version 1 is not used, nor will Protocol version 1 compatibility 741 ## mode be used. 742 if [ `grep -c "^Protocol" /etc/ssh/sshd_config` -gt 0 ] 743 then 744 sed -i "/^Protocol/ c\Protocol 2" /etc/ssh/sshd_config 745 else 746 echo "Protocol 2" >> /etc/ssh/sshd_config 747 fi 686 748 687 749 … … 828 890 EOF 829 891 sed -i "/^#Banner/ c\Banner /etc/issue" /etc/ssh/sshd_config 830 831 832 # GEN000420: CAT II) (Previously â G011) The IAO will ensure the Legal Notice Logon833 # Warning Banner includes the five points outlined in the CJCSM 6510.01.834 892 sed -i "s/^\(PATH=.*\)/\/usr\/bin\/gdialog --yesno \"\`cat \/etc\/issue\`\"\nif( test 1 -eq \$\? ); then\n \/usr\/bin\/gdialog --infobox \"Logging out in 10 Seconds\" 1 20 \&\n sleep 10\n exit 1\nfi\n\n\1/" /etc/gdm/PreSession/Default 835 893 … … 852 910 # 4.B.4.a(24)(c) 853 911 # KickStart Actions: None 854 912 855 913 ## (GEN000460: CAT II) (Previously â G013) The SA will ensure, after three consecutive 856 914 ## failed logon attempts for an account, the account is locked for 15 minutes or until … … 898 956 # 4.B.4.a(26)(a)(3) 899 957 # KickStart Actions: 900 958 959 ## FIXME: Find STIG for this 901 960 echo 'Ciphers aes256-cbc,aes192-cbc,blowfish-cbc,cast128-cbc,aes128-cbc,3des-cbc' >> /etc/ssh/ssh_config 902 961 … … 957 1016 958 1017 ## (GEN003600: CAT II) The SA will ensure network parameters are securely set. 1018 ## FIXME: This should be a sed replace/append 959 1019 cat <<-EOF > /etc/sysctl.conf 960 1020 net.ipv4.ip_forward = 0 … … 965 1025 EOF 966 1026 1027 ## (GEN005600: CAT II) The SA will ensure IP forwarding is disabled if the 1028 ## system is not dedicated as a router. 1029 sed -i "/net\.ipv4\.ip_forward/ c\net.ipv4.ip_forward = 0" /etc/sysctl.conf 1030 967 1031 ## (GEN003960: CAT II) (Previously â G631) The SA will ensure the owner of 968 1032 ## the traceroute command is root. 969 1033 chown root /bin/traceroute 970 1034 971 1035 ## (GEN003980: CAT II) (Previously â G632) The SA will ensure the group 972 1036 ## owner of the traceroute command is root, sys, or bin. 973 1037 chgrp root /bin/traceroute 974 1038 975 1039 ## (GEN004000: CAT II) (Previously â G633) The SA will ensure the traceroute 976 1040 ## command has permissions of 700, or more restrictive. … … 990 1054 /sbin/chkconfig xinetd off 991 1055 1056 ## (GEN003860: CAT III) (Previously â V046) The SA will ensure finger is not 1057 ## enabled. 1058 /sbin/chkconfig finger off 1059 992 1060 ## (GEN003740: CAT II) (Previously â G108) The SA will ensure the inetd.conf 993 1061 ## (xinetd.conf for Linux) file has permissions of 440, or more restrictive. … … 998 1066 chmod 440 /etc/xinetd.conf 999 1067 1000 1068 1001 1069 # 4.B.4.b(5)(b) 1002 1070 # KickStart Actions: Actions Listed Below … … 1010 1078 ## log on to their personal account and invoke the /bin/su - command to switch 1011 1079 ## user to root. 1012 1080 1013 1081 # Configure sshd and login to consult pam_access.so 1014 1082 sed -i '/^account/ a\account\t\trequired\tpam_access.so' /etc/pam.d/sshd … … 1097 1165 chown root:root /etc/cron.deny 1098 1166 1167 ## (GEN003300: CAT II) (Previously â G212) The SA will ensure the at.deny file 1168 ## is not empty. 1169 awk -F: '{print $1}' /etc/passwd | grep -v root > /etc/at.deny 1170 1171 ## (GEN003320: CAT II) (Previously â G213) The SA will ensure default system 1172 ## accounts (with the possible exception of root) are not listed in the 1173 ## at.allow file. If there is only an at.deny file, the default accounts 1174 ## (with the possible exception of root) will be listed there. 1175 echo "root" > /etc/at.allow 1176 1177 ## (GEN003340: CAT II) (Previously â G214) The SA will ensure the at.allow and 1178 ## at.deny files have permissions of 600, or more restrictive. 1179 chmod 600 /etc/at.allow 1180 chmod 600 /etc/at.deny 1181 1182 ## (GEN003400: CAT II) (Previously â G625) The SA will ensure the at (or 1183 ## equivalent) directory has permissions of 755, or more restrictive. 1184 chmod 755 /var/spool/at/spool 1185 1186 ## (GEN003420: CAT II) (Previously â G626) The SA will ensure the owner and 1187 ## group owner of the at (or equivalent) directory is root, sys, bin, or daemon. 1188 chown root:root /var/spool/at/spool 1189 1190 ## (GEN003460: CAT II) (Previously â G629) The SA will ensure the owner and 1191 ## group owner of the at.allow file is root. 1192 chown root:root /etc/at.allow 1193 1194 ## (GEN003480: CAT II) (Previously â G630) The SA will ensure the owner and 1195 ## group owner of the at.deny file is root. 1196 chown root:root /etc/at.deny 1197 1099 1198 ## (GEN001120: CAT II) (Previously â G500) The SA will configure the 1100 1199 ## encryption program for direct root access only from the system console. 1101 1200 sed -i "/^#PermitRootLogin/ c\PermitRootLogin no" /etc/ssh/sshd_config 1102 1103 ## GEN002260: CAT III) (Previously â G076) The SA will ensure all local filesystems are1104 ## checked at least weekly against the system baseline to detect any extraneous device files.1105 ## FIXME: This doesn't satisfy the STIG1106 find /dev -type b -or -type c -or -type s >> /root/blockdevices.`date +%Y:%m:%d644`.txt1107 1201 1108 1202 ## (GEN002560: CAT II) (Previously â G089) The SA will ensure the system and … … 1133 1227 ## or more restrictive. 1134 1228 find /usr/share/man -type f -not -perm 644 -exec chmod 644 {} \; 1229 1230 ## (GEN003040: CAT II) The SA will ensure the owner of crontabs is root or the 1231 ## crontab creator. 1232 chown root /etc/cron.hourly/* 1233 chown root /etc/cron.daily/* 1234 chown root /etc/cron.weekly/* 1235 chown root /etc/cron.monthly/* 1236 chown root /etc/cron.d/* 1237 chown root /var/spool/cron/* 1135 1238 1136 1239 ## (GEN003080: CAT II) (Previously â G205) The SA will ensure crontabs have … … 1143 1246 chmod 600 /etc/crontab 1144 1247 chmod -R 600 /etc/cron.d 1145 1248 1146 1249 ## (GEN003100: CAT II) (Previously â G206) The SA will ensure cron and crontab 1147 1250 ## directories have permissions of 755, or more restrictive. … … 1176 1279 chown root:root /var/crash 1177 1280 chmod -R 700 /var/crash 1178 1281 1179 1282 ## (GEN04540: CAT II) The SA will ensure the help sendmail command is 1180 1283 ## disabled. … … 1187 1290 ## O SmtpGreetingMessage= Mail Server Ready ; $b 1188 1291 sed -i '/SmtpGreetingMessage/ c\O SmtpGreetingMessage= Mail Server Ready ; $b' /etc/mail/sendmail.cf 1292 1293 ## (GEN004360: CAT II) (Previously â G127) The SA will ensure the aliases file 1294 ## is owned by root. 1295 chown root /etc/aliases 1296 1297 ## (GEN004380: CAT II) (Previously â G128) The SA will ensure the aliases file 1298 ## has permissions of 644, or more restrictive. 1299 chmod 644 /etc/aliases 1189 1300 1190 1301 # GEN005360: CAT II - The SA will ensure the owner of the snmpd.conf file is root with a group … … 1217 1328 find /dev -name "*ty*" -exec chmod 700 {} \; 1218 1329 1330 ## (LNX00320: CAT I) (Previously â L140) The SA will delete accounts that 1331 ## provide a special privilege such as shutdown and halt. 1332 /usr/sbin/userdel shutdown 1333 /usr/sbin/userdel halt 1334 /usr/sbin/userdel sync 1335 1219 1336 ## (LNX00340: CAT II) (Previously â L142) The SA will delete accounts that 1220 1337 ## provide no operational purpose, such as games or operator, and will delete … … 1225 1342 /usr/sbin/userdel gopher 1226 1343 /usr/sbin/userdel nfsnobody 1227 1344 1228 1345 ## (GEN004640: CAT I) (Previously â V126) The SA will ensure the decode entry 1229 1346 ## is disabled (deleted or commented out) from the alias file. … … 1231 1348 /usr/bin/newaliases 1232 1349 1233 ## (GEN004500: CAT II) (Previously â G136) The SA will ensure the critical1234 ## sendmail log file has permissions of 644, or more restrictive.1235 chmod 644 /var/log/maillog1236 1237 1350 ## (LNX00440: CAT II) (Previously â L046) The SA will ensure /etc/login.access 1238 1351 ## or /etc/security/access.conf file will be 640, or more restrictive. 1239 1352 chmod 640 /etc/security/access.conf 1240 1353 1354 ## (GEN006100: CAT II) (Previously â L050) The SA will ensure the owner of 1355 ## the/etc/samba/smb.conf file is root. 1356 chown root /etc/samba/smb.conf 1357 1358 ## (GEN006120: CAT II) (Previously â L051) The SA will ensure the group owner 1359 ## of the /etc/samba/smb.conf file is root. 1360 chgrp root /etc/samba/smb.conf 1361 1362 ## (GEN006140: CAT II) (Previously â L052) The SA will ensure the 1363 ## /etc/samba/smb.conf file has permissions of 644, or more restrictive. 1364 chmod 644 /etc/samba/smb.conf 1365 1241 1366 ## (GEN006160: CAT II) (Previously â L054) The SA will ensure the owner of 1242 1367 ## smbpasswd is root. 1243 1368 chown root /usr/bin/smbpasswd 1244 1369 1370 ## (GEN006180: CAT II) (Previously â L055) The SA will ensure group owner of 1371 ## smbpasswd is root. 1372 chgrp root /usr/bin/smbpasswd 1373 1374 ## (GEN006200: CAT II) (Previously â L057) The SA will configure permissions 1375 ## for smbpasswd to 600, or more restrictive. 1376 chmod 600 /usr/bin/smbpasswd 1377 1378 ## (GEN003760: CAT II) (Previously â G109) The SA will ensure the owner of the 1379 ## services file is root or bin. 1380 chown root /etc/services 1381 1382 ## (GEN003780: CAT II) (Previously â G110) The SA will ensure the services 1383 ## file has permissions of 644, or more restrictive. 1384 chmod 644 /etc/services 1385 1386 ## (GEN005740: CAT II) (Previously â G178) The SA will ensure the owner of the 1387 ## export configuration file is root. 1388 chown root /etc/exports 1389 1390 ## (GEN005760: CAT III) (Previously â G179) The SA will ensure the export 1391 ## configuration file has permissions of 644, or more restrictive. 1392 chmod 644 /etc/exports 1393 1394 ## (GEN006260: CAT II) (Previously â L154) The SA will ensure the 1395 ## /etc/news/hosts.nntp file has permissions of 600, or more restrictive. 1396 chmod 600 /etc/news/hosts.nntp 1397 1398 ## (GEN006280: CAT II) (Previously â L156) The SA will ensure the 1399 ## /etc/news/hosts.nntp.nolimit file has permissions of 600, or more 1400 ## restrictive. 1401 chmod 600 /etc/news/hosts.nntp.nolimit 1402 1403 ## (GEN006300: CAT II) (Previously â L158) The SA will ensure the 1404 ## /etc/news/nnrp.access file has permissions of 600, or more restrictive. 1405 chmod 600 /etc/news/nnrp.access 1406 1407 ## (GEN006320: CAT II) (Previously â L160) The SA will ensure the 1408 # /etc/news/passwd.nntp file has permissions of 600, or more restrictive. 1409 chmod 600 /etc/news/passwd.nntp 1410 1411 ## (GEN006340: CAT II) (Previously â L162) The SA will ensure the owner of all 1412 ## files under the /etc/news subdirectory is root or news. 1413 chown -R root /etc/news/* 1414 1415 ## (GEN006360: CAT II) (Previously â L164) The SA will ensure the group owner 1416 ## of all files in /etc/news is root or news. 1417 chgrp -R root /etc/news/* 1418 1245 1419 # GEN000960 1246 # FIXME: Wrong number, Need to find correct 1420 # FIXME: Wrong number, I don't think this is a stig 1421 # Maybe it is about deleting unused system users 1247 1422 # If we're not running an POP/IMAP server, remove the user dovecot 1248 1423 rpm -q dovecot 2>&1 > /dev/null … … 1263 1438 fi 1264 1439 1265 1266 1440 # 4.B.4.b(6) 1267 1441 # KickStart Actions: None … … 1751 1925 1752 1926 # AC-1: Access Control Policy and Procedures 1927 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1753 1928 1754 1929 # AC-2: Account Management 1930 # Kickstart Actions: 1931 1932 # AC-2(1) 1933 # Kickstart Actions: 1934 1935 # AC-2(2) 1936 # Kickstart Actions: 1937 1938 # AC-2(3) 1939 # Kickstart Actions: 1940 1941 # AC-2(4) 1942 # Kickstart Actions: 1755 1943 1756 1944 # AC-3: Access Enforcement 1945 # Kickstart Actions: 1946 1947 # AC-3(1) 1948 # Kickstart Actions: 1757 1949 1758 1950 # AC-4: Information Flow Enforcement 1951 # Kickstart Actions: 1952 1953 # AC-4(1) 1954 # Kickstart Actions: 1955 1956 # AC-4(2) 1957 # Kickstart Actions: 1958 1959 # AC-4(3) 1960 # Kickstart Actions: 1759 1961 1760 1962 # AC-5: Separation of Duties 1963 # Kickstart Actions: 1761 1964 1762 1965 # AC-6: Least Privilege 1966 # Kickstart Actions: 1763 1967 1764 1968 # AC-7: Unsuccessful Login Attempts 1969 # Kickstart Actions: 1970 1971 # AC-7(1) 1972 # Kickstart Actions: 1765 1973 1766 1974 # AC-8: System Use Notification 1975 # Kickstart Actions: 1767 1976 1768 1977 # AC-9: Previous Logon Notification 1978 # Kickstart Actions: 1769 1979 1770 1980 # AC-10: Concurrent Session Control 1981 # Kickstart Actions: 1771 1982 1772 1983 # AC-11: Session Lock 1984 # Kickstart Actions: 1773 1985 1774 1986 # AC-12: Session Termination 1987 # Kickstart Actions: 1988 1989 # AC-12(1) 1990 # Kickstart Actions: 1775 1991 1776 1992 # AC-13: Supervision and ReviewâAccess Control 1993 # Kickstart Actions: 1994 1995 # AC-13(1) 1996 # Kickstart Actions: 1777 1997 1778 1998 # AC-14: Permitted Actions without Identification or Authentication 1999 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2000 2001 # AC-14(1) 2002 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1779 2003 1780 2004 # AC-15: Automated Marking 2005 # Kickstart Actions: 1781 2006 1782 2007 # AC-16: Automated Labeling 2008 # Kickstart Actions: None 1783 2009 1784 2010 # AC-17: Remote Access 2011 # Kickstart Actions: 2012 2013 # AC-17(1) 2014 # Kickstart Actions: 2015 2016 # AC-17(2) 2017 # Kickstart Actions: 2018 2019 # AC-17(3) 2020 # Kickstart Actions: 2021 2022 # AC-17(4) 2023 # Kickstart Actions: 1785 2024 1786 2025 # AC-18: Wireless Access Restrictions 2026 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2027 2028 # AC-18(1) 2029 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2030 2031 # AC-18(2) 2032 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1787 2033 1788 2034 # AC-19: Access Control for Portable and Mobile Devices 2035 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1789 2036 1790 2037 # AC-20: Use of External Information Systems 2038 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2039 2040 # AC-20(1) 2041 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1791 2042 1792 2043 … … 1795 2046 1796 2047 # AT-1: Security Awareness and Training Policy and Procedures 2048 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1797 2049 1798 2050 # AT-2: Security Awareness 2051 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1799 2052 1800 2053 # AT-3: Security Training 2054 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1801 2055 1802 2056 # AT-4: Security Training Records 2057 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1803 2058 1804 2059 # AT-5: Contacts with Security Groups and Associations 2060 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1805 2061 1806 2062 … … 1809 2065 1810 2066 # AU-1: Audit and Accountability Policy and Procedures 2067 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1811 2068 1812 2069 # AU-2: Auditable Events 2070 # Kickstart Actions: 2071 2072 # AU-2(1) 2073 # Kickstart Actions: 2074 2075 # AU-2(2) 2076 # Kickstart Actions: 2077 2078 # AU-2(3) 2079 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1813 2080 1814 2081 # AU-3: Content of Audit Records 2082 # Kickstart Actions: 2083 2084 # AU-2(1) 2085 # Kickstart Actions: 2086 2087 # AU-2(2) 2088 # Kickstart Actions: 1815 2089 1816 2090 # AU-4: Audit Storage Capacity 2091 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1817 2092 1818 2093 # AU-5: Response to Audit Processing Failures 2094 # Kickstart Actions: 2095 2096 # AU-5(1) 2097 # Kickstart Actions: 2098 2099 # AU-5(2) 2100 # Kickstart Actions: 1819 2101 1820 2102 # AU-6: Audit Monitoring, Analysis, and Reporting 2103 # Kickstart Actions: 2104 2105 # AU-6(1) 2106 # Kickstart Actions: 2107 2108 # AU-6(2) 2109 # Kickstart Actions: 1821 2110 1822 2111 # AU-7: Audit Reduction and Report Generation 2112 # Kickstart Actions: 2113 2114 # AU-7(1) 2115 # Kickstart Actions: 1823 2116 1824 2117 # AU-8: Time Stamps 2118 # Kickstart Actions: 2119 2120 # AU-8(1) 2121 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1825 2122 1826 2123 # AU-9: Protection of Audit Information 2124 # Kickstart Actions: 2125 2126 # AU-9(1) 2127 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1827 2128 1828 2129 # AU-10: Non-repudiation 2130 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1829 2131 1830 2132 # AU-11: Audit Record Retention 2133 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1831 2134 1832 2135 … … 1835 2138 1836 2139 # CA-1: Certification, Accreditation, and Security Assessment Policies and Procedures 2140 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1837 2141 1838 2142 # CA-2: Security Assessments 2143 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1839 2144 1840 2145 # CA-3: Information System Connections 2146 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1841 2147 1842 2148 # CA-4: Security Certification 2149 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2150 2151 # CA-4(1) 2152 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1843 2153 1844 2154 # CA-5: Plan of Action and Milestones 2155 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1845 2156 1846 2157 # CA-6: Security Accreditation 2158 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1847 2159 1848 2160 # CA-7: Continuous Monitoring 2161 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2162 2163 # CA-7(1) 2164 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1849 2165 1850 2166 … … 1853 2169 1854 2170 # CM-1: Configuration Management Policy and Procedures 2171 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1855 2172 1856 2173 # CM-2: Baseline Configuration 2174 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2175 2176 # CM-2(1) 2177 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2178 2179 # CM-2(2) 2180 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1857 2181 1858 2182 # CM-3: Configuration Change Control 2183 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2184 2185 # CM-3(1) 2186 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1859 2187 1860 2188 # CM-4: Monitoring Configuration Changes 2189 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1861 2190 1862 2191 # CM-5: Access Restrictions for Change 2192 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2193 2194 # CM-5(1) 2195 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1863 2196 1864 2197 # CM-6: Configuration Settings 2198 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2199 2200 # CM-6(1) 2201 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1865 2202 1866 2203 # CM-7: Least Functionality 2204 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2205 2206 # CM-7(1) 2207 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1867 2208 1868 2209 # CM-8: Information System Component Inventory 2210 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2211 2212 # CM-8(1) 2213 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2214 2215 # CM-8(2) 2216 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1869 2217 1870 2218 … … 1873 2221 1874 2222 # CP-1: Contingency Planning Policy and Procedures 2223 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1875 2224 1876 2225 # CP-2: Contingency Plan 2226 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2227 2228 # CP-2(1) 2229 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2230 2231 # CP-2(2) 2232 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1877 2233 1878 2234 # CP-3: Contingency Training 2235 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2236 2237 # CP-3(1) 2238 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2239 2240 # CP-3(2) 2241 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1879 2242 1880 2243 # CP-4: Contingency Plan Testing and Exercises 2244 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2245 2246 # CP-4(1) 2247 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2248 2249 # CP-4(2) 2250 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2251 2252 # CP-4(3) 2253 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1881 2254 1882 2255 # CP-5: Contingency Plan Update 2256 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1883 2257 1884 2258 # CP-6: Alternate Storage Site 2259 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2260 2261 # CP-6(1) 2262 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2263 2264 # CP-6(2) 2265 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2266 2267 # CP-6(3) 2268 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1885 2269 1886 2270 # CP-7: Alternate Processing Site 2271 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2272 2273 # CP-7(1) 2274 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2275 2276 # CP-7(2) 2277 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2278 2279 # CP-7(3) 2280 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2281 2282 # CP-7(4) 2283 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1887 2284 1888 2285 # CP-8: Telecommunications Services 2286 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2287 2288 # CP-8(1) 2289 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2290 2291 # CP-8(2) 2292 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2293 2294 # CP-8(3) 2295 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2296 2297 # CP-8(4) 2298 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1889 2299 1890 2300 # CP-9: Information System Backup 2301 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2302 2303 # CP-9(1) 2304 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2305 2306 # CP-9(2) 2307 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2308 2309 # CP-9(3) 2310 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2311 2312 # CP-9(4) 2313 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1891 2314 1892 2315 # CP-10: Information System Recovery and Reconstitution Identification and Authentication 2316 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2317 2318 # CP-10(1) 2319 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1893 2320 1894 2321 … … 1897 2324 1898 2325 # IA-1: Identification and Authentication Policy and Procedures 2326 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1899 2327 1900 2328 # IA-2: User Identification and Authentication 2329 # Kickstart Actions: 2330 2331 # IA-2(1) 2332 # Kickstart Actions: 2333 2334 # IA-2(2) 2335 # Kickstart Actions: 2336 2337 # IA-2(3) 2338 # Kickstart Actions: 1901 2339 1902 2340 # IA-3: Device Identification and Authentication 2341 # Kickstart Actions: 1903 2342 1904 2343 # IA-4: Identifier Management 2344 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1905 2345 1906 2346 # IA-5: Authenticator Management 2347 # Kickstart Actions: 1907 2348 1908 2349 # IA-6: Authenticator Feedback 2350 # Kickstart Actions: 1909 2351 1910 2352 # IA-7: Cryptographic Module Authentication Incident Response 2353 # Kickstart Actions: 1911 2354 1912 2355 … … 1915 2358 1916 2359 # IR-1: Incident Response Policy and Procedures 2360 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1917 2361 1918 2362 # IR-2: Incident Response Training 2363 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2364 2365 # IR-2(1) 2366 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2367 2368 # IR-2(2) 2369 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1919 2370 1920 2371 # IR-3: Incident Response Testing and Exercises 2372 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2373 2374 # IR-3(1) 2375 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1921 2376 1922 2377 # IR-4: Incident Handling 2378 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2379 2380 # IR-4(1) 2381 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1923 2382 1924 2383 # IR-5: Incident Monitoring 2384 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2385 2386 # IR-5(1) 2387 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1925 2388 1926 2389 # IR-6: Incident Reporting 2390 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2391 2392 # IR-6(1) 2393 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1927 2394 1928 2395 # IR-7: Incident Response Assistance 2396 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2397 2398 # IR-7(1) 2399 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1929 2400 1930 2401 … … 1933 2404 1934 2405 # MA-1: System Maintenance Policy and Procedures 2406 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1935 2407 1936 2408 # MA-2: Controlled Maintenance 2409 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2410 2411 # MA-2(1) 2412 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2413 2414 # MA-2(2) 2415 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 1937 2416 1938 2417 # MA-3: Maintenance Tools 2418 # Kickstart Actions: None - PROCEDURAL REQUIREMENT 2419  
