CIS Debian 9 Server L2 v1.0.0

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS Debian 9 Server L2 v1.0.0

Updated: 4/6/2020

Authority: CIS

Plugin: Unix

Revision: 1.3

Estimated Item Count: 128

File Details

Filename: CIS_Debian_Linux_9_Server_v1.0.0_L2.audit

Size: 351 kB

MD5: 95c1462eba85ef66be045a40e1175c45
SHA256: 4fe995717f9f327985091c75953830bc1c776eeb650ef1c84e556b8d11f57d1f

Audit Changelog

 
Revision 1.3

Apr 6, 2020

Miscellaneous
  • Audit deprecated.
  • Metadata updated.
Revision 1.2

Sep 9, 2019

Functional Update
  • 4.1.10 Ensure discretionary access control permission modification events are collected - auditctl chmod fchmod fchmodat
  • 4.1.10 Ensure discretionary access control permission modification events are collected - auditctl chmod fchmod fchmodat x64
  • 4.1.10 Ensure discretionary access control permission modification events are collected - auditctl chown fchown fchownat lchown
  • 4.1.10 Ensure discretionary access control permission modification events are collected - auditctl chown fchown fchownat lchown x64
  • 4.1.10 Ensure discretionary access control permission modification events are collected - auditctl lsetxattr setxattr fsetxattr removexattr
  • 4.1.10 Ensure discretionary access control permission modification events are collected - auditctl setxattr x64
  • 4.1.11 Ensure unsuccessful unauthorized file access attempts are collected - auditctl EACCES
  • 4.1.11 Ensure unsuccessful unauthorized file access attempts are collected - auditctl EACCES x64
  • 4.1.11 Ensure unsuccessful unauthorized file access attempts are collected - auditctl EPERM
  • 4.1.11 Ensure unsuccessful unauthorized file access attempts are collected - auditctl EPERM x64
  • 4.1.13 Ensure successful file system mounts are collected - auditctl mount
  • 4.1.13 Ensure successful file system mounts are collected - auditctl mount x64
  • 4.1.14 Ensure file deletion events by users are collected - auditctl delete
  • 4.1.14 Ensure file deletion events by users are collected - auditctl delete x64
  • 4.1.17 Ensure kernel module loading and unloading is collected - auditctl init_module
  • 4.1.4 Ensure events that modify date and time information are collected - auditctl adjtimex
  • 4.1.4 Ensure events that modify date and time information are collected - auditctl clock_settime
  • 4.1.4 Ensure events that modify date and time information are collected - auditctl clock_settime x64
  • 4.1.4 Ensure events that modify date and time information are collected - auditctl settimeofday,adjtimex x64
  • 4.1.6 Ensure events that modify the system's network environment are collected - /etc/sysconfig/network
  • 4.1.6 Ensure events that modify the system's network environment are collected - auditctl 'sethostname setdomainname'
  • 4.1.6 Ensure events that modify the system's network environment are collected - auditctl 'sethostname setdomainname' x64
  • 4.1.7 Ensure events that modify the system's Mandatory Access Controls are collected - auditctl /etc/apparmor
  • 4.1.7 Ensure events that modify the system's Mandatory Access Controls are collected - auditctl /etc/apparmor.d
Informational Update
  • 4.1.6 Ensure events that modify the system's network environment are collected - /etc/sysconfig/network
Added
  • 4.1.6 Ensure events that modify the system's network environment are collected - auditctl '/etc/network'
Removed
  • 4.1.6 Ensure events that modify the system's network environment are collected - auditctl '/etc/sysconfig/network'
Revision 1.1

May 21, 2019

Functional Update
  • 4.1.1.2 Ensure system is disabled when audit logs are full - space_left_action
Miscellaneous
  • References updated.