Item Search

NameAudit NamePluginCategory
1.1.1.6 Ensure mounting of squashfs filesystems is disabled - modprobeCIS Debian Family Server L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.12 Ensure separate partition exists for /var/log/auditCIS Debian Family Server L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

1.1.13 Ensure separate partition exists for /homeCIS Debian Family Server L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.1.1 Disable IPv6 - sysctl allCIS Debian Family Server L2 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.5.1 Ensure DCCP is disabled - lsmodCIS Debian Family Server L2 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

3.5.3 Ensure RDS is disabled - lsmodCIS Debian Family Server L2 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

3.5.4 Ensure TIPC is disabled - lsmodCIS Debian Family Server L2 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

4.1.1.2 Ensure auditd service is enabledCIS Debian Family Server L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.2.1 Ensure audit log storage size is configuredCIS Debian Family Server L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.2.3 Ensure system is disabled when audit logs are full - admin_space_left_actionCIS Debian Family Server L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.2.3 Ensure system is disabled when audit logs are full - space_left_actionCIS Debian Family Server L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.3 Ensure events that modify date and time information are collected - auditctl clock_settime x64CIS Debian Family Server L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

4.1.3 Ensure events that modify date and time information are collected - clock_settimeCIS Debian Family Server L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

4.1.5 Ensure events that modify the system's network environment are collected - sethostname setdomainnameCIS Debian Family Server L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

4.1.6 Ensure events that modify the system's Mandatory Access Controls are collected - /etc/apparmor.dCIS Debian Family Server L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

4.1.10 Ensure unsuccessful unauthorized file access attempts are collected - EACCESCIS Debian Family Server L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.10 Ensure unsuccessful unauthorized file access attempts are collected - EPERMCIS Debian Family Server L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.11 Ensure use of privileged commands is collectedCIS Debian Family Server L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

4.1.13 Ensure file deletion events by users are collected - auditctl delete x64CIS Debian Family Server L2 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

4.1.13 Ensure file deletion events by users are collected - deleteCIS Debian Family Server L2 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

4.1.15 Ensure system administrator command executions (sudo) are collected - b32 actionsCIS Debian Family Server L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.16 Ensure kernel module loading and unloading is collected - /sbin/insmodCIS Debian Family Server L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

4.1.16 Ensure kernel module loading and unloading is collected - auditctl /sbin/insmodCIS Debian Family Server L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

4.1.17 Ensure the audit configuration is immutableCIS Debian Family Server L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

5.1.6 Ensure permissions on /etc/cron.monthly are configuredCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

5.1.8 Ensure cron is restricted to authorized users - cron.denyCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

5.2.7 Ensure SSH IgnoreRhosts is enabledCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

5.2.11 Ensure SSH PermitUserEnvironment is disabledCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

5.2.18 Ensure SSH warning banner is configuredCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

5.3.1 Ensure password creation requirements are configured - password complexityCIS Debian Family Workstation L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.3.3 Ensure password reuse is limitedCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

5.3.4 Ensure password hashing algorithm is SHA-512CIS Debian Family Workstation L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.3 Ensure password expiration warning days is 7 or more - login.defsCIS Debian Family Workstation L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.4 Ensure inactive password lock is 30 days or less - useraddCIS Debian Family Workstation L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.3 Ensure default group for the root account is GID 0CIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

5.4.5 Ensure default user shell timeout is 900 seconds or lessCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

5.6 Ensure access to the su command is restrictedCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

6.1.3 Ensure permissions on /etc/passwd- are configuredCIS Debian Family Workstation L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

6.1.10 Ensure no world writable files existCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

6.1.11 Ensure no unowned files or directories existCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

6.1.12 Ensure no ungrouped files or directories existCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

6.1.13 Audit SUID executablesCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

6.2.4 Ensure users own their home directoriesCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

6.2.7 Ensure no users have .netrc filesCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

6.2.8 Ensure no users have .forward filesCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

6.2.11 Ensure root PATH IntegrityCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

6.2.12 Ensure all groups in /etc/passwd exist in /etc/groupCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

6.2.14 Ensure no duplicate GIDs existCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

6.2.15 Ensure no duplicate user names existCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

6.2.16 Ensure no duplicate group names existCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL