CIS Ubuntu Linux 18.04 LTS Server L1 v2.1.0

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS Ubuntu Linux 18.04 LTS Server L1 v2.1.0

Updated: 6/17/2024

Authority: CIS

Plugin: Unix

Revision: 1.41

Estimated Item Count: 306

File Details

Filename: CIS_Ubuntu_18.04_LTS_Server_v2.1.0_L1.audit

Size: 651 kB

MD5: 516164d7667ef94f073c3254b9d26497
SHA256: b9a6a2558b3a2fb8b37c3a14a11e2bb1899a262a5c220b051805a2b44fa52be6

Audit Items

DescriptionCategories
1.1.1.1 Ensure mounting of cramfs filesystems is disabled - lsmod
1.1.1.1 Ensure mounting of cramfs filesystems is disabled - modprobe
1.1.1.2 Ensure mounting of freevxfs filesystems is disabled - lsmod
1.1.1.2 Ensure mounting of freevxfs filesystems is disabled - modprobe
1.1.1.3 Ensure mounting of jffs2 filesystems is disabled - lsmod
1.1.1.3 Ensure mounting of jffs2 filesystems is disabled - modprobe
1.1.1.4 Ensure mounting of hfs filesystems is disabled - lsmod
1.1.1.4 Ensure mounting of hfs filesystems is disabled - modprobe
1.1.1.5 Ensure mounting of hfsplus filesystems is disabled - lsmod
1.1.1.5 Ensure mounting of hfsplus filesystems is disabled - modprobe
1.1.1.6 Ensure mounting of udf filesystems is disabled - lsmod
1.1.1.6 Ensure mounting of udf filesystems is disabled - modprobe
1.1.2 Ensure /tmp is configured
1.1.3 Ensure nodev option set on /tmp partition
1.1.4 Ensure nosuid option set on /tmp partition
1.1.5 Ensure noexec option set on /tmp partition
1.1.6 Ensure /dev/shm is configured
1.1.7 Ensure nodev option set on /dev/shm partition
1.1.8 Ensure nosuid option set on /dev/shm partition
1.1.9 Ensure noexec option set on /dev/shm partition
1.1.12 Ensure /var/tmp partition includes the nodev option
1.1.13 Ensure /var/tmp partition includes the nosuid option
1.1.14 Ensure /var/tmp partition includes the noexec option
1.1.18 Ensure /home partition includes the nodev option
1.1.19 Ensure nodev option set on removable media partitions
1.1.20 Ensure nosuid option set on removable media partitions
1.1.21 Ensure noexec option set on removable media partitions
1.1.22 Ensure sticky bit is set on all world-writable directories
1.1.23 Disable Automounting
1.1.24 Disable USB Storage - lsmod
1.1.24 Disable USB Storage - modprobe
1.2.1 Ensure package manager repositories are configured
1.2.2 Ensure GPG keys are configured
1.3.1 Ensure AIDE is installed - aide
1.3.1 Ensure AIDE is installed - aide-common
1.3.2 Ensure filesystem integrity is regularly checked
1.4.1 Ensure permissions on bootloader config are not overridden - chmod
1.4.1 Ensure permissions on bootloader config are not overridden - if line
1.4.2 Ensure bootloader password is set - 'passwd_pbkdf2'
1.4.2 Ensure bootloader password is set - 'set superusers'
1.4.3 Ensure permissions on bootloader config are configured
1.4.4 Ensure authentication required for single user mode
1.5.1 Ensure XD/NX support is enabled
1.5.2 Ensure address space layout randomization (ASLR) is enabled - config
1.5.2 Ensure address space layout randomization (ASLR) is enabled - sysctl
1.5.3 Ensure prelink is disabled
1.5.4 Ensure core dumps are restricted - limits config
1.5.4 Ensure core dumps are restricted - processsizemax
1.5.4 Ensure core dumps are restricted - storage
1.5.4 Ensure core dumps are restricted - sysctl