CIS Debian 9 Workstation L2 v1.0.0

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS Debian 9 Workstation L2 v1.0.0

Updated: 4/6/2020

Authority: CIS

Plugin: Unix

Revision: 1.3

Estimated Item Count: 130

File Details

Filename: CIS_Debian_Linux_9_Workstation_v1.0.0_L2.audit

Size: 354 kB

MD5: 73011b73b6f0dc656a0d0e08395cc99d
SHA256: ebf2744a4b6cfef9cabcf991d081965c65bddcea54606319511d6033c892b617

Audit Changelog

 
Revision 1.3

Apr 6, 2020

Miscellaneous
  • Audit deprecated.
  • Metadata updated.
Revision 1.2

Sep 9, 2019

Functional Update
  • 4.1.10 Ensure discretionary access control permission modification events are collected - auditctl chmod fchmod fchmodat
  • 4.1.10 Ensure discretionary access control permission modification events are collected - auditctl chmod fchmod fchmodat x64
  • 4.1.10 Ensure discretionary access control permission modification events are collected - auditctl chown fchown fchownat lchown
  • 4.1.10 Ensure discretionary access control permission modification events are collected - auditctl chown fchown fchownat lchown x64
  • 4.1.10 Ensure discretionary access control permission modification events are collected - auditctl lsetxattr setxattr fsetxattr removexattr
  • 4.1.10 Ensure discretionary access control permission modification events are collected - auditctl setxattr x64
  • 4.1.11 Ensure unsuccessful unauthorized file access attempts are collected - auditctl EACCES
  • 4.1.11 Ensure unsuccessful unauthorized file access attempts are collected - auditctl EACCES x64
  • 4.1.11 Ensure unsuccessful unauthorized file access attempts are collected - auditctl EPERM
  • 4.1.11 Ensure unsuccessful unauthorized file access attempts are collected - auditctl EPERM x64
  • 4.1.13 Ensure successful file system mounts are collected - auditctl mount
  • 4.1.13 Ensure successful file system mounts are collected - auditctl mount x64
  • 4.1.14 Ensure file deletion events by users are collected - auditctl delete
  • 4.1.14 Ensure file deletion events by users are collected - auditctl delete x64
  • 4.1.17 Ensure kernel module loading and unloading is collected - auditctl init_module
  • 4.1.4 Ensure events that modify date and time information are collected - auditctl adjtimex
  • 4.1.4 Ensure events that modify date and time information are collected - auditctl clock_settime
  • 4.1.4 Ensure events that modify date and time information are collected - auditctl clock_settime x64
  • 4.1.4 Ensure events that modify date and time information are collected - auditctl settimeofday,adjtimex x64
  • 4.1.6 Ensure events that modify the system's network environment are collected - /etc/sysconfig/network
  • 4.1.6 Ensure events that modify the system's network environment are collected - auditctl 'sethostname setdomainname'
  • 4.1.6 Ensure events that modify the system's network environment are collected - auditctl 'sethostname setdomainname' x64
  • 4.1.7 Ensure events that modify the system's Mandatory Access Controls are collected - auditctl /etc/apparmor
  • 4.1.7 Ensure events that modify the system's Mandatory Access Controls are collected - auditctl /etc/apparmor.d
Informational Update
  • 4.1.6 Ensure events that modify the system's network environment are collected - /etc/sysconfig/network
Added
  • 4.1.6 Ensure events that modify the system's network environment are collected - auditctl '/etc/network'
Removed
  • 4.1.6 Ensure events that modify the system's network environment are collected - auditctl '/etc/sysconfig/network'
Revision 1.1

May 21, 2019

Functional Update
  • 4.1.1.2 Ensure system is disabled when audit logs are full - space_left_action
Miscellaneous
  • References updated.