800-53|SI-7(9)

Title

VERIFY BOOT PROCESS

Description

The information system verifies the integrity of the boot process of [Assignment: organization-defined devices].

Supplemental

Ensuring the integrity of boot processes is critical to starting devices in known/trustworthy states. Integrity verification mechanisms provide organizational personnel with assurance that only trusted code is executed during boot processes.

Reference Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

Parent Title: SOFTWARE, FIRMWARE, AND INFORMATION INTEGRITY

Family: SYSTEM AND INFORMATION INTEGRITY

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.2.1 Use an EFI passwordUnixCIS Apple OSX 10.6 Snow Leopard L2 v1.0.0
1.2.3.9 Set 'Choose the boot-start drivers that can be initialized:' to 'Enabled:Good, unknown and bad but critical'WindowsCIS Windows 8 L1 v1.0.0
1.2.4.2.2.28 Set 'Minimum characters:' to 'Enabled:7 or more characters'WindowsCIS Windows 8 L1 v1.0.0
1.4.1 Enable SELinux in /etc/grub.conf 'enforcing != 0'UnixCIS Red Hat Enterprise Linux 5 L2 v2.2
1.4.1 Enable SELinux in /etc/grub.conf 'selinux != 0'UnixCIS Red Hat Enterprise Linux 5 L2 v2.2
1.4.1 Ensure permissions on bootloader config are configuredUnixCIS Amazon Linux v2.1.0 L1
1.4.1 Ensure permissions on bootloader config are configuredUnixCIS Ubuntu Linux 16.04 LTS Workstation L1 v1.1.0
1.4.1 Ensure permissions on bootloader config are configuredUnixCIS Oracle Linux 6 Server L1 v1.1.0
1.4.1 Ensure permissions on bootloader config are configuredUnixCIS Debian 8 Server L1 v2.0.1
1.4.1 Ensure permissions on bootloader config are configuredUnixCIS Amazon Linux 2 v1.0.0 L1
1.4.1 Ensure permissions on bootloader config are configuredUnixCIS CentOS 6 Server L1 v2.1.0
1.4.1 Ensure permissions on bootloader config are configuredUnixCIS Oracle Linux 6 Workstation L1 v1.1.0
1.4.1 Ensure permissions on bootloader config are configuredUnixCIS SUSE Linux Enterprise Workstation 11 L1 v2.1.1
1.4.1 Ensure permissions on bootloader config are configuredUnixCIS Ubuntu Linux 14.04 LTS Workstation L1 v2.1.0
1.4.1 Ensure permissions on bootloader config are configuredUnixCIS SUSE Linux Enterprise Workstation 12 L1 v2.1.0
1.4.1 Ensure permissions on bootloader config are configuredUnixCIS Red Hat 6 Server L1 v2.1.0
1.4.1 Ensure permissions on bootloader config are configuredUnixCIS Red Hat 6 Workstation L1 v2.1.0
1.4.1 Ensure permissions on bootloader config are configuredUnixCIS Ubuntu Linux 14.04 LTS Server L1 v2.1.0
1.4.1 Ensure permissions on bootloader config are configuredUnixCIS Debian 8 Workstation L1 v2.0.1
1.4.1 Ensure permissions on bootloader config are configuredUnixCIS CentOS 6 Workstation L1 v2.1.0
1.4.1 Ensure permissions on bootloader config are configuredUnixCIS SUSE Linux Enterprise Server 11 L1 v2.1.1
1.4.1 Ensure permissions on bootloader config are configuredUnixCIS SUSE Linux Enterprise Server 12 L1 v2.1.0
1.4.1 Ensure permissions on bootloader config are configuredUnixCIS Ubuntu Linux 16.04 LTS Server L1 v1.1.0
1.4.2 Ensure authentication required for single user modeUnixCIS Amazon Linux v2.1.0 L1
1.4.2 Ensure authentication required for single user mode - emergency.serviceUnixCIS Amazon Linux 2 v1.0.0 L1
1.4.2 Ensure authentication required for single user mode - rescue.serviceUnixCIS Amazon Linux 2 v1.0.0 L1
1.4.2 Ensure bootloader password is setUnixCIS CentOS 6 Server L1 v2.1.0
1.4.2 Ensure bootloader password is setUnixCIS Red Hat 6 Server L1 v2.1.0
1.4.2 Ensure bootloader password is setUnixCIS Oracle Linux 6 Server L1 v1.1.0
1.4.2 Ensure bootloader password is setUnixCIS Red Hat 6 Workstation L1 v2.1.0
1.4.2 Ensure bootloader password is setUnixCIS CentOS 6 Workstation L1 v2.1.0
1.4.2 Ensure bootloader password is setUnixCIS Oracle Linux 6 Workstation L1 v1.1.0
1.4.2 Ensure bootloader password is set - 'passwd_pbkdf2'UnixCIS Ubuntu Linux 16.04 LTS Server L1 v1.1.0
1.4.2 Ensure bootloader password is set - 'passwd_pbkdf2'UnixCIS Ubuntu Linux 16.04 LTS Workstation L1 v1.1.0
1.4.2 Ensure bootloader password is set - 'set superusers'UnixCIS Ubuntu Linux 16.04 LTS Server L1 v1.1.0
1.4.2 Ensure bootloader password is set - 'set superusers'UnixCIS Ubuntu Linux 16.04 LTS Workstation L1 v1.1.0
1.4.2 Ensure bootloader password is set - password_pbkdf2UnixCIS SUSE Linux Enterprise Server 12 L1 v2.1.0
1.4.2 Ensure bootloader password is set - password_pbkdf2UnixCIS SUSE Linux Enterprise Workstation 12 L1 v2.1.0
1.4.2 Ensure bootloader password is set - password_pbkdf2UnixCIS Debian 8 Workstation L1 v2.0.1
1.4.2 Ensure bootloader password is set - password_pbkdf2UnixCIS Debian 8 Server L1 v2.0.1
1.4.2 Ensure bootloader password is set - set superusersUnixCIS Debian 8 Workstation L1 v2.0.1
1.4.2 Ensure bootloader password is set - set superusersUnixCIS Debian 8 Server L1 v2.0.1
1.4.2 Ensure bootloader password is set - superusersUnixCIS SUSE Linux Enterprise Server 12 L1 v2.1.0
1.4.2 Ensure bootloader password is set - superusersUnixCIS SUSE Linux Enterprise Workstation 12 L1 v2.1.0
1.4.3 Ensure authentication required for single user mode - emergencyUnixCIS SUSE Linux Enterprise Workstation 12 L1 v2.1.0
1.4.3 Ensure authentication required for single user mode - emergencyUnixCIS SUSE Linux Enterprise Server 12 L1 v2.1.0
1.4.3 Ensure authentication required for single user mode - rescueUnixCIS SUSE Linux Enterprise Workstation 12 L1 v2.1.0
1.4.3 Ensure authentication required for single user mode - rescueUnixCIS SUSE Linux Enterprise Server 12 L1 v2.1.0
1.4.3 Ensure authentication required for single user mode - rescue.serviceUnixCIS CentOS 6 Server L1 v2.1.0
1.4.3 Ensure authentication required for single user mode - rescue.serviceUnixCIS Oracle Linux 6 Server L1 v1.1.0