Item Search

NameAudit NamePluginCategory
1.1.1.1 Ensure mounting of cramfs filesystems is disabled - /etc/modprobe.d/CIS.confCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

1.1.5 Ensure noexec option set on /tmp partitionCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

1.1.8 Ensure nodev option set on /var/tmp partitionCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

1.3.1 Ensure AIDE is installedCIS Amazon Linux v2.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

1.5.1 Ensure core dumps are restricted - /etc/sysctl.conf, /etc/sysctl.d/*CIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

1.5.3 Ensure address space layout randomization (ASLR) is enabled - sysctlCIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND INFORMATION INTEGRITY

1.5.4 Ensure prelink is disabledCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

1.7.1.2 Ensure local login warning banner is configured properly - banner textCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

1.7.1.2 Ensure local login warning banner is configured properly - mrsvCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

1.8 Ensure updates, patches, and additional security software are installedCIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND INFORMATION INTEGRITY

2.1.3 Ensure discard services are not enabled - discard-dgramCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.1.4 Ensure echo services are not enabled - echo-streamCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.1.6 Ensure rsh server is not enabled - rloginCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.1.9 Ensure tftp server is not enabledCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.1.11 Ensure xinetd is not enabledCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.2.1.2 Ensure ntp is configured - daemonCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.2.1.2 Ensure ntp is configured - restrict -6CIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.2.8 Ensure DNS Server is not enabledCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.3 Establish a Secure Baseline - Make sure that application/management/wbem only allows local connections (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/rpc/cde-calendar-manager is only limited to local connectionsCIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/rpc/mdcomm:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/rpc/rstat:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/shell:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/telnet:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3.4 Ensure telnet client is not installedCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

3.1.1 Ensure IP forwarding is disabled - sysctlCIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1.2 Ensure packet redirect sending is disabled - 'net.ipv4.conf.default.send_redirects = 0 /etc/sysctl.conf /etc/sysctl.d/*'CIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1.2 Ensure packet redirect sending is disabled 'net.ipv4.conf.all.send_redirects = 0 /etc/sysctl.conf /etc/sysctl.d/*'CIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1.2 Ensure packet redirect sending is disabled 'net.ipv4.conf.default.send_redirects = 0 - sysctl'CIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1.6 Disable Response to ICMP Netmask Requests - Check ip_respond_to_address_mask_broadcast value. Expected value: 0.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1.7 Disable ICMPv6 Redirect Messages - Check ip6_send_redirects value. Expected value: 1.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1.9 Disable Response to Multicast Echo Request - Check ip_respond_to_echo_multicast value. Expected value: 0.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1.17 Set Maximum Number of Incoming Connections - Check tcp_conn_req_max_q value. Expected value: 1024.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2 Restrict Core Dumps to Protected Directory - Check if COREADM_GLOB_CONTENT is set to defaultCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

3.2 Restrict Core Dumps to Protected Directory - Check if COREADM_GLOB_LOG_ENABLED is set to yesCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

3.2.1 Ensure source routed packets are not accepted - 'net.ipv4.conf.all.accept_source_route = 0 - sysctl'CIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.3 Ensure secure ICMP redirects are not accepted - 'net.ipv4.conf.default.secure_redirects = 0 /etc/sysctl.conf /etc/sysctl.d/*'CIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.7 Ensure Reverse Path Filtering is enabled - 'net.ipv4.conf.all.rp_filter = 1 /etc/sysctl.conf /etc/sysctl.d/*'CIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.3.1 Ensure IPv6 router advertisements are not accepted - 'net.ipv6.conf.all.accept_ra = 0 /etc/sysctl.conf /etc/sysctl.d/*'CIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.3.1 Ensure IPv6 router advertisements are not accepted - 'net.ipv6.conf.all.accept_ra = 0 sysctl'CIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.3.1 Ensure IPv6 router advertisements are not accepted - 'net.ipv6.conf.default.accept_ra = 0 /etc/sysctl.conf /etc/sysctl.d/*'CIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.3.2 Ensure IPv6 redirects are not accepted - 'sysctl net.ipv6.conf.default.accept_redirects = 0'CIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.4.2 Ensure /etc/hosts.allow is configuredCIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.4.4 Ensure permissions on /etc/hosts.allow are configuredCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

4.2.2.3 Ensure syslog-ng default file permissions configuredCIS Amazon Linux v2.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

4.2.4 Ensure permissions on all logfiles are configuredCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

5.1.1 Ensure cron daemon is enabledCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

5.2.1 Ensure permissions on /etc/ssh/sshd_config are configuredCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

5.2.13 Ensure SSH LoginGraceTime is set to one minute or lessCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

5.3.2 Ensure lockout for failed password attempts is configured - password-auth 'auth [success=1 default=bad] pam_unix.so'CIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL