Revision 1.24Jul 14, 2021
Functional Update
- 1.1.10 Ensure noexec option set on /var/tmp partition
- 1.1.14 Ensure nodev option set on /home partition
- 1.1.15 Ensure nodev option set on /dev/shm partition
- 1.1.16 Ensure nosuid option set on /dev/shm partition
- 1.1.17 Ensure noexec option set on /dev/shm partition
- 1.1.3 Ensure nodev option set on /tmp partition
- 1.1.4 Ensure nosuid option set on /tmp partition
- 1.1.5 Ensure noexec option set on /tmp partition
- 1.1.8 Ensure nodev option set on /var/tmp partition
- 1.1.9 Ensure nosuid option set on /var/tmp partition
- 3.4.4.2.2 Ensure IPv6 loopback traffic is configured
- 3.4.4.2.3 Ensure IPv6 outbound and established connections are configured
- 3.4.4.2.4 Ensure IPv6 firewall rules exist for all open ports - firewall rules
- 3.4.4.2.4 Ensure IPv6 firewall rules exist for all open ports - ports
- 4.2.1.5 Ensure rsyslog is configured to send logs to a remote log host
- 4.2.1.6 Ensure remote rsyslog messages are only accepted on designated log hosts. - InputTCPServerRun
- 4.2.1.6 Ensure remote rsyslog messages are only accepted on designated log hosts. - ModLoad imtcp
Informational Update
- 3.4.4.2.2 Ensure IPv6 loopback traffic is configured
- 3.4.4.2.3 Ensure IPv6 outbound and established connections are configured
- 3.4.4.2.4 Ensure IPv6 firewall rules exist for all open ports - firewall rules
- 3.4.4.2.4 Ensure IPv6 firewall rules exist for all open ports - ports
- 4.2.1.5 Ensure rsyslog is configured to send logs to a remote log host
- 4.2.1.6 Ensure remote rsyslog messages are only accepted on designated log hosts. - InputTCPServerRun
- 4.2.1.6 Ensure remote rsyslog messages are only accepted on designated log hosts. - ModLoad imtcp