Item Search

NameAudit NamePluginCategory
1.2.1 Ensure package manager repositories are properly configuredCIS NGINX v3.0.0 L1 ProxyUnix

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.6.1.4 Ensure SETroubleshoot is not installedCIS Amazon Linux v2.1.0 L2Unix

CONFIGURATION MANAGEMENT

2.2.3 Ensure the NGINX service account has an invalid shellCIS NGINX v3.0.0 L1 LoadbalancerUnix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.3.2 Ensure access to NGINX directories and files is restrictedCIS NGINX v3.0.0 L1 LoadbalancerUnix

ACCESS CONTROL, MEDIA PROTECTION

2.4.1 Ensure NGINX only listens for network connections on authorized portsCIS NGINX v3.0.0 L1 ProxyUnix

PLANNING, SYSTEM AND SERVICES ACQUISITION

2.4.3 Ensure keepalive_timeout is 10 seconds or less, but not 0CIS NGINX v3.0.0 L1 LoadbalancerUnix

SYSTEM AND SERVICES ACQUISITION

2.4.4 Ensure send_timeout is set to 10 seconds or less, but not 0CIS NGINX v3.0.0 L1 ProxyUnix

SYSTEM AND SERVICES ACQUISITION

2.5.1 Ensure server_tokens directive is set to `off`CIS NGINX v3.0.0 L1 LoadbalancerUnix

SYSTEM AND SERVICES ACQUISITION

3.2 Ensure access logging is enabledCIS NGINX v3.0.0 L1 LoadbalancerUnix

AUDIT AND ACCOUNTABILITY

3.6.3 Ensure loopback traffic is configured - INPUTCIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

4.1.1.2 Ensure system is disabled when audit logs are full - 'action_mail_acct is configured'CIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.1.2 Ensure system is disabled when audit logs are full - 'space_left_action is configured'CIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.4 Ensure events that modify date and time information are collected - auditctl adjtimexCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.4 Ensure events that modify date and time information are collected - clock_settime b64CIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.5 Ensure events that modify user/group information are collected - '/etc/group'CIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.5 Ensure events that modify user/group information are collected - '/etc/security/opasswd'CIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.5 Ensure events that modify user/group information are collected - 'auditctl /etc/passwd'CIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.5 Ensure events that modify user/group information are collected - 'auditctl /etc/security/opasswd'CIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.5 Ensure events that modify user/group information are collected - 'auditctl /etc/shadow'CIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.6 Ensure awareness of TLS 1.3 new Diffie-Hellman parametersCIS NGINX v3.0.0 L1 LoadbalancerUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.1.6 Ensure events that modify the system's network environment are collected - auditctl issueCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.6 Ensure events that modify the system's network environment are collected - issue.netCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.8 Ensure login and logout events are collected - /var/run/faillock/CIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.9 Ensure session initiation information is collected - auditctl utmpCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.9 Ensure session initiation information is collected - auditctl wtmpCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.9 Ensure session initiation information is collected - btmpCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.10 Ensure discretionary access control permission modification events are collected - auditctl b64CIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.10 Ensure discretionary access control permission modification events are collected - chown/fchown/fchownat/lchownCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.11 Ensure unsuccessful unauthorized file access attempts are collected - auditctl EACCESCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.13 Ensure successful file system mounts are collected - auditctl mountsCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.16 Ensure system administrator actions (sudolog) are collectedCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.2.2.1 Ensure syslog-ng service is enabledCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

4.2.2.2 Ensure logging is configuredCIS Amazon Linux v2.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

4.2.2.5 Ensure remote syslog-ng messages are only accepted on designated log hostsCIS Amazon Linux v2.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

5.1.4 Ensure permissions on /etc/cron.daily are configuredCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

5.1.7 Ensure permissions on /etc/cron.d are configuredCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

5.1.8 Ensure at/cron is restricted to authorized users - cron.deny does not existCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

5.2.2 Ensure SSH Protocol is set to 2CIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

5.2.13 Ensure SSH LoginGraceTime is set to one minute or lessCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

5.3.1 Ensure password creation requirements are configured - try_first_passCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.3 Ensure password expiration warning days is 7 or more - login.defsCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.4 Ensure inactive password lock is 30 days or less - useraddCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

5.4.1.5 Ensure all users last password change date is in the pastCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

5.5 Ensure access to the su command is restricted - pam_wheel.soCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

5.5 Ensure access to the su command is restricted - wheel group contains rootCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

6.1.11 Ensure no unowned files or directories existCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

6.1.14 Audit SGID executablesCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

6.2.9 Ensure users own their home directoriesCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

6.2.11 Ensure no users have .forward filesCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

6.2.15 Ensure all groups in /etc/passwd exist in /etc/groupCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL