CSCv7|9.4

Title

Apply Host-based Firewalls or Port Filtering

Description

Apply host-based firewalls or port filtering tools on end systems, with a default-deny rule that drops all traffic except those services and ports that are explicitly allowed.

Reference Item Details

Category: Limitation and Control of Network Ports, Protocols, and Services

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1.2 Ensure /tmp is configuredUnixCIS Amazon Linux 2 v2.0.0 L1
1.1.2 Ensure /tmp is configuredUnixCIS CentOS 7 v3.1.1 Server L1
1.1.2 Ensure /tmp is configuredUnixCIS CentOS 7 v3.1.2 Workstation L1
1.1.2 Ensure /tmp is configuredUnixCIS Red Hat EL7 Server L1 v3.1.1
1.1.2 Ensure /tmp is configuredUnixCIS Red Hat EL7 Server L1 v3.0.1
1.1.2 Ensure /tmp is configuredUnixCIS Red Hat EL7 Workstation L1 v3.0.1
1.1.2 Ensure /tmp is configuredUnixCIS SUSE Linux Enterprise 15 Workstation L1 v1.0.0
1.1.2 Ensure /tmp is configuredUnixCIS CentOS 7 v3.1.1 Workstation L1
1.1.2 Ensure /tmp is configuredUnixCIS Oracle Linux 7 Server L1 v3.1.1
1.1.2 Ensure /tmp is configuredUnixCIS Red Hat EL7 Workstation L1 v3.1.1
1.1.2 Ensure /tmp is configuredUnixCIS Fedora 19 Family Linux Workstation L1 v1.0.0
1.1.2 Ensure /tmp is configuredUnixCIS CentOS 7 v3.1.2 Server L1
1.1.2 Ensure /tmp is configuredUnixCIS Oracle Linux 7 Workstation L1 v3.1.1
1.1.2 Ensure /tmp is configuredUnixCIS Fedora 19 Family Linux Server L1 v1.0.0
1.1.2 Ensure /tmp is configuredUnixCIS SUSE Linux Enterprise 15 Server L1 v1.0.0
1.1.2 Ensure separate partition exists for /tmpUnixCIS SUSE Linux Enterprise Workstation 11 L2 v2.1.1
1.1.2 Ensure separate partition exists for /tmpUnixCIS SUSE Linux Enterprise Server 11 L2 v2.1.1
1.2.14 Ensure that the admission control plugin SecurityContextConstraint is setOpenShiftCIS RedHat OpenShift Container Platform v1.6.0 L1
1.2.14 Ensure that the admission control plugin SecurityContextConstraint is setOpenShiftCIS RedHat OpenShift Container Platform 4 v1.4.0 L1
1.2.14 Ensure that the admission control plugin SecurityContextConstraint is setOpenShiftCIS RedHat OpenShift Container Platform 4 v1.5.0 L1
1.2.15 Ensure that the admission control plugin NodeRestriction is setOpenShiftCIS RedHat OpenShift Container Platform 4 v1.4.0 L1
1.2.15 Ensure that the admission control plugin NodeRestriction is setOpenShiftCIS RedHat OpenShift Container Platform 4 v1.5.0 L1
1.2.15 Ensure that the admission control plugin NodeRestriction is setOpenShiftCIS RedHat OpenShift Container Platform v1.6.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - AdmissionOpenShiftCIS RedHat OpenShift Container Platform 4 v1.2.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - AdmissionOpenShiftCIS RedHat OpenShift Container Platform 4 v1.3.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - Allow PrivilegedOpenShiftCIS RedHat OpenShift Container Platform 4 v1.2.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - Allow PrivilegedOpenShiftCIS RedHat OpenShift Container Platform 4 v1.3.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - anyuidOpenShiftCIS RedHat OpenShift Container Platform 4 v1.2.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - anyuidOpenShiftCIS RedHat OpenShift Container Platform 4 v1.3.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - DisabledOpenShiftCIS RedHat OpenShift Container Platform 4 v1.2.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - DisabledOpenShiftCIS RedHat OpenShift Container Platform 4 v1.3.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - hostaccessOpenShiftCIS RedHat OpenShift Container Platform 4 v1.3.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - hostaccessOpenShiftCIS RedHat OpenShift Container Platform 4 v1.2.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - hostmount-anyuidOpenShiftCIS RedHat OpenShift Container Platform 4 v1.2.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - hostmount-anyuidOpenShiftCIS RedHat OpenShift Container Platform 4 v1.3.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - hostnetworkOpenShiftCIS RedHat OpenShift Container Platform 4 v1.2.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - hostnetworkOpenShiftCIS RedHat OpenShift Container Platform 4 v1.3.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - node-exporterOpenShiftCIS RedHat OpenShift Container Platform 4 v1.2.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - node-exporterOpenShiftCIS RedHat OpenShift Container Platform 4 v1.3.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - nonrootOpenShiftCIS RedHat OpenShift Container Platform 4 v1.2.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - nonrootOpenShiftCIS RedHat OpenShift Container Platform 4 v1.3.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - OverridesOpenShiftCIS RedHat OpenShift Container Platform 4 v1.2.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - OverridesOpenShiftCIS RedHat OpenShift Container Platform 4 v1.3.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - privilegedOpenShiftCIS RedHat OpenShift Container Platform 4 v1.3.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - privilegedOpenShiftCIS RedHat OpenShift Container Platform 4 v1.2.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - restrictedOpenShiftCIS RedHat OpenShift Container Platform 4 v1.2.0 L1
1.2.16 Ensure that the admission control plugin SecurityContextConstraint is set - restrictedOpenShiftCIS RedHat OpenShift Container Platform 4 v1.3.0 L1
1.2.17 Ensure that the --insecure-port argument is set to 0OpenShiftCIS RedHat OpenShift Container Platform 4 v1.5.0 L1
1.2.17 Ensure that the --insecure-port argument is set to 0OpenShiftCIS RedHat OpenShift Container Platform 4 v1.4.0 L1
1.2.17 Ensure that the --insecure-port argument is set to 0OpenShiftCIS RedHat OpenShift Container Platform v1.6.0 L1