CIS MongoDB 4 L1 OS Linux v1.0.0

Audit Details

Name: CIS MongoDB 4 L1 OS Linux v1.0.0

Updated: 12/8/2023

Authority: CIS

Plugin: Unix

Revision: 1.12

Estimated Item Count: 17

File Details

Filename: CIS_MongoDB_4_Benchmark_Level_1_OS_Linux_v1.0.0.audit

Size: 60.7 kB

MD5: ef99f12ea0e28471e542b7fe1e79d3e8
SHA256: 3dc370ec7db9c16c9913704f786e566af8703e753835f8da5c60d0523f2e11a0

Audit Items

DescriptionCategories
2.1 Ensure Authentication is configured

IDENTIFICATION AND AUTHENTICATION

2.2 Ensure that MongoDB does not bypass authentication via the localhost exception

IDENTIFICATION AND AUTHENTICATION

2.3 Ensure authentication is enabled in the sharded cluster - authenticationMechanisms

CONFIGURATION MANAGEMENT

2.3 Ensure authentication is enabled in the sharded cluster - CAFile

CONFIGURATION MANAGEMENT

2.3 Ensure authentication is enabled in the sharded cluster - clusterAuthMode

CONFIGURATION MANAGEMENT

2.3 Ensure authentication is enabled in the sharded cluster - clusterFile

CONFIGURATION MANAGEMENT

2.3 Ensure authentication is enabled in the sharded cluster - PEMKeyFile

CONFIGURATION MANAGEMENT

3.3 Ensure that MongoDB is run using a non-privileged, dedicated service account

ACCESS CONTROL

4.2 Ensure Weak Protocols are Disabled

SYSTEM AND COMMUNICATIONS PROTECTION

4.3 Ensure Encryption of Data in Transit TLS or SSL (Transport Encryption)

SYSTEM AND COMMUNICATIONS PROTECTION

5.1 Ensure that system activity is audited

AUDIT AND ACCOUNTABILITY

6.1 Ensure that MongoDB uses a non-default port

SYSTEM AND INFORMATION INTEGRITY

7.1 Ensure appropriate key file permissions are set - CAFile

IDENTIFICATION AND AUTHENTICATION

7.1 Ensure appropriate key file permissions are set - keyFile

IDENTIFICATION AND AUTHENTICATION

7.1 Ensure appropriate key file permissions are set - PEMKeyFile

IDENTIFICATION AND AUTHENTICATION

7.2 Ensure appropriate database file permissions are set.

ACCESS CONTROL

CIS_MongoDB_4_Benchmark_Level_1_OS_Linux_v1.0.0.audit from CIS MongoDB 4 Benchmark