CIS Red Hat EL8 Server L1 v2.0.0

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS Red Hat EL8 Server L1 v2.0.0

Updated: 2/27/2024

Authority: CIS

Plugin: Unix

Revision: 1.32

Estimated Item Count: 329

File Details

Filename: CIS_Red_Hat_EL8_Server_v2.0.0_L1.audit

Size: 723 kB

MD5: befa0190ff4e77134bf05e83ea927a61
SHA256: c3d022fc082f50e0693def77e062b99054bcb20fd378e52803dfe1144c423044

Audit Items

DescriptionCategories
1.1.1.1 Ensure mounting of cramfs filesystems is disabled - blacklist
1.1.1.1 Ensure mounting of cramfs filesystems is disabled - lsmod
1.1.1.1 Ensure mounting of cramfs filesystems is disabled - modprobe
1.1.2.1 Ensure /tmp is a separate partition - config check
1.1.2.1 Ensure /tmp is a separate partition - mount check
1.1.2.2 Ensure nodev option set on /tmp partition
1.1.2.3 Ensure noexec option set on /tmp partition
1.1.2.4 Ensure nosuid option set on /tmp partition
1.1.3.2 Ensure nodev option set on /var partition
1.1.3.3 Ensure noexec option set on /var partition
1.1.3.4 Ensure nosuid option set on /var partition
1.1.4.2 Ensure noexec option set on /var/tmp partition
1.1.4.3 Ensure nosuid option set on /var/tmp partition
1.1.4.4 Ensure nodev option set on /var/tmp partition
1.1.5.2 Ensure nodev option set on /var/log partition
1.1.5.3 Ensure noexec option set on /var/log partition
1.1.5.4 Ensure nosuid option set on /var/log partition
1.1.6.2 Ensure noexec option set on /var/log/audit partition
1.1.6.3 Ensure nodev option set on /var/log/audit partition
1.1.6.4 Ensure nosuid option set on /var/log/audit partition
1.1.7.2 Ensure nodev option set on /home partition
1.1.7.3 Ensure nosuid option set on /home partition
1.1.7.4 Ensure usrquota option set on /home partition
1.1.7.5 Ensure grpquota option set on /home partition
1.1.8.1 Ensure nodev option set on /dev/shm partition
1.1.8.2 Ensure noexec option set on /dev/shm partition
1.1.8.3 Ensure nosuid option set on /dev/shm partition
1.1.9 Disable Automounting
1.1.10 Disable USB Storage - lsmod
1.1.10 Disable USB Storage - modprobe
1.2.1 Ensure Red Hat Subscription Manager connection is configured
1.2.2 Ensure GPG keys are configured - gpgkey
1.2.2 Ensure GPG keys are configured - show rpm keys
1.2.3 Ensure gpgcheck is globally activated - /etc/yum.repos.d/*
1.2.3 Ensure gpgcheck is globally activated - dnf.conf
1.2.4 Ensure package manager repositories are configured
1.3.1 Ensure AIDE is installed
1.3.2 Ensure filesystem integrity is regularly checked - cron
1.3.2 Ensure filesystem integrity is regularly checked - systemctl is-enabled aidecheck.service
1.3.2 Ensure filesystem integrity is regularly checked - systemctl is-enabled aidecheck.timer
1.3.2 Ensure filesystem integrity is regularly checked - systemctl status aidecheck.timer
1.4.1 Ensure bootloader password is set
1.4.2 Ensure permissions on bootloader config are configured
1.4.3 Ensure authentication is required when booting into rescue mode
1.5.1 Ensure core dump storage is disabled
1.5.2 Ensure core dump backtraces are disabled
1.5.3 Ensure address space layout randomization (ASLR) is enabled - /etc/sysctl.d/*
1.6.1.1 Ensure SELinux is installed
1.6.1.2 Ensure SELinux is not disabled in bootloader configuration
1.6.1.3 Ensure SELinux policy is configured - /etc/selinux/config