4.4.2.2.1 Ensure pam_pwquality module is enabled | CIS Amazon Linux 2 v3.0.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
4.4.2.2.5 Ensure password same consecutive characters is configured | CIS Amazon Linux 2 v3.0.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
4.4.2.4.4 Ensure pam_unix includes use_authtok | CIS Amazon Linux 2 v3.0.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
4.5.1.2 Ensure password expiration is 365 days or less | CIS Amazon Linux 2 v3.0.0 L1 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
4.5.1.3 Ensure password expiration warning days is 7 or more | CIS Amazon Linux 2 v3.0.0 L1 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
4.5.1.4 Ensure inactive password lock is 30 days or less | CIS Amazon Linux 2 v3.0.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
4.5.2.3 Ensure system accounts are secured | CIS Amazon Linux 2 v3.0.0 L1 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
4.5.3.2 Ensure default user shell timeout is configured | CIS Amazon Linux 2 v3.0.0 L1 | Unix | ACCESS CONTROL |
5.1.1.5 Ensure logging is configured | CIS Amazon Linux 2 v3.0.0 L1 | Unix | AUDIT AND ACCOUNTABILITY |
5.1.1.7 Ensure rsyslog is not configured to receive logs from a remote client | CIS Amazon Linux 2 v3.0.0 L1 | Unix | AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
6.1.5 Ensure permissions on /etc/shadow are configured | CIS Amazon Linux 2 v3.0.0 L1 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
6.2.1 Ensure accounts in /etc/passwd use shadowed passwords | CIS Amazon Linux 2 v3.0.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
autofs.service active | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
avahi | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
avahi-daemon.socket avahi-daemon.service enabled | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
CASA-VN-000240 - The Cisco ASA must be configured to use FIPS-validated SHA-2 or higher for Internet Key Exchange (IKE) Phase 2. | DISA STIG Cisco ASA VPN v2r2 | Cisco | SYSTEM AND COMMUNICATIONS PROTECTION |
Check for IPv6 | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
config file permitrootlogin setting | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
Disabled accounts | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
dnsmasq.service active | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
Ensure at least one file named /etc/libuser.conf exists and matches pattern | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
Ensure at least one file named /etc/login.defs exists and matches pattern | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
firewalld check - enabled | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
firewalld check - in use | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
firewalld check - installed | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
hook output | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
ip6 saddr ::1 | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
ip6tables | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
ip6tables active | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
ip6tables list | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
iptables | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
Loopback on Port 465 | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
minclass | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
mrsv not included in /etc/issue.net | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
named.service active | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
Old format InputTCPServerRun | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
password-auth authfail deny | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
password-auth authfail unlock_time | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
review open ports and ip6tables rules | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
rpcbind exist | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
samba services exist | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
sshd maxsessions setting | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
sshd_config | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
system-auth authfail | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
system-auth pam_faillock | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
system-auth preauth | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
system-auth preauth deny | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
Trusted Cert | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
xinetd.service enabled | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |
ypserv.service active | CIS Amazon Linux 2 v3.0.0 L1 | Unix | |