1.1.1 Ensure mounting of squashfs filesystems is disabled - lsmod | CONFIGURATION MANAGEMENT |
1.1.1 Ensure mounting of squashfs filesystems is disabled - modprobe | CONFIGURATION MANAGEMENT |
1.1.2 Ensure /tmp is configured | CONFIGURATION MANAGEMENT |
1.1.3 Ensure nodev option set on /tmp partition | CONFIGURATION MANAGEMENT |
1.1.4 Ensure nosuid option set on /tmp partition | CONFIGURATION MANAGEMENT |
1.1.5 Ensure noexec option set on /tmp partition | CONFIGURATION MANAGEMENT |
1.1.8 Ensure nodev option set on /var/tmp partition | CONFIGURATION MANAGEMENT |
1.1.9 Ensure nosuid option set on /var/tmp partition | CONFIGURATION MANAGEMENT |
1.1.10 Ensure noexec option set on /var/tmp partition | CONFIGURATION MANAGEMENT |
1.1.14 Ensure nodev option set on /home partition | CONFIGURATION MANAGEMENT |
1.1.15 Ensure nodev option set on /dev/shm partition | CONFIGURATION MANAGEMENT |
1.1.16 Ensure nosuid option set on /dev/shm partition | CONFIGURATION MANAGEMENT |
1.1.17 Ensure noexec option set on /dev/shm partition | CONFIGURATION MANAGEMENT |
1.1.18 Ensure sticky bit is set on all world-writable directories | CONFIGURATION MANAGEMENT |
1.1.19 Disable Automounting | CONFIGURATION MANAGEMENT |
1.2.1 Ensure package manager repositories are configured | SYSTEM AND INFORMATION INTEGRITY |
1.2.2 Ensure GPG keys are configured | SYSTEM AND INFORMATION INTEGRITY |
1.2.3 Ensure gpgcheck is globally activated | SYSTEM AND INFORMATION INTEGRITY |
1.3.1 Ensure AIDE is installed | AUDIT AND ACCOUNTABILITY |
1.3.2 Ensure filesystem integrity is regularly checked | AUDIT AND ACCOUNTABILITY |
1.4.1 Ensure permissions on bootloader config are configured | CONFIGURATION MANAGEMENT |
1.4.2 Ensure authentication required for single user mode - emergency.service | CONFIGURATION MANAGEMENT |
1.4.2 Ensure authentication required for single user mode - rescue.service | CONFIGURATION MANAGEMENT |
1.5.1 Ensure core dumps are restricted - fs.suid_dumpable (sysctl.conf/sysctl.d) | CONFIGURATION MANAGEMENT |
1.5.1 Ensure core dumps are restricted - hard core (limits.conf/limits.d) | CONFIGURATION MANAGEMENT |
1.5.1 Ensure core dumps are restricted - sysctl | CONFIGURATION MANAGEMENT |
1.5.2 Ensure address space layout randomization (ASLR) is enabled - sysctl | CONFIGURATION MANAGEMENT |
1.5.2 Ensure address space layout randomization (ASLR) is enabled - sysctl.conf/sysctl.d | CONFIGURATION MANAGEMENT |
1.5.3 Ensure prelink is disabled | AUDIT AND ACCOUNTABILITY |
1.7.1.1 Ensure message of the day is configured properly - banner text | CONFIGURATION MANAGEMENT |
1.7.1.1 Ensure message of the day is configured properly - msrv | CONFIGURATION MANAGEMENT |
1.7.1.2 Ensure local login warning banner is configured properly - banner check | CONFIGURATION MANAGEMENT |
1.7.1.2 Ensure local login warning banner is configured properly - msrv | CONFIGURATION MANAGEMENT |
1.7.1.3 Ensure remote login warning banner is configured properly - banner check | CONFIGURATION MANAGEMENT |
1.7.1.3 Ensure remote login warning banner is configured properly - msrv | CONFIGURATION MANAGEMENT |
1.7.1.4 Ensure permissions on /etc/motd are configured | CONFIGURATION MANAGEMENT |
1.7.1.5 Ensure permissions on /etc/issue are configured | CONFIGURATION MANAGEMENT |
1.7.1.6 Ensure permissions on /etc/issue.net are configured | CONFIGURATION MANAGEMENT |
1.8 Ensure updates, patches, and additional security software are installed | SYSTEM AND INFORMATION INTEGRITY |
2.1.1.1 Ensure time synchronization is in use | AUDIT AND ACCOUNTABILITY |
2.1.1.2 Ensure ntp is configured - -u ntp:ntp | AUDIT AND ACCOUNTABILITY |
2.1.1.2 Ensure ntp is configured - NTP server/pool | AUDIT AND ACCOUNTABILITY |
2.1.1.2 Ensure ntp is configured - restrict -4 | AUDIT AND ACCOUNTABILITY |
2.1.1.2 Ensure ntp is configured - restrict -6 | AUDIT AND ACCOUNTABILITY |
2.1.1.3 Ensure chrony is configured - chrony server/pool | AUDIT AND ACCOUNTABILITY |
2.1.1.3 Ensure chrony is configured - OPTIONS | AUDIT AND ACCOUNTABILITY |
2.1.2 Ensure X Window System is not installed | CONFIGURATION MANAGEMENT |
2.1.3 Ensure Avahi Server is not enabled | CONFIGURATION MANAGEMENT |
2.1.4 Ensure CUPS is not enabled | CONFIGURATION MANAGEMENT |
2.1.5 Ensure DHCP Server is not enabled | CONFIGURATION MANAGEMENT |