CIS Amazon Linux 2 STIG v2.0.0 L2 Server

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS Amazon Linux 2 STIG v2.0.0 L2 Server

Updated: 6/9/2026

Authority: CIS

Plugin: Unix

Revision: 1.6

Estimated Item Count: 36

File Details

Filename: CIS_Amazon_Linux_2_STIG_v2.0.0_L2_Server.audit

Size: 227 kB

MD5: 3f79ad40b7dc02c3a32e0184e6306b65
SHA256: 66ce5b3f32593ccfd17f84be4e536bfaf138b6e9d63a3d8fe74cea3bc37b5cd9

Audit Items

DescriptionCategories
1.1.1.2 Ensure mounting of squashfs filesystems is disabled
1.1.10 Ensure separate partition exists for /var

CONFIGURATION MANAGEMENT

1.1.11 Ensure separate partition exists for /var/tmp
1.1.15 Ensure separate partition exists for /var/log
1.1.16 Ensure separate partition exists for /var/log/audit

CONFIGURATION MANAGEMENT

1.1.17 Ensure separate partition exists for /home
1.6.1.5 Ensure the SELinux mode is enforcing

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

3.1.1 Disable IPv6
3.4.1 Ensure DCCP is disabled

IDENTIFICATION AND AUTHENTICATION

3.4.2 Ensure SCTP is disabled
4.1.1.1 Ensure auditd is installed
4.1.1.2 Ensure auditd service is enabled and running

AUDIT AND ACCOUNTABILITY

4.1.1.3 Ensure auditing for processes that start prior to auditd is enabled
4.1.2.1 Ensure audit log storage size is configured
4.1.2.2 Ensure audit logs are not automatically deleted
4.1.2.5 Ensure system is disabled when audit logs are full

AUDIT AND ACCOUNTABILITY

4.1.2.7 Ensure audit_backlog_limit is sufficient
4.1.3.1 Ensure events that modify date and time information are collected
4.1.3.2 Ensure system administrator command executions (sudo) are collected
4.1.3.3 Ensure session initiation information is collected
4.1.3.4 Ensure events that modify the system's Mandatory Access Controls are collected
4.1.3.5 Ensure events that modify the system's network environment are collected
4.1.3.6 Ensure successful file system mounts are collected
4.1.3.7 Ensure kernel module loading and unloading is collected

AUDIT AND ACCOUNTABILITY

4.1.3.8 Ensure changes to system administration scope (sudoers) is collected

AUDIT AND ACCOUNTABILITY, MAINTENANCE

4.1.3.9 Ensure file deletion events by users are collected

AUDIT AND ACCOUNTABILITY, MAINTENANCE

4.1.3.10 Ensure use of privileged commands is collected

AUDIT AND ACCOUNTABILITY, MAINTENANCE

4.1.3.11 Ensure unsuccessful unauthorized file access attempts are collected

AUDIT AND ACCOUNTABILITY, MAINTENANCE

4.1.3.12 Ensure discretionary access control permission modification events are collected

AUDIT AND ACCOUNTABILITY

4.1.3.13 Ensure login and logout events are collected

AUDIT AND ACCOUNTABILITY, MAINTENANCE

4.1.3.14 Ensure events that modify user/group information are collected

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

4.1.3.41 Ensure the audit configuration is immutable
5.3.8 Ensure SSH X11 forwarding is disabled

CONFIGURATION MANAGEMENT

5.3.23 Ensure SSH AllowTcpForwarding is disabled
6.1.1 Audit system file permissions

CONFIGURATION MANAGEMENT

CIS_Amazon_Linux_2_STIG_v2.0.0_L2_Server.audit from CIS Amazon Linux 2 STIG v2.0.0