Item Search

NameAudit NamePluginCategory
1.1.1.4 Ensure mounting of hfs filesystems is disabled - modprobeCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.3 Ensure nodev option set on /tmp partitionCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.4 Ensure nosuid option set on /tmp partitionCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.21 Ensure sticky bit is set on all world-writable directoriesCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.5.2 Ensure bootloader password is set - password_pbkdf2CIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.6.2 Ensure address space layout randomization (ASLR) is enabledCIS Debian Family Workstation L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

1.6.2 Ensure address space layout randomization (ASLR) is enabled - sysctlCIS Debian Family Workstation L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

1.7.1.1 Ensure AppArmor is installedCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

1.7.1.2 Ensure AppArmor is enabled in the bootloader configuration - apparmor=1CIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

1.7.1.2 Ensure AppArmor is enabled in the bootloader configuration - security=apparmorCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

1.7.1.3 Ensure all AppArmor Profiles are in enforce or complain mode - profiles loadedCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

2.1.1.3 Ensure chrony is configured - ntp serverCIS Debian Family Workstation L1 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

2.1.1.3 Ensure chrony is configured - package ntpCIS Debian Family Workstation L1 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

2.1.1.4 Ensure ntp is configured - RUNASUSERCIS Debian Family Workstation L1 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

2.1.5 Ensure DHCP Server is not installed - dhcpdCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

2.1.5 Ensure DHCP Server is not installed - isc-dhcp-server6CIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

2.1.7 Ensure NFS is not installedCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

2.1.12 Ensure Samba is not installedCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

2.1.13 Ensure HTTP Proxy Server is not installedCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

2.1.15 Ensure mail transfer agent is configured for local-only mode - /etc/exim4/update-exim4.conf.confCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

2.2.1 Ensure NIS Client is not installedCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.3.1 Ensure source routed packets are not accepted - files 'net.ipv4.conf.all.accept_source_route = 0'CIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.3.1 Ensure source routed packets are not accepted - net.ipv6.conf.default.accept_source_route = 0CIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.3.2 Ensure ICMP redirects are not accepted - files net.ipv6.conf.all.accept_redirects= 0CIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.3.3 Ensure secure ICMP redirects are not accepted - net.ipv4.conf.all.secure_redirects = 0CIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.3.3 Ensure secure ICMP redirects are not accepted - net.ipv4.conf.default.secure_redirects = 0CIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.3.6 Ensure bogus ICMP responses are ignored - files net.ipv4.icmp_ignore_bogus_error_responses = 1CIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.3.8 Ensure TCP SYN Cookies is enabled - files net.ipv4.tcp_syncookies = 1CIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.3.9 Ensure IPv6 router advertisements are not accepted - net.ipv6.conf.default.accept_ra = 0CIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.6.1.2 Ensure iptables-persistent is not installedCIS Debian Family Workstation L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.6.1.4 Ensure loopback traffic is configured - deny in from 127.0.0.0/8CIS Debian Family Workstation L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.6.2.6 Ensure loopback traffic is configured - v6CIS Debian Family Workstation L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.6.2.8 Ensure default deny firewall policy - inputCIS Debian Family Workstation L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.6.2.8 Ensure default deny firewall policy - outputCIS Debian Family Workstation L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.6.3.2.1 Ensure default deny firewall policy - FORWARDCIS Debian Family Workstation L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.6.3.2.1 Ensure default deny firewall policy - INPUTCIS Debian Family Workstation L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.6.3.3.3 Ensure IPv6 outbound and established connections are configuredCIS Debian Family Workstation L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

4.2.2.3 Ensure journald is configured to write logfiles to persistent diskCIS Debian Family Workstation L1 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

5.1.1 Ensure cron daemon is enabled and running - runningCIS Debian Family Workstation L1 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

5.3.2 Ensure lockout for failed password attempts is configured - pam_tally2.soCIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL

5.3.4 Ensure password hashing algorithm is SHA-512CIS Debian Family Server L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.3 Ensure password expiration warning days is 7 or more - usersCIS Debian Family Server L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.4 Ensure inactive password lock is 30 days or less - usersCIS Debian Family Server L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.3 Ensure default group for the root account is GID 0CIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL

6.1.2 Ensure permissions on /etc/passwd are configuredCIS Debian Family Server L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

6.1.7 Ensure permissions on /etc/shadow- are configuredCIS Debian Family Server L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

6.1.8 Ensure permissions on /etc/gshadow are configuredCIS Debian Family Server L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

6.1.9 Ensure permissions on /etc/gshadow- are configuredCIS Debian Family Server L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

6.1.13 Audit SUID executablesCIS Debian Family Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

6.2.10 Ensure root is the only UID 0 accountCIS Debian Family Server L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION