Definition of CIS Benchmark for Red Hat Enterprise Linux 8 for rhel8
based on https://www.cisecurity.org/cis-benchmarks/#red_hat_linux
reload_dconf_db: Reload Dconf database
Description: None
Levels:
Automated: yes
Selections:
- dconf_db_up_to_date: Make sure that the dconf databases are up-to-date with regards to respective keyfiles
enable_authselect: Enable Authselect
Description: None
Levels:
Automated: yes
Selections:
1.1.1.1: Ensure cramfs kernel module is not available (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.1.2: Ensure freevxfs kernel module is not available (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.1.3: Ensure hfs kernel module is not available (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.1.4: Ensure hfsplus kernel module is not available (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.1.5: Ensure jffs2 kernel module is not available (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.1.6: Ensure squashfs kernel module is not available (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.1.7: Ensure udf kernel module is not available (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.1.8: Ensure usb-storage kernel module is not available (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.1.1: Ensure /tmp is a separate partition (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.1.2: Ensure nodev option set on /tmp partition (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.1.3: Ensure nosuid option set on /tmp partition (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.1.4: Ensure noexec option set on /tmp partition (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.2.1: Ensure /dev/shm is a separate partition (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.2.2: Ensure nodev option set on /dev/shm partition (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.2.3: Ensure nosuid option set on /dev/shm partition (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.2.4: Ensure noexec option set on /dev/shm partition (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.3.1: Ensure separate partition exists for /home (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.3.2: Ensure nodev option set on /home partition (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.3.3: Ensure nosuid option set on /home partition (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.4.1: Ensure separate partition exists for /var (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.4.2: Ensure nodev option set on /var partition (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.4.3: Ensure nosuid option set on /var partition (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.5.1: Ensure separate partition exists for /var/tmp (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.5.2: Ensure nodev option set on /var/tmp partition (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.5.3: Ensure nosuid option set on /var/tmp partition (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.3.5.4: Ensure noexec option set on /var/tmp partition (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.6.1: Ensure separate partition exists for /var/log (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.6.2: Ensure nodev option set on /var/log partition (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.6.3: Ensure nosuid option set on /var/log partition (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.6.4: Ensure noexec option set on /var/log partition (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.7.1: Ensure separate partition exists for /var/log/audit (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.7.2: Ensure nodev option set on /var/log/audit partition (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.7.3: Ensure nosuid option set on /var/log/audit partition (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.1.2.7.4: Ensure noexec option set on /var/log/audit partition (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.2.1: Ensure GPG keys are configured (Manual)
Description: None
Levels:
Automated: no
No rules selected
1.2.2: Ensure gpgcheck is globally activated (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.2.3: Ensure repo_gpgcheck is globally activated (Manual)
Description: None
Levels:
Automated: no
No rules selected
1.2.4: Ensure package manager repositories are configured (Manual)
Description: None
Levels:
Automated: no
No rules selected
1.2.5: Ensure updates, patches, and additional security software are installed (Manual)
Description: None
Levels:
Automated: no
No rules selected
1.3.1: Ensure bootloader password is set (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.3.2: Ensure permissions on bootloader config are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.4.1: Ensure address space layout randomization (ASLR) is enabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.4.2: Ensure ptrace_scope is restricted (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.4.3: Ensure core dump backtraces are disabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.4.4: Ensure core dump storage is disabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.5.1.1: Ensure SELinux is installed (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.5.1.2: Ensure SELinux is not disabled in bootloader configuration (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.5.1.3: Ensure SELinux policy is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.5.1.4: Ensure the SELinux mode is not disabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.5.1.5: Ensure the SELinux mode is enforcing (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.5.1.6: Ensure no unconfined services exist (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.5.1.7: Ensure the MCS Translation Service (mcstrans) is not installed (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.5.1.8: Ensure SETroubleshoot is not installed (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.6.1: Ensure system wide crypto policy is not set to legacy (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.6.2: Ensure system wide crypto policy disables sha1 hash and signature support (Automated)
Description: None
Levels:
Automated: yes
No rules selected
1.6.3: Ensure system wide crypto policy disables cbc for ssh (Automated)
Description: None
Levels:
Automated: no
No rules selected
1.6.4: Ensure system wide crypto policy disables macs less than 128 bits (Automated)
Description: None
Levels:
Automated: no
No rules selected
1.7.1: Ensure message of the day is configured properly (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.7.2: Ensure local login warning banner is configured properly (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.7.3: Ensure remote login warning banner is configured properly (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.7.4: Ensure access to /etc/motd is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.7.5: Ensure access to /etc/issue is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.7.6: Ensure access to /etc/issue.net is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.8.1: Ensure GNOME Display Manager is removed (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.8.2: Ensure GDM login banner is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.8.3: Ensure GDM disable-user-list option is enabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.8.4: Ensure GDM screen locks when the user is idle (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.8.5: Ensure GDM screen locks cannot be overridden (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.8.6: Ensure GDM automatic mounting of removable media is disabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.8.7: Ensure GDM disabling automatic mounting of removable media is not overridden (Automated)
Description: None
Levels:
Automated: yes
No rules selected
1.8.8: Ensure GDM autorun-never is enabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
1.8.9: Ensure GDM autorun-never is not overridden (Automated)
Description: None
Levels:
Automated: yes
No rules selected
1.8.10: Ensure XDMCP is not enabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.1.1: Ensure time synchronization is in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.1.2: Ensure chrony is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.1.3: Ensure chrony is not run as the root user (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.2.1: Ensure autofs services are not in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.2.2: Ensure avahi daemon services are not in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.2.3: Ensure dhcp server services are not in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.2.4: Ensure dns server services are not in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.2.5: Ensure dnsmasq services are not in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.2.6: Ensure samba file server services are not in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.2.7: Ensure ftp server services are not in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.2.8: Ensure message access server services are not in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.2.9: Ensure network file system services are not in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.2.10: Ensure nis server services are not in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.2.11: Ensure print server services are not in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.2.12: Ensure rpcbind services are not in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.2.13: Ensure rsync services are not in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.2.14: Ensure snmp services are not in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.2.15: Ensure telnet server services are not in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.2.16: Ensure tftp server services are not in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.2.17: Ensure web proxy server services are not in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.2.18: Ensure web server services are not in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.2.19: Ensure xinetd services are not in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.2.20: Ensure X window server services are not in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.2.21: Ensure mail transfer agents are configured for local-only mode (Automated)
Description: None
Levels:
Automated: no
Selections:
2.2.22: Ensure only approved services are listening on a network interface (Manual)
Description: None
Levels:
Automated: no
No rules selected
2.3.1: Ensure ftp client is not installed (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.3.2: Ensure LDAP client is not installed (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.3.3: Ensure NIS Client is not installed (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.3.4: Ensure telnet client is not installed (Automated)
Description: None
Levels:
Automated: yes
Selections:
2.3.5: Ensure tftp client is not installed (Automated)
Description: None
Levels:
Automated: yes
Selections:
3.1.1: Ensure IPv6 status is identified (Manual)
Description: None
Levels:
Automated: no
No rules selected
3.1.2: Ensure wireless interfaces are disabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
3.1.3: Ensure bluetooth services are not in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
3.2.1: Ensure dccp kernel module is not available (Automated)
Description: None
Levels:
Automated: yes
Selections:
3.2.2: Ensure tipc kernel module is not available (Automated)
Description: None
Levels:
Automated: yes
Selections:
3.2.3: Ensure rds kernel module is not available (Automated)
Description: None
Levels:
Automated: yes
Selections:
3.2.4: Ensure sctp kernel module is not available (Automated)
Description: None
Levels:
Automated: yes
Selections:
3.3.1: Ensure ip forwarding is disabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
3.3.2: Ensure packet redirect sending is disabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
3.3.3: Ensure bogus icmp responses are ignored (Automated)
Description: None
Levels:
Automated: yes
Selections:
3.3.4: Ensure broadcast icmp requests are ignored(Automated)
Description: None
Levels:
Automated: yes
Selections:
3.3.5: Ensure icmp redirects are not accepted (Automated)
Description: None
Levels:
Automated: yes
Selections:
3.3.6: Ensure secure icmp redirects are not accepted (Automated)
Description: None
Levels:
Automated: yes
Selections:
3.3.7: Ensure reverse path filtering is enabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
3.3.8: Ensure source routed packets are not accepted (Automated)
Description: None
Levels:
Automated: yes
Selections:
3.3.9: Ensure suspicious packets are logged (Automated)
Description: None
Levels:
Automated: yes
Selections:
3.3.10: Ensure tcp sync cookies is enabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
3.3.11: Ensure IPv6 router advertisements are not accepted (Automated)
Description: None
Levels:
Automated: yes
Selections:
3.4.1.1: Ensure nftables is installed (Automated)
Description: None
Levels:
Automated: yes
Selections:
3.4.1.2: Ensure a single firewall configuration utility is in use (Automated)
Description: None
Levels:
Automated: yes
Selections:
3.4.2.1: Ensure nftables base chains exist (Automated)
Description: None
Levels:
Automated: no
No rules selected
3.4.2.2: Ensure host based firewall loopback traffic is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
3.4.2.3: Ensure firewalld drops unnecessary services and ports (Manual)
Description: None
Levels:
Automated: no
No rules selected
3.4.2.4: Ensure nftables established connections are configured (Manual)
Description: None
Levels:
Automated: no
No rules selected
3.4.2.5: Ensure nftables default deny firewall policy (Automated)
Description: None
Levels:
Automated: no
No rules selected
4.1.1.1: Ensure cron daemon is enabled and active (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.1.1.2: Ensure permissions on /etc/crontab are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.1.1.3: Ensure permissions on /etc/cron.hourly are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.1.1.4: Ensure permissions on /etc/cron.daily are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.1.1.5: Ensure permissions on /etc/cron.weekly are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.1.1.6: Ensure permissions on /etc/cron.monthly are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.1.1.7: Ensure permissions on /etc/cron.d are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.1.1.8: Ensure cron is restricted to authorized users (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.1.2.1: Ensure at is restricted to authorized users (Automated)
Description: None
Levels:
Automated: no
Selections:
4.2.1: Ensure permissions on /etc/ssh/sshd_config are configured (Automated)
Description: None
Levels:
Automated: no
Selections:
4.2.2: Ensure permissions on SSH private host key files are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.2.3: Ensure permissions on SSH public host key files are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.2.4: Ensure sshd access is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.2.5: Ensure sshd Banner is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.2.6: Ensure sshd Ciphers are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.2.7: Ensure sshd ClientAliveInterval and ClientAliveCountMax are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.2.8: Ensure sshd DisableForwarding is enabled (Automated)
Description: None
Levels:
Automated: no
No rules selected
4.2.9: Ensure sshd HostbasedAuthentication is disabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.2.10: Ensure sshd IgnoreRhosts is enabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.2.11: Ensure sshd KexAlgorithms is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.2.12: Ensure sshd LoginGraceTime is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.2.13: Ensure sshd LogLevel is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.2.14: Ensure sshd MACs are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.2.15: Ensure sshd MaxAuthTries is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.2.16: Ensure sshd MaxSessions is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.2.17: Ensure sshd MaxStartups is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.2.18: Ensure sshd PermitEmptyPasswords is disabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.2.19: Ensure sshd PermitRootLogin is disabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.2.20: Ensure sshd PermitUserEnvironment is disabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.2.21: Ensure sshd UsePAM is enabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.2.22: Ensure sshd crypto_policy is not set (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.3.1: Ensure sudo is installed (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.3.2: Ensure sudo commands use pty (Automated)
Description: None
Levels:
Automated: yes
Selections:
- sudo_add_use_pty: Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo use_pty
4.3.3: Ensure sudo log file exists (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.3.4: Ensure users must provide password for escalation (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.3.5: Ensure re-authentication for privilege escalation is not disabled globally (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.3.6: Ensure sudo authentication timeout is configured correctly (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.3.7: Ensure access to the su command is restricted (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.4.1.1: Ensure latest version of pam is installed (Automated)
Description: None
Levels:
Automated: no
No rules selected
4.4.1.2: Ensure latest version of authselect is installed (Automated)
Description: None
Levels:
Automated: no
No rules selected
4.4.2.1: Ensure active authselect profile includes pam modules (Automated)
Description: None
Levels:
Automated: no
No rules selected
4.4.2.2: Ensure pam_faillock module is enabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.4.2.3: Ensure pam_pwquality module is enabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.4.2.4: Ensure pam_pwhistory module is enabled (Automated)
Description: None
Levels:
Automated: yes
No rules selected
4.4.2.5: Ensure pam_unix module is enabled (Automated)
Description: None
Levels:
Automated: no
No rules selected
4.4.3.1.1: Ensure password failed attempts lockout is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.4.3.1.2: Ensure password unlock time is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.4.3.1.3: Ensure password failed attempts lockout includes root account (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.4.3.2.1: Ensure password number of changed characters is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.4.3.2.2: Ensure password length is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.4.3.2.3: Ensure password complexity is configured (Manual)
Description: None
Levels:
Automated: yes
Selections:
4.4.3.2.4: Ensure password same consecutive characters is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.4.3.2.5: Ensure password maximum sequential characters is configured (Automated)
Description: None
Levels:
Automated: no
No rules selected
4.4.3.2.6: Ensure password dictionary check is enabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.4.3.2.7: Ensure password quality is enforced for the root user (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.4.3.3.1: Ensure password history remember is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.4.3.3.2: Ensure password history is enforced for the root user (Automated)
Description: None
Levels:
Automated: no
No rules selected
4.4.3.3.3: Ensure pam_pwhistory includes use_authtok (Automated)
Description: None
Levels:
Automated: no
No rules selected
4.4.3.4.1: Ensure pam_unix does not include nullok (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.4.3.4.2: Ensure pam_unix does not include remember (Automated)
Description: None
Levels:
Automated: no
No rules selected
4.4.3.4.3: Ensure pam_unix includes a strong password hashing algorithm (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.4.3.4.4: Ensure pam_unix includes use_authtok (Automated)
Description: None
Levels:
Automated: no
No rules selected
4.5.1.1: Ensure strong password hashing algorithm is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.5.1.2: Ensure password expiration is 365 days or less (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.5.1.3: Ensure password expiration warning days is 7 or more (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.5.1.4: Ensure inactive password lock is 30 days or less (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.5.1.5: Ensure all users last password change date is in the past (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.5.2.1: Ensure default group for the root account is GID 0 (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.5.2.2: Ensure root user umask is configured (Automated)
Description: None
Levels:
Automated: no
No rules selected
4.5.2.3: Ensure system accounts are secured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.5.2.4: Ensure root password is set (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.5.3.1: Ensure nologin is not listed in /etc/shells (Automated)
Description: None
Levels:
Automated: no
No rules selected
4.5.3.2: Ensure default user shell timeout is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
4.5.3.3: Ensure default user umask is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.1.1.1: Ensure rsyslog is installed (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.1.1.2: Ensure rsyslog service is enabled (Manual)
Description: None
Levels:
Automated: yes
Selections:
5.1.1.3: Ensure journald is configured to send logs to rsyslog (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.1.1.4: Ensure rsyslog default file permissions are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.1.1.5: Ensure logging is configured (Manual)
Description: None
Levels:
Automated: no
No rules selected
5.1.1.6: Ensure rsyslog is configured to send logs to a remote log host (Manual)
Description: None
Levels:
Automated: no
No rules selected
5.1.1.7: Ensure rsyslog is not configured to recieve logs from a remote client (Automated)
Description: None
Levels:
Automated: yes
Selections:
- rsyslog_nolisten: Ensure rsyslog Does Not Accept Remote Messages Unless Acting As Log Server
5.1.2.1.1: Ensure systemd-journal-remote is installed (Manual)
Description: None
Levels:
Automated: no
No rules selected
5.1.2.1.2: Ensure systemd-journal-remote is configured (Manual)
Description: None
Levels:
Automated: no
No rules selected
5.1.2.1.3: Ensure systemd-journal-remote is enabled (Manual)
Description: None
Levels:
Automated: no
No rules selected
5.1.2.1.4: Ensure journald is not configured to recieve logs from a remote client (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.1.2.2: Ensure journald service is enabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.1.2.3: Ensure journald is configured to compress large log files (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.1.2.4: Ensure journald is configured to write logfiles to persistent disk (Automated)
Description: None
Levels:
Automated: yes
Selections:
- journald_storage: Ensure journald is configured to write log files to persistent disk
5.1.2.5: Ensure journald is not configured to send logs to rsyslog (Manual)
Description: None
Levels:
Automated: no
No rules selected
5.1.2.6: Ensure journald log rotation is configured per site policy (Manual)
Description: None
Levels:
Automated: no
No rules selected
5.1.3: Ensure logrotate is configured (Manual)
Description: None
Levels:
Automated: no
No rules selected
5.1.4: Ensure all logfiles have appropriate access configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.1.1: Ensure audit is installed (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.1.2: Ensure auditing for processes that start prior to auditd is enabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.1.3: Ensure audit_backlog_limit is sufficient (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.1.4: Ensure auditd service is enabled (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.2.1: Ensure audit log storage size is configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.2.2: Ensure audit logs are not automatically deleted (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.2.3: Ensure system is disabled when audit logs are full (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.2.4: Ensure system warns when audit logs are low on space (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.3.1: Ensure changes to system administration scope (sudoers) is collected (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.3.2: Ensure actions as another user are always logged (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.3.3: Ensure events that modify the sudo log file are collected (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.3.4: Ensure events that modify date and time information are collected (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.3.5: Ensure events that modify the system's network environment are collected (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.3.6: Ensure use of privileged commands are collected (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.3.7: Ensure unsuccessful file access attempts are collected (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.3.8: Ensure events that modify user/group information are collected (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.3.9: Ensure discretionary access control permission modification events are collected (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.3.10: Ensure successful file system mounts are collected (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.3.11: Ensure session initiation information is collected (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.3.12: Ensure login and logout events are collected (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.3.13: Ensure file deletion events by users are collected (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.3.14: Ensure events that modify the system's Mandatory Access Controls are collected (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.3.15: Ensure successful and unsuccessful attempts to use the chcon command are recorded (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.3.16: Ensure successful and unsuccessful attempts to use the setfacl command are recorded (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.3.17: Ensure successful and unsuccessful attempts to use the chacl command are recorded (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.3.18: Ensure successful and unsuccessful attempts to use the usermod command are recorded (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.3.19: Ensure kernel module loading, unloading and modification is collected (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.3.20: Ensure the audit configuration is immutable (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.3.21: Ensure the running and on disk configuration is the same (Manual)
Description: None
Levels:
Automated: no
No rules selected
5.2.4.1: Ensure the audit log directory is 0750 or more restrictive (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.4.2: Ensure audit log files are mode 0640 or less permissive (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.4.3: Ensure only authorized users own audit log files (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.4.4: Ensure only authorized groups are assigned ownership of audit log files (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.4.5: Ensure audit configuration files are 640 or more restrictive (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.4.6: Ensure audit configuration files are owned by root (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.4.7: Ensure audit configuration files belong to group root (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.4.8: Ensure audit tools are 755 or more restrictive (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.4.9: Ensure audit tools are owned by root (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.2.4.10: Ensure audit tools belong to group root (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.3.1: Ensure AIDE is installed (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.3.2: Ensure filesystem integrity is regularly checked (Automated)
Description: None
Levels:
Automated: yes
Selections:
5.3.3: Ensure cryptographic mechanisms are used to protect the integrity of audit tools (Automated)
Description: None
Levels:
Automated: yes
Selections:
6.1.1: Ensure permissions on /etc/passwd are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
6.1.2: Ensure permissions on /etc/passwd- are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
6.1.3: Ensure permissions on /etc/security/opasswd are configured (Automated)
Description: None
Levels:
Automated: no
Selections:
6.1.4: Ensure permissions on /etc/group are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
6.1.5: Ensure permissions on /etc/group- are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
6.1.6: Ensure permissions on /etc/shadow are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
6.1.7: Ensure permissions on /etc/shadow- are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
6.1.8: Ensure permissions on /etc/gshadow are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
6.1.9: Ensure permissions on /etc/gshadow- are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
6.1.10: Ensure permissions on /etc/shells are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
6.1.11: Ensure world writable files and directories are secured (Automated)
Description: None
Levels:
Automated: yes
Selections:
6.1.12: Ensure no unowned or ungrouped files or directories exist (Automated)
Description: None
Levels:
Automated: no
Selections:
6.1.13: Ensure SUID and SGID files are reviewed (Manual)
Description: None
Levels:
Automated: no
No rules selected
6.1.14: Audit system file permissions (Manual)
Description: None
Levels:
Automated: no
No rules selected
6.2.1: Ensure accounts in /etc/passwd use shadowed passwords (Automated)
Description: None
Levels:
Automated: yes
Selections:
6.2.2: Ensure /etc/shadow password fields are not empty (Automated)
Description: None
Levels:
Automated: yes
Selections:
6.2.3: Ensure all groups in /etc/passwd exist in /etc/group (Automated)
Description: None
Levels:
Automated: yes
Selections:
6.2.4: Ensure no duplicate UIDs exist (Automated)
Description: None
Levels:
Automated: yes
Selections:
6.2.5: Ensure no duplicate GIDs exist (Automated)
Description: None
Levels:
Automated: yes
Selections:
6.2.6: Ensure no duplicate user names exist (Automated)
Description: None
Levels:
Automated: yes
Selections:
6.2.7: Ensure no duplicate group names exist (Automated)
Description: None
Levels:
Automated: yes
Selections:
6.2.8: Ensure root path integrity (Automated)
Description: None
Levels:
Automated: yes
Selections:
6.2.9: Ensure root is the only UID 0 account (Automated)
Description: None
Levels:
Automated: yes
Selections:
6.2.10: Ensure local interactive user home directories are configured (Automated)
Description: None
Levels:
Automated: yes
Selections:
6.2.11: Ensure local interactive user dot files access is configured (Automated)
Description: None
Levels:
Automated: no
Selections: