Description: Users should protect their BIOS or UEFI with a password.
Levels:Automated: no
No rules selected
Description: Users should disable features and devices in the BIOS or UEFI that are not in use and should only include trusted devices in the boot order.
Levels:Automated: no
No rules selected
Description: When possible, users should use a 64-bit system and hardware that supports it.
Levels:Automated: no
No rules selected
Description: Users should apply the Fedora Common User Security Policy in the installer.
Levels:Automated: no
No rules selected
Description: Users should put the /home, /tmp, /var, /var/tmp and /var/log directories on separate partitions.
Levels:Automated: no
No rules selected
Description: Users should ensure that all account passwords adhere to the password rules in rule 4.1.
Levels:Automated: no
No rules selected
Description: Users should encrypt their disk with a passphrase that adheres to the password rules in rule 4.1.
Levels:Automated: no
No rules selected
Description: If the BIOS or UEFI does not allow password protection of the boot process, users should set a bootloader password.
Levels:Automated: no
Selections:Description: Users should apply updates from the GNOME Software application at least once per day.
Levels:Automated: no
Selections:Description: Directories /home (-noexec), /tmp, /var, /var/tmp and /var/log mount option configuration.
Levels:Automated: yes
Selections:Description: System cryto policy configuation and ensuring it is not overridden in critical components.
Levels:Automated: yes
Selections:Description: Auditd and journald configutation.
Levels:Automated: yes
Selections:Description: User and critical system file permissions and ownership, user and group file and directory ownership, identifiers.
Levels:Automated: no
Selections:Description: Enable ASLR and ExecShield, restrict exposed kernel pointer.
Levels:Automated: yes
Selections:Description: Do not show user list, disable xdmpc and auto login, set up idle lock and protect the settings.
Levels:Automated: yes
Selections:Description: Chrony and time-based scheduler security configuration.
Levels:Automated: yes
Selections:Description: Users should remove any services that are not necessary for normal system usage.
Levels:Automated: no
Selections:Description: All account passwords must be passphrases of at least 4 words and 15 characters with at least three character classes, generated with a large wordlist and a source of randomness.
Levels:Automated: no
Selections:Description: Secure sudo configuration.
Levels:Automated: yes
Selections:Description: Secure ssh server configuration.
Levels:Automated: yes
Selections:Description: If users did not configure IPv6 on the system and it is not needed, it should be disabled.
Levels:Automated: no
Selections:Description: Users should ensure that all network interfaces are in the appropriate firewall zone and that ports and services allowed by the firewall are reduced to the necessary minimum.
Levels:Automated: no
Selections:Description: Users should install the Firefox Flatpak from FlatHub and use it instead of the default Firefox application. If the default Firefox application must be used, the users should apply the Common User Security Profile for Mozilla Firefox CaC profile.
Levels:Automated: no
No rules selected
Description: Ensure SELinux is installed and enabled, in enforcing mode using targeted policy.
Levels:Automated: no
Selections:Description: Users should perform periodic system scans and remediations with the Common User Security Profile by using the oscap tool or SCAP Workbench.
Levels:Automated: no
No rules selected