Revision 1.7Jul 23, 2026

Informational Update
  • 1.3.1.10 Ensure SELinux prevents nonprivileged users from executing privileged functions
  • 1.4.3 Ensure the operating system requires authentication for rescue mode
  • 1.5.16 Ensure the operating system restricts exposed kernel pointer addresses access
  • 1.5.5 Ensure the storing of core dumps is disabled
  • 1.5.6 Ensure the operating system is not configured to acquire save or process core dumps
  • 1.8.18 Ensure the operating system initiates a session lock for all connection types using smartcard when the smartcard is removed
  • 1.9 Ensure the \"tmux\" package installed
  • 2.3.4 Ensure the operating system is securely comparing internal information system clocks at least every 24 hours with an NTP server
  • 2.3.5 Ensure the operating system disables network management of the chrony daemon
  • 2.3.6 Ensure the operating system disables the chrony daemon from acting as a server
  • 2.5.2 Ensure USBGuard has a policy configured
  • 3.3.12 Ensure net.ipv4.conf.all.forwarding is disabled
  • 5.2.8 Ensure the sudoers security policy is configured to use the invoking user's password for privilege escalation
  • 5.2.9 Ensure sudo timestamp_timeout is configured
  • 5.3.3.2.17 Ensure retry is configured on the pam_pwquality module in /etc/pam.d/system-auth
  • 5.3.3.2.18 Ensure retry is configured on the pam_pwquality module in /etc/pam.d/password-auth
  • 5.3.3.2.19 Ensure retry is configured in /etc/security/pwquality.conf
  • 5.3.3.3.4 Ensure remember is configured on the pam_pwhistory module in /etc/pam.d/password-auth
  • 5.3.3.3.5 Ensure remember is configured on the pam_pwhistory module in /etc/pam.d/system-auth
  • 5.4.1.2 Ensure minimum password days is configured
  • 6.1.1 Ensure AIDE is installed
  • 6.2.2.12 Ensure the operating system has the packages required for encrypting offloaded audit logs
  • 6.2.2.13 Ensure the the operating system authenticates the remote logging server for off-loading audit logs
  • 6.2.2.15 Ensure the audit system off-loads audit records onto a different system or media from the system being audited
  • 6.3.3.13 Ensure file deletion events by users are collected
  • 7.1.11 Ensure world writable files and directories are secured
Miscellaneous
  • Metadata updated.
  • References updated.