| Jan 6, 2025 MiscellaneousAudit deprecated.Metadata updated.References updated.
 | 
| Jun 17, 2024 | 
| Jun 14, 2024 Functional Update1.1.1.1 Ensure mounting of squashfs filesystems is disabled1.1.10 Ensure separate partition exists for /var1.1.11 Ensure separate partition exists for /var/tmp1.1.15 Ensure separate partition exists for /var/log1.1.16 Ensure separate partition exists for /var/log/audit1.1.17 Ensure separate partition exists for /home1.1.23 Disable Automounting1.7.1.4 Ensure all AppArmor Profiles are enforcing4.1.1.1 Ensure auditd is installed4.1.1.3 Ensure auditing for processes that start prior to auditd is enabled4.1.11 Ensure use of privileged commands is collected4.1.17 Ensure the audit configuration is immutable4.1.2.1 Ensure audit log storage size is configured4.1.2.2 Ensure audit logs are not automatically deleted4.1.2.4 Ensure audit_backlog_limit is sufficient5.2.20 Ensure SSH AllowTcpForwarding is disabled6.1.1 Audit system file permissions
Informational Update1.1.1.1 Ensure mounting of squashfs filesystems is disabled1.1.10 Ensure separate partition exists for /var1.1.11 Ensure separate partition exists for /var/tmp1.1.15 Ensure separate partition exists for /var/log1.1.16 Ensure separate partition exists for /var/log/audit1.1.17 Ensure separate partition exists for /home1.1.23 Disable Automounting1.7.1.4 Ensure all AppArmor Profiles are enforcing4.1.1.1 Ensure auditd is installed4.1.1.3 Ensure auditing for processes that start prior to auditd is enabled4.1.11 Ensure use of privileged commands is collected4.1.17 Ensure the audit configuration is immutable4.1.2.1 Ensure audit log storage size is configured4.1.2.2 Ensure audit logs are not automatically deleted4.1.2.4 Ensure audit_backlog_limit is sufficient5.2.20 Ensure SSH AllowTcpForwarding is disabled6.1.1 Audit system file permissions
MiscellaneousMetadata updated.References updated.See also link updated.Variables updated.
Added1.1.1.3 Ensure mounting of FAT filesystems is limited2.2.3 Ensure Avahi Server is not installed3.1.1 Disable IPv63.1.2 Ensure wireless interfaces are disabled3.4.1 Ensure DCCP is disabled3.4.2 Ensure SCTP is disabled4.1.1.2 Ensure auditd service is enabled and running4.1.10 Ensure unsuccessful unauthorized file access attempts are collected4.1.12 Ensure successful file system mounts are collected4.1.13 Ensure file deletion events by users are collected4.1.14 Ensure changes to system administration scope (sudoers) is collected4.1.15 Ensure system administrator actions (sudolog) are collected4.1.16 Ensure kernel module loading and unloading is collected4.1.2.3 Ensure system is disabled when audit logs are full4.1.3 Ensure events that modify date and time information are collected4.1.4 Ensure events that modify user/group information are collected4.1.5 Ensure events that modify the system's network environment are collected4.1.6 Ensure events that modify the system's Mandatory Access Controls are collected4.1.7 Ensure login and logout events are collected4.1.8 Ensure session initiation information is collected4.1.9 Ensure discretionary access control permission modification events are collected
 | 
| Mar 18, 2024 Functional Update4.1.11 Ensure use of privileged commands is collected
MiscellaneousMetadata updated.Variables updated.
 | 
| Dec 20, 2023 | 
| Sep 19, 2023 Functional Update4.1.10 Ensure unsuccessful unauthorized file access attempts are collected - auditctl b32 EACCES4.1.10 Ensure unsuccessful unauthorized file access attempts are collected - auditctl b32 EPERM4.1.10 Ensure unsuccessful unauthorized file access attempts are collected - auditctl b64 EACCES4.1.10 Ensure unsuccessful unauthorized file access attempts are collected - auditctl b64 EPERM4.1.10 Ensure unsuccessful unauthorized file access attempts are collected - b32 EACCES4.1.10 Ensure unsuccessful unauthorized file access attempts are collected - b32 EPERM4.1.10 Ensure unsuccessful unauthorized file access attempts are collected - b64 EACCES4.1.10 Ensure unsuccessful unauthorized file access attempts are collected - b64 EPERM4.1.12 Ensure successful file system mounts are collected - auditctl b64 mount4.1.12 Ensure successful file system mounts are collected - b64 mount4.1.13 Ensure file deletion events by users are collected - auditctl b32 delete4.1.13 Ensure file deletion events by users are collected - auditctl b64 delete4.1.13 Ensure file deletion events by users are collected - b32 delete4.1.13 Ensure file deletion events by users are collected - b64 delete4.1.14 Ensure changes to system administration scope (sudoers) is collected - auditctl sudoers4.1.14 Ensure changes to system administration scope (sudoers) is collected - auditctl sudoers.d4.1.14 Ensure changes to system administration scope (sudoers) is collected - sudoers4.1.14 Ensure changes to system administration scope (sudoers) is collected - sudoers.d4.1.16 Ensure kernel module loading and unloading is collected - auditctl insmod4.1.16 Ensure kernel module loading and unloading is collected - auditctl modprobe4.1.16 Ensure kernel module loading and unloading is collected - auditctl rmmod4.1.16 Ensure kernel module loading and unloading is collected - insmod4.1.16 Ensure kernel module loading and unloading is collected - modprobe4.1.16 Ensure kernel module loading and unloading is collected - rmmod4.1.2.1 Ensure audit log storage size is configured4.1.2.2 Ensure audit logs are not automatically deleted4.1.3 Ensure events that modify date and time information are collected - auditctl b32 /etc/localtime4.1.3 Ensure events that modify date and time information are collected - auditctl b32 adjtimex4.1.3 Ensure events that modify date and time information are collected - auditctl b32 clock_settime4.1.3 Ensure events that modify date and time information are collected - auditctl b64 adjtimex4.1.3 Ensure events that modify date and time information are collected - auditctl b64 clock_settime4.1.3 Ensure events that modify date and time information are collected - b32 /etc/localtime4.1.3 Ensure events that modify date and time information are collected - b32 adjtimex4.1.3 Ensure events that modify date and time information are collected - b32 clock_settime4.1.3 Ensure events that modify date and time information are collected - b64 adjtimex4.1.3 Ensure events that modify date and time information are collected - b64 clock_settime4.1.4 Ensure events that modify user/group information are collected - /etc/group4.1.4 Ensure events that modify user/group information are collected - /etc/passwd4.1.4 Ensure events that modify user/group information are collected - /etc/security/opasswd4.1.4 Ensure events that modify user/group information are collected - /etc/shadow4.1.4 Ensure events that modify user/group information are collected - auditctl /etc/group4.1.4 Ensure events that modify user/group information are collected - auditctl /etc/passwd4.1.4 Ensure events that modify user/group information are collected - auditctl /etc/security/opasswd4.1.4 Ensure events that modify user/group information are collected - auditctl /etc/shadow4.1.5 Ensure events that modify the system's network environment are collected - /etc/hosts4.1.5 Ensure events that modify the system's network environment are collected - /etc/issue4.1.5 Ensure events that modify the system's network environment are collected - /etc/issue.net4.1.5 Ensure events that modify the system's network environment are collected - /etc/sysconfig/network4.1.5 Ensure events that modify the system's network environment are collected - auditctl /etc/hosts4.1.5 Ensure events that modify the system's network environment are collected - auditctl /etc/issue4.1.5 Ensure events that modify the system's network environment are collected - auditctl /etc/issue.net4.1.5 Ensure events that modify the system's network environment are collected - auditctl /etc/sysconfig/network4.1.5 Ensure events that modify the system's network environment are collected - auditctl b32 sethostname4.1.5 Ensure events that modify the system's network environment are collected - auditctl b64 sethostname4.1.5 Ensure events that modify the system's network environment are collected - b32 sethostname4.1.5 Ensure events that modify the system's network environment are collected - b64 sethostname4.1.6 Ensure events that modify the system's Mandatory Access Controls are collected - /etc/selinux4.1.6 Ensure events that modify the system's Mandatory Access Controls are collected - /usr/share/selinux4.1.6 Ensure events that modify the system's Mandatory Access Controls are collected - auditctl /etc/selinux4.1.6 Ensure events that modify the system's Mandatory Access Controls are collected - auditctl /usr/share/selinux4.1.7 Ensure login and logout events are collected - /var/log/faillog4.1.7 Ensure login and logout events are collected - /var/log/lastlog4.1.7 Ensure login and logout events are collected - /var/log/tallylog4.1.7 Ensure login and logout events are collected - auditctl /var/log/faillog4.1.7 Ensure login and logout events are collected - auditctl /var/log/lastlog4.1.7 Ensure login and logout events are collected - auditctl /var/log/tallylog4.1.8 Ensure session initiation information is collected - /var/log/btmp4.1.8 Ensure session initiation information is collected - /var/log/wtmp4.1.8 Ensure session initiation information is collected - /var/run/utmp4.1.8 Ensure session initiation information is collected - auditctl /var/log/btmp4.1.8 Ensure session initiation information is collected - auditctl /var/log/wtmp4.1.8 Ensure session initiation information is collected - auditctl /var/run/utmp4.1.9 Ensure discretionary access control permission modification events are collected - auditctl b32 chmod4.1.9 Ensure discretionary access control permission modification events are collected - auditctl b32 chown4.1.9 Ensure discretionary access control permission modification events are collected - auditctl b32 xattr4.1.9 Ensure discretionary access control permission modification events are collected - auditctl b64 chmod4.1.9 Ensure discretionary access control permission modification events are collected - auditctl b64 chown4.1.9 Ensure discretionary access control permission modification events are collected - auditctl b64 xattr4.1.9 Ensure discretionary access control permission modification events are collected - b32 chmod4.1.9 Ensure discretionary access control permission modification events are collected - b32 chown4.1.9 Ensure discretionary access control permission modification events are collected - b32 xattr4.1.9 Ensure discretionary access control permission modification events are collected - b64 chmod4.1.9 Ensure discretionary access control permission modification events are collected - b64 chown4.1.9 Ensure discretionary access control permission modification events are collected - b64 xattr
MiscellaneousMetadata updated.References updated.
Added4.1.12 Ensure successful file system mounts are collected - auditctl b32 mount4.1.12 Ensure successful file system mounts are collected - b32 mount4.1.16 Ensure kernel module loading and unloading is collected - auditctl b32 init_module, delete_module4.1.16 Ensure kernel module loading and unloading is collected - auditctl b64 init_module, delete_module4.1.16 Ensure kernel module loading and unloading is collected - b32 init_module, delete_module4.1.16 Ensure kernel module loading and unloading is collected - b64 init_module, delete_module
Removed4.1.12 Ensure successful file system mounts are collected - 32b mount4.1.12 Ensure successful file system mounts are collected - auditctl 32b mount4.1.16 Ensure kernel module loading and unloading is collected - auditctl init_module, delete_module4.1.16 Ensure kernel module loading and unloading is collected - init_module, delete_module
 | 
| Jul 5, 2023 Functional Update4.1.2.3 Ensure system is disabled when audit logs are full - action_mail_acct4.1.2.3 Ensure system is disabled when audit logs are full - admin_space_left_action
 | 
| Apr 12, 2023 MiscellaneousMetadata updated.Platform check updated.Variables updated.
 | 
| Mar 7, 2023 MiscellaneousMetadata updated.References updated.
 | 
| Jan 4, 2023 MiscellaneousMetadata updated.Variables updated.
 |