CIS PostgreSQL 11 DB v1.0.0

Audit Details

Name: CIS PostgreSQL 11 DB v1.0.0

Updated: 6/27/2023

Authority: CIS

Plugin: PostgreSQLDB

Revision: 1.0

Estimated Item Count: 46

File Details

Filename: CIS_PostgreSQL_11_v1.0.0_L1_Database.audit

Size: 156 kB

MD5: 55c2fa3db222bbabccb10f115ad95ff4
SHA256: 164d08a6b5c27673335f4b9df254a8fca1a1b5c884087ad231d7716edae5a971

Audit Items

DescriptionCategories
3.1.2 Ensure the log destinations are set correctly

AUDIT AND ACCOUNTABILITY

3.1.3 Ensure the logging collector is enabled

AUDIT AND ACCOUNTABILITY

3.1.4 Ensure the log file destination directory is set correctly

AUDIT AND ACCOUNTABILITY

3.1.5 Ensure the filename pattern for log files is set correctly

AUDIT AND ACCOUNTABILITY

3.1.6 Ensure the log file permissions are set correctly

ACCESS CONTROL

3.1.7 Ensure 'log_truncate_on_rotation' is enabled

AUDIT AND ACCOUNTABILITY

3.1.8 Ensure the maximum log file lifetime is set correctly

AUDIT AND ACCOUNTABILITY

3.1.9 Ensure the maximum log file size is set correctly

AUDIT AND ACCOUNTABILITY

3.1.10 Ensure the correct syslog facility is selected

AUDIT AND ACCOUNTABILITY

3.1.11 Ensure the program name for PostgreSQL syslog messages is correct

AUDIT AND ACCOUNTABILITY

3.1.12 Ensure the correct messages are written to the server log

AUDIT AND ACCOUNTABILITY

3.1.13 Ensure the correct SQL statements generating errors are recorded

AUDIT AND ACCOUNTABILITY

3.1.14 Ensure 'debug_print_parse' is disabled

CONFIGURATION MANAGEMENT

3.1.15 Ensure 'debug_print_rewritten' is disabled

CONFIGURATION MANAGEMENT

3.1.16 Ensure 'debug_print_plan' is disabled

CONFIGURATION MANAGEMENT

3.1.17 Ensure 'debug_pretty_print' is enabled

AUDIT AND ACCOUNTABILITY

3.1.18 Ensure 'log_connections' is enabled

AUDIT AND ACCOUNTABILITY

3.1.19 Ensure 'log_disconnections' is enabled

AUDIT AND ACCOUNTABILITY

3.1.20 Ensure 'log_error_verbosity' is set correctly

AUDIT AND ACCOUNTABILITY

3.1.21 Ensure 'log_hostname' is set correctly

CONFIGURATION MANAGEMENT

3.1.22 Ensure 'log_line_prefix' is set correctly

AUDIT AND ACCOUNTABILITY

3.1.23 Ensure 'log_statement' is set correctly

AUDIT AND ACCOUNTABILITY

3.1.24 Ensure 'log_timezone' is set correctly

AUDIT AND ACCOUNTABILITY

3.2 Ensure the PostgreSQL Audit Extension (pgAudit) is enabled - audit.log

AUDIT AND ACCOUNTABILITY

3.2 Ensure the PostgreSQL Audit Extension (pgAudit) is enabled - pgaudit installed

AUDIT AND ACCOUNTABILITY

4.2 Ensure excessive administrative privileges are revoked

CONFIGURATION MANAGEMENT

4.4 Ensure excessive DML privileges are revoked

CONFIGURATION MANAGEMENT

4.5 Use pg_permission extension to audit object permissions

CONFIGURATION MANAGEMENT

4.6 Ensure Row Level Security (RLS) is configured correctly

ACCESS CONTROL

4.7 Ensure the set_user extension is installed

ACCESS CONTROL

4.8 Make use of default roles

CONFIGURATION MANAGEMENT

6.1 Ensure 'Attack Vectors' Runtime Parameters are Configured

CONFIGURATION MANAGEMENT

6.2 Ensure 'backend' runtime parameters are configured correctly

CONFIGURATION MANAGEMENT

6.3 Ensure 'Postmaster' Runtime Parameters are Configured

CONFIGURATION MANAGEMENT

6.4 Ensure 'SIGHUP' Runtime Parameters are Configured

CONFIGURATION MANAGEMENT

6.5 Ensure 'Superuser' Runtime Parameters are Configured

CONFIGURATION MANAGEMENT

6.6 Ensure 'User' Runtime Parameters are Configured

CONFIGURATION MANAGEMENT

6.8 Ensure SSL is enabled and configured correctly

SYSTEM AND COMMUNICATIONS PROTECTION

6.9 Ensure the pgcrypto extension is installed and configured correctly

SYSTEM AND COMMUNICATIONS PROTECTION

7.1 Ensure a replication-only user is created and used for streaming replication

ACCESS CONTROL

7.2 Ensure base backups are configured and functional

CONTINGENCY PLANNING

7.4 Ensure streaming replication parameters are configured correctly

SYSTEM AND COMMUNICATIONS PROTECTION

8.1 Ensure PostgreSQL configuration files are outside the data cluster

CONFIGURATION MANAGEMENT

8.2 Ensure PostgreSQL subdirectory locations are outside the data cluster

CONFIGURATION MANAGEMENT

8.4 Ensure miscellaneous configuration settings are correct

CONFIGURATION MANAGEMENT

CIS_PostgreSQL_11_v1.0.0_L1_DB.audit from CIS PostgreSQL 12 Benchmark v1.0.0