CIS SUSE Linux Enterprise Server 12 L1 v3.0.0

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS SUSE Linux Enterprise Server 12 L1 v3.0.0

Updated: 8/23/2022

Authority: Operating Systems and Applications

Plugin: Unix

Revision: 1.8

Estimated Item Count: 272

File Details

Filename: CIS_SUSE_Linux_Enterprise_Server_12_v3.0.0_L1.audit

Size: 542 kB

MD5: ce4bba98a1da8e4ca6cc891243c3f8d1
SHA256: a5dba68740b16a19cdec0a466b00acfdaa6554c39a841c2891f4084142aef83e

Audit Items

DescriptionCategories
1.1.1.2 Ensure mounting of udf filesystems is disabled
1.1.2 Ensure /tmp is configured - config check
1.1.2 Ensure /tmp is configured - mount
1.1.3 Ensure noexec option set on /tmp partition
1.1.4 Ensure nodev option set on /tmp partition
1.1.5 Ensure nosuid option set on /tmp partition
1.1.6 Ensure /dev/shm is configured - fstab
1.1.6 Ensure /dev/shm is configured - mount
1.1.7 Ensure noexec option set on /dev/shm partition
1.1.8 Ensure nodev option set on /dev/shm partition
1.1.9 Ensure nosuid option set on /dev/shm partition
1.1.12 Ensure noexec option set on /var/tmp partition
1.1.13 Ensure nodev option set on /var/tmp partition
1.1.14 Ensure nosuid option set on /var/tmp partition
1.1.18 Ensure nodev option set on /home partition
1.1.19 Ensure noexec option set on removable media partitions
1.1.20 Ensure nodev option set on removable media partitions
1.1.21 Ensure nosuid option set on removable media partitions
1.1.22 Ensure sticky bit is set on all world-writable directories
1.1.23 Disable Automounting
1.2.1 Ensure GPG keys are configured
1.2.2 Ensure package manager repositories are configured
1.2.3 Ensure gpgcheck is globally activated
1.3.1 Ensure AIDE is installed
1.3.2 Ensure filesystem integrity is regularly checked - aidecheck.service
1.3.2 Ensure filesystem integrity is regularly checked - aidecheck.timer
1.3.2 Ensure filesystem integrity is regularly checked - cron
1.4.1 Ensure bootloader password is set - password_pbkdf2
1.4.1 Ensure bootloader password is set - superusers
1.4.2 Ensure permissions on bootloader config are configured
1.4.3 Ensure authentication required for single user mode - emergency
1.4.3 Ensure authentication required for single user mode - rescue
1.5.1 Ensure core dumps are restricted - /sbin/sysctl fs.suid_dumpable
1.5.1 Ensure core dumps are restricted - hard core 0
1.5.1 Ensure core dumps are restricted - sysctl.conf fs.suid_dumpable
1.5.1 Ensure core dumps are restricted - systemd-coredump ProcessSizeMax
1.5.1 Ensure core dumps are restricted - systemd-coredump Storage
1.5.2 Ensure XD/NX support is enabled
1.5.3 Ensure address space layout randomization (ASLR) is enabled - sysctl
1.5.3 Ensure address space layout randomization (ASLR) is enabled - sysctl.conf
1.5.4 Ensure prelink is disabled
1.6.1.1 Ensure AppArmor is installed - apparmor-parser
1.6.1.1 Ensure AppArmor is installed - apparmor-profiles
1.6.1.1 Ensure AppArmor is installed - apparmor-utils
1.6.1.1 Ensure AppArmor is installed - libapparmor1
1.6.1.2 Ensure AppArmor is enabled in the bootloader configuration - apparmor=1
1.6.1.2 Ensure AppArmor is enabled in the bootloader configuration - security=apparmor
1.6.1.3 Ensure all AppArmor Profiles are in enforce or complain mode - processes unconfined
1.6.1.3 Ensure all AppArmor Profiles are in enforce or complain mode - profiles loaded
1.7.1.1 Ensure message of the day is configured properly - banner text