Item Search

NameAudit NamePluginCategory
1.1.6 Ensure separate partition exists for /varCIS Amazon Linux v2.1.0 L2Unix

CONFIGURATION MANAGEMENT

1.1.13 Ensure separate partition exists for /homeCIS Amazon Linux v2.1.0 L2Unix

CONFIGURATION MANAGEMENT

1.6.1.6 Ensure no unconfined daemons existCIS Amazon Linux v2.1.0 L2Unix

ACCESS CONTROL

2.2.1 Ensure that NGINX is run using a non-privileged, dedicated service accountCIS NGINX v3.0.0 L1 LoadbalancerUnix

ACCESS CONTROL

2.3.2 Ensure access to NGINX directories and files is restrictedCIS NGINX v3.0.0 L1 ProxyUnix

ACCESS CONTROL, MEDIA PROTECTION

2.3.3 Ensure the NGINX process ID (PID) file is securedCIS NGINX v3.0.0 L1 LoadbalancerUnix

ACCESS CONTROL, MEDIA PROTECTION

2.3.3 Ensure the NGINX process ID (PID) file is securedCIS NGINX v3.0.0 L1 ProxyUnix

ACCESS CONTROL, MEDIA PROTECTION

2.4.1 Ensure NGINX only listens for network connections on authorized portsCIS NGINX v3.0.0 L1 LoadbalancerUnix

PLANNING, SYSTEM AND SERVICES ACQUISITION

3.2 Ensure access logging is enabledCIS NGINX v3.0.0 L1 ProxyUnix

AUDIT AND ACCOUNTABILITY

4.1.1.2 Ensure system is disabled when audit logs are full - 'admin_space_left_action'CIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.3 Ensure private key permissions are restrictedCIS NGINX v3.0.0 L1 ProxyUnix

ACCESS CONTROL, MEDIA PROTECTION

4.1.4 Ensure events that modify date and time information are collected - auditctl localtimeCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.4 Ensure events that modify date and time information are collected - clock_settime b32CIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.4 Ensure events that modify date and time information are collected - time-changeCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.5 Disable weak ciphersCIS NGINX v3.0.0 L1 LoadbalancerUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.1.5 Ensure events that modify user/group information are collected - 'auditctl /etc/gshadow'CIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.6 Ensure events that modify the system's network environment are collected - 64b sethostnameCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.6 Ensure events that modify the system's network environment are collected - issueCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.7 Ensure Online Certificate Status Protocol (OCSP) stapling is enabledCIS NGINX v3.0.0 L1 LoadbalancerUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.1.9 Ensure session initiation information is collected - auditctl btmpCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.10 Ensure discretionary access control permission modification events are collected - auditctl b64 chmod/fchmod/fchmodatCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.10 Ensure discretionary access control permission modification events are collected - auditctl b64 chown/fchown/fchownat/lchownCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.10 Ensure discretionary access control permission modification events are collected - auditctl chown/fchown/fchownat/lchownCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.10 Ensure discretionary access control permission modification events are collected - chmod/fchmod/fchmodatCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.11 Ensure unsuccessful unauthorized file access attempts are collected - auditctl b64 EACCESCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.11 Ensure unsuccessful unauthorized file access attempts are collected - b64 EACCESCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.11 Ensure unsuccessful unauthorized file access attempts are collected - EACCESCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.14 Ensure file deletion events by users are collectedCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.15 Ensure changes to system administration scope (sudoers) is collected - auditctl /etc/sudoersCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

5.1.2 Ensure only approved HTTP methods are allowedCIS NGINX v3.0.0 L1 LoadbalancerUnix

PLANNING, SYSTEM AND SERVICES ACQUISITION

5.2.9 Ensure SSH PermitEmptyPasswords is disabledCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

5.3.1 Ensure password creation requirements are configured - dcreditCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

5.3.1 Ensure password creation requirements are configured - retry=3CIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

5.3.2 Ensure lockout for failed password attempts is configured - password-auth 'auth required pam_faillock.so preauth audit silent deny=5 unlock_time=900'CIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

5.3.2 Ensure lockout for failed password attempts is configured - system-auth 'auth sufficient pam_faillock.so authsucc audit deny=5 unlock_time=900'CIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

5.3.3 Ensure password reuse is limited - password-authCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

5.3.3 Ensure password reuse is limited - system-authCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

5.3.4 Ensure password hashing algorithm is SHA-512 - system-authCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.4.1.1 Ensure password expiration is 365 days or less - login.defsCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.2 Ensure minimum days between password changes is 7 or more - login.defsCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

6.1.1 Audit system file permissionsCIS Amazon Linux v2.1.0 L2Unix

SYSTEM AND INFORMATION INTEGRITY

6.1.3 Ensure permissions on /etc/shadow are configuredCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

6.1.7 Ensure permissions on /etc/shadow- are configuredCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

6.1.8 Ensure permissions on /etc/group- are configuredCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

6.1.9 Ensure permissions on /etc/gshadow- are configuredCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

6.1.10 Ensure no world writable files existCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

6.2.2 Ensure no legacy '+' entries exist in /etc/passwdCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

6.2.3 Ensure no legacy '+' entries exist in /etc/shadowCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

6.2.5 Ensure root is the only UID 0 accountCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

6.2.8 Ensure users' home directories permissions are 750 or more restrictiveCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT