Revision 1.6Jan 6, 2025
Informational Update
- 1.1.1.1 Ensure mounting of cramfs filesystems is disabled
- 1.1.1.2 Ensure mounting of freevxfs filesystems is disabled
- 1.1.1.3 Ensure mounting of jffs2 filesystems is disabled
- 1.1.1.4 Ensure mounting of hfs filesystems is disabled
- 1.1.1.5 Ensure mounting of hfsplus filesystems is disabled
- 1.1.10 Disable USB Storage
- 1.8.2 Ensure GDM login banner is configured
- 1.8.5 Ensure GDM screen locks cannot be overridden
- 1.8.6 Ensure GDM automatic mounting of removable media is disabled
- 1.8.7 Ensure GDM disabling automatic mounting of removable media is not overridden
- 1.8.8 Ensure GDM autorun-never is enabled
- 1.8.9 Ensure GDM autorun-never is not overridden
- 2.1.3.1 Ensure systemd-timesyncd configured with authorized timeserver
- 3.1.2 Ensure wireless interfaces are disabled
- 4.1.8 Ensure cron is restricted to authorized users
- 4.1.9 Ensure at is restricted to authorized users
- 4.2.2 Ensure access to SSH key files is configured
- 4.4.5 Ensure all current passwords uses the configured hashing algorithm
- 4.5.2 Ensure system accounts are secured
- 5.1.3 Ensure all logfiles have appropriate access configured
- 6.1.10 Ensure world writable files and directories are secured
- 6.1.9 Ensure permissions on /etc/security/opasswd are configured
- 6.2.10 Ensure local interactive user dot files access is configured
- 6.2.9 Ensure local interactive user home directories are configured