<Group id="srg_support" hidden="true">
<title>Documentation to Support DISA OS SRG Mapping</title>
<description>These groups exist to document how the Red Hat Enterprise Linux
product meets (or does not meet) requirements listed in the DISA OS SRG, for
those cases where Groups or Rules elsewhere in scap-security-guide do
not clearly relate.
</description>


<!-- The CCI/SRG items referenced here are:
     - satisfied (through design and implementation)
     - selected in DoD baseline (per CNSS 1253) -->
<Rule id="met_inherently_generic">
<title>Product Meets this Requirement</title>
<rationale>
Red Hat Enterprise Linux meets this requirement through design and implementation.
</rationale>
<ocil>RHEL9 supports this requirement and cannot be configured to be out of
compliance. This is a permanent not a finding.
</ocil>
<description>
This requirement is a permanent not a finding. No fix is required.
</description>
<!-- Note: This XCCDF rule is used to group DISA requirements. As such,
          it should not have CCE association -->
<ref disa="15,42,56,206,1084,66,85,86,185,223,171,172,1694,770,804,162,163,164,345,346,1096,1111,1291,386,156,186,1083,1082,1090,804,1127,1128,1129,1248,1265,1314,1362,1368,1310,1311,1328,1399,1400,1404,1405,1427,1499,1632,1693,1665,1674" />
</Rule>


<!-- The CCI/SRG items referenced here relate to auditing, and are:
     - satisfied (through design and implementation)
     - selected in DoD baseline (per CNSS 1253) -->
<Rule id="met_inherently_auditing">
<title>Product Meets this Requirement</title>
<rationale>
The Red Hat Enterprise Linux audit system meets this requirement through design and implementation.
</rationale>
<ocil>The RHEL9 auditing system supports this requirement and cannot be configured to be out of
compliance. Every audit record in RHEL includes a timestamp, the operation attempted,
success or failure of the operation, the subject involved (executable/process),
the object involved (file/path), and security labels for the subject and object.
It also includes the ability to label events with custom key labels.  The auditing system
centralizes the recording of audit events for the entire system and includes
reduction (<tt>ausearch</tt>), reporting (<tt>aureport</tt>), and real-time
response (<tt>audispd</tt>) facilities.
This is a permanent not a finding.
</ocil>
<description>
This requirement is a permanent not a finding. No fix is required.
</description>
<!-- Note: This XCCDF rule is used to group DISA requirements. As such,
          it should not have CCE association -->
<ref disa="130,157,131,132,133,134,135,159,174" />
</Rule>


<!-- The CCI/SRG item referenced here are:
     - satisfied (through design and implementation)
     - not selected in a DoD baseline -->
<Rule id="met_inherently_nonselected">
<title>Product Meets this Requirement</title>
<rationale>
Red Hat Enterprise Linux meets this requirement through design and implementation.
</rationale>
<ocil>RHEL9 supports this requirement and cannot be configured to be out of
compliance. This is a permanent not a finding.
</ocil>
<description>
This requirement is a permanent not a finding. No fix is required.
</description>
<!-- Note: This XCCDF rule is used to group DISA requirements. As such,
          it should not have CCE association -->
<ref disa="34,35,99,154,226,802,872,1086,1087,1089,1091,1424,1426,1428,1209,1214,1237,1269,1338,1425,1670" />
</Rule>


<!-- The CCI/SRG item listed here are:
     - satisfied (by Rules in the guidance, which include the reference)
     - not selected in DoD baseline -->
<!-- disa="26,32,771,772,831,884,888,1095,1115,1117,1250,1348,1353,1464,1496" -->


<!-- The CCI/SRG item referenced here are:
     - not satisfied
     - not selected in a DoD baseline
     - considered out of scope -->
<Rule id="unmet_nonfinding_nonselected_scope">
<title>Guidance Does Not Meet this Requirement Due to Impracticality or Scope</title>
<rationale>
The guidance does not meet this requirement.
The requirement is impractical or out of scope.
</rationale>
<ocil>
RHEL9 cannot support this requirement without assistance from an external
application, policy, or service. This requirement is NA.
</ocil>
<description>
This requirement is NA. No fix is required.
</description>
<!-- Note: This XCCDF rule is used to group DISA requirements. As such,
          it should not have CCE association -->
<ref disa="21,25,28,29,30,165,221,354,553,779,780,781,1009,1094,1123,1124,1125,1132,1135,1140,1141,1142,1143,1145,1147,1148,1166,1339,1340,1341,1350,1356,1373,1374,1383,1391,1392,1395,1662" />
</Rule>


<!-- The CCI/SRG items referenced here are:
     - not satisfied
     - not selected in a DoD baseline
     - considered permanent findings -->
<Rule id="unmet_finding_nonselected">
<title>Implementation of the Requirement is Not Supported</title>
<rationale>
RHEL9 does not support this requirement.
</rationale>
<ocil>
This is a permanent finding.
</ocil>
<description>
This requirement is a permanent finding and cannot be fixed. An appropriate
mitigation for the system must be implemented but this finding cannot be
considered fixed.
</description>
<ref disa="20,31,52,144,1158,1294,1295,1500" />
<!-- Note: CCI 52 supported for text login, but not graphical -->
</Rule>


<!-- The CCI/SRG items referenced here are:
     - not satisfied
     - selected in a DoD baseline
     - considered NA -->
<Rule id="unmet_nonfinding_scope">
<title>Guidance Does Not Meet this Requirement Due to Impracticality or Scope</title>
<rationale>
The guidance does not meet this requirement.
The requirement is impractical or out of scope.
</rationale>
<ocil>
RHEL9 cannot support this requirement without assistance from an external
application, policy, or service. This requirement is NA.
</ocil>
<description>
This requirement is NA. No fix is required.
</description>
<!-- Note: This XCCDF rule is used to group DISA requirements. As such,
     it should not have CCE association -->
<ref disa="27,218,219,371,372,535,537,539,1682,370,37,24,1112,1126,1143,1149,1157,1159,1210,1211,1274,1372,1376,1377,1352,1401,1555,1556,1150" />
</Rule>

<Rule id="update_process">
<title>A process for prompt installation of OS updates must exist.</title>
<rationale>
This is a manual inquiry about update procedure.
</rationale>
<ocil>
Ask an administrator if a process exists to promptly and automatically apply OS
software updates.  If such a process does not exist, this is a finding.
<br /><br />
If the OS update process limits automatic updates of software packages, where
such updates would impede normal system operation, to scheduled maintenance
windows, but still within IAVM-dictated timeframes, this is not a finding.
</ocil>
<description>
Procedures to promptly apply software updates must be established and
executed. The Red Hat operating system provides support for automating such a
process, by running the yum program through a cron job or by managing the
system and its packages through the Red Hat Network or a Satellite Server.
</description>
<ref disa="1232" />
<!-- Note: This is a process, as such, will not receive a CCE -->
</Rule>

</Group>
