Example: bankruptcy

CIS Red Hat Enterprise Linux 8 Benchmark

CIS Red Hat Enterprise Linux 8 Benchmark - 09-30-2019 1 | P a g e Terms of Use Please see the below link for our current terms of use: 2 | P a g e Table of Contents Terms of Use .. 1 Overview .. 13 Intended Audience .. 13 Consensus Guidance .. 13 Typographical Conventions .. 14 Scoring Information .. 14 Profile Definitions .. 15 Acknowledgements .. 16 Recommendations .. 18 1 Initial Setup .. 18 Filesystem Configuration .. 19 Disable unused filesystems .. 20 Ensure mounting of cramfs filesystems is disabled (Scored) .. 21 Ensure mounting of vFAT filesystems is limited (Not Scored) .. 23 Ensure mounting of squashfs filesystems is disabled (Scored) .. 25 Ensure mounting of udf filesystems is disabled (Scored) .. 27 Ensure /tmp is configured (Scored) .. 29 Ensure nodev option set on /tmp partition (Scored).

1.8.1.6 Ensure permissions on /etc/issue.net are configured (Scored).....120 1.8.2 Ensure GDM login banner is configured (Scored).....121 1.9 Ensure updates, patches, and additional security software are installed

Tags:

  Security, Linux, Enterprise, Benchmark, Cis red hat enterprise linux 8 benchmark

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of CIS Red Hat Enterprise Linux 8 Benchmark

1 CIS Red Hat Enterprise Linux 8 Benchmark - 09-30-2019 1 | P a g e Terms of Use Please see the below link for our current terms of use: 2 | P a g e Table of Contents Terms of Use .. 1 Overview .. 13 Intended Audience .. 13 Consensus Guidance .. 13 Typographical Conventions .. 14 Scoring Information .. 14 Profile Definitions .. 15 Acknowledgements .. 16 Recommendations .. 18 1 Initial Setup .. 18 Filesystem Configuration .. 19 Disable unused filesystems .. 20 Ensure mounting of cramfs filesystems is disabled (Scored) .. 21 Ensure mounting of vFAT filesystems is limited (Not Scored) .. 23 Ensure mounting of squashfs filesystems is disabled (Scored) .. 25 Ensure mounting of udf filesystems is disabled (Scored) .. 27 Ensure /tmp is configured (Scored) .. 29 Ensure nodev option set on /tmp partition (Scored).

2 32 Ensure nosuid option set on /tmp partition (Scored) .. 34 Ensure noexec option set on /tmp partition (Scored) .. 36 Ensure separate partition exists for /var (Scored).. 38 Ensure separate partition exists for /var/tmp (Scored) .. 40 Ensure nodev option set on /var/tmp partition (Scored) .. 42 Ensure nosuid option set on /var/tmp partition (Scored) .. 43 Ensure noexec option set on /var/tmp partition (Scored) .. 44 Ensure separate partition exists for /var/log (Scored) .. 45 Ensure separate partition exists for /var/log/audit (Scored) .. 47 Ensure separate partition exists for /home (Scored) .. 49 Ensure nodev option set on /home partition (Scored) .. 51 3 | P a g e Ensure nodev option set on /dev/shm partition (Scored) .. 53 Ensure nosuid option set on /dev/shm partition (Scored) .. 55 Ensure noexec option set on /dev/shm partition (Scored) .. 57 Ensure nodev option set on removable media partitions (Not Scored).

3 59 Ensure nosuid option set on removable media partitions (Not Scored) .. 60 Ensure noexec option set on removable media partitions (Not Scored) .. 61 Ensure sticky bit is set on all world-writable directories (Scored) .. 62 Disable Automounting (Scored) .. 63 Disable USB Storage (Scored) .. 65 Configure Software Updates .. 67 Ensure Red Hat Subscription Manager connection is configured (Not Scored) .. 67 Disable the rhnsd Daemon (Not Scored) .. 69 Ensure GPG keys are configured (Not Scored) .. 70 Ensure gpgcheck is globally activated (Scored) .. 71 Ensure package manager repositories are configured (Not Scored) .. 72 Configure sudo .. 73 Ensure sudo is installed (Scored) .. 74 Ensure sudo commands use pty (Scored) .. 76 Ensure sudo log file exists (Scored) .. 78 Filesystem Integrity Checking .. 80 Ensure AIDE is installed (Scored) .. 81 Ensure filesystem integrity is regularly checked (Scored).

4 83 Secure Boot Settings .. 85 Ensure permissions on bootloader config are configured (Scored) .. 86 Ensure bootloader password is set (Scored) .. 88 Ensure authentication required for single user mode (Scored) .. 90 Additional Process Hardening .. 92 Ensure core dumps are restricted (Scored) .. 93 Ensure address space layout randomization (ASLR) is enabled (Scored) .. 95 Mandatory Access Control .. 97 4 | P a g e Configure SELinux .. 98 Ensure SELinux is installed (Scored) .. 100 Ensure SELinux is not disabled in bootloader configuration (Scored) .. 101 Ensure SELinux policy is configured (Scored) .. 103 Ensure the SELinux state is enforcing (Scored) .. 105 Ensure no unconfined services exist (Scored) .. 106 Ensure SETroubleshoot is not installed (Scored) .. 107 Ensure the MCS Translation Service (mcstrans) is not installed (Scored) .. 108 Warning 109 Command Line Warning Banners.

5 110 Ensure message of the day is configured properly (Scored) .. 111 Ensure local login warning banner is configured properly (Scored) .. 113 Ensure remote login warning banner is configured properly (Scored).. 115 Ensure permissions on /etc/motd are configured (Scored) .. 117 Ensure permissions on /etc/issue are configured (Scored) .. 118 Ensure permissions on / are configured (Scored) .. 120 Ensure GDM login banner is configured (Scored) .. 121 Ensure updates, patches, and additional security software are installed (Scored) .. 123 Ensure system-wide crypto policy is not legacy (Scored) .. 125 Ensure system-wide crypto policy is FUTURE or FIPS (Scored) .. 127 2 Services .. 129 inetd Services .. 130 Ensure xinetd is not installed (Scored) .. 131 Special Purpose Services .. 132 Time Synchronization .. 133 Ensure time synchronization is in use (Not Scored) .. 134 Ensure chrony is configured (Scored).

6 136 Ensure X Window System is not installed (Scored) .. 138 Ensure rsync service is not enabled (Scored) .. 139 5 | P a g e Ensure Avahi Server is not enabled (Scored) .. 141 Ensure SNMP Server is not enabled (Scored) .. 143 Ensure HTTP Proxy Server is not enabled (Scored).. 145 Ensure Samba is not enabled (Scored) .. 146 Ensure IMAP and POP3 server is not enabled (Scored) .. 147 Ensure HTTP server is not enabled (Scored) .. 149 Ensure FTP Server is not enabled (Scored) .. 151 Ensure DNS Server is not enabled (Scored) .. 153 Ensure NFS is not enabled (Scored) .. 154 Ensure RPC is not enabled (Scored).. 156 Ensure LDAP server is not enabled (Scored) .. 158 Ensure DHCP Server is not enabled (Scored) .. 160 Ensure CUPS is not enabled (Scored) .. 162 Ensure NIS Server is not enabled (Scored) .. 164 Ensure mail transfer agent is configured for local-only mode (Scored).

7 166 Service Clients .. 168 Ensure NIS Client is not installed (Scored) .. 169 Ensure telnet client is not installed (Scored) .. 171 Ensure LDAP client is not installed (Scored) .. 173 3 Network Configuration .. 174 Network Parameters (Host Only) .. 175 Ensure IP forwarding is disabled (Scored) .. 176 Ensure packet redirect sending is disabled (Scored) .. 178 Network Parameters (Host and Router) .. 180 Ensure source routed packets are not accepted (Scored) .. 181 Ensure ICMP redirects are not accepted (Scored) .. 184 Ensure secure ICMP redirects are not accepted (Scored) .. 187 Ensure suspicious packets are logged (Scored) .. 189 Ensure broadcast ICMP requests are ignored (Scored) .. 191 Ensure bogus ICMP responses are ignored (Scored) .. 193 6 | P a g e Ensure Reverse Path Filtering is enabled (Scored) .. 195 Ensure TCP SYN Cookies is enabled (Scored) .. 197 Ensure IPv6 router advertisements are not accepted (Scored).

8 199 Uncommon Network Protocols .. 201 Ensure DCCP is disabled (Scored) .. 202 Ensure SCTP is disabled (Scored) .. 203 Ensure RDS is disabled (Scored) .. 204 Ensure TIPC is disabled (Scored).. 205 Firewall Configuration .. 206 Ensure Firewall software is installed .. 207 Ensure a Firewall package is installed (Scored) .. 208 Configure 210 Ensure firewalld service is enabled and running (Scored) .. 211 Ensure iptables is not enabled (Scored) .. 213 Ensure nftables is not enabled (Scored) .. 215 Ensure default zone is set (Scored) .. 217 Ensure network interfaces are assigned to appropriate zone (Not Scored) .. 219 Ensure unnecessary services and ports are not accepted (Not Scored) .. 221 Configure nftables .. 223 Ensure iptables are flushed (Not Scored) .. 227 Ensure a table exists (Scored) .. 229 Ensure base chains exist (Scored) .. 231 Ensure loopback traffic is configured (Scored).

9 233 Ensure outbound and established connections are configured (Not Scored) .. 235 Ensure default deny firewall policy (Scored) .. 237 Ensure nftables service is enabled (Scored) .. 239 Ensure nftables rules are permanent (Scored) .. 240 Configure iptables .. 243 Ensure default deny firewall policy (Scored) .. 246 7 | P a g e Ensure loopback traffic is configured (Scored).. 248 Ensure outbound and established connections are configured (Not Scored) .. 250 Ensure firewall rules exist for all open ports (Scored) .. 252 Ensure IPv6 default deny firewall policy (Scored) .. 256 Ensure IPv6 loopback traffic is configured (Scored) .. 258 Ensure IPv6 outbound and established connections are configured (Not Scored) .. 260 Ensure IPv6 firewall rules exist for all open ports (Not Scored) .. 262 Ensure wireless interfaces are disabled (Scored) .. 265 Disable IPv6 (Not Scored).

10 267 4 Logging and Auditing .. 268 Configure System Accounting (auditd) .. 269 Ensure auditing is enabled .. 270 Ensure auditd is installed (Scored) .. 271 Ensure auditd service is enabled (Scored) .. 272 Ensure auditing for processes that start prior to auditd is enabled (Scored) .. 274 Ensure audit_backlog_limit is sufficient (Scored) .. 276 Configure Data Retention .. 278 Ensure audit log storage size is configured (Scored) .. 279 Ensure audit logs are not automatically deleted (Scored) .. 281 Ensure system is disabled when audit logs are full (Scored) .. 283 Ensure changes to system administration scope (sudoers) is collected (Scored) .. 284 Ensure login and logout events are collected (Scored) .. 286 Ensure session initiation information is collected (Scored) .. 288 Ensure events that modify date and time information are collected (Scored) .. 290 Ensure events that modify the system's Mandatory Access Controls are collected (Scored).