CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG

Audit Details

Name: CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG

Updated: 10/3/2023

Authority: CIS

Plugin: Unix

Revision: 1.14

Estimated Item Count: 354

File Details

Filename: CIS_Red_Hat_EL7_STIG_v2.0.0_STIG.audit

Size: 1.14 MB

MD5: 2386574a5f2026ab29465418307d86a5
SHA256: 0bccb3378985f5ef3d07db1435d7b5929d54d08896d66687c29600954396c2c2

Audit Changelog

 
Revision 1.14

Oct 3, 2023

Functional Update
  • 1.11 Ensure anti-virus is installed and running
Revision 1.13

Sep 19, 2023

Functional Update
  • 1.1.26 Ensure all world-writable directories are group-owned.
  • 1.4.4 Ensure boot loader does not allow removable media
  • 1.6.1.10 Ensure system device files are labeled - device_t
  • 1.6.1.10 Ensure system device files are labeled - unlabeled_t
  • 5.3.36 Ensure no '.shosts' files exist on the system - .shosts files exist on the system
  • 5.3.37 Ensure no 'shosts.equiv' files exist on the system - shosts.equiv files exist on the system
  • 6.1.10 Ensure no world writable files exist
  • 6.1.11 Ensure no unowned files or directories exist
  • 6.1.12 Ensure no ungrouped files or directories exist
  • 6.1.16 Ensure all world-writable directories are owned by root, sys, bin, or an application User Identifier
  • 6.2.20 Ensure that all files and directories contained in local interactive user home directories are owned by the user
  • 6.2.21 Ensure local interactive user is a member of the group owner.
  • 6.2.22 Ensure users' files and directories within the home directory permissions are 750 or more restrictive
Miscellaneous
  • Metadata updated.
  • References updated.
  • Variables updated.
Revision 1.12

Jul 20, 2023

Functional Update
  • 6.2.12 Ensure users own their home directories
Revision 1.11

May 19, 2023

Functional Update
  • 1.8.18 Ensure graphical user interface automounter is disabled - automount
  • 1.8.18 Ensure graphical user interface automounter is disabled - automount-open
  • 1.8.18 Ensure graphical user interface automounter is disabled - automount=false
  • 1.8.18 Ensure graphical user interface automounter is disabled - autorun-never
  • 1.8.18 Ensure graphical user interface automounter is disabled - autorun-never=true
Revision 1.10

Apr 12, 2023

Functional Update
  • 5.4.1 Ensure password creation requirements are configured - dcredit
  • 5.4.1 Ensure password creation requirements are configured - lcredit
  • 5.4.1 Ensure password creation requirements are configured - ocredit
  • 5.4.1 Ensure password creation requirements are configured - ucredit
  • 5.4.7 Ensure minimum and maximum requirements are set for password changes - difok
  • 5.4.7 Ensure minimum and maximum requirements are set for password changes - maxclassrepeat
  • 5.4.7 Ensure minimum and maximum requirements are set for password changes - maxrepeat
  • 5.4.7 Ensure minimum and maximum requirements are set for password changes - minclass
  • 5.4.7 Ensure minimum and maximum requirements are set for password changes - minlen
  • 5.5.1.10 Ensure delay between logon prompts on failure
  • 5.5.1.2 Ensure minimum days between password changes is configured - login.defs
  • 5.5.1.6 Ensure shadow file is configured to use only encrypted representations of passwords
  • 5.5.1.7 Ensure password expiration is 60 Day maximum for new users
  • 5.5.10 Ensure upon user creation a home directory is assigned.
  • 5.5.8 Ensure Default user umask is 077
Miscellaneous
  • Metadata updated.
  • Platform check updated.
  • Variables updated.
Revision 1.9

Apr 3, 2023

Functional Update
  • 1.4.5 Ensure version 7.2 or newer booted with a BIOS have a unique name for the grub superusers account
  • 1.8.18 Ensure graphical user interface automounter is disabled - automount
  • 1.8.18 Ensure graphical user interface automounter is disabled - automount-open
  • 1.8.18 Ensure graphical user interface automounter is disabled - automount-open=false
  • 1.8.18 Ensure graphical user interface automounter is disabled - automount=false
  • 1.8.18 Ensure graphical user interface automounter is disabled - autorun-never
  • 1.8.18 Ensure graphical user interface automounter is disabled - autorun-never=true
  • 6.2.13 Ensure users' home directories permissions are 750 or more restrictive
Revision 1.8

Mar 20, 2023

Functional Update
  • 5.3.10 Ensure SSH IgnoreRhosts is enabled
Revision 1.7

Mar 7, 2023

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.6

Jan 4, 2023

Functional Update
  • 1.12 Ensure host-based intrusion detection tool is used - mcafeetp package
  • 1.5.8 Ensure DNS is servers are configured - nameserver 1
  • 1.5.8 Ensure DNS is servers are configured - nameserver 2
  • 5.2.7 Ensure sudo authentication timeout is configured - sudo command.
  • 5.2.8 Ensure users password required for privilege escalation when using sudo - rootpw
  • 5.2.8 Ensure users password required for privilege escalation when using sudo - runaspw
  • 5.2.8 Ensure users password required for privilege escalation when using sudo - targetpw
  • 5.3.28 Ensure SSH IgnoreUserKnownHosts is enabled
  • 5.3.30 Ensure SSH does not permit GSSAPI - GSSAPI authentication unless needed.
  • 5.3.32 Ensure SSH performs checks of home directory configuration files
Miscellaneous
  • Metadata updated.
Revision 1.5

Dec 7, 2022

Miscellaneous
  • Variables updated.