CIS Ubuntu 12.04 LTS Benchmark L2 v1.0.0

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS Ubuntu 12.04 LTS Benchmark L2 v1.0.0

Updated: 1/18/2016

Authority: CIS

Plugin: Unix

Revision: 1.2

Estimated Item Count: 66

File Details

Filename: CIS_Ubuntu_12.04_LTS_Server_v1.0.0_L2.audit

Size: 134 kB

MD5: 567c34a1be614f3cbd78a5d98ea48e84
SHA256: 8e5f08a1a3433efe892dfb14859b866cee866a4bbb34c15ccd555423cefa7e11

Audit Items

DescriptionCategories
2.18 Disable Mounting of cramfs Filesystems
2.19 Disable Mounting of freevxfs Filesystems
2.20 Disable Mounting of jffs2 Filesystems
2.21 Disable Mounting of hfs Filesystems
2.22 Disable Mounting of hfsplus Filesystems
2.23 Disable Mounting of squashfs Filesystems
2.24 Disable Mounting of udf Filesystems
4.5 Activate AppArmor - '0 processes unconfined'
4.5 Activate AppArmor - '0 profiles in complain mode'
4.5 Activate AppArmor - 'Profiles are loaded' - Review
8.1.1.1 Configure Audit Log Storage Size
8.1.1.2 Disable System on Audit Log Full - 'action_mail_acct is configured'
8.1.1.2 Disable System on Audit Log Full - 'admin_space_left_action = halt'
8.1.1.2 Disable System on Audit Log Full- 'space_left_action = email'
8.1.1.3 Keep All Auditing Information
8.1.2 Install and Enable auditd Service
8.1.3 Enable Auditing for Processes That Start Prior to auditd
8.1.4 Record Events That Modify Date and Time Information - '64bit adjtimex'
8.1.4 Record Events That Modify Date and Time Information - '64bit clock_settime'
8.1.4 Record Events That Modify Date and Time Information- '32bit adjtimex'
8.1.4 Record Events That Modify Date and Time Information- '32bit clock_settime'
8.1.4 Record Events That Modify Date and Time Information- 'time-change'
8.1.5 Record Events That Modify User/Group Information - '/etc/group'
8.1.5 Record Events That Modify User/Group Information - '/etc/gshadow'
8.1.5 Record Events That Modify User/Group Information - '/etc/passwd'
8.1.5 Record Events That Modify User/Group Information- '/etc/security/opasswd'
8.1.5 Record Events That Modify User/Group Information- '/etc/shadow'
8.1.6 Record Events That Modify the System's Network Environment - '/etc/hosts'
8.1.6 Record Events That Modify the System's Network Environment - '/etc/network'
8.1.6 Record Events That Modify the System's Network Environment- '/etc/issue.net'
8.1.6 Record Events That Modify the System's Network Environment- '/etc/issue'
8.1.6 Record Events That Modify the System's Network Environment- '32bit sethostname'
8.1.6 Record Events That Modify the System's Network Environment- '64bit sethostname'
8.1.7 Record Events That Modify the System's Mandatory Access Controls
8.1.8 Collect Login and Logout Events- '/var/log/faillog'
8.1.8 Collect Login and Logout Events- '/var/log/lastlog'
8.1.8 Collect Login and Logout Events- '/var/log/tallylog'
8.1.9 Collect Session Initiation Information- '/var/log/btmp'
8.1.9 Collect Session Initiation Information- '/var/log/wtmp'
8.1.9 Collect Session Initiation Information- '/var/run/utmp'
8.1.10 Collect Discretionary Access Control Permission Modification Events- '32bit chmod/fchmod/fchmodat'
8.1.10 Collect Discretionary Access Control Permission Modification Events- '32bit chown/fchown/fchownat/lchown'
8.1.10 Collect Discretionary Access Control Permission Modification Events- '32bit setxattr'
8.1.10 Collect Discretionary Access Control Permission Modification Events- '64bit chmod/fchmod/fchmodat'
8.1.10 Collect Discretionary Access Control Permission Modification Events- '64bit chown/fchown/fchownat/lchown'
8.1.10 Collect Discretionary Access Control Permission Modification Events- '64bit setxattr'
8.1.11 Collect Unsuccessful Unauthorized Access Attempts to Files- '32bit EACCES'
8.1.11 Collect Unsuccessful Unauthorized Access Attempts to Files- '32bit EPERM'
8.1.11 Collect Unsuccessful Unauthorized Access Attempts to Files- '64bit EACCES'
8.1.11 Collect Unsuccessful Unauthorized Access Attempts to Files- '64bit EPERM'