CIS Bottlerocket L1

Audit Details

Name: CIS Bottlerocket L1

Updated: 6/17/2024

Authority: CIS

Plugin: Unix

Revision: 1.1

Estimated Item Count: 14

File Details

Filename: CIS_Bottlerocket_v1.0.0_L1.audit

Size: 32.2 kB

MD5: ec6e163b893c6206f61ee7c8c29d535b
SHA256: 5af5f67149df4ee3935860c1fd511a0572b53806f3a82444daaa6faa27d4008a

Audit Items

DescriptionCategories
1.2.1 Ensure software update repositories are configured

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.3.1 Ensure dm-verity is configured

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

1.4.1 Ensure setuid programs do not create core dumps

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

1.4.2 Ensure address space layout randomization (ASLR) is enabled

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

1.4.3 Ensure unprivileged eBPF is disabled

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

1.5.1 Ensure SELinux is configured

ACCESS CONTROL, MEDIA PROTECTION

1.6 Ensure updates, patches, and additional security software are installed

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

2.1.1.1 Ensure chrony is configured

AUDIT AND ACCOUNTABILITY

3.2.5 Ensure broadcast ICMP requests are ignored

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

3.2.6 Ensure bogus ICMP responses are ignored

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

3.2.7 Ensure TCP SYN Cookies is enabled

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

4.1.1.1 Ensure journald is configured to write logfiles to persistent disk

AUDIT AND ACCOUNTABILITY

4.1.2 Ensure permissions on journal files are configured

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

CIS_Bottlerocket_v1.0.0_L1.audit from CIS Bottlerocket Benchmark Level 1