Item Search

NameAudit NamePluginCategory
'*.=warning;*.=err -/var/log/warn'CIS Amazon Linux 2 v3.0.0 L1Unix
'*.crit /var/log/warn'CIS Amazon Linux 2 v3.0.0 L1Unix
'cron.* /var/log/cron'CIS Amazon Linux 2 v3.0.0 L1Unix
'mail.info -/var/log/mail.info'CIS Amazon Linux 2 v3.0.0 L1Unix
/etc/at.allow file permissionsCIS Amazon Linux 2 v3.0.0 L1Unix
/etc/motd existCIS Amazon Linux 2 v3.0.0 L1Unix
/etc/systemd/journald.confCIS Amazon Linux 2 v3.0.0 L1Unix
1.1.1.5 Ensure jffs2 kernel module is not availableCIS Amazon Linux 2 v3.0.0 L1Unix

CONFIGURATION MANAGEMENT

1.1.2.2.1 Ensure /dev/shm is a separate partitionCIS Amazon Linux 2 v3.0.0 L1Unix

CONFIGURATION MANAGEMENT

1.1.2.2.4 Ensure noexec option set on /dev/shm partitionCIS Amazon Linux 2 v3.0.0 L1Unix

ACCESS CONTROL, MEDIA PROTECTION

1.1.2.5.3 Ensure nosuid option set on /var/tmp partitionCIS Amazon Linux 2 v3.0.0 L1Unix

ACCESS CONTROL, MEDIA PROTECTION

1.2.4 Ensure package manager repositories are configuredCIS Amazon Linux 2 v3.0.0 L1Unix

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.4.1 Ensure address space layout randomization (ASLR) is enabledCIS Amazon Linux 2 v3.0.0 L1Unix

SYSTEM AND INFORMATION INTEGRITY

1.5.1.3 Ensure SELinux policy is configuredCIS Amazon Linux 2 v3.0.0 L1Unix

ACCESS CONTROL, MEDIA PROTECTION

1.6.2 Ensure local login warning banner is configured properlyCIS Amazon Linux 2 v3.0.0 L1Unix

ACCESS CONTROL

1.6.4 Ensure access to /etc/motd is configuredCIS Amazon Linux 2 v3.0.0 L1Unix

ACCESS CONTROL, MEDIA PROTECTION

1.6.6 Ensure access to /etc/issue.net is configuredCIS Amazon Linux 2 v3.0.0 L1Unix

ACCESS CONTROL, MEDIA PROTECTION

2.2.3 Ensure dhcp server services are not in useCIS Amazon Linux 2 v3.0.0 L1Unix

CONFIGURATION MANAGEMENT

2.2.6 Ensure samba file server services are not in useCIS Amazon Linux 2 v3.0.0 L1Unix

CONFIGURATION MANAGEMENT

2.2.10 Ensure nis server services are not in useCIS Amazon Linux 2 v3.0.0 L1Unix

CONFIGURATION MANAGEMENT

2.3.5 Ensure tftp client is not installedCIS Amazon Linux 2 v3.0.0 L1Unix

CONFIGURATION MANAGEMENT

3.3.2 Ensure packet redirect sending is disabledCIS Amazon Linux 2 v3.0.0 L1Unix

CONFIGURATION MANAGEMENT

3.3.3 Ensure bogus icmp responses are ignoredCIS Amazon Linux 2 v3.0.0 L1Unix

CONFIGURATION MANAGEMENT

3.3.4 Ensure broadcast icmp requests are ignoredCIS Amazon Linux 2 v3.0.0 L1Unix

CONFIGURATION MANAGEMENT

3.3.5 Ensure icmp redirects are not acceptedCIS Amazon Linux 2 v3.0.0 L1Unix

CONFIGURATION MANAGEMENT

3.3.8 Ensure source routed packets are not acceptedCIS Amazon Linux 2 v3.0.0 L1Unix

CONFIGURATION MANAGEMENT

3.3.11 Ensure ipv6 router advertisements are not acceptedCIS Amazon Linux 2 v3.0.0 L1Unix

CONFIGURATION MANAGEMENT

3.4.1.2 Ensure a single firewall configuration utility is in useCIS Amazon Linux 2 v3.0.0 L1Unix

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.4.2.4 Ensure network interfaces are assigned to appropriate zoneCIS Amazon Linux 2 v3.0.0 L1Unix

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.4.3.4 Ensure nftables base chains existCIS Amazon Linux 2 v3.0.0 L1Unix

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.4.3.8 Ensure nftables service is enabled and activeCIS Amazon Linux 2 v3.0.0 L1Unix

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.2.6 Ensure sshd Ciphers are configuredCIS Amazon Linux 2 v3.0.0 L1Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.2.14 Ensure sshd LogLevel is configuredCIS Amazon Linux 2 v3.0.0 L1Unix

AUDIT AND ACCOUNTABILITY

4.3.2 Ensure sudo commands use ptyCIS Amazon Linux 2 v3.0.0 L1Unix

ACCESS CONTROL

4.4.2.1.1 Ensure pam_faillock module is enabledCIS Amazon Linux 2 v3.0.0 L1Unix

ACCESS CONTROL

4.4.2.1.2 Ensure password failed attempts lockout is configuredCIS Amazon Linux 2 v3.0.0 L1Unix

ACCESS CONTROL

5.3.4 Ensure password hashing algorithm is SHA-512 - password-authCIS Aliyun Linux 2 L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.2 Ensure minimum days between password changes is 7 or more - usersCIS Aliyun Linux 2 L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.4 Ensure inactive password lock is 30 days or less - usersCIS Aliyun Linux 2 L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.4 Ensure default user umask is 027 or more restrictive - /etc/profile /etc/profile.d/*.shCIS Aliyun Linux 2 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

6.1.9 Ensure permissions on /etc/gshadow- are configuredCIS Aliyun Linux 2 L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

6.2.1 Ensure password fields are not emptyCIS Aliyun Linux 2 L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

6.2.5 Ensure root is the only UID 0 accountCIS Aliyun Linux 2 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

6.2.13 Ensure users' .netrc Files are not group or world accessibleCIS Aliyun Linux 2 L1 v1.0.0Unix

ACCESS CONTROL

6.2.17 Ensure no duplicate GIDs existCIS Aliyun Linux 2 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

6.2.19 Ensure no duplicate group names existCIS Aliyun Linux 2 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

Check if Postfix is installedCIS Aliyun Linux 2 L1 v1.0.0Unix
Check NTP installedCIS Aliyun Linux 2 L1 v1.0.0Unix
Check writable dirs in root path variableCIS Aliyun Linux 2 L1 v1.0.0Unix
Ensure ntp is configured - ExecStartCIS Aliyun Linux 2 L1 v1.0.0Unix