Item Search

NameAudit NamePluginCategory
1.1 Ensure packages are obtained from authorized repositoriesCIS PostgreSQL 9.5 OS v1.1.0Unix

CONFIGURATION MANAGEMENT

2.1 Ensure the file permissions mask is correctCIS PostgreSQL 9.5 OS v1.1.0Unix

ACCESS CONTROL

2.2 Ensure the PostgreSQL pg_wheel group membership is correct - /etc/groupsCIS PostgreSQL 9.5 OS v1.1.0Unix

ACCESS CONTROL

2.3 Disable RPC Encryption KeyCIS Solaris 11.1 L1 v1.0.0Unix
2.5 Disable NIS Client Services - clientCIS Solaris 11.1 L1 v1.0.0Unix
2.11 Configure TCP Wrappers - hosts.allowCIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

2.11 Configure TCP Wrappers - hosts.denyCIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1 Restrict Core Dumps to Protected Directory - global core file contentCIS Solaris 11.1 L1 v1.0.0Unix

ACCESS CONTROL

3.1.3 Ensure the logging collector is enabledCIS PostgreSQL 9.6 DB v1.0.0PostgreSQLDB

AUDIT AND ACCOUNTABILITY

3.1.6 Ensure the log file permissions are set correctlyCIS PostgreSQL 9.5 DB v1.1.0PostgreSQLDB

ACCESS CONTROL

3.1.7 Ensure 'log_truncate_on_rotation' is enabledCIS PostgreSQL 9.6 DB v1.0.0PostgreSQLDB

AUDIT AND ACCOUNTABILITY

3.1.8 Ensure the maximum log file lifetime is set correctlyCIS PostgreSQL 9.6 DB v1.0.0PostgreSQLDB

AUDIT AND ACCOUNTABILITY

3.1.9 Ensure the maximum log file size is set correctlyCIS PostgreSQL 9.5 DB v1.1.0PostgreSQLDB

AUDIT AND ACCOUNTABILITY

3.1.13 Ensure the correct SQL statements generating errors are recordedCIS PostgreSQL 9.6 DB v1.0.0PostgreSQLDB

AUDIT AND ACCOUNTABILITY

3.1.18 Ensure 'log_connections' is enabledCIS PostgreSQL 9.6 DB v1.0.0PostgreSQLDB

AUDIT AND ACCOUNTABILITY

3.1.22 Ensure 'log_line_prefix' is set correctlyCIS PostgreSQL 9.6 DB v1.0.0PostgreSQLDB

AUDIT AND ACCOUNTABILITY

3.1.24 Ensure 'log_timezone' is set correctlyCIS PostgreSQL 9.6 DB v1.0.0PostgreSQLDB

AUDIT AND ACCOUNTABILITY

3.2 Enable Stack Protection - set noexec_user_stack = 1CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

3.2 Enable Stack Protection - set noexec_user_stack_log = 1CIS Solaris 11.1 L1 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

3.3 Enable Strong TCP Sequence Number Generation - TCP_STRONG_ISS = 2CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.4 Disable Source Packet Forwarding - persistent ipv4 = 0CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.4 Disable Source Packet Forwarding - persistent ipv6 = 0CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.7 Disable Response to ICMP Broadcast Timestamp Requests - current ip = 0CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.8 Disable Response to ICMP Broadcast Netmask Requests - persistent ip = 0CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.11 Ignore ICMP Redirect Messages - persistent ipv4 = 1CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.14 Disable TCP Reverse IP Source Routing - persistent tcp = 0CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.17 Disable Network Routing - ipv4-forwarding persistent = disabledCIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

4.1 Ensure sudo is configured correctlyCIS PostgreSQL 9.6 OS v1.0.0Unix

ACCESS CONTROL

4.3 Ensure excessive function privileges are revokedCIS PostgreSQL 9.6 DB v1.0.0PostgreSQLDB

ACCESS CONTROL

5.2 Ensure login via 'host' TCP/IP Socket is configured correctlyCIS PostgreSQL 9.5 OS v1.1.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

5.2 Ensure login via 'host' TCP/IP Socket is configured correctlyCIS PostgreSQL 9.6 OS v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

6.1 Ensure 'Attack Vectors' Runtime Parameters are ConfiguredCIS PostgreSQL 9.6 DB v1.0.0PostgreSQLDB

CONFIGURATION MANAGEMENT

6.2 Disable 'nobody' Access for RPC Encryption Key Storage ServiceCIS Solaris 11.1 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

6.3 Disable X11 Forwarding for SSH - X11Forwarding = noCIS Solaris 11.1 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

6.6 Ensure 'User' Runtime Parameters are ConfiguredCIS PostgreSQL 9.5 DB v1.1.0PostgreSQLDB

ACCESS CONTROL

6.11 Remove Autologin Capabilities from the GNOME desktop - pam.d/gdm-autologinCIS Solaris 11.1 L1 v1.0.0Unix

ACCESS CONTROL

6.15 Set Retry Limit for Account Lockout - RETRIES = 3CIS Solaris 11.1 L1 v1.0.0Unix

ACCESS CONTROL

6.17 Secure the GRUB Menu (Intel) - grub.cfg timeout = 30CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

7.1 Ensure SSL Certificates are Configured For Replication - ssl key fileCIS PostgreSQL 9.6 DB v1.0.0PostgreSQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

7.4 Ensure WAL archiving is configured and functional - archive_modeCIS PostgreSQL 9.6 OS v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

8.3 Ensure the backup and restore tool, 'pgBackRest', is installed and configuredCIS PostgreSQL 9.5 OS v1.1.0Unix

CONTINGENCY PLANNING

8.4 Ensure miscellaneous configuration settings are correctCIS PostgreSQL 9.5 DB v1.1.0PostgreSQLDB

CONFIGURATION MANAGEMENT

9.4 Verify No Legacy '+' Entries Exist in passwd, shadow, and group Files - Check for shadow.CIS Solaris 10 L1 v5.2Unix

CONFIGURATION MANAGEMENT

9.5 Verify that no UID 0 accounts exist other than rootCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

9.8 Check User Dot File Permissions. Please audit the results of this check and take action in accordance with corporate policy.CIS Solaris 10 L1 v5.2Unix
9.25 Find Files and Directories with Extended AttributesCIS Solaris 10 L1 v5.2Unix
10.1 Enable process accounting at boot timeCIS Solaris 10 L2 v5.2Unix
11.1 Samba: Enable SSH Port Forwarding in Web Admin ToolCIS Solaris 10 L2 v5.2Unix

CONFIGURATION MANAGEMENT

11.6 Samba: Set Secure smb.conf File Options - permissionsCIS Solaris 10 L2 v5.2Unix
11.7 sendmail: Set Secure Logfile Ownership to the root UserCIS Solaris 10 L2 v5.2Unix