CIS Ubuntu Linux 22.04 LTS Workstation L1 v1.0.0

Audit Details

Name: CIS Ubuntu Linux 22.04 LTS Workstation L1 v1.0.0

Updated: 11/15/2022

Authority: CIS

Plugin: Unix

Revision: 1.0

Estimated Item Count: 350

File Details

Filename: CIS_Ubuntu_22.04_LTS_v1.0.0_Workstation_L1.audit

Size: 1.2 MB

MD5: 68364b5c505c663fc1bd67e1c46451d2
SHA256: 98203426d2822e0d4dae7600d09e1010e81b0a573341653ffda667396c7ccef2

Audit Items

DescriptionCategories
1.1.1.1 Ensure mounting of cramfs filesystems is disabled - blacklist

CONFIGURATION MANAGEMENT

1.1.1.1 Ensure mounting of cramfs filesystems is disabled - lsmod

CONFIGURATION MANAGEMENT

1.1.1.1 Ensure mounting of cramfs filesystems is disabled - modprobe

CONFIGURATION MANAGEMENT

1.1.2.1 Ensure /tmp is a separate partition

ACCESS CONTROL, MEDIA PROTECTION

1.1.2.2 Ensure nodev option set on /tmp partition

ACCESS CONTROL, MEDIA PROTECTION

1.1.2.3 Ensure noexec option set on /tmp partition

ACCESS CONTROL, MEDIA PROTECTION

1.1.2.4 Ensure nosuid option set on /tmp partition

ACCESS CONTROL, MEDIA PROTECTION

1.1.3.2 Ensure nodev option set on /var partition

ACCESS CONTROL, MEDIA PROTECTION

1.1.3.3 Ensure nosuid option set on /var partition

ACCESS CONTROL, MEDIA PROTECTION

1.1.4.2 Ensure noexec option set on /var/tmp partition

ACCESS CONTROL, MEDIA PROTECTION

1.1.4.3 Ensure nosuid option set on /var/tmp partition

ACCESS CONTROL, MEDIA PROTECTION

1.1.4.4 Ensure nodev option set on /var/tmp partition

ACCESS CONTROL, MEDIA PROTECTION

1.1.5.2 Ensure nodev option set on /var/log partition

ACCESS CONTROL, MEDIA PROTECTION

1.1.5.3 Ensure noexec option set on /var/log partition

ACCESS CONTROL, MEDIA PROTECTION

1.1.5.4 Ensure nosuid option set on /var/log partition

ACCESS CONTROL, MEDIA PROTECTION

1.1.6.2 Ensure noexec option set on /var/log/audit partition

ACCESS CONTROL, MEDIA PROTECTION

1.1.6.3 Ensure nodev option set on /var/log/audit partition

ACCESS CONTROL, MEDIA PROTECTION

1.1.6.4 Ensure nosuid option set on /var/log/audit partition

ACCESS CONTROL, MEDIA PROTECTION

1.1.7.2 Ensure nodev option set on /home partition

ACCESS CONTROL, MEDIA PROTECTION

1.1.7.3 Ensure nosuid option set on /home partition

ACCESS CONTROL, MEDIA PROTECTION

1.1.8.1 Ensure nodev option set on /dev/shm partition

ACCESS CONTROL, MEDIA PROTECTION

1.1.8.2 Ensure noexec option set on /dev/shm partition

ACCESS CONTROL, MEDIA PROTECTION

1.1.8.3 Ensure nosuid option set on /dev/shm partition

ACCESS CONTROL, MEDIA PROTECTION

1.2.1 Ensure package manager repositories are configured

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.2.2 Ensure GPG keys are configured

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.3.1 Ensure AIDE is installed - aide

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

1.3.1 Ensure AIDE is installed - aide-common

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

1.3.2 Ensure filesystem integrity is regularly checked

AUDIT AND ACCOUNTABILITY

1.4.1 Ensure bootloader password is set - 'passwd_pbkdf2'

IDENTIFICATION AND AUTHENTICATION

1.4.1 Ensure bootloader password is set - 'set superusers'

IDENTIFICATION AND AUTHENTICATION

1.4.2 Ensure permissions on bootloader config are configured

ACCESS CONTROL, MEDIA PROTECTION

1.4.3 Ensure authentication required for single user mode

IDENTIFICATION AND AUTHENTICATION

1.5.1 Ensure address space layout randomization (ASLR) is enabled - config

SYSTEM AND INFORMATION INTEGRITY

1.5.1 Ensure address space layout randomization (ASLR) is enabled - sysctl

SYSTEM AND INFORMATION INTEGRITY

1.5.2 Ensure prelink is not installed

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

1.5.3 Ensure Automatic Error Reporting is not enabled - active

CONFIGURATION MANAGEMENT

1.5.3 Ensure Automatic Error Reporting is not enabled - enabled

CONFIGURATION MANAGEMENT

1.5.4 Ensure core dumps are restricted - limits config

ACCESS CONTROL

1.5.4 Ensure core dumps are restricted - processsizemax

ACCESS CONTROL

1.5.4 Ensure core dumps are restricted - storage

ACCESS CONTROL

1.5.4 Ensure core dumps are restricted - sysctl

ACCESS CONTROL

1.5.4 Ensure core dumps are restricted - sysctl config

ACCESS CONTROL, CONFIGURATION MANAGEMENT

1.6.1.1 Ensure AppArmor is installed

ACCESS CONTROL, MEDIA PROTECTION

1.6.1.2 Ensure AppArmor is enabled in the bootloader configuration - apparmor

ACCESS CONTROL, MEDIA PROTECTION

1.6.1.2 Ensure AppArmor is enabled in the bootloader configuration - security

ACCESS CONTROL, MEDIA PROTECTION

1.6.1.3 Ensure all AppArmor Profiles are in enforce or complain mode - loaded

ACCESS CONTROL, MEDIA PROTECTION

1.6.1.3 Ensure all AppArmor Profiles are in enforce or complain mode - unconfined

ACCESS CONTROL, MEDIA PROTECTION

1.7.1 Ensure message of the day is configured properly - banner

ACCESS CONTROL

1.7.1 Ensure message of the day is configured properly - platform flags

CONFIGURATION MANAGEMENT

1.7.2 Ensure local login warning banner is configured properly - banner

ACCESS CONTROL