Revision 1.12Oct 5, 2020
Functional Update
- 1.4.2 Ensure filesystem integrity is regularly checked
- 3.4.1.1 Ensure a Firewall package is installed
- 3.4.4.2.1 Ensure IPv6 default deny firewall policy - Chain FORWARD
- 3.4.4.2.1 Ensure IPv6 default deny firewall policy - Chain INPUT
- 3.4.4.2.1 Ensure IPv6 default deny firewall policy - Chain OUTPUT
- 3.4.4.2.2 Ensure IPv6 loopback traffic is configured - INPUT
- 3.4.4.2.2 Ensure IPv6 loopback traffic is configured - OUTPUT
- 3.4.4.2.3 Ensure IPv6 outbound and established connections are configured
- 3.4.4.2.4 Ensure IPv6 firewall rules exist for all open ports
- 4.2.1.1 Ensure rsyslog is installed
- 4.2.1.2 Ensure rsyslog Service is enabled
- 4.2.1.3 Ensure rsyslog default file permissions configured
- 4.2.1.4 Ensure logging is configured
- 4.2.1.5 Ensure rsyslog is configured to send logs to a remote log host
- 4.2.1.6 Ensure remote rsyslog messages are only accepted on designated log hosts. - InputTCPServerRun 514
- 4.2.1.6 Ensure remote rsyslog messages are only accepted on designated log hosts. - ModLoad imtcp
- 5.4.1 Ensure password creation requirements are configured - password complexity