1.1.1.1 Ensure mounting of cramfs filesystems is disabled | CONFIGURATION MANAGEMENT |
1.1.1.2 Ensure mounting of freevxfs filesystems is disabled | CONFIGURATION MANAGEMENT |
1.1.1.3 Ensure mounting of jffs2 filesystems is disabled | CONFIGURATION MANAGEMENT |
1.1.1.4 Ensure mounting of hfs filesystems is disabled | CONFIGURATION MANAGEMENT |
1.1.1.5 Ensure mounting of hfsplus filesystems is disabled | CONFIGURATION MANAGEMENT |
1.1.1.6 Ensure mounting of squashfs filesystems is disabled | CONFIGURATION MANAGEMENT |
1.1.1.7 Ensure mounting of udf filesystems is disabled | CONFIGURATION MANAGEMENT |
1.1.3 Ensure nodev option set on /tmp partition | ACCESS CONTROL |
1.1.4 Ensure nosuid option set on /tmp partition | ACCESS CONTROL |
1.1.7 Ensure nodev option set on /var/tmp partition | ACCESS CONTROL |
1.1.8 Ensure nosuid option set on /var/tmp partition | ACCESS CONTROL |
1.1.9 Ensure noexec option set on /var/tmp partition | ACCESS CONTROL |
1.1.13 Ensure nodev option set on /home partition | ACCESS CONTROL |
1.1.14 Ensure nodev option set on /run/shm partition | ACCESS CONTROL |
1.1.15 Ensure nosuid option set on /run/shm partition | ACCESS CONTROL |
1.1.16 Ensure noexec option set on /run/shm partition | ACCESS CONTROL |
1.1.17 Ensure nodev option set on removable media partitions | ACCESS CONTROL |
1.1.18 Ensure nosuid option set on removable media partitions | ACCESS CONTROL |
1.1.19 Ensure noexec option set on removable media partitions | ACCESS CONTROL |
1.1.20 Ensure sticky bit is set on all world-writable directories | ACCESS CONTROL |
1.1.21 Disable Automounting | CONFIGURATION MANAGEMENT |
1.2.1 Ensure package manager repositories are configured | SYSTEM AND INFORMATION INTEGRITY |
1.2.2 Ensure GPG keys are configured | SYSTEM AND INFORMATION INTEGRITY |
1.3.1 Ensure AIDE is installed | CONFIGURATION MANAGEMENT |
1.3.2 Ensure filesystem integrity is regularly checked | SYSTEM AND INFORMATION INTEGRITY |
1.4.1 Ensure permissions on bootloader config are configured | SYSTEM AND INFORMATION INTEGRITY |
1.4.2 Ensure bootloader password is set - 'passwd_pbkdf2' | SYSTEM AND INFORMATION INTEGRITY |
1.4.2 Ensure bootloader password is set - 'set superusers' | SYSTEM AND INFORMATION INTEGRITY |
1.4.3 Ensure authentication required for single user mode | IDENTIFICATION AND AUTHENTICATION |
1.5.1 Ensure core dumps are restricted -'fs.suid_dumpable' | ACCESS CONTROL |
1.5.1 Ensure core dumps are restricted -'hard core' | ACCESS CONTROL |
1.5.2 Ensure XD/NX support is enabled | SYSTEM AND INFORMATION INTEGRITY |
1.5.3 Ensure address space layout randomization (ASLR) is enabled | CONFIGURATION MANAGEMENT |
1.5.4 Ensure prelink is disabled | CONFIGURATION MANAGEMENT |
1.7.1.1 Ensure message of the day is configured properly | CONFIGURATION MANAGEMENT |
1.7.1.2 Ensure local login warning banner is configured properly | CONFIGURATION MANAGEMENT |
1.7.1.3 Ensure remote login warning banner is configured properly | CONFIGURATION MANAGEMENT |
1.7.1.4 Ensure permissions on /etc/motd are configured | CONFIGURATION MANAGEMENT |
1.7.1.5 Ensure permissions on /etc/issue are configured | CONFIGURATION MANAGEMENT |
1.7.1.6 Ensure permissions on /etc/issue.net are configured | CONFIGURATION MANAGEMENT |
1.7.2 Ensure GDM login banner is configured - 'banner-message-enable' | ACCESS CONTROL |
1.7.2 Ensure GDM login banner is configured - 'banner-message-text' | ACCESS CONTROL |
1.7.2 Ensure GDM login banner is configured - 'file-db' | ACCESS CONTROL |
1.7.2 Ensure GDM login banner is configured - 'system-db' | ACCESS CONTROL |
1.7.2 Ensure GDM login banner is configured - 'user-db' | ACCESS CONTROL |
1.8 Ensure updates, patches, and additional security software are installed | SYSTEM AND INFORMATION INTEGRITY |
2.1.1 Ensure chargen services are not enabled - '/etc/inetd.conf' | CONFIGURATION MANAGEMENT |
2.1.1 Ensure chargen services are not enabled - 'chargen-dgram' | CONFIGURATION MANAGEMENT |
2.1.1 Ensure chargen services are not enabled - 'chargen-stream' | CONFIGURATION MANAGEMENT |
2.1.2 Ensure daytime services are not enabled - '/etc/inetd.conf' | CONFIGURATION MANAGEMENT |