CIS Amazon Linux 2 STIG v2.0.0 L1 Workstation

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS Amazon Linux 2 STIG v2.0.0 L1 Workstation

Updated: 6/9/2026

Authority: CIS

Plugin: Unix

Revision: 1.4

Estimated Item Count: 201

File Details

Filename: CIS_Amazon_Linux_2_STIG_v2.0.0_L1_Workstation.audit

Size: 556 kB

MD5: a6cd1b637e2b8da15ecd0d6d655a6dc1
SHA256: 648b76bc55b00d0dd3c4c63daace553590a4c69848acb0e837d8809f520bc4e5

Audit Items

DescriptionCategories
1.1.1.1 Ensure mounting of cramfs filesystems is disabled
1.1.1.3 Ensure mounting of udf filesystems is disabled
1.1.2 Ensure /tmp is configured

CONFIGURATION MANAGEMENT

1.1.3 Ensure noexec option set on /tmp partition
1.1.4 Ensure nodev option set on /tmp partition
1.1.5 Ensure nosuid option set on /tmp partition
1.1.6 Ensure /dev/shm is configured
1.1.7 Ensure noexec option set on /dev/shm partition

CONFIGURATION MANAGEMENT

1.1.8 Ensure nodev option set on /dev/shm partition

CONFIGURATION MANAGEMENT

1.1.9 Ensure nosuid option set on /dev/shm partition

CONFIGURATION MANAGEMENT

1.1.12 Ensure /var/tmp partition includes the noexec option
1.1.13 Ensure /var/tmp partition includes the nodev option
1.1.14 Ensure /var/tmp partition includes the nosuid option
1.1.18 Ensure /home partition includes the nodev option
1.1.20 Ensure removable media partitions include noexec option
1.1.21 Ensure nodev option set on removable media partitions
1.1.22 Ensure nosuid option set on removable media partitions

CONFIGURATION MANAGEMENT

1.1.25 Ensure sticky bit is set on all world-writable directories
1.2.1 Ensure GPG keys are configured
1.2.2 Ensure package manager repositories are configured
1.2.3 Ensure gpgcheck is globally activated

CONFIGURATION MANAGEMENT

1.3.1 Ensure AIDE is installed

CONFIGURATION MANAGEMENT

1.3.2 Ensure filesystem integrity is regularly checked

CONFIGURATION MANAGEMENT

1.4.2 Ensure permissions on bootloader config are configured
1.4.3 Ensure authentication required for single user mode

ACCESS CONTROL

1.5.1 Ensure core dumps are restricted
1.5.2 Ensure XD/NX support is enabled
1.5.3 Ensure address space layout randomization (ASLR) is enabled

CONFIGURATION MANAGEMENT

1.5.4 Ensure prelink is not installed
1.6.1.1 Ensure SELinux is installed
1.6.1.2 Ensure SELinux is not disabled in bootloader configuration
1.6.1.3 Ensure SELinux policy is configured

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

1.6.1.4 Ensure the SELinux mode is enforcing or permissive
1.6.1.6 Ensure no unconfined services exist
1.6.1.8 Ensure the MCS Translation Service (mcstrans) is not installed
1.7.1 Ensure message of the day is configured properly
1.7.2 Ensure local login warning banner is configured properly
1.7.4 Ensure remote login warning banner is configured properly
1.7.5 Ensure permissions on /etc/motd are configured
1.7.6 Ensure permissions on /etc/issue are configured
1.7.7 Ensure permissions on /etc/issue.net are configured
1.9 Ensure updates, patches, and additional security software are installed

CONFIGURATION MANAGEMENT

2.1.1 Ensure xinetd is not installed
2.2.1.1 Ensure time synchronization is in use
2.2.1.2 Ensure chrony is configured
2.2.1.3 Ensure ntp is configured
2.2.5 Ensure DHCP Server is not installed
2.2.6 Ensure LDAP server is not installed
2.2.7 Ensure DNS Server is not installed
2.2.8 Ensure FTP Server is not installed

CONFIGURATION MANAGEMENT