CIS Amazon Linux 2 STIG v1.0.0 L3

Audit Details

Name: CIS Amazon Linux 2 STIG v1.0.0 L3

Updated: 4/24/2024

Authority: CIS

Plugin: Unix

Revision: 1.19

Estimated Item Count: 168

File Details

Filename: CIS_Amazon_Linux_2_STIG_v1.0.0_L3.audit

Size: 471 kB

MD5: 8a670ce80060eb0d1a9047548fce6502
SHA256: dfd22f721b837eb681aae838eb133a5188662da72a75e0a7b2d0437810b2a854

Audit Changelog

 
Revision 1.19

Apr 24, 2024

Functional Update
  • 4.5 Ensure system notification is sent out when voume is 75% full
Miscellaneous
  • Metadata updated.
Revision 1.18

Apr 3, 2024

Miscellaneous
  • Metadata updated.
  • Platform check updated.
Revision 1.17

Oct 3, 2023

Functional Update
  • 1.9 Ensure anti-virus is installed and running
Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.16

May 30, 2023

Functional Update
  • 4.8 Enure off-load of audit logs - path
  • 4.8 Enure off-load of audit logs - type
Revision 1.15

May 2, 2023

Functional Update
  • 5.4.1.9 Ensure password expiration is 60 Day maximum for exisiting passwords
Miscellaneous
  • References updated.
Revision 1.14

Apr 12, 2023

Functional Update
  • 5.3.5 Ensure minimum and maximum requirements are set for password changes - difok
  • 5.3.5 Ensure minimum and maximum requirements are set for password changes - maxclassrepeat
  • 5.3.5 Ensure minimum and maximum requirements are set for password changes - maxrepeat
  • 5.3.5 Ensure minimum and maximum requirements are set for password changes - minclass
  • 5.3.5 Ensure minimum and maximum requirements are set for password changes - minlen
  • 5.4.1.10 Ensure delay between logon prompts on failure
  • 5.4.1.6 Ensure encrypted respresentation of passwords is set.
  • 5.4.1.8 Ensure password expiration is 60 Day maximum for new users
  • 5.4.8 Ensure Default user umask is 077
  • 6.2.28 Ensure upon user creation a home directory is assigned.
Miscellaneous
  • Metadata updated.
  • Platform check updated.
  • References updated.
  • Variables updated.
Revision 1.13

Mar 7, 2023

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.12

Jan 4, 2023

Functional Update
  • 1.5.7 Ensure DNS is servers are configured - nameserver 1
  • 1.5.7 Ensure DNS is servers are configured - nameserver 2
  • 5.2.25 Ensure SSH setting for 'IgnoreUserKnownHosts' is enabled - IgnoreUserKnownHosts is enabled.
  • 5.2.27 Ensure SSH does not permit GSSAPI
  • 5.2.29 Ensrue SSH performs checks of home directory configuration files.
Miscellaneous
  • Metadata updated.
  • References updated.
  • Variables updated.
Revision 1.11

Dec 7, 2022

Miscellaneous
  • Metadata updated.
Revision 1.10

Nov 14, 2022

Functional Update
  • 4.1.21 Ensure auditing of all privileged functions - setgid 32 bit
  • 4.1.21 Ensure auditing of all privileged functions - setgid 64 bit
  • 4.1.21 Ensure auditing of all privileged functions - setuid 32 bit
  • 4.1.21 Ensure auditing of all privileged functions - setuid 64 bit