Skip to content

Commit 9cadd45

Browse files
authored
Merge pull request #14612 from Arden97/fix_14560
Add postfix package requirement and audit retention controls to multiple profile controls
2 parents 9cbb2a0 + 715670a commit 9cadd45

25 files changed

Lines changed: 28 additions & 3 deletions

File tree

controls/hipaa.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1248,6 +1248,7 @@ controls:
12481248
- auditd_data_retention_max_log_file_action
12491249
- auditd_data_retention_max_log_file_action_stig
12501250
- auditd_data_retention_space_left_action
1251+
- package_postfix_installed
12511252
- package_rsyslog_installed
12521253
- service_rsyslog_enabled
12531254
- partition_for_var_log_audit

controls/pcidss_3.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2130,6 +2130,7 @@ controls:
21302130
- auditd_data_retention_space_left
21312131
- auditd_data_retention_admin_space_left_action
21322132
- auditd_data_retention_action_mail_acct
2133+
- package_postfix_installed
21332134

21342135
- id: Req-10.8
21352136
title: 10.8 Ensure that security policies and operational procedures for monitoring all access

controls/pcidss_4.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2967,6 +2967,7 @@ controls:
29672967
- auditd_data_retention_admin_space_left_action
29682968
- auditd_data_retention_space_left
29692969
- auditd_data_retention_space_left_action
2970+
- package_postfix_installed
29702971
- package_logrotate_installed
29712972
- timer_logrotate_enabled
29722973
related_rules:

controls/srg_gpos/SRG-OS-000046-GPOS-00022.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,7 @@ controls:
55
title: {{{ full_name }}} must alert the ISSO and SA (at a minimum) in the event
66
of an audit processing failure.
77
rules:
8+
- package_postfix_installed
89
- postfix_client_configure_mail_alias
910
- postfix_client_configure_mail_alias_postmaster
1011
- var_postfix_root_mail_alias=mil_sysadmin

linux_os/guide/services/mail/package_postfix_installed/rule.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,7 @@ severity: medium
1515
identifiers:
1616
cce@rhel8: CCE-85983-5
1717
cce@rhel9: CCE-85984-3
18+
cce@rhel10: CCE-86466-0
1819

1920
references:
2021
srg: SRG-OS-000046-GPOS-00022

products/rhel10/controls/cis_rhel10.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2622,8 +2622,11 @@ controls:
26222622
- l2_workstation
26232623
status: automated
26242624
rules:
2625+
- auditd_data_retention_action_mail_acct
26252626
- auditd_data_retention_admin_space_left_action
26262627
- auditd_data_retention_space_left_action
2628+
- package_postfix_installed
2629+
- var_auditd_action_mail_acct=root
26272630
- var_auditd_admin_space_left_action=cis_rhel10
26282631
- var_auditd_space_left_action=cis_rhel10
26292632

products/rhel9/controls/cis_rhel9.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2560,6 +2560,7 @@ controls:
25602560
- auditd_data_retention_action_mail_acct
25612561
- auditd_data_retention_admin_space_left_action
25622562
- auditd_data_retention_space_left_action
2563+
- package_postfix_installed
25632564
- var_auditd_action_mail_acct=root
25642565
- var_auditd_admin_space_left_action=cis_rhel9
25652566
- var_auditd_space_left_action=cis_rhel9

products/sle12/profiles/default.profile

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,6 @@ selections:
3333
- sudo_vdsm_nopasswd
3434
- ntpd_configure_restrictions
3535
- fapolicyd_prevent_home_folder_access
36-
- package_postfix_installed
3736
- audit_privileged_commands_poweroff
3837
- accounts_password_pam_unix_rounds_password_auth
3938
- sudoers_no_root_target

products/sle12/profiles/pci-dss-4.profile

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -95,6 +95,7 @@ selections:
9595
- '!use_pam_wheel_for_su'
9696
- use_pam_wheel_group_for_su
9797
- var_pam_wheel_group_for_su=cis
98+
- '!package_postfix_installed'
9899
# Following rules once had a prodtype incompatible with the sle12 product
99100
- '!set_firewalld_default_zone'
100101
- '!accounts_password_pam_dcredit'

products/sle12/profiles/pci-dss.profile

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,7 @@ selections:
1717
- sshd_approved_ciphers=cis_sle12
1818
- var_multiple_time_servers=suse
1919
- var_multiple_time_pools=suse
20+
- '!package_postfix_installed'
2021
# Exclude from PCI DISS profile all rules related to ntp and timesyncd and keep only
2122
# rules related to chrony
2223
- '!ntpd_specify_multiple_servers'

0 commit comments

Comments
 (0)