Item Search

NameAudit NamePluginCategory
1.1.1.2 Ensure mounting of freevxfs filesystems is disabled - /etc/modprobe.d/CIS.confCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

1.1.1.7 Ensure mounting of udf filesystems is disabled - /etc/modprobe.d/CIS.confCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

1.1.18 Ensure sticky bit is set on all world-writable directoriesCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

1.1.19 Disable AutomountingCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

1.2.3 Ensure gpgcheck is globally activatedCIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND INFORMATION INTEGRITY

1.5.2 Ensure XD/NX support is enabledCIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND INFORMATION INTEGRITY

1.7.1.4 Ensure permissions on /etc/motd are configuredCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

1.7.1.5 Ensure permissions on /etc/issue are configuredCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

1.7.1.6 Ensure permissions on /etc/issue.net are configuredCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.1.1 Ensure chargen services are not enabled - chargen-streamCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.1.2 Ensure daytime services are not enabled - daytime-dgramCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.1.5 Ensure time services are not enabled - time-dgramCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.1.6 Ensure rsh server is not enabled - rshCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.2.1.2 Ensure ntp is configured - remote serverCIS Amazon Linux v2.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

2.2.11 Ensure IMAP and POP3 server is not enabledCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.2.16 Ensure NIS Server is not enabledCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.3.1 Ensure NIS Client is not installedCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.3.2 Ensure rsh client is not installedCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

3.1.1 Ensure IP forwarding is disabled - '/etc/sysctl.conf /etc/sysctl.d/*'CIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.1 Ensure source routed packets are not accepted - 'net.ipv4.conf.default.accept_source_route = 0 - sysctl'CIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.2 Ensure ICMP redirects are not accepted - 'net.ipv4.conf.default.accept_redirects = 0 /etc/sysctl.conf sysctl.d/*'CIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.3 Ensure secure ICMP redirects are not accepted - 'net.ipv4.conf.all.secure_redirects = 0 /etc/sysctl.conf /etc/sysctl.d/*'CIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.4 Ensure suspicious packets are logged - net.ipv4.conf.default.log_martians = 1 sysctlCIS Amazon Linux v2.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

3.2.6 Ensure bogus ICMP responses are ignored - sysctlCIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.7 Ensure Reverse Path Filtering is enabled - 'net.ipv4.conf.default.rp_filter = 1 sysctl'CIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.8 Ensure TCP SYN Cookies is enabled - sysctlCIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.3.1 Ensure IPv6 router advertisements are not accepted - 'sysctl net.ipv6.conf.default.accept_ra = 0'CIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.3.2 Ensure IPv6 redirects are not accepted - 'net.ipv6.conf.all.accept_redirects = 0 /etc/sysctl.conf /etc/sysctl.d/*'CIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.6.3 Ensure loopback traffic is configured - OUTPUTCIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

4.2.1.1 Ensure rsyslog Service is enabled - chkconfigCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

4.2.1.3 Ensure rsyslog default file permissions configuredCIS Amazon Linux v2.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

4.2.1.5 Ensure remote rsyslog messages are only accepted on designated log hosts. - $ModLoad imtcpCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

4.2.3 Ensure rsyslog or syslog-ng is installedCIS Amazon Linux v2.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

5.1.2 Ensure permissions on /etc/crontab are configuredCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

5.1.5 Ensure permissions on /etc/cron.weekly are configuredCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

5.1.7 Ensure permissions on /etc/cron.d are configuredCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

5.1.8 Ensure at/cron is restricted to authorized users - at.allowCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

5.1.8 Ensure at/cron is restricted to authorized users - cron.deny does not existCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

5.2.6 Ensure SSH IgnoreRhosts is enabledCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

5.2.8 Ensure SSH root login is disabledCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

5.2.11 Ensure only approved MAC algorithms are usedCIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.12 Ensure SSH Idle Timeout Interval is configured - ClientAliveCountMaxCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

5.3.1 Ensure password creation requirements are configured - try_first_passCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

5.3.2 Ensure lockout for failed password attempts is configured - password-auth 'auth [default=die] pam_faillock.so authfail audit deny=5 unlock_time=900'CIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

5.3.2 Ensure lockout for failed password attempts is configured - password-auth 'auth sufficient pam_faillock.so authsucc audit deny=5 unlock_time=900'CIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

6.1.9 Ensure permissions on /etc/gshadow- are configuredCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

6.1.11 Ensure no unowned files or directories existCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

6.2.10 Ensure users' dot files are not group or world writableCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

6.2.17 Ensure no duplicate GIDs existCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

6.2.18 Ensure no duplicate user names existCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION