CIS SUSE Linux Enterprise Workstation 12 L1 v3.0.0

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS SUSE Linux Enterprise Workstation 12 L1 v3.0.0

Updated: 8/23/2022

Authority: CIS

Plugin: Unix

Revision: 1.8

Estimated Item Count: 268

File Details

Filename: CIS_SUSE_Linux_Enterprise_Workstation_12_v3.0.0_L1.audit

Size: 556 kB

MD5: e6e4051f328df874b2f7e35f12a759b6
SHA256: d06eecb7e9711fba56556ba846e1f7a679eab061341315d4f33e31b9769cbed3

Audit Items

DescriptionCategories
1.1.1.2 Ensure mounting of udf filesystems is disabled
1.1.2 Ensure /tmp is configured - config check
1.1.2 Ensure /tmp is configured - mount
1.1.3 Ensure noexec option set on /tmp partition
1.1.4 Ensure nodev option set on /tmp partition
1.1.5 Ensure nosuid option set on /tmp partition
1.1.6 Ensure /dev/shm is configured - fstab
1.1.6 Ensure /dev/shm is configured - mount
1.1.7 Ensure noexec option set on /dev/shm partition
1.1.8 Ensure nodev option set on /dev/shm partition
1.1.9 Ensure nosuid option set on /dev/shm partition
1.1.12 Ensure noexec option set on /var/tmp partition
1.1.13 Ensure nodev option set on /var/tmp partition
1.1.14 Ensure nosuid option set on /var/tmp partition
1.1.18 Ensure nodev option set on /home partition
1.1.19 Ensure noexec option set on removable media partitions
1.1.20 Ensure nodev option set on removable media partitions
1.1.21 Ensure nosuid option set on removable media partitions
1.1.22 Ensure sticky bit is set on all world-writable directories
1.2.1 Ensure GPG keys are configured
1.2.2 Ensure package manager repositories are configured
1.2.3 Ensure gpgcheck is globally activated
1.3.1 Ensure AIDE is installed
1.3.2 Ensure filesystem integrity is regularly checked - aidecheck.service
1.3.2 Ensure filesystem integrity is regularly checked - aidecheck.timer
1.3.2 Ensure filesystem integrity is regularly checked - cron
1.4.1 Ensure bootloader password is set - password_pbkdf2
1.4.1 Ensure bootloader password is set - superusers
1.4.2 Ensure permissions on bootloader config are configured
1.4.3 Ensure authentication required for single user mode - emergency
1.4.3 Ensure authentication required for single user mode - rescue
1.5.1 Ensure core dumps are restricted - /sbin/sysctl fs.suid_dumpable
1.5.1 Ensure core dumps are restricted - hard core 0
1.5.1 Ensure core dumps are restricted - sysctl.conf fs.suid_dumpable
1.5.1 Ensure core dumps are restricted - systemd-coredump ProcessSizeMax
1.5.1 Ensure core dumps are restricted - systemd-coredump Storage
1.5.2 Ensure XD/NX support is enabled
1.5.3 Ensure address space layout randomization (ASLR) is enabled - sysctl
1.5.3 Ensure address space layout randomization (ASLR) is enabled - sysctl.conf
1.5.4 Ensure prelink is disabled
1.6.1.1 Ensure AppArmor is installed - apparmor-parser
1.6.1.1 Ensure AppArmor is installed - apparmor-profiles
1.6.1.1 Ensure AppArmor is installed - apparmor-utils
1.6.1.1 Ensure AppArmor is installed - libapparmor1
1.6.1.2 Ensure AppArmor is enabled in the bootloader configuration - apparmor=1
1.6.1.2 Ensure AppArmor is enabled in the bootloader configuration - security=apparmor
1.6.1.3 Ensure all AppArmor Profiles are in enforce or complain mode - processes unconfined
1.6.1.3 Ensure all AppArmor Profiles are in enforce or complain mode - profiles loaded
1.7.1.1 Ensure message of the day is configured properly - banner text
1.7.1.1 Ensure message of the day is configured properly - mrsv