CMMC Coverage Report
Summary
Detail
Paper Policy
The following controls require administrative documentation:
CentOS 7 (8/209 [3%])
- oval:simp.cis.3.1.2.CentOS7.1.1.10_Ensure_separate_partition_exists_for_var:def:1
- Title: Ensure separate partition exists for /var
- NOTE: There is no way to safely change this on a running system.
- oval:simp.cis.3.1.2.CentOS7.1.1.11_Ensure_separate_partition_exists_for_vartmp:def:1
- Title: Ensure separate partition exists for /var/tmp
- NOTE: There is no way to safely change this on a running system.
- oval:simp.cis.3.1.2.CentOS7.1.1.17_Ensure_separate_partition_exists_for_home:def:1
- Title: Ensure separate partition exists for /home
- NOTE: There is no way to safely change this on a running system.
- oval:simp.cis.3.1.2.CentOS7.6.1.10_Ensure_no_world_writable_files_exist:def:1
- Title: Ensure no world writable files exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
- oval:simp.cis.3.1.2.CentOS7.6.1.13_Audit_SUID_executables:def:1
- Title: Audit SUID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
- oval:simp.cis.3.1.2.CentOS7.6.1.14_Audit_SGID_executables:def:1
- Title: Audit SGID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
- oval:simp.cis.3.1.2.CentOS7.6.1.1_Audit_system_file_permissions:def:1
- Title: Audit system file permissions
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
- oval:simp.cis.3.1.2.CentOS7.1.6.1.6_Ensure_no_unconfined_services_exist:def:1
- Title: Ensure no unconfined services exist
- NOTE: We have no viable method of remediation.
CentOS 8 (17/233 [7%])
- oval:simp.cis.2.0.0.CentOS8.4.2.2.7_Ensure_journald_default_file_permissions_configured:def:1
- Title: Ensure journald default file permissions configured
- NOTE: This is site-specific and cannot be managed by the product
- oval:simp.cis.2.0.0.CentOS8.6.1.11_Ensure_no_world_writable_files_exist:def:1
- Title: Ensure no world writable files exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
- oval:simp.cis.2.0.0.CentOS8.6.1.14_Audit_SUID_executables:def:1
- Title: Audit SUID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
- oval:simp.cis.2.0.0.CentOS8.6.1.15_Audit_SGID_executables:def:1
- Title: Audit SGID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
- oval:simp.cis.2.0.0.CentOS8.1.1.3.1_Ensure_separate_partition_exists_for_var:def:1
- Title: Ensure separate partition exists for /var
- NOTE: There is no way to safely change this on a running system.
- oval:simp.cis.2.0.0.CentOS8.1.1.4.1_Ensure_separate_partition_exists_for_vartmp:def:1
- Title: Ensure separate partition exists for /var/tmp
- NOTE: There is no way to safely change this on a running system.
- oval:simp.cis.2.0.0.CentOS8.1.1.7.1_Ensure_separate_partition_exists_for_home:def:1
- Title: Ensure separate partition exists for /home
- NOTE: There is no way to safely change this on a running system.
- oval:simp.cis.2.0.0.CentOS8.1.1.7.4_Ensure_usrquota_option_set_on_home_partition:def:1
- Title: Ensure usrquota option set on /home partition
- NOTE: Since mountpoints cannot be safely managed automatically, this option will not be set by the product.
- oval:simp.cis.2.0.0.CentOS8.1.1.7.5_Ensure_grpquota_option_set_on_home_partition:def:1
- Title: Ensure grpquota option set on /home partition
- NOTE: Since mountpoints cannot be safely managed automatically, this option will not be set by the product.
- oval:simp.cis.2.0.0.CentOS8.6.1.1_Audit_system_file_permissions:def:1
- Title: Audit system file permissions
- NOTE: The product doesn’t have the capability to run and identify discrepencies in the output of an audit run. The product also cannot accept any risk on behalf of the user.
- oval:simp.cis.2.0.0.CentOS8.5.3.4_Ensure_users_must_provide_password_for_escalation:def:1
- Title: Ensure users must provide password for escalation
- NOTE: Users had to make a conscious decision to set “NOPASSWD” in sudoers on a running system. Automatically undoing these settings could negatively impact the system.
- oval:simp.cis.2.0.0.CentOS8.5.3.5_Ensure_re-authentication_for_privilege_escalation_is_not_disabled_globally:def:1
- Title: Ensure re-authentication for privilege escalation is not disabled globally
- NOTE: Users had to make a conscious decision to set “!authenticate” in sudoers on a running system. Automatically undoing these settings could negatively impact the system.
- oval:simp.cis.2.0.0.CentOS8.4.2.1.3_Ensure_journald_is_configured_to_send_logs_to_rsyslog:def:1
- Title: Ensure journald is configured to send logs to rsyslog
- NOTE: The rules request that journald both be configured to send logs to rsyslog and to not send logs to rsyslog. Since the rules directly conflict with each other, the product will enforce the rule that doesn’t rely on the existence and configuration of an rsyslog server with highly system-specific configuration.
- oval:simp.cis.2.0.0.CentOS8.4.2.1.6_Ensure_rsyslog_is_configured_to_send_logs_to_a_remote_log_host:def:1
- Title: Ensure rsyslog is configured to send logs to a remote log host
- NOTE: This is specific to the organization and can not be set by our product.
- oval:simp.cis.2.0.0.CentOS8.4.2.2.1.2_Ensure_systemd-journal-remote_is_configured:def:1
- Title: Ensure systemd-journal-remote is configured
- NOTE: This is specific to the organization and can not be set by our product.
- oval:simp.cis.2.0.0.CentOS8.4.2.2.1.3_Ensure_systemd-journal-remote_is_enabled:def:1
- Title: Ensure systemd-journal-remote is enabled
- NOTE: The product cannot appropriately configure the systemd-journald-remote service because it is highly system-specific. Since the product cannot configure the service, it cannot control whether the service runs or not.
- oval:simp.cis.2.0.0.CentOS8.1.6.1.6_Ensure_no_unconfined_services_exist:def:1
- Title: Ensure no unconfined services exist
- NOTE: We have no viable method of remediation.
OracleLinux 7 (8/209 [3%])
- oval:simp.cis.3.1.1.OracleLinux7.1.1.10_Ensure_separate_partition_exists_for_var:def:1
- Title: Ensure separate partition exists for /var
- NOTE: There is no way to safely change this on a running system.
- oval:simp.cis.3.1.1.OracleLinux7.1.1.11_Ensure_separate_partition_exists_for_vartmp:def:1
- Title: Ensure separate partition exists for /var/tmp
- NOTE: There is no way to safely change this on a running system.
- oval:simp.cis.3.1.1.OracleLinux7.1.1.17_Ensure_separate_partition_exists_for_home:def:1
- Title: Ensure separate partition exists for /home
- NOTE: There is no way to safely change this on a running system.
- oval:simp.cis.3.1.1.OracleLinux7.6.1.10_Ensure_no_world_writable_files_exist:def:1
- Title: Ensure no world writable files exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
- oval:simp.cis.3.1.1.OracleLinux7.6.1.13_Audit_SUID_executables:def:1
- Title: Audit SUID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
- oval:simp.cis.3.1.1.OracleLinux7.6.1.14_Audit_SGID_executables:def:1
- Title: Audit SGID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
- oval:simp.cis.3.1.1.OracleLinux7.6.1.1_Audit_system_file_permissions:def:1
- Title: Audit system file permissions
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
- oval:simp.cis.3.1.1.OracleLinux7.1.6.1.6_Ensure_no_unconfined_services_exist:def:1
- Title: Ensure no unconfined services exist
- NOTE: We have no viable method of remediation.
OracleLinux 8 (18/231 [7%])
- oval:simp.cis.2.0.0.OracleLinux8.4.2.2.7_Ensure_journald_default_file_permissions_configured:def:1
- Title: Ensure journald default file permissions configured
- NOTE: This is site-specific and cannot be managed by the product
- oval:simp.cis.2.0.0.OracleLinux8.6.1.11_Ensure_no_world_writable_files_exist:def:1
- Title: Ensure no world writable files exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
- oval:simp.cis.2.0.0.OracleLinux8.6.1.14_Audit_SUID_executables:def:1
- Title: Audit SUID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
- oval:simp.cis.2.0.0.OracleLinux8.6.1.15_Audit_SGID_executables:def:1
- Title: Audit SGID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
- oval:simp.cis.2.0.0.OracleLinux8.1.1.3.1_Ensure_separate_partition_exists_for_var:def:1
- Title: Ensure separate partition exists for /var
- NOTE: There is no way to safely change this on a running system.
- oval:simp.cis.2.0.0.OracleLinux8.1.1.4.1_Ensure_separate_partition_exists_for_vartmp:def:1
- Title: Ensure separate partition exists for /var/tmp
- NOTE: There is no way to safely change this on a running system.
- oval:simp.cis.2.0.0.OracleLinux8.1.1.7.1_Ensure_separate_partition_exists_for_home:def:1
- Title: Ensure separate partition exists for /home
- NOTE: There is no way to safely change this on a running system.
- oval:simp.cis.2.0.0.OracleLinux8.1.1.7.4_Ensure_usrquota_option_set_on_home_partition:def:1
- Title: Ensure usrquota option set on /home partition
- NOTE: Since mountpoints cannot be safely managed automatically, this option will not be set by the product.
- oval:simp.cis.2.0.0.OracleLinux8.1.1.7.5_Ensure_grpquota_option_set_on_home_partition:def:1
- Title: Ensure grpquota option set on /home partition
- NOTE: Since mountpoints cannot be safely managed automatically, this option will not be set by the product.
- oval:simp.cis.2.0.0.OracleLinux8.6.1.1_Audit_system_file_permissions:def:1
- Title: Audit system file permissions
- NOTE: The product doesn’t have the capability to run and identify discrepencies in the output of an audit run. The product also cannot accept any risk on behalf of the user.
- oval:simp.cis.2.0.0.OracleLinux8.5.2.4_Ensure_SSH_access_is_limited:def:1
- Title: Ensure SSH access is limited
- NOTE: The product cannot reliably determine the users or groups that need to access a given system, this configuration will be system-specific and could lock legitimate users out if assumptions are made.
- oval:simp.cis.2.0.0.OracleLinux8.5.3.4_Ensure_users_must_provide_password_for_escalation:def:1
- Title: Ensure users must provide password for escalation
- NOTE: Users had to make a conscious decision to set “NOPASSWD” in sudoers on a running system. Automatically undoing these settings could negatively impact the system.
- oval:simp.cis.2.0.0.OracleLinux8.5.3.5_Ensure_re-authentication_for_privilege_escalation_is_not_disabled_globally:def:1
- Title: Ensure re-authentication for privilege escalation is not disabled globally
- NOTE: Users had to make a conscious decision to set “!authenticate” in sudoers on a running system. Automatically undoing these settings could negatively impact the system.
- oval:simp.cis.2.0.0.OracleLinux8.4.2.1.3_Ensure_journald_is_configured_to_send_logs_to_rsyslog:def:1
- Title: Ensure journald is configured to send logs to rsyslog
- NOTE: The rules request that journald both be configured to send logs to rsyslog and to not send logs to rsyslog. Since the rules directly conflict with each other, the product will enforce the rule that doesn’t rely on the existence and configuration of an rsyslog server with highly system-specific configuration.
- oval:simp.cis.2.0.0.OracleLinux8.4.2.1.6_Ensure_rsyslog_is_configured_to_send_logs_to_a_remote_log_host:def:1
- Title: Ensure rsyslog is configured to send logs to a remote log host
- NOTE: This is specific to the organization and can not be set by our product.
- oval:simp.cis.2.0.0.OracleLinux8.4.2.2.1.2_Ensure_systemd-journal-remote_is_configured:def:1
- Title: Ensure systemd-journal-remote is configured
- NOTE: This is specific to the organization and can not be set by our product.
- oval:simp.cis.2.0.0.OracleLinux8.4.2.2.1.3_Ensure_systemd-journal-remote_is_enabled:def:1
- Title: Ensure systemd-journal-remote is enabled
- NOTE: The product cannot appropriately configure the systemd-journald-remote service because it is highly system-specific. Since the product cannot configure the service, it cannot control whether the service runs or not.
- oval:simp.cis.2.0.0.OracleLinux8.1.6.1.6_Ensure_no_unconfined_services_exist:def:1
- Title: Ensure no unconfined services exist
- NOTE: We have no viable method of remediation.
RedHat 7 (8/210 [3%])
- oval:simp.cis.3.1.1.RedHat7.1.1.10_Ensure_separate_partition_exists_for_var:def:1
- Title: Ensure separate partition exists for /var
- NOTE: There is no way to safely change this on a running system.
- oval:simp.cis.3.1.1.RedHat7.1.1.11_Ensure_separate_partition_exists_for_vartmp:def:1
- Title: Ensure separate partition exists for /var/tmp
- NOTE: There is no way to safely change this on a running system.
- oval:simp.cis.3.1.1.RedHat7.1.1.17_Ensure_separate_partition_exists_for_home:def:1
- Title: Ensure separate partition exists for /home
- NOTE: There is no way to safely change this on a running system.
- oval:simp.cis.3.1.1.RedHat7.6.1.10_Ensure_no_world_writable_files_exist:def:1
- Title: Ensure no world writable files exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
- oval:simp.cis.3.1.1.RedHat7.6.1.13_Audit_SUID_executables:def:1
- Title: Audit SUID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
- oval:simp.cis.3.1.1.RedHat7.6.1.14_Audit_SGID_executables:def:1
- Title: Audit SGID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
- oval:simp.cis.3.1.1.RedHat7.6.1.1_Audit_system_file_permissions:def:1
- Title: Audit system file permissions
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
- oval:simp.cis.3.1.1.RedHat7.1.6.1.6_Ensure_no_unconfined_services_exist:def:1
- Title: Ensure no unconfined services exist
- NOTE: We have no viable method of remediation.
RedHat 8 (18/233 [7%])
- oval:simp.cis.2.0.0.RedHat8.4.2.2.7_Ensure_journald_default_file_permissions_configured:def:1
- Title: Ensure journald default file permissions configured
- NOTE: This is site-specific and cannot be managed by the product
- oval:simp.cis.2.0.0.RedHat8.6.1.11_Ensure_no_world_writable_files_exist:def:1
- Title: Ensure no world writable files exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
- oval:simp.cis.2.0.0.RedHat8.6.1.14_Audit_SUID_executables:def:1
- Title: Audit SUID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
- oval:simp.cis.2.0.0.RedHat8.6.1.15_Audit_SGID_executables:def:1
- Title: Audit SGID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
- oval:simp.cis.2.0.0.RedHat8.1.1.3.1_Ensure_separate_partition_exists_for_var:def:1
- Title: Ensure separate partition exists for /var
- NOTE: There is no way to safely change this on a running system.
- oval:simp.cis.2.0.0.RedHat8.1.1.4.1_Ensure_separate_partition_exists_for_vartmp:def:1
- Title: Ensure separate partition exists for /var/tmp
- NOTE: There is no way to safely change this on a running system.
- oval:simp.cis.2.0.0.RedHat8.1.1.7.1_Ensure_separate_partition_exists_for_home:def:1
- Title: Ensure separate partition exists for /home
- NOTE: There is no way to safely change this on a running system.
- oval:simp.cis.2.0.0.RedHat8.1.1.7.4_Ensure_usrquota_option_set_on_home_partition:def:1
- Title: Ensure usrquota option set on /home partition
- NOTE: Since mountpoints cannot be safely managed automatically, this option will not be set by the product.
- oval:simp.cis.2.0.0.RedHat8.1.1.7.5_Ensure_grpquota_option_set_on_home_partition:def:1
- Title: Ensure grpquota option set on /home partition
- NOTE: Since mountpoints cannot be safely managed automatically, this option will not be set by the product.
- oval:simp.cis.2.0.0.RedHat8.6.1.1_Audit_system_file_permissions:def:1
- Title: Audit system file permissions
- NOTE: The product doesn’t have the capability to run and identify discrepencies in the output of an audit run. The product also cannot accept any risk on behalf of the user.
- oval:simp.cis.2.0.0.RedHat8.5.2.4_Ensure_SSH_access_is_limited:def:1
- Title: Ensure SSH access is limited
- NOTE: The product cannot reliably determine the users or groups that need to access a given system, this configuration will be system-specific and could lock legitimate users out if assumptions are made.
- oval:simp.cis.2.0.0.RedHat8.5.3.4_Ensure_users_must_provide_password_for_escalation:def:1
- Title: Ensure users must provide password for escalation
- NOTE: Users had to make a conscious decision to set “NOPASSWD” in sudoers on a running system. Automatically undoing these settings could negatively impact the system.
- oval:simp.cis.2.0.0.RedHat8.5.3.5_Ensure_re-authentication_for_privilege_escalation_is_not_disabled_globally:def:1
- Title: Ensure re-authentication for privilege escalation is not disabled globally
- NOTE: Users had to make a conscious decision to set “!authenticate” in sudoers on a running system. Automatically undoing these settings could negatively impact the system.
- oval:simp.cis.2.0.0.RedHat8.4.2.1.3_Ensure_journald_is_configured_to_send_logs_to_rsyslog:def:1
- Title: Ensure journald is configured to send logs to rsyslog
- NOTE: The rules request that journald both be configured to send logs to rsyslog and to not send logs to rsyslog. Since the rules directly conflict with each other, the product will enforce the rule that doesn’t rely on the existence and configuration of an rsyslog server with highly system-specific configuration.
- oval:simp.cis.2.0.0.RedHat8.4.2.1.6_Ensure_rsyslog_is_configured_to_send_logs_to_a_remote_log_host:def:1
- Title: Ensure rsyslog is configured to send logs to a remote log host
- NOTE: This is specific to the organization and can not be set by our product.
- oval:simp.cis.2.0.0.RedHat8.4.2.2.1.2_Ensure_systemd-journal-remote_is_configured:def:1
- Title: Ensure systemd-journal-remote is configured
- NOTE: This is specific to the organization and can not be set by our product.
- oval:simp.cis.2.0.0.RedHat8.4.2.2.1.3_Ensure_systemd-journal-remote_is_enabled:def:1
- Title: Ensure systemd-journal-remote is enabled
- NOTE: The product cannot appropriately configure the systemd-journald-remote service because it is highly system-specific. Since the product cannot configure the service, it cannot control whether the service runs or not.
- oval:simp.cis.2.0.0.RedHat8.1.6.1.6_Ensure_no_unconfined_services_exist:def:1
- Title: Ensure no unconfined services exist
- NOTE: We have no viable method of remediation.
Mapped
The following controls are mapped:
CentOS 7 (201/209 [96%])
- oval:simp.cis.3.1.2.CentOS7.1.1.1.1_Ensure_mounting_of_cramfs_filesystems_is_disabled:def:1
- Title: Ensure mounting of cramfs filesystems is disabled
- oval:simp.cis.3.1.2.CentOS7.1.1.1.2_Ensure_mounting_of_squashfs_filesystems_is_disabled:def:1
- Title: Ensure mounting of squashfs filesystems is disabled
- oval:simp.cis.3.1.2.CentOS7.1.1.1.3_Ensure_mounting_of_udf_filesystems_is_disabled:def:1
- Title: Ensure mounting of udf filesystems is disabled
- oval:simp.cis.3.1.2.CentOS7.1.1.4_Ensure_nodev_option_set_on_tmp_partition:def:1
- Title: Ensure nodev option set on /tmp partition
- oval:simp.cis.3.1.2.CentOS7.1.1.5_Ensure_nosuid_option_set_on_tmp_partition:def:1
- Title: Ensure nosuid option set on /tmp partition
- oval:simp.cis.3.1.2.CentOS7.1.1.6_Ensure_devshm_is_configured:def:1
- Title: Ensure /dev/shm is configured
- oval:simp.cis.3.1.2.CentOS7.1.1.8_Ensure_nodev_option_set_on_devshm_partition:def:1
- Title: Ensure nodev option set on /dev/shm partition
- oval:simp.cis.3.1.2.CentOS7.1.1.9_Ensure_nosuid_option_set_on_devshm_partition:def:1
- Title: Ensure nosuid option set on /dev/shm partition
- oval:simp.cis.3.1.2.CentOS7.1.1.13_Ensure_vartmp_partition_includes_the_nodev_option:def:1
- Title: Ensure /var/tmp partition includes the nodev option
- oval:simp.cis.3.1.2.CentOS7.1.1.14_Ensure_vartmp_partition_includes_the_nosuid_option:def:1
- Title: Ensure /var/tmp partition includes the nosuid option
- oval:simp.cis.3.1.2.CentOS7.1.1.18_Ensure_home_partition_includes_the_nodev_option:def:1
- Title: Ensure /home partition includes the nodev option
- oval:simp.cis.3.1.2.CentOS7.1.1.20_Ensure_nodev_option_set_on_removable_media_partitions:def:1
- Title: Ensure nodev option set on removable media partitions
- oval:simp.cis.3.1.2.CentOS7.1.1.21_Ensure_nosuid_option_set_on_removable_media_partitions:def:1
- Title: Ensure nosuid option set on removable media partitions
- oval:simp.cis.3.1.2.CentOS7.1.1.22_Ensure_sticky_bit_is_set_on_all_world-writable_directories:def:1
- Title: Ensure sticky bit is set on all world-writable directories
- oval:simp.cis.3.1.2.CentOS7.1.4.1_Ensure_bootloader_password_is_set:def:1
- Title: Ensure bootloader password is set
- oval:simp.cis.3.1.2.CentOS7.1.4.2_Ensure_permissions_on_bootloader_config_are_configured:def:1
- Title: Ensure permissions on bootloader config are configured
- oval:simp.cis.3.1.2.CentOS7.1.4.3_Ensure_authentication_required_for_single_user_mode:def:1
- Title: Ensure authentication required for single user mode
- oval:simp.cis.3.1.2.CentOS7.1.5.1_Ensure_core_dumps_are_restricted:def:1
- Title: Ensure core dumps are restricted
- oval:simp.cis.3.1.2.CentOS7.1.7.1_Ensure_message_of_the_day_is_configured_properly:def:1
- Title: Ensure message of the day is configured properly
- oval:simp.cis.3.1.2.CentOS7.1.7.2_Ensure_local_login_warning_banner_is_configured_properly:def:1
- Title: Ensure local login warning banner is configured properly
- oval:simp.cis.3.1.2.CentOS7.1.7.3_Ensure_remote_login_warning_banner_is_configured_properly:def:1
- Title: Ensure remote login warning banner is configured properly
- oval:simp.cis.3.1.2.CentOS7.1.8.2_Ensure_GDM_login_banner_is_configured:def:1
- Title: Ensure GDM login banner is configured
- oval:simp.cis.3.1.2.CentOS7.1.8.3_Ensure_last_logged_in_user_display_is_disabled:def:1
- Title: Ensure last logged in user display is disabled
- oval:simp.cis.3.1.2.CentOS7.3.2.1_Ensure_IP_forwarding_is_disabled:def:1
- Title: Ensure IP forwarding is disabled
- oval:simp.cis.3.1.2.CentOS7.3.2.2_Ensure_packet_redirect_sending_is_disabled:def:1
- Title: Ensure packet redirect sending is disabled
- oval:simp.cis.3.1.2.CentOS7.3.3.1_Ensure_source_routed_packets_are_not_accepted:def:1
- Title: Ensure source routed packets are not accepted
- oval:simp.cis.3.1.2.CentOS7.3.3.2_Ensure_ICMP_redirects_are_not_accepted:def:1
- Title: Ensure ICMP redirects are not accepted
- oval:simp.cis.3.1.2.CentOS7.3.3.3_Ensure_secure_ICMP_redirects_are_not_accepted:def:1
- Title: Ensure secure ICMP redirects are not accepted
- oval:simp.cis.3.1.2.CentOS7.3.3.5_Ensure_broadcast_ICMP_requests_are_ignored:def:1
- Title: Ensure broadcast ICMP requests are ignored
- oval:simp.cis.3.1.2.CentOS7.3.3.6_Ensure_bogus_ICMP_responses_are_ignored:def:1
- Title: Ensure bogus ICMP responses are ignored
- oval:simp.cis.3.1.2.CentOS7.3.3.7_Ensure_Reverse_Path_Filtering_is_enabled:def:1
- Title: Ensure Reverse Path Filtering is enabled
- oval:simp.cis.3.1.2.CentOS7.3.3.8_Ensure_TCP_SYN_Cookies_is_enabled:def:1
- Title: Ensure TCP SYN Cookies is enabled
- oval:simp.cis.3.1.2.CentOS7.3.3.9_Ensure_IPv6_router_advertisements_are_not_accepted:def:1
- Title: Ensure IPv6 router advertisements are not accepted
- oval:simp.cis.3.1.2.CentOS7.4.1.16_Ensure_kernel_module_loading_and_unloading_is_collected:def:1
- Title: Ensure kernel module loading and unloading is collected
- oval:simp.cis.3.1.2.CentOS7.4.2.1.3_Ensure_rsyslog_default_file_permissions_configured:def:1
- Title: Ensure rsyslog default file permissions configured
- oval:simp.cis.3.1.2.CentOS7.4.2.3_Ensure_permissions_on_all_logfiles_are_configured:def:1
- Title: Ensure permissions on all logfiles are configured
- oval:simp.cis.3.1.2.CentOS7.5.1.1_Ensure_cron_daemon_is_enabled_and_running:def:1
- Title: Ensure cron daemon is enabled and running
- oval:simp.cis.3.1.2.CentOS7.5.1.3_Ensure_permissions_on_etccron.hourly_are_configured:def:1
- Title: Ensure permissions on /etc/cron.hourly are configured
- oval:simp.cis.3.1.2.CentOS7.5.3.12_Ensure_SSH_PermitUserEnvironment_is_disabled:def:1
- Title: Ensure SSH PermitUserEnvironment is disabled
- oval:simp.cis.3.1.2.CentOS7.5.3.17_Ensure_SSH_LoginGraceTime_is_set_to_one_minute_or_less:def:1
- Title: Ensure SSH LoginGraceTime is set to one minute or less
- oval:simp.cis.3.1.2.CentOS7.5.3.18_Ensure_SSH_warning_banner_is_configured:def:1
- Title: Ensure SSH warning banner is configured
- oval:simp.cis.3.1.2.CentOS7.5.3.19_Ensure_SSH_PAM_is_enabled:def:1
- Title: Ensure SSH PAM is enabled
- oval:simp.cis.3.1.2.CentOS7.5.3.21_Ensure_SSH_MaxStartups_is_configured:def:1
- Title: Ensure SSH MaxStartups is configured
- oval:simp.cis.3.1.2.CentOS7.5.3.22_Ensure_SSH_MaxSessions_is_limited:def:1
- Title: Ensure SSH MaxSessions is limited
- oval:simp.cis.3.1.2.CentOS7.5.5.3_Ensure_default_group_for_the_root_account_is_GID_0:def:1
- Title: Ensure default group for the root account is GID 0
- oval:simp.cis.3.1.2.CentOS7.5.5.5_Ensure_default_user_umask_is_configured:def:1
- Title: Ensure default user umask is configured
- NOTE: The umask will be set to 027 within /etc/profile.d/simp.sh, however, this check still fails the scan.
- oval:simp.cis.3.1.2.CentOS7.5.6_Ensure_root_login_is_restricted_to_system_console:def:1
- Title: Ensure root login is restricted to system console
- oval:simp.cis.3.1.2.CentOS7.5.7_Ensure_access_to_the_su_command_is_restricted:def:1
- Title: Ensure access to the su command is restricted
- oval:simp.cis.3.1.2.CentOS7.6.2.4_Ensure_shadow_group_is_empty:def:1
- Title: Ensure shadow group is empty
- oval:simp.cis.3.1.2.CentOS7.6.2.9_Ensure_root_is_the_only_UID_0_account:def:1
- Title: Ensure root is the only UID 0 account
- oval:simp.cis.3.1.2.CentOS7.6.2.10_Ensure_root_PATH_Integrity:def:1
- Title: Ensure root PATH Integrity
- oval:simp.cis.3.1.2.CentOS7.6.2.11_Ensure_all_users_home_directories_exist:def:1
- Title: Ensure all users’ home directories exist
- oval:simp.cis.3.1.2.CentOS7.6.2.15Ensure_no_users_have.forward_files:def:1
- Title: Ensure no users have .forward files
- oval:simp.cis.3.1.2.CentOS7.1.6.1.1_Ensure_SELinux_is_installed:def:1
- Title: Ensure SELinux is installed
- oval:simp.cis.3.1.2.CentOS7.1.6.1.2_Ensure_SELinux_is_not_disabled_in_bootloader_configuration:def:1
- Title: Ensure SELinux is not disabled in bootloader configuration
- oval:simp.cis.3.1.2.CentOS7.1.6.1.3_Ensure_SELinux_policy_is_configured:def:1
- Title: Ensure SELinux policy is configured
- oval:simp.cis.3.1.2.CentOS7.1.6.1.4_Ensure_the_SELinux_mode_is_enforcing_or_permissive:def:1
- Title: Ensure the SELinux mode is enforcing or permissive
- oval:simp.cis.3.1.2.CentOS7.1.6.1.5_Ensure_the_SELinux_mode_is_enforcing:def:1
- Title: Ensure the SELinux mode is enforcing
- oval:simp.cis.3.1.2.CentOS7.1.6.1.7_Ensure_SETroubleshoot_is_not_installed:def:1
- Title: Ensure SETroubleshoot is not installed
- oval:simp.cis.3.1.2.CentOS7.1.7.4_Ensure_permissions_on_etcmotd_are_configured:def:1
- Title: Ensure permissions on /etc/motd are configured
- oval:simp.cis.3.1.2.CentOS7.1.7.5_Ensure_permissions_on_etcissue_are_configured:def:1
- Title: Ensure permissions on /etc/issue are configured
- oval:simp.cis.3.1.2.CentOS7.1.7.6_Ensure_permissions_on_etcissue.net_are_configured:def:1
- Title: Ensure permissions on /etc/issue.net are configured
- oval:simp.cis.3.1.2.CentOS7.5.1.2_Ensure_permissions_on_etccrontab_are_configured:def:1
- Title: Ensure permissions on /etc/crontab are configured
- oval:simp.cis.3.1.2.CentOS7.5.1.4_Ensure_permissions_on_etccron.daily_are_configured:def:1
- Title: Ensure permissions on /etc/cron.daily are configured
- oval:simp.cis.3.1.2.CentOS7.5.1.5_Ensure_permissions_on_etccron.weekly_are_configured:def:1
- Title: Ensure permissions on /etc/cron.weekly are configured
- oval:simp.cis.3.1.2.CentOS7.5.1.6_Ensure_permissions_on_etccron.monthly_are_configured:def:1
- Title: Ensure permissions on /etc/cron.monthly are configured
- oval:simp.cis.3.1.2.CentOS7.5.1.7_Ensure_permissions_on_etccron.d_are_configured:def:1
- Title: Ensure permissions on /etc/cron.d are configured
- oval:simp.cis.3.1.2.CentOS7.5.3.1_Ensure_permissions_on_etcsshsshd_config_are_configured:def:1
- Title: Ensure permissions on /etc/ssh/sshd_config are configured
- oval:simp.cis.3.1.2.CentOS7.5.3.2_Ensure_permissions_on_SSH_private_host_key_files_are_configured:def:1
- Title: Ensure permissions on SSH private host key files are configured
- oval:simp.cis.3.1.2.CentOS7.5.3.3_Ensure_permissions_on_SSH_public_host_key_files_are_configured:def:1
- Title: Ensure permissions on SSH public host key files are configured
- oval:simp.cis.3.1.2.CentOS7.6.1.2_Ensure_permissions_on_etcpasswd_are_configured:def:1
- Title: Ensure permissions on /etc/passwd are configured
- oval:simp.cis.3.1.2.CentOS7.6.1.3_Ensure_permissions_on_etcpasswd-_are_configured:def:1
- Title: Ensure permissions on /etc/passwd- are configured
- oval:simp.cis.3.1.2.CentOS7.6.1.4_Ensure_permissions_on_etcshadow_are_configured:def:1
- Title: Ensure permissions on /etc/shadow are configured
- oval:simp.cis.3.1.2.CentOS7.6.1.5_Ensure_permissions_on_etcshadow-_are_configured:def:1
- Title: Ensure permissions on /etc/shadow- are configured
- oval:simp.cis.3.1.2.CentOS7.6.1.7_Ensure_permissions_on_etcgshadow_are_configured:def:1
- Title: Ensure permissions on /etc/gshadow are configured
- oval:simp.cis.3.1.2.CentOS7.6.1.8_Ensure_permissions_on_etcgroup_are_configured:def:1
- Title: Ensure permissions on /etc/group are configured
- oval:simp.cis.3.1.2.CentOS7.6.1.9_Ensure_permissions_on_etcgroup-_are_configured:def:1
- Title: Ensure permissions on /etc/group- are configured
- oval:simp.cis.3.1.2.CentOS7.6.2.12_Ensure_users_own_their_home_directories:def:1
- Title: Ensure users own their home directories
- oval:simp.cis.3.1.2.CentOS7.6.2.13_Ensure_users_home_directories_permissions_are_750_or_more_restrictive:def:1
- Title: Ensure users’ home directories permissions are 750 or more restrictive
- oval:simp.cis.3.1.2.CentOS7.6.2.14_Ensure_users_dot_files_are_not_group_or_world_writable:def:1
- Title: Ensure users’ dot files are not group or world writable
- oval:simp.cis.3.1.2.CentOS7.5.5.1.4_Ensure_inactive_password_lock_is_30_days_or_less:def:1
- Title: Ensure inactive password lock is 30 days or less
- oval:simp.cis.3.1.2.CentOS7.4.1.7_Ensure_login_and_logout_events_are_collected:def:1
- Title: Ensure login and logout events are collected
- oval:simp.cis.3.1.2.CentOS7.4.1.8_Ensure_session_initiation_information_is_collected:def:1
- Title: Ensure session initiation information is collected
- oval:simp.cis.3.1.2.CentOS7.5.3.16_Ensure_SSH_Idle_Timeout_Interval_is_configured:def:1
- Title: Ensure SSH Idle Timeout Interval is configured
- oval:simp.cis.3.1.2.CentOS7.5.5.4_Ensure_default_user_shell_timeout_is_configured:def:1
- Title: Ensure default user shell timeout is configured
-
*NOTE: The scanner fails to pickup on the format the product uses for setting the timeout: [ $TMOUT ] |
|
export TMOUT=900. The setting is also set in a nonstandard location: /etc/profile.d/simp.sh.* |
- oval:simp.cis.3.1.2.CentOS7.1.1.23_Disable_Automounting:def:1
- Title: Disable Automounting
- oval:simp.cis.3.1.2.CentOS7.1.1.24_Disable_USB_Storage:def:1
- Title: Disable USB Storage
- oval:simp.cis.3.1.2.CentOS7.5.3.4_Ensure_SSH_access_is_limited:def:1
- Title: Ensure SSH access is limited
- oval:simp.cis.3.1.2.CentOS7.5.3.10_Ensure_SSH_root_login_is_disabled:def:1
- Title: Ensure SSH root login is disabled
- oval:simp.cis.3.1.2.CentOS7.3.1.2_Ensure_wireless_interfaces_are_disabled:def:1
- Title: Ensure wireless interfaces are disabled
- oval:simp.cis.3.1.2.CentOS7.3.3.4_Ensure_suspicious_packets_are_logged:def:1
- Title: Ensure suspicious packets are logged
- oval:simp.cis.3.1.2.CentOS7.4.1.1.1_Ensure_auditd_is_installed:def:1
- Title: Ensure auditd is installed
- oval:simp.cis.3.1.2.CentOS7.4.1.1.2_Ensure_auditd_service_is_enabled_and_running:def:1
- Title: Ensure auditd service is enabled and running
- oval:simp.cis.3.1.2.CentOS7.4.1.1.3_Ensure_auditing_for_processes_that_start_prior_to_auditd_is_enabled:def:1
- Title: Ensure auditing for processes that start prior to auditd is enabled
- oval:simp.cis.3.1.2.CentOS7.4.1.2.2_Ensure_audit_logs_are_not_automatically_deleted:def:1
- Title: Ensure audit logs are not automatically deleted
- oval:simp.cis.3.1.2.CentOS7.4.1.2.3_Ensure_system_is_disabled_when_audit_logs_are_full:def:1
- Title: Ensure system is disabled when audit logs are full
- oval:simp.cis.3.1.2.CentOS7.4.1.2.4_Ensure_audit_backlog_limit_is_sufficient:def:1
- Title: Ensure audit_backlog_limit is sufficient
- oval:simp.cis.3.1.2.CentOS7.4.1.5_Ensure_events_that_modify_the_systems_network_environment_are_collected:def:1
- Title: Ensure events that modify the system’s network environment are collected
- oval:simp.cis.3.1.2.CentOS7.4.1.11_Ensure_use_of_privileged_commands_is_collected:def:1
- Title: Ensure use of privileged commands is collected
- NOTE: The available setuid/setgid commands on a given system could vary greatly. Several of the more common commands are audited, but there is currently no automated way to identify and audit all possible setuid/setgid commands available on any given system.
- oval:simp.cis.3.1.2.CentOS7.4.1.12_Ensure_successful_file_system_mounts_are_collected:def:1
- Title: Ensure successful file system mounts are collected
- oval:simp.cis.3.1.2.CentOS7.4.1.13_Ensure_file_deletion_events_by_users_are_collected:def:1
- Title: Ensure file deletion events by users are collected
- oval:simp.cis.3.1.2.CentOS7.4.1.17_Ensure_the_audit_configuration_is_immutable:def:1
- Title: Ensure the audit configuration is immutable
- oval:simp.cis.3.1.2.CentOS7.4.2.1.1_Ensure_rsyslog_is_installed:def:1
- Title: Ensure rsyslog is installed
- oval:simp.cis.3.1.2.CentOS7.4.2.1.2_Ensure_rsyslog_Service_is_enabled_and_running:def:1
- Title: Ensure rsyslog Service is enabled and running
- oval:simp.cis.3.1.2.CentOS7.4.2.1.4_Ensure_logging_is_configured:def:1
- Title: Ensure logging is configured
- oval:simp.cis.3.1.2.CentOS7.4.2.2.3_Ensure_journald_is_configured_to_write_logfiles_to_persistent_disk:def:1
- Title: Ensure journald is configured to write logfiles to persistent disk
- oval:simp.cis.3.1.2.CentOS7.5.3.5_Ensure_SSH_LogLevel_is_appropriate:def:1
- Title: Ensure SSH LogLevel is appropriate
- oval:simp.cis.3.1.2.CentOS7.2.2.1.1_Ensure_time_synchronization_is_in_use:def:1
- Title: Ensure time synchronization is in use
- oval:simp.cis.3.1.2.CentOS7.2.2.1.2_Ensure_chrony_is_configured:def:1
- Title: Ensure chrony is configured
- NOTE: We are configuring the system to use ntpd instead of chrony.
- oval:simp.cis.3.1.2.CentOS7.2.2.1.3_Ensure_ntp_is_configured:def:1
- Title: Ensure ntp is configured
- oval:simp.cis.3.1.2.CentOS7.1.1.3_Ensure_noexec_option_set_on_tmp_partition:def:1
- Title: Ensure noexec option set on /tmp partition
- oval:simp.cis.3.1.2.CentOS7.1.1.7_Ensure_noexec_option_set_on_devshm_partition:def:1
- Title: Ensure noexec option set on /dev/shm partition
- oval:simp.cis.3.1.2.CentOS7.1.1.12_Ensure_vartmp_partition_includes_the_noexec_option:def:1
- Title: Ensure /var/tmp partition includes the noexec option
- oval:simp.cis.3.1.2.CentOS7.1.1.19_Ensure_removable_media_partitions_include_noexec_option:def:1
- Title: Ensure removable media partitions include noexec option
- oval:simp.cis.3.1.2.CentOS7.1.8.1_Ensure_GNOME_Display_Manager_is_removed:def:1
- Title: Ensure GNOME Display Manager is removed
- oval:simp.cis.3.1.2.CentOS7.2.1.1_Ensure_xinetd_is_not_installed:def:1
- Title: Ensure xinetd is not installed
- oval:simp.cis.3.1.2.CentOS7.2.2.2_Ensure_X11_Server_components_are_not_installed:def:1
- Title: Ensure X11 Server components are not installed
- oval:simp.cis.3.1.2.CentOS7.2.2.13_Ensure_net-snmp_is_not_installed:def:1
- Title: Ensure net-snmp is not installed
- oval:simp.cis.3.1.2.CentOS7.2.2.14_Ensure_NIS_server_is_not_installed:def:1
- Title: Ensure NIS server is not installed
- oval:simp.cis.3.1.2.CentOS7.2.2.15_Ensure_telnet-server_is_not_installed:def:1
- Title: Ensure telnet-server is not installed
- oval:simp.cis.3.1.2.CentOS7.2.3.1_Ensure_NIS_Client_is_not_installed:def:1
- Title: Ensure NIS Client is not installed
- oval:simp.cis.3.1.2.CentOS7.2.3.2_Ensure_rsh_client_is_not_installed:def:1
- Title: Ensure rsh client is not installed
- oval:simp.cis.3.1.2.CentOS7.2.3.3_Ensure_talk_client_is_not_installed:def:1
- Title: Ensure talk client is not installed
- oval:simp.cis.3.1.2.CentOS7.2.3.4_Ensure_telnet_client_is_not_installed:def:1
- Title: Ensure telnet client is not installed
- oval:simp.cis.3.1.2.CentOS7.2.3.5_Ensure_LDAP_client_is_not_installed:def:1
- Title: Ensure LDAP client is not installed
- oval:simp.cis.3.1.2.CentOS7.5.4.1_Ensure_password_creation_requirements_are_configured:def:1
- Title: Ensure password creation requirements are configured
- oval:simp.cis.3.1.2.CentOS7.5.5.1.1_Ensure_password_expiration_is_365_days_or_less:def:1
- Title: Ensure password expiration is 365 days or less
- NOTE: The product sets PASS_MAX_DAYS in /etc/login.defs, however, there is currently no mechanisme to enforce the setting for existing users in /etc/shadow.
- oval:simp.cis.3.1.2.CentOS7.5.5.1.2_Ensure_minimum_days_between_password_changes_is_configured:def:1
- Title: Ensure minimum days between password changes is configured
- NOTE: The product sets PASS_MIN_DAYS in /etc/login.defs, however, there is currently no mechanisme to enforce the setting for existing users in /etc/shadow.
- oval:simp.cis.3.1.2.CentOS7.5.5.1.3_Ensure_password_expiration_warning_days_is_7_or_more:def:1
- Title: Ensure password expiration warning days is 7 or more
- oval:simp.cis.3.1.2.CentOS7.5.5.1.5_Ensure_all_users_last_password_change_date_is_in_the_past:def:1
- Title: Ensure all users last password change date is in the past
- oval:simp.cis.3.1.2.CentOS7.6.2.1_Ensure_accounts_in_etcpasswd_use_shadowed_passwords:def:1
- Title: Ensure accounts in /etc/passwd use shadowed passwords
- oval:simp.cis.3.1.2.CentOS7.6.2.2_Ensure_etcshadow_password_fields_are_not_empty:def:1
- Title: Ensure /etc/shadow password fields are not empty
- oval:simp.cis.3.1.2.CentOS7.5.4.3_Ensure_password_hashing_algorithm_is_SHA-512:def:1
- Title: Ensure password hashing algorithm is SHA-512
- oval:simp.cis.3.1.2.CentOS7.6.1.6_Ensure_permissions_on_etcgshadow-_are_configured:def:1
- Title: Ensure permissions on /etc/gshadow- are configured
- oval:simp.cis.3.1.2.CentOS7.6.2.16Ensure_no_users_have.netrc_files:def:1
- Title: Ensure no users have .netrc files
- oval:simp.cis.3.1.2.CentOS7.6.2.17Ensure_no_users_have.rhosts_files:def:1
- Title: Ensure no users have .rhosts files
- oval:simp.cis.3.1.2.CentOS7.5.3.14_Ensure_only_strong_MAC_algorithms_are_used:def:1
- Title: Ensure only strong MAC algorithms are used
- oval:simp.cis.3.1.2.CentOS7.4.2.2.1_Ensure_journald_is_configured_to_send_logs_to_rsyslog:def:1
- Title: Ensure journald is configured to send logs to rsyslog
- oval:simp.cis.3.1.2.CentOS7.4.2.1.5_Ensure_rsyslog_is_configured_to_send_logs_to_a_remote_log_host:def:1
- Title: Ensure rsyslog is configured to send logs to a remote log host
- oval:simp.cis.3.1.2.CentOS7.5.4.2_Ensure_lockout_for_failed_password_attempts_is_configured:def:1
- Title: Ensure lockout for failed password attempts is configured
- oval:simp.cis.3.1.2.CentOS7.1.6.1.8_Ensure_the_MCS_Translation_Service_mcstrans_is_not_installed:def:1
- Title: Ensure the MCS Translation Service (mcstrans) is not installed
- oval:simp.cis.3.1.2.CentOS7.1.8.4_Ensure_XDCMP_is_not_enabled:def:1
- Title: Ensure XDCMP is not enabled
- oval:simp.cis.3.1.2.CentOS7.2.2.3_Ensure_Avahi_Server_is_not_installed:def:1
- Title: Ensure Avahi Server is not installed
- oval:simp.cis.3.1.2.CentOS7.2.2.4_Ensure_CUPS_is_not_installed:def:1
- Title: Ensure CUPS is not installed
- oval:simp.cis.3.1.2.CentOS7.2.2.5_Ensure_DHCP_Server_is_not_installed:def:1
- Title: Ensure DHCP Server is not installed
- oval:simp.cis.3.1.2.CentOS7.2.2.6_Ensure_LDAP_server_is_not_installed:def:1
- Title: Ensure LDAP server is not installed
- oval:simp.cis.3.1.2.CentOS7.2.2.7_Ensure_DNS_Server_is_not_installed:def:1
- Title: Ensure DNS Server is not installed
- oval:simp.cis.3.1.2.CentOS7.2.2.8_Ensure_FTP_Server_is_not_installed:def:1
- Title: Ensure FTP Server is not installed
- oval:simp.cis.3.1.2.CentOS7.2.2.9_Ensure_HTTP_server_is_not_installed:def:1
- Title: Ensure HTTP server is not installed
- oval:simp.cis.3.1.2.CentOS7.2.2.10_Ensure_IMAP_and_POP3_server_is_not_installed:def:1
- Title: Ensure IMAP and POP3 server is not installed
- oval:simp.cis.3.1.2.CentOS7.2.2.11_Ensure_Samba_is_not_installed:def:1
- Title: Ensure Samba is not installed
- oval:simp.cis.3.1.2.CentOS7.2.2.12_Ensure_HTTP_Proxy_Server_is_not_installed:def:1
- Title: Ensure HTTP Proxy Server is not installed
- oval:simp.cis.3.1.2.CentOS7.2.2.16_Ensure_mail_transfer_agent_is_configured_for_local-only_mode:def:1
- Title: Ensure mail transfer agent is configured for local-only mode
- oval:simp.cis.3.1.2.CentOS7.2.2.17_Ensure_nfs-utils_is_not_installed_or_the__nfs-server_service_is_masked:def:1
- Title: Ensure nfs-utils is not installed or the nfs-server service is masked
- oval:simp.cis.3.1.2.CentOS7.2.2.18_Ensure_rpcbind_is_not_installed_or_the__rpcbind_services_are_masked:def:1
- Title: Ensure rpcbind is not installed or the rpcbind services are masked
- oval:simp.cis.3.1.2.CentOS7.2.2.19_Ensure_rsync_is_not_installed_or_the_rsyncd_service_is_masked:def:1
- Title: Ensure rsync is not installed or the rsyncd service is masked
- oval:simp.cis.3.1.2.CentOS7.2.4_Ensure_nonessential_services_are_removed_or_masked:def:1
- Title: Ensure nonessential services are removed or masked
- oval:simp.cis.3.1.2.CentOS7.3.4.1_Ensure_DCCP_is_disabled:def:1
- Title: Ensure DCCP is disabled
- oval:simp.cis.3.1.2.CentOS7.3.4.2_Ensure_SCTP_is_disabled:def:1
- Title: Ensure SCTP is disabled
- oval:simp.cis.3.1.2.CentOS7.3.5.3.2.3_Ensure_iptables_rules_exist_for_all_open_ports:def:1
- Title: Ensure iptables rules exist for all open ports
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.3.1.2.CentOS7.4.2.1.6_Ensure_remote_rsyslog_messages_are_only_accepted_on_designated_log_hosts.:def:1
- Title: Ensure remote rsyslog messages are only accepted on designated log hosts.
- oval:simp.cis.3.1.2.CentOS7.5.3.6_Ensure_SSH_X11_forwarding_is_disabled:def:1
- Title: Ensure SSH X11 forwarding is disabled
- oval:simp.cis.3.1.2.CentOS7.5.3.8_Ensure_SSH_IgnoreRhosts_is_enabled:def:1
- Title: Ensure SSH IgnoreRhosts is enabled
- oval:simp.cis.3.1.2.CentOS7.5.3.20_Ensure_SSH_AllowTcpForwarding_is_disabled:def:1
- Title: Ensure SSH AllowTcpForwarding is disabled
- oval:simp.cis.3.1.2.CentOS7.1.1.2_Ensure_tmp_is_configured:def:1
- Title: Ensure /tmp is configured
- oval:simp.cis.3.1.2.CentOS7.3.1.1_Disable_IPv6:def:1
- Title: Disable IPv6
- NOTE: Disabled via sysctl instead of kernel command line
- oval:simp.cis.3.1.2.CentOS7.3.5.1.1_Ensure_firewalld_is_installed:def:1
- Title: Ensure firewalld is installed
- oval:simp.cis.3.1.2.CentOS7.3.5.1.2_Ensure_iptables-services_not_installed_with_firewalld:def:1
- Title: Ensure iptables-services not installed with firewalld
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.3.1.2.CentOS7.3.5.1.3_Ensure_nftables_either_not_installed_or_masked_with_firewalld:def:1
- Title: Ensure nftables either not installed or masked with firewalld
- oval:simp.cis.3.1.2.CentOS7.3.5.1.4_Ensure_firewalld_service_enabled_and_running:def:1
- Title: Ensure firewalld service enabled and running
- oval:simp.cis.3.1.2.CentOS7.3.5.1.5_Ensure_firewalld_default_zone_is_set:def:1
- Title: Ensure firewalld default zone is set
- oval:simp.cis.3.1.2.CentOS7.3.5.1.6_Ensure_network_interfaces_are_assigned_to_appropriate_zone:def:1
- Title: Ensure network interfaces are assigned to appropriate zone
- oval:simp.cis.3.1.2.CentOS7.3.5.1.7_Ensure_firewalld_drops_unnecessary_services_and_ports:def:1
- Title: Ensure firewalld drops unnecessary services and ports
- oval:simp.cis.3.1.2.CentOS7.3.5.2.1_Ensure_nftables_is_installed:def:1
- Title: Ensure nftables is installed
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.3.1.2.CentOS7.3.5.2.2_Ensure_firewalld_is_either_not_installed_or_masked_with_nftables:def:1
- Title: Ensure firewalld is either not installed or masked with nftables
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.3.1.2.CentOS7.3.5.2.3_Ensure_iptables-services_not_installed_with_nftables:def:1
- Title: Ensure iptables-services not installed with nftables
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.3.1.2.CentOS7.3.5.2.4_Ensure_iptables_are_flushed_with_nftables:def:1
- Title: Ensure iptables are flushed with nftables
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.3.1.2.CentOS7.3.5.2.5_Ensure_an_nftables_table_exists:def:1
- Title: Ensure an nftables table exists
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.3.1.2.CentOS7.3.5.2.6_Ensure_nftables_base_chains_exist:def:1
- Title: Ensure nftables base chains exist
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.3.1.2.CentOS7.3.5.2.7_Ensure_nftables_loopback_traffic_is_configured:def:1
- Title: Ensure nftables loopback traffic is configured
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.3.1.2.CentOS7.3.5.2.8_Ensure_nftables_outbound_and_established_connections_are_configured:def:1
- Title: Ensure nftables outbound and established connections are configured
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.3.1.2.CentOS7.3.5.2.9_Ensure_nftables_default_deny_firewall_policy:def:1
- Title: Ensure nftables default deny firewall policy
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.3.1.2.CentOS7.3.5.2.10_Ensure_nftables_service_is_enabled:def:1
- Title: Ensure nftables service is enabled
- oval:simp.cis.3.1.2.CentOS7.3.5.2.11_Ensure_nftables_rules_are_permanent:def:1
- Title: Ensure nftables rules are permanent
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.3.1.2.CentOS7.3.5.3.1.1_Ensure_iptables_packages_are_installed:def:1
- Title: Ensure iptables packages are installed
- oval:simp.cis.3.1.2.CentOS7.3.5.3.1.2_Ensure_nftables_is_not_installed_with_iptables:def:1
- Title: Ensure nftables is not installed with iptables
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.3.1.2.CentOS7.3.5.3.1.3_Ensure_firewalld_is_either_not_installed_or_masked_with_iptables:def:1
- Title: Ensure firewalld is either not installed or masked with iptables
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.3.1.2.CentOS7.3.5.3.2.1_Ensure_iptables_loopback_traffic_is_configured:def:1
- Title: Ensure iptables loopback traffic is configured
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.3.1.2.CentOS7.3.5.3.2.2_Ensure_iptables_outbound_and_established_connections_are_configured:def:1
- Title: Ensure iptables outbound and established connections are configured
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.3.1.2.CentOS7.3.5.3.2.4_Ensure_iptables_default_deny_firewall_policy:def:1
- Title: Ensure iptables default deny firewall policy
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.3.1.2.CentOS7.3.5.3.2.5_Ensure_iptables_rules_are_saved:def:1
- Title: Ensure iptables rules are saved
- oval:simp.cis.3.1.2.CentOS7.3.5.3.2.6_Ensure_iptables_is_enabled_and_running:def:1
- Title: Ensure iptables is enabled and running
- oval:simp.cis.3.1.2.CentOS7.3.5.3.3.1_Ensure_ip6tables_loopback_traffic_is_configured:def:1
- Title: Ensure ip6tables loopback traffic is configured
- oval:simp.cis.3.1.2.CentOS7.3.5.3.3.2_Ensure_ip6tables_outbound_and_established_connections_are_configured:def:1
- Title: Ensure ip6tables outbound and established connections are configured
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.3.1.2.CentOS7.3.5.3.3.3_Ensure_ip6tables_firewall_rules_exist_for_all_open_ports:def:1
- Title: Ensure ip6tables firewall rules exist for all open ports
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.3.1.2.CentOS7.3.5.3.3.4_Ensure_ip6tables_default_deny_firewall_policy:def:1
- Title: Ensure ip6tables default deny firewall policy
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.3.1.2.CentOS7.3.5.3.3.5_Ensure_ip6tables_rules_are_saved:def:1
- Title: Ensure ip6tables rules are saved
- oval:simp.cis.3.1.2.CentOS7.3.5.3.3.6_Ensure_ip6tables_is_enabled_and_running:def:1
- Title: Ensure ip6tables is enabled and running
- oval:simp.cis.3.1.2.CentOS7.5.3.13_Ensure_only_strong_Ciphers_are_used:def:1
- Title: Ensure only strong Ciphers are used
- oval:simp.cis.3.1.2.CentOS7.5.3.15_Ensure_only_strong_Key_Exchange_algorithms_are_used:def:1
- Title: Ensure only strong Key Exchange algorithms are used
- oval:simp.cis.3.1.2.CentOS7.5.3.7_Ensure_SSH_MaxAuthTries_is_set_to_4_or_less:def:1
- Title: Ensure SSH MaxAuthTries is set to 4 or less
CentOS 8 (216/233 [92%])
- oval:simp.cis.2.0.0.CentOS8.1.7.1_Ensure_message_of_the_day_is_configured_properly:def:1
- Title: Ensure message of the day is configured properly
- oval:simp.cis.2.0.0.CentOS8.1.7.2_Ensure_local_login_warning_banner_is_configured_properly:def:1
- Title: Ensure local login warning banner is configured properly
- oval:simp.cis.2.0.0.CentOS8.1.7.3_Ensure_remote_login_warning_banner_is_configured_properly:def:1
- Title: Ensure remote login warning banner is configured properly
- oval:simp.cis.2.0.0.CentOS8.1.8.2_Ensure_GDM_login_banner_is_configured:def:1
- Title: Ensure GDM login banner is configured
- oval:simp.cis.2.0.0.CentOS8.1.8.3_Ensure_last_logged_in_user_display_is_disabled:def:1
- Title: Ensure last logged in user display is disabled
- oval:simp.cis.2.0.0.CentOS8.3.2.1_Ensure_IP_forwarding_is_disabled:def:1
- Title: Ensure IP forwarding is disabled
- oval:simp.cis.2.0.0.CentOS8.3.2.2_Ensure_packet_redirect_sending_is_disabled:def:1
- Title: Ensure packet redirect sending is disabled
- oval:simp.cis.2.0.0.CentOS8.3.3.1_Ensure_source_routed_packets_are_not_accepted:def:1
- Title: Ensure source routed packets are not accepted
- oval:simp.cis.2.0.0.CentOS8.3.3.2_Ensure_ICMP_redirects_are_not_accepted:def:1
- Title: Ensure ICMP redirects are not accepted
- oval:simp.cis.2.0.0.CentOS8.3.3.3_Ensure_secure_ICMP_redirects_are_not_accepted:def:1
- Title: Ensure secure ICMP redirects are not accepted
- oval:simp.cis.2.0.0.CentOS8.3.3.5_Ensure_broadcast_ICMP_requests_are_ignored:def:1
- Title: Ensure broadcast ICMP requests are ignored
- oval:simp.cis.2.0.0.CentOS8.3.3.6_Ensure_bogus_ICMP_responses_are_ignored:def:1
- Title: Ensure bogus ICMP responses are ignored
- oval:simp.cis.2.0.0.CentOS8.3.3.7_Ensure_Reverse_Path_Filtering_is_enabled:def:1
- Title: Ensure Reverse Path Filtering is enabled
- oval:simp.cis.2.0.0.CentOS8.3.3.8_Ensure_TCP_SYN_Cookies_is_enabled:def:1
- Title: Ensure TCP SYN Cookies is enabled
- oval:simp.cis.2.0.0.CentOS8.3.3.9_Ensure_IPv6_router_advertisements_are_not_accepted:def:1
- Title: Ensure IPv6 router advertisements are not accepted
- oval:simp.cis.2.0.0.CentOS8.4.1.3.10_Ensure_successful_file_system_mounts_are_collected:def:1
- Title: Ensure successful file system mounts are collected
- oval:simp.cis.2.0.0.CentOS8.4.1.3.19_Ensure_kernel_module_loading_unloading_and_modification_is_collected:def:1
- Title: Ensure kernel module loading unloading and modification is collected
- oval:simp.cis.2.0.0.CentOS8.4.2.1.4_Ensure_rsyslog_default_file_permissions_are_configured:def:1
- Title: Ensure rsyslog default file permissions are configured
- oval:simp.cis.2.0.0.CentOS8.4.2.3_Ensure_permissions_on_all_logfiles_are_configured:def:1
- Title: Ensure permissions on all logfiles are configured
- NOTE: btmp, lastlog, and wtmp will not have any permissions stripped from them. Doing so could cause login issues for users.
- oval:simp.cis.2.0.0.CentOS8.5.1.1_Ensure_cron_daemon_is_enabled:def:1
- Title: Ensure cron daemon is enabled
- oval:simp.cis.2.0.0.CentOS8.5.1.2_Ensure_permissions_on_etccrontab_are_configured:def:1
- Title: Ensure permissions on /etc/crontab are configured
- oval:simp.cis.2.0.0.CentOS8.5.1.3_Ensure_permissions_on_etccron.hourly_are_configured:def:1
- Title: Ensure permissions on /etc/cron.hourly are configured
- oval:simp.cis.2.0.0.CentOS8.5.1.4_Ensure_permissions_on_etccron.daily_are_configured:def:1
- Title: Ensure permissions on /etc/cron.daily are configured
- oval:simp.cis.2.0.0.CentOS8.5.1.5_Ensure_permissions_on_etccron.weekly_are_configured:def:1
- Title: Ensure permissions on /etc/cron.weekly are configured
- oval:simp.cis.2.0.0.CentOS8.5.1.6_Ensure_permissions_on_etccron.monthly_are_configured:def:1
- Title: Ensure permissions on /etc/cron.monthly are configured
- oval:simp.cis.2.0.0.CentOS8.5.1.7_Ensure_permissions_on_etccron.d_are_configured:def:1
- Title: Ensure permissions on /etc/cron.d are configured
- oval:simp.cis.2.0.0.CentOS8.5.2.1_Ensure_permissions_on_etcsshsshd_config_are_configured:def:1
- Title: Ensure permissions on /etc/ssh/sshd_config are configured
- oval:simp.cis.2.0.0.CentOS8.5.2.2_Ensure_permissions_on_SSH_private_host_key_files_are_configured:def:1
- Title: Ensure permissions on SSH private host key files are configured
- oval:simp.cis.2.0.0.CentOS8.5.2.3_Ensure_permissions_on_SSH_public_host_key_files_are_configured:def:1
- Title: Ensure permissions on SSH public host key files are configured
- oval:simp.cis.2.0.0.CentOS8.5.2.6_Ensure_SSH_PAM_is_enabled:def:1
- Title: Ensure SSH PAM is enabled
- oval:simp.cis.2.0.0.CentOS8.5.2.10_Ensure_SSH_PermitUserEnvironment_is_disabled:def:1
- Title: Ensure SSH PermitUserEnvironment is disabled
- oval:simp.cis.2.0.0.CentOS8.5.2.15_Ensure_SSH_warning_banner_is_configured:def:1
- Title: Ensure SSH warning banner is configured
- oval:simp.cis.2.0.0.CentOS8.5.2.17_Ensure_SSH_MaxStartups_is_configured:def:1
- Title: Ensure SSH MaxStartups is configured
- oval:simp.cis.2.0.0.CentOS8.5.2.18_Ensure_SSH_MaxSessions_is_set_to_10_or_less:def:1
- Title: Ensure SSH MaxSessions is set to 10 or less
- oval:simp.cis.2.0.0.CentOS8.5.2.19_Ensure_SSH_LoginGraceTime_is_set_to_one_minute_or_less:def:1
- Title: Ensure SSH LoginGraceTime is set to one minute or less
- oval:simp.cis.2.0.0.CentOS8.5.3.2_Ensure_sudo_commands_use_pty:def:1
- Title: Ensure sudo commands use pty
- oval:simp.cis.2.0.0.CentOS8.5.3.7_Ensure_access_to_the_su_command_is_restricted:def:1
- Title: Ensure access to the su command is restricted
- oval:simp.cis.2.0.0.CentOS8.5.6.4_Ensure_default_group_for_the_root_account_is_GID_0:def:1
- Title: Ensure default group for the root account is GID 0
- oval:simp.cis.2.0.0.CentOS8.6.1.2_Ensure_sticky_bit_is_set_on_all_world-writable_directories:def:1
- Title: Ensure sticky bit is set on all world-writable directories
- oval:simp.cis.2.0.0.CentOS8.6.2.7_Ensure_root_PATH_Integrity:def:1
- Title: Ensure root PATH Integrity
- oval:simp.cis.2.0.0.CentOS8.6.2.8_Ensure_root_is_the_only_UID_0_account:def:1
- Title: Ensure root is the only UID 0 account
- oval:simp.cis.2.0.0.CentOS8.6.2.9_Ensure_all_users_home_directories_exist:def:1
- Title: Ensure all users’ home directories exist
- oval:simp.cis.2.0.0.CentOS8.6.2.14Ensure_no_users_have.forward_files:def:1
- Title: Ensure no users have .forward files
- oval:simp.cis.2.0.0.CentOS8.1.1.2.3_Ensure_noexec_option_set_on_tmp_partition:def:1
- Title: Ensure noexec option set on /tmp partition
- oval:simp.cis.2.0.0.CentOS8.1.1.2.4_Ensure_nosuid_option_set_on_tmp_partition:def:1
- Title: Ensure nosuid option set on /tmp partition
- oval:simp.cis.2.0.0.CentOS8.1.1.3.2_Ensure_nodev_option_set_on_var_partition:def:1
- Title: Ensure nodev option set on /var partition
- oval:simp.cis.2.0.0.CentOS8.1.1.3.3_Ensure_noexec_option_set_on_var_partition:def:1
- Title: Ensure noexec option set on /var partition
- oval:simp.cis.2.0.0.CentOS8.1.1.3.4_Ensure_nosuid_option_set_on_var_partition:def:1
- Title: Ensure nosuid option set on /var partition
- oval:simp.cis.2.0.0.CentOS8.1.1.4.2_Ensure_noexec_option_set_on_vartmp_partition:def:1
- Title: Ensure noexec option set on /var/tmp partition
- oval:simp.cis.2.0.0.CentOS8.1.1.4.3_Ensure_nosuid_option_set_on_vartmp_partition:def:1
- Title: Ensure nosuid option set on /var/tmp partition
- oval:simp.cis.2.0.0.CentOS8.1.1.4.4_Ensure_nodev_option_set_on_vartmp_partition:def:1
- Title: Ensure nodev option set on /var/tmp partition
- oval:simp.cis.2.0.0.CentOS8.1.1.5.2_Ensure_nodev_option_set_on_varlog_partition:def:1
- Title: Ensure nodev option set on /var/log partition
- oval:simp.cis.2.0.0.CentOS8.1.1.5.3_Ensure_noexec_option_set_on_varlog_partition:def:1
- Title: Ensure noexec option set on /var/log partition
- oval:simp.cis.2.0.0.CentOS8.1.1.5.4_Ensure_nosuid_option_set_on_varlog_partition:def:1
- Title: Ensure nosuid option set on /var/log partition
- oval:simp.cis.2.0.0.CentOS8.1.1.6.2_Ensure_noexec_option_set_on_varlogaudit_partition:def:1
- Title: Ensure noexec option set on /var/log/audit partition
- oval:simp.cis.2.0.0.CentOS8.1.1.6.3_Ensure_nodev_option_set_on_varlogaudit_partition:def:1
- Title: Ensure nodev option set on /var/log/audit partition
- oval:simp.cis.2.0.0.CentOS8.1.1.6.4_Ensure_nosuid_option_set_on_varlogaudit_partition:def:1
- Title: Ensure nosuid option set on /var/log/audit partition
- oval:simp.cis.2.0.0.CentOS8.1.1.7.2_Ensure_nodev_option_set_on_home_partition:def:1
- Title: Ensure nodev option set on /home partition
- oval:simp.cis.2.0.0.CentOS8.1.1.7.3_Ensure_nosuid_option_set_on_home_partition:def:1
- Title: Ensure nosuid option set on /home partition
- oval:simp.cis.2.0.0.CentOS8.1.1.8.1_Ensure_nodev_option_set_on_devshm_partition:def:1
- Title: Ensure nodev option set on /dev/shm partition
- oval:simp.cis.2.0.0.CentOS8.1.1.8.2_Ensure_noexec_option_set_on_devshm_partition:def:1
- Title: Ensure noexec option set on /dev/shm partition
- oval:simp.cis.2.0.0.CentOS8.1.1.8.3_Ensure_nosuid_option_set_on_devshm_partition:def:1
- Title: Ensure nosuid option set on /dev/shm partition
- oval:simp.cis.2.0.0.CentOS8.1.4.1_Ensure_bootloader_password_is_set:def:1
- Title: Ensure bootloader password is set
- oval:simp.cis.2.0.0.CentOS8.1.4.2_Ensure_permissions_on_bootloader_config_are_configured:def:1
- Title: Ensure permissions on bootloader config are configured
- oval:simp.cis.2.0.0.CentOS8.1.6.1.1_Ensure_SELinux_is_installed:def:1
- Title: Ensure SELinux is installed
- oval:simp.cis.2.0.0.CentOS8.1.6.1.2_Ensure_SELinux_is_not_disabled_in_bootloader_configuration:def:1
- Title: Ensure SELinux is not disabled in bootloader configuration
- oval:simp.cis.2.0.0.CentOS8.1.6.1.3_Ensure_SELinux_policy_is_configured:def:1
- Title: Ensure SELinux policy is configured
- oval:simp.cis.2.0.0.CentOS8.1.6.1.4_Ensure_the_SELinux_mode_is_not_disabled:def:1
- Title: Ensure the SELinux mode is not disabled
- oval:simp.cis.2.0.0.CentOS8.1.6.1.5_Ensure_the_SELinux_mode_is_enforcing:def:1
- Title: Ensure the SELinux mode is enforcing
- oval:simp.cis.2.0.0.CentOS8.1.6.1.7_Ensure_SETroubleshoot_is_not_installed:def:1
- Title: Ensure SETroubleshoot is not installed
- oval:simp.cis.2.0.0.CentOS8.1.7.4_Ensure_permissions_on_etcmotd_are_configured:def:1
- Title: Ensure permissions on /etc/motd are configured
- oval:simp.cis.2.0.0.CentOS8.1.7.5_Ensure_permissions_on_etcissue_are_configured:def:1
- Title: Ensure permissions on /etc/issue are configured
- oval:simp.cis.2.0.0.CentOS8.1.7.6_Ensure_permissions_on_etcissue.net_are_configured:def:1
- Title: Ensure permissions on /etc/issue.net are configured
- oval:simp.cis.2.0.0.CentOS8.5.6.2_Ensure_system_accounts_are_secured:def:1
- Title: Ensure system accounts are secured
- oval:simp.cis.2.0.0.CentOS8.5.6.5_Ensure_default_user_umask_is_027_or_more_restrictive:def:1
- Title: Ensure default user umask is 027 or more restrictive
- NOTE: The umask will be set to 027 within /etc/profile.d/simp.sh, however, this check still fails the scan.
- oval:simp.cis.2.0.0.CentOS8.6.2.10_Ensure_users_own_their_home_directories:def:1
- Title: Ensure users own their home directories
- oval:simp.cis.2.0.0.CentOS8.6.2.11_Ensure_users_home_directories_permissions_are_750_or_more_restrictive:def:1
- Title: Ensure users’ home directories permissions are 750 or more restrictive
- oval:simp.cis.2.0.0.CentOS8.6.2.12_Ensure_users_dot_files_are_not_group_or_world_writable:def:1
- Title: Ensure users’ dot files are not group or world writable
- oval:simp.cis.2.0.0.CentOS8.6.2.13Ensure_users.netrc_Files_are_not_group_or_world_accessible:def:1
- Title: Ensure users’ .netrc Files are not group or world accessible
- oval:simp.cis.2.0.0.CentOS8.4.1.3.12_Ensure_login_and_logout_events_are_collected:def:1
- Title: Ensure login and logout events are collected
- oval:simp.cis.2.0.0.CentOS8.5.2.20_Ensure_SSH_Idle_Timeout_Interval_is_configured:def:1
- Title: Ensure SSH Idle Timeout Interval is configured
- oval:simp.cis.2.0.0.CentOS8.5.6.3_Ensure_default_user_shell_timeout_is_900_seconds_or_less:def:1
- Title: Ensure default user shell timeout is 900 seconds or less
-
*NOTE: The scanner fails to pickup on the format the product uses for setting the timeout: [ $TMOUT ] |
|
export TMOUT=900. The setting is also set in a nonstandard location: /etc/profile.d/simp.sh.* |
- oval:simp.cis.2.0.0.CentOS8.1.1.9_Disable_Automounting:def:1
- Title: Disable Automounting
- oval:simp.cis.2.0.0.CentOS8.1.8.5_Ensure_automatic_mounting_of_removable_media_is_disabled:def:1
- Title: Ensure automatic mounting of removable media is disabled
- oval:simp.cis.2.0.0.CentOS8.5.2.4_Ensure_SSH_access_is_limited:def:1
- Title: Ensure SSH access is limited
- oval:simp.cis.2.0.0.CentOS8.5.2.7_Ensure_SSH_root_login_is_disabled:def:1
- Title: Ensure SSH root login is disabled
- oval:simp.cis.2.0.0.CentOS8.5.3.1_Ensure_sudo_is_installed:def:1
- Title: Ensure sudo is installed
- oval:simp.cis.2.0.0.CentOS8.5.3.6_Ensure_sudo_authentication_timeout_is_configured_correctly:def:1
- Title: Ensure sudo authentication timeout is configured correctly
- oval:simp.cis.2.0.0.CentOS8.1.1.10_Disable_USB_Storage:def:1
- Title: Disable USB Storage
- oval:simp.cis.2.0.0.CentOS8.3.1.4_Ensure_wireless_interfaces_are_disabled:def:1
- Title: Ensure wireless interfaces are disabled
- oval:simp.cis.2.0.0.CentOS8.3.3.4_Ensure_suspicious_packets_are_logged:def:1
- Title: Ensure suspicious packets are logged
- oval:simp.cis.2.0.0.CentOS8.4.1.1.1_Ensure_auditd_is_installed:def:1
- Title: Ensure auditd is installed
- oval:simp.cis.2.0.0.CentOS8.4.1.1.2_Ensure_auditd_service_is_enabled:def:1
- Title: Ensure auditd service is enabled
- oval:simp.cis.2.0.0.CentOS8.4.1.1.3_Ensure_auditing_for_processes_that_start_prior_to_auditd_is_enabled:def:1
- Title: Ensure auditing for processes that start prior to auditd is enabled
- oval:simp.cis.2.0.0.CentOS8.4.1.1.4_Ensure_audit_backlog_limit_is_sufficient:def:1
- Title: Ensure audit_backlog_limit is sufficient
- oval:simp.cis.2.0.0.CentOS8.4.1.3.6_Ensure_use_of_privileged_commands_are_collected:def:1
- Title: Ensure use of privileged commands are collected
- NOTE: The available setuid/setgid commands on a given system could vary greatly. Several of the more common commands are audited, but there is currently no automated way to identify and audit all possible setuid/setgid commands available on any given system.
- oval:simp.cis.2.0.0.CentOS8.4.1.3.15_Ensure_successful_and_unsuccessful_attempts_to_use_the_chcon_command_are_recorded:def:1
- Title: Ensure successful and unsuccessful attempts to use the chcon command are recorded
- oval:simp.cis.2.0.0.CentOS8.4.1.3.16_Ensure_successful_and_unsuccessful_attempts_to_use_the_setfacl_command_are_recorded:def:1
- Title: Ensure successful and unsuccessful attempts to use the setfacl command are recorded
- oval:simp.cis.2.0.0.CentOS8.4.1.3.17_Ensure_successful_and_unsuccessful_attempts_to_use_the_chacl_command_are_recorded:def:1
- Title: Ensure successful and unsuccessful attempts to use the chacl command are recorded
- oval:simp.cis.2.0.0.CentOS8.4.1.3.18_Ensure_successful_and_unsuccessful_attempts_to_use_the_usermod_command_are_recorded:def:1
- Title: Ensure successful and unsuccessful attempts to use the usermod command are recorded
- oval:simp.cis.2.0.0.CentOS8.4.1.3.20_Ensure_the_audit_configuration_is_immutable:def:1
- Title: Ensure the audit configuration is immutable
- oval:simp.cis.2.0.0.CentOS8.4.2.1.1_Ensure_rsyslog_is_installed:def:1
- Title: Ensure rsyslog is installed
- oval:simp.cis.2.0.0.CentOS8.4.2.1.2_Ensure_rsyslog_service_is_enabled:def:1
- Title: Ensure rsyslog service is enabled
- oval:simp.cis.2.0.0.CentOS8.4.2.1.5_Ensure_logging_is_configured:def:1
- Title: Ensure logging is configured
- oval:simp.cis.2.0.0.CentOS8.4.2.1.7_Ensure_rsyslog_is_not_configured_to_recieve_logs_from_a_remote_client:def:1
- Title: Ensure rsyslog is not configured to recieve logs from a remote client
- NOTE: Including the product’s rsyslog class will purge any rsyslog configuration not specified by the user in hieradata or by other rules that require specific rsyslog configuration.
- oval:simp.cis.2.0.0.CentOS8.4.2.2.1.1_Ensure_systemd-journal-remote_is_installed:def:1
- Title: Ensure systemd-journal-remote is installed
- oval:simp.cis.2.0.0.CentOS8.4.2.2.1.4_Ensure_journald_is_not_configured_to_recieve_logs_from_a_remote_client:def:1
- Title: Ensure journald is not configured to recieve logs from a remote client
- oval:simp.cis.2.0.0.CentOS8.4.2.2.2_Ensure_journald_service_is_enabled:def:1
- Title: Ensure journald service is enabled
- NOTE: Simply including the journald class will include a default journald configuration and ensure the service is enabled.
- oval:simp.cis.2.0.0.CentOS8.4.2.2.3_Ensure_journald_is_configured_to_compress_large_log_files:def:1
- Title: Ensure journald is configured to compress large log files
- oval:simp.cis.2.0.0.CentOS8.4.2.2.4_Ensure_journald_is_configured_to_write_logfiles_to_persistent_disk:def:1
- Title: Ensure journald is configured to write logfiles to persistent disk
- oval:simp.cis.2.0.0.CentOS8.4.2.2.5_Ensure_journald_is_not_configured_to_send_logs_to_rsyslog:def:1
- Title: Ensure journald is not configured to send logs to rsyslog
- oval:simp.cis.2.0.0.CentOS8.4.2.2.6_Ensure_journald_log_rotation_is_configured_per_site_policy:def:1
- Title: Ensure journald log rotation is configured per site policy
- oval:simp.cis.2.0.0.CentOS8.5.2.5_Ensure_SSH_LogLevel_is_appropriate:def:1
- Title: Ensure SSH LogLevel is appropriate
- oval:simp.cis.2.0.0.CentOS8.2.1.1_Ensure_time_synchronization_is_in_use:def:1
- Title: Ensure time synchronization is in use
- oval:simp.cis.2.0.0.CentOS8.2.1.2_Ensure_chrony_is_configured:def:1
- Title: Ensure chrony is configured
- NOTE: We are configuring the system to use ntpd instead of chrony.
- oval:simp.cis.2.0.0.CentOS8.1.8.1_Ensure_GNOME_Display_Manager_is_removed:def:1
- Title: Ensure GNOME Display Manager is removed
- oval:simp.cis.2.0.0.CentOS8.2.2.1_Ensure_xinetd_is_not_installed:def:1
- Title: Ensure xinetd is not installed
- oval:simp.cis.2.0.0.CentOS8.2.2.14_Ensure_net-snmp_is_not_installed:def:1
- Title: Ensure net-snmp is not installed
- oval:simp.cis.2.0.0.CentOS8.2.2.15_Ensure_NIS_server_is_not_installed:def:1
- Title: Ensure NIS server is not installed
- oval:simp.cis.2.0.0.CentOS8.2.2.16_Ensure_telnet-server_is_not_installed:def:1
- Title: Ensure telnet-server is not installed
- oval:simp.cis.2.0.0.CentOS8.2.3.1_Ensure_NIS_Client_is_not_installed:def:1
- Title: Ensure NIS Client is not installed
- oval:simp.cis.2.0.0.CentOS8.2.3.2_Ensure_rsh_client_is_not_installed:def:1
- Title: Ensure rsh client is not installed
- oval:simp.cis.2.0.0.CentOS8.2.3.3_Ensure_talk_client_is_not_installed:def:1
- Title: Ensure talk client is not installed
- oval:simp.cis.2.0.0.CentOS8.2.3.4_Ensure_telnet_client_is_not_installed:def:1
- Title: Ensure telnet client is not installed
- oval:simp.cis.2.0.0.CentOS8.2.3.5_Ensure_LDAP_client_is_not_installed:def:1
- Title: Ensure LDAP client is not installed
- oval:simp.cis.2.0.0.CentOS8.1.4.3_Ensure_authentication_is_required_when_booting_into_rescue_mode:def:1
- Title: Ensure authentication is required when booting into rescue mode
- oval:simp.cis.2.0.0.CentOS8.5.5.1_Ensure_password_creation_requirements_are_configured:def:1
- Title: Ensure password creation requirements are configured
- oval:simp.cis.2.0.0.CentOS8.5.5.3_Ensure_password_reuse_is_limited:def:1
- Title: Ensure password reuse is limited
- NOTE: Password reuse will be limited through pam instead of authselect. The product will support authselect in a future release.
- oval:simp.cis.2.0.0.CentOS8.5.6.1.1_Ensure_password_expiration_is_365_days_or_less:def:1
- Title: Ensure password expiration is 365 days or less
- NOTE: The product sets PASS_MAX_DAYS in /etc/login.defs, however, there is currently no mechanism to enforce the setting for existing users in /etc/shadow.
- oval:simp.cis.2.0.0.CentOS8.5.6.1.2_Ensure_minimum_days_between_password_changes_is_7_or_more:def:1
- Title: Ensure minimum days between password changes is 7 or more
- NOTE: The PASS_MIN_DAYS value in /etc/login.defs will be set to 7 as requested, however, the product has no mechanism to change this value on all existing users.
- oval:simp.cis.2.0.0.CentOS8.5.6.1.3_Ensure_password_expiration_warning_days_is_7_or_more:def:1
- Title: Ensure password expiration warning days is 7 or more
- oval:simp.cis.2.0.0.CentOS8.5.6.1.4_Ensure_inactive_password_lock_is_30_days_or_less:def:1
- Title: Ensure inactive password lock is 30 days or less
- NOTE: The system will be configured to make accounts inactive after 30 days of inactivity, however, the product has no mechanism to change this value on existing users.
- oval:simp.cis.2.0.0.CentOS8.5.6.1.5_Ensure_all_users_last_password_change_date_is_in_the_past:def:1
- Title: Ensure all users last password change date is in the past
- oval:simp.cis.2.0.0.CentOS8.6.2.1_Ensure_password_fields_are_not_empty:def:1
- Title: Ensure password fields are not empty
- oval:simp.cis.2.0.0.CentOS8.5.5.4_Ensure_password_hashing_algorithm_is_SHA-512:def:1
- Title: Ensure password hashing algorithm is SHA-512
- oval:simp.cis.2.0.0.CentOS8.6.1.3_Ensure_permissions_on_etcpasswd_are_configured:def:1
- Title: Ensure permissions on /etc/passwd are configured
- oval:simp.cis.2.0.0.CentOS8.6.1.4_Ensure_permissions_on_etcshadow_are_configured:def:1
- Title: Ensure permissions on /etc/shadow are configured
- oval:simp.cis.2.0.0.CentOS8.6.1.5_Ensure_permissions_on_etcgroup_are_configured:def:1
- Title: Ensure permissions on /etc/group are configured
- oval:simp.cis.2.0.0.CentOS8.6.1.6_Ensure_permissions_on_etcgshadow_are_configured:def:1
- Title: Ensure permissions on /etc/gshadow are configured
- oval:simp.cis.2.0.0.CentOS8.6.1.7_Ensure_permissions_on_etcpasswd-_are_configured:def:1
- Title: Ensure permissions on /etc/passwd- are configured
- oval:simp.cis.2.0.0.CentOS8.6.1.8_Ensure_permissions_on_etcshadow-_are_configured:def:1
- Title: Ensure permissions on /etc/shadow- are configured
- oval:simp.cis.2.0.0.CentOS8.6.1.9_Ensure_permissions_on_etcgroup-_are_configured:def:1
- Title: Ensure permissions on /etc/group- are configured
- oval:simp.cis.2.0.0.CentOS8.6.1.10_Ensure_permissions_on_etcgshadow-_are_configured:def:1
- Title: Ensure permissions on /etc/gshadow- are configured
- oval:simp.cis.2.0.0.CentOS8.6.2.15Ensure_no_users_have.netrc_files:def:1
- Title: Ensure no users have .netrc files
- oval:simp.cis.2.0.0.CentOS8.6.2.16Ensure_no_users_have.rhosts_files:def:1
- Title: Ensure no users have .rhosts files
- oval:simp.cis.2.0.0.CentOS8.5.4.1_Ensure_custom_authselect_profile_is_used:def:1
- Title: Ensure custom authselect profile is used
- oval:simp.cis.2.0.0.CentOS8.5.4.2_Ensure_authselect_includes_with-faillock:def:1
- Title: Ensure authselect includes with-faillock
- oval:simp.cis.2.0.0.CentOS8.5.5.2_Ensure_lockout_for_failed_password_attempts_is_configured:def:1
- Title: Ensure lockout for failed password attempts is configured
- oval:simp.cis.2.0.0.CentOS8.1.1.1.1_Ensure_mounting_of_cramfs_filesystems_is_disabled:def:1
- Title: Ensure mounting of cramfs filesystems is disabled
- oval:simp.cis.2.0.0.CentOS8.1.1.1.2_Ensure_mounting_of_squashfs_filesystems_is_disabled:def:1
- Title: Ensure mounting of squashfs filesystems is disabled
- oval:simp.cis.2.0.0.CentOS8.1.1.1.3_Ensure_mounting_of_udf_filesystems_is_disabled:def:1
- Title: Ensure mounting of udf filesystems is disabled
- oval:simp.cis.2.0.0.CentOS8.1.1.2.1_Ensure_tmp_is_a_separate_partition:def:1
- Title: Ensure /tmp is a separate partition
- NOTE: /tmp will be configured as a bindmount with the following options: bind,nodev,noexec,nosuid. The test for this rule, however, is looking for /tmp in /etc/fstab.
- oval:simp.cis.2.0.0.CentOS8.1.1.2.2_Ensure_nodev_option_set_on_tmp_partition:def:1
- Title: Ensure nodev option set on /tmp partition
- oval:simp.cis.2.0.0.CentOS8.1.6.1.8_Ensure_the_MCS_Translation_Service_mcstrans_is_not_installed:def:1
- Title: Ensure the MCS Translation Service (mcstrans) is not installed
- oval:simp.cis.2.0.0.CentOS8.1.8.4_Ensure_XDMCP_is_not_enabled:def:1
- Title: Ensure XDMCP is not enabled
- oval:simp.cis.2.0.0.CentOS8.2.2.2_Ensure_xorg-x11-server-common_is_not_installed:def:1
- Title: Ensure xorg-x11-server-common is not installed
- oval:simp.cis.2.0.0.CentOS8.2.2.3_Ensure_Avahi_Server_is_not_installed:def:1
- Title: Ensure Avahi Server is not installed
- oval:simp.cis.2.0.0.CentOS8.2.2.4_Ensure_CUPS_is_not_installed:def:1
- Title: Ensure CUPS is not installed
- oval:simp.cis.2.0.0.CentOS8.2.2.5_Ensure_DHCP_Server_is_not_installed:def:1
- Title: Ensure DHCP Server is not installed
- oval:simp.cis.2.0.0.CentOS8.2.2.6_Ensure_DNS_Server_is_not_installed:def:1
- Title: Ensure DNS Server is not installed
- oval:simp.cis.2.0.0.CentOS8.2.2.7_Ensure_FTP_Server_is_not_installed:def:1
- Title: Ensure FTP Server is not installed
- oval:simp.cis.2.0.0.CentOS8.2.2.8_Ensure_VSFTP_Server_is_not_installed:def:1
- Title: Ensure VSFTP Server is not installed
- oval:simp.cis.2.0.0.CentOS8.2.2.9_Ensure_TFTP_Server_is_not_installed:def:1
- Title: Ensure TFTP Server is not installed
- oval:simp.cis.2.0.0.CentOS8.2.2.10_Ensure_a_web_server_is_not_installed:def:1
- Title: Ensure a web server is not installed
- oval:simp.cis.2.0.0.CentOS8.2.2.11_Ensure_IMAP_and_POP3_server_is_not_installed:def:1
- Title: Ensure IMAP and POP3 server is not installed
- oval:simp.cis.2.0.0.CentOS8.2.2.12_Ensure_Samba_is_not_installed:def:1
- Title: Ensure Samba is not installed
- oval:simp.cis.2.0.0.CentOS8.2.2.13_Ensure_HTTP_Proxy_Server_is_not_installed:def:1
- Title: Ensure HTTP Proxy Server is not installed
- oval:simp.cis.2.0.0.CentOS8.2.2.17_Ensure_mail_transfer_agent_is_configured_for_local-only_mode:def:1
- Title: Ensure mail transfer agent is configured for local-only mode
- oval:simp.cis.2.0.0.CentOS8.2.2.18_Ensure_nfs-utils_is_not_installed_or_the__nfs-server_service_is_masked:def:1
- Title: Ensure nfs-utils is not installed or the nfs-server service is masked
- oval:simp.cis.2.0.0.CentOS8.2.2.19_Ensure_rpcbind_is_not_installed_or_the__rpcbind_services_are_masked:def:1
- Title: Ensure rpcbind is not installed or the rpcbind services are masked
- oval:simp.cis.2.0.0.CentOS8.2.2.20_Ensure_rsync_is_not_installed_or_the_rsyncd_service_is_masked:def:1
- Title: Ensure rsync is not installed or the rsyncd service is masked
- oval:simp.cis.2.0.0.CentOS8.2.3.6_Ensure_TFTP_client_is_not_installed:def:1
- Title: Ensure TFTP client is not installed
- oval:simp.cis.2.0.0.CentOS8.2.4_Ensure_nonessential_services_are_removed_or_masked:def:1
- Title: Ensure nonessential services are removed or masked
- oval:simp.cis.2.0.0.CentOS8.3.1.2_Ensure_SCTP_is_disabled:def:1
- Title: Ensure SCTP is disabled
- oval:simp.cis.2.0.0.CentOS8.3.1.3_Ensure_DCCP_is_disabled:def:1
- Title: Ensure DCCP is disabled
- oval:simp.cis.2.0.0.CentOS8.3.4.3.2.3_Ensure_iptables_rules_exist_for_all_open_ports:def:1
- Title: Ensure iptables rules exist for all open ports
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.CentOS8.5.2.11_Ensure_SSH_IgnoreRhosts_is_enabled:def:1
- Title: Ensure SSH IgnoreRhosts is enabled
- oval:simp.cis.2.0.0.CentOS8.5.2.12_Ensure_SSH_X11_forwarding_is_disabled:def:1
- Title: Ensure SSH X11 forwarding is disabled
- oval:simp.cis.2.0.0.CentOS8.5.2.13_Ensure_SSH_AllowTcpForwarding_is_disabled:def:1
- Title: Ensure SSH AllowTcpForwarding is disabled
- oval:simp.cis.2.0.0.CentOS8.3.1.1_Verify_if_IPv6_is_enabled_on_the_system:def:1
- Title: Verify if IPv6 is enabled on the system
- oval:simp.cis.2.0.0.CentOS8.3.4.1.1_Ensure_firewalld_is_installed:def:1
- Title: Ensure firewalld is installed
- oval:simp.cis.2.0.0.CentOS8.3.4.1.2_Ensure_iptables-services_not_installed_with_firewalld:def:1
- Title: Ensure iptables-services not installed with firewalld
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.CentOS8.3.4.1.3_Ensure_nftables_either_not_installed_or_masked_with_firewalld:def:1
- Title: Ensure nftables either not installed or masked with firewalld
- oval:simp.cis.2.0.0.CentOS8.3.4.1.4_Ensure_firewalld_service_enabled_and_running:def:1
- Title: Ensure firewalld service enabled and running
- oval:simp.cis.2.0.0.CentOS8.3.4.1.5_Ensure_firewalld_default_zone_is_set:def:1
- Title: Ensure firewalld default zone is set
- oval:simp.cis.2.0.0.CentOS8.3.4.1.6_Ensure_network_interfaces_are_assigned_to_appropriate_zone:def:1
- Title: Ensure network interfaces are assigned to appropriate zone
- oval:simp.cis.2.0.0.CentOS8.3.4.1.7_Ensure_firewalld_drops_unnecessary_services_and_ports:def:1
- Title: Ensure firewalld drops unnecessary services and ports
- oval:simp.cis.2.0.0.CentOS8.3.4.2.1_Ensure_nftables_is_installed:def:1
- Title: Ensure nftables is installed
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.CentOS8.3.4.2.2_Ensure_firewalld_is_either_not_installed_or_masked_with_nftables:def:1
- Title: Ensure firewalld is either not installed or masked with nftables
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.CentOS8.3.4.2.3_Ensure_iptables-services_not_installed_with_nftables:def:1
- Title: Ensure iptables-services not installed with nftables
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.CentOS8.3.4.2.4_Ensure_iptables_are_flushed_with_nftables:def:1
- Title: Ensure iptables are flushed with nftables
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.CentOS8.3.4.2.5_Ensure_an_nftables_table_exists:def:1
- Title: Ensure an nftables table exists
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.CentOS8.3.4.2.6_Ensure_nftables_base_chains_exist:def:1
- Title: Ensure nftables base chains exist
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.CentOS8.3.4.2.7_Ensure_nftables_loopback_traffic_is_configured:def:1
- Title: Ensure nftables loopback traffic is configured
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.CentOS8.3.4.2.8_Ensure_nftables_outbound_and_established_connections_are_configured:def:1
- Title: Ensure nftables outbound and established connections are configured
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.CentOS8.3.4.2.9_Ensure_nftables_default_deny_firewall_policy:def:1
- Title: Ensure nftables default deny firewall policy
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.CentOS8.3.4.2.10_Ensure_nftables_service_is_enabled:def:1
- Title: Ensure nftables service is enabled
- oval:simp.cis.2.0.0.CentOS8.3.4.2.11_Ensure_nftables_rules_are_permanent:def:1
- Title: Ensure nftables rules are permanent
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.CentOS8.3.4.3.1.1_Ensure_iptables_packages_are_installed:def:1
- Title: Ensure iptables packages are installed
- oval:simp.cis.2.0.0.CentOS8.3.4.3.1.2_Ensure_nftables_is_not_installed_with_iptables:def:1
- Title: Ensure nftables is not installed with iptables
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.CentOS8.3.4.3.1.3_Ensure_firewalld_is_either_not_installed_or_masked_with_iptables:def:1
- Title: Ensure firewalld is either not installed or masked with iptables
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.CentOS8.3.4.3.2.1_Ensure_iptables_loopback_traffic_is_configured:def:1
- Title: Ensure iptables loopback traffic is configured
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.CentOS8.3.4.3.2.2_Ensure_iptables_outbound_and_established_connections_are_configured:def:1
- Title: Ensure iptables outbound and established connections are configured
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.CentOS8.3.4.3.2.4_Ensure_iptables_default_deny_firewall_policy:def:1
- Title: Ensure iptables default deny firewall policy
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.CentOS8.3.4.3.2.5_Ensure_iptables_rules_are_saved:def:1
- Title: Ensure iptables rules are saved
- oval:simp.cis.2.0.0.CentOS8.3.4.3.2.6_Ensure_iptables_is_enabled_and_active:def:1
- Title: Ensure iptables is enabled and active
- oval:simp.cis.2.0.0.CentOS8.3.4.3.3.1_Ensure_ip6tables_loopback_traffic_is_configured:def:1
- Title: Ensure ip6tables loopback traffic is configured
- oval:simp.cis.2.0.0.CentOS8.3.4.3.3.2_Ensure_ip6tables_outbound_and_established_connections_are_configured:def:1
- Title: Ensure ip6tables outbound and established connections are configured
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.CentOS8.3.4.3.3.3_Ensure_ip6tables_firewall_rules_exist_for_all_open_ports:def:1
- Title: Ensure ip6tables firewall rules exist for all open ports
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.CentOS8.3.4.3.3.4_Ensure_ip6tables_default_deny_firewall_policy:def:1
- Title: Ensure ip6tables default deny firewall policy
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.CentOS8.3.4.3.3.5_Ensure_ip6tables_rules_are_saved:def:1
- Title: Ensure ip6tables rules are saved
- oval:simp.cis.2.0.0.CentOS8.3.4.3.3.6_Ensure_ip6tables_is_enabled_and_active:def:1
- Title: Ensure ip6tables is enabled and active
- oval:simp.cis.2.0.0.CentOS8.1.10_Ensure_system-wide_crypto_policy_is_not_legacy:def:1
- Title: Ensure system-wide crypto policy is not legacy
- oval:simp.cis.2.0.0.CentOS8.5.2.14_Ensure_system-wide_crypto_policy_is_not_over-ridden:def:1
- Title: Ensure system-wide crypto policy is not over-ridden
- oval:simp.cis.2.0.0.CentOS8.4.1.3.11_Ensure_session_initiation_information_is_collected:def:1
- Title: Ensure session initiation information is collected
- oval:simp.cis.2.0.0.CentOS8.5.2.16_Ensure_SSH_MaxAuthTries_is_set_to_4_or_less:def:1
- Title: Ensure SSH MaxAuthTries is set to 4 or less
OracleLinux 7 (201/209 [96%])
- oval:simp.cis.3.1.1.OracleLinux7.1.1.1.1_Ensure_mounting_of_cramfs_filesystems_is_disabled:def:1
- Title: Ensure mounting of cramfs filesystems is disabled
- oval:simp.cis.3.1.1.OracleLinux7.1.1.1.2_Ensure_mounting_of_squashfs_filesystems_is_disabled:def:1
- Title: Ensure mounting of squashfs filesystems is disabled
- oval:simp.cis.3.1.1.OracleLinux7.1.1.1.3_Ensure_mounting_of_udf_filesystems_is_disabled:def:1
- Title: Ensure mounting of udf filesystems is disabled
- oval:simp.cis.3.1.1.OracleLinux7.1.1.4_Ensure_nodev_option_set_on_tmp_partition:def:1
- Title: Ensure nodev option set on /tmp partition
- oval:simp.cis.3.1.1.OracleLinux7.1.1.5_Ensure_nosuid_option_set_on_tmp_partition:def:1
- Title: Ensure nosuid option set on /tmp partition
- oval:simp.cis.3.1.1.OracleLinux7.1.1.6_Ensure_devshm_is_configured:def:1
- Title: Ensure /dev/shm is configured
- oval:simp.cis.3.1.1.OracleLinux7.1.1.8_Ensure_nodev_option_set_on_devshm_partition:def:1
- Title: Ensure nodev option set on /dev/shm partition
- oval:simp.cis.3.1.1.OracleLinux7.1.1.9_Ensure_nosuid_option_set_on_devshm_partition:def:1
- Title: Ensure nosuid option set on /dev/shm partition
- oval:simp.cis.3.1.1.OracleLinux7.1.1.13_Ensure_vartmp_partition_includes_the_nodev_option:def:1
- Title: Ensure /var/tmp partition includes the nodev option
- oval:simp.cis.3.1.1.OracleLinux7.1.1.14_Ensure_vartmp_partition_includes_the_nosuid_option:def:1
- Title: Ensure /var/tmp partition includes the nosuid option
- oval:simp.cis.3.1.1.OracleLinux7.1.1.18_Ensure_home_partition_includes_the_nodev_option:def:1
- Title: Ensure /home partition includes the nodev option
- oval:simp.cis.3.1.1.OracleLinux7.1.1.20_Ensure_nodev_option_set_on_removable_media_partitions:def:1
- Title: Ensure nodev option set on removable media partitions
- oval:simp.cis.3.1.1.OracleLinux7.1.1.21_Ensure_nosuid_option_set_on_removable_media_partitions:def:1
- Title: Ensure nosuid option set on removable media partitions
- oval:simp.cis.3.1.1.OracleLinux7.1.1.22_Ensure_sticky_bit_is_set_on_all_world-writable_directories:def:1
- Title: Ensure sticky bit is set on all world-writable directories
- oval:simp.cis.3.1.1.OracleLinux7.1.4.1_Ensure_bootloader_password_is_set:def:1
- Title: Ensure bootloader password is set
- oval:simp.cis.3.1.1.OracleLinux7.1.4.2_Ensure_permissions_on_bootloader_config_are_configured:def:1
- Title: Ensure permissions on bootloader config are configured
- oval:simp.cis.3.1.1.OracleLinux7.1.4.3_Ensure_authentication_required_for_single_user_mode:def:1
- Title: Ensure authentication required for single user mode
- oval:simp.cis.3.1.1.OracleLinux7.1.5.1_Ensure_core_dumps_are_restricted:def:1
- Title: Ensure core dumps are restricted
- oval:simp.cis.3.1.1.OracleLinux7.1.7.1_Ensure_message_of_the_day_is_configured_properly:def:1
- Title: Ensure message of the day is configured properly
- oval:simp.cis.3.1.1.OracleLinux7.1.7.2_Ensure_local_login_warning_banner_is_configured_properly:def:1
- Title: Ensure local login warning banner is configured properly
- oval:simp.cis.3.1.1.OracleLinux7.1.7.3_Ensure_remote_login_warning_banner_is_configured_properly:def:1
- Title: Ensure remote login warning banner is configured properly
- oval:simp.cis.3.1.1.OracleLinux7.1.8.2_Ensure_GDM_login_banner_is_configured:def:1
- Title: Ensure GDM login banner is configured
- oval:simp.cis.3.1.1.OracleLinux7.1.8.3_Ensure_last_logged_in_user_display_is_disabled:def:1
- Title: Ensure last logged in user display is disabled
- oval:simp.cis.3.1.1.OracleLinux7.3.2.1_Ensure_IP_forwarding_is_disabled:def:1
- Title: Ensure IP forwarding is disabled
- oval:simp.cis.3.1.1.OracleLinux7.3.2.2_Ensure_packet_redirect_sending_is_disabled:def:1
- Title: Ensure packet redirect sending is disabled
- oval:simp.cis.3.1.1.OracleLinux7.3.3.1_Ensure_source_routed_packets_are_not_accepted:def:1
- Title: Ensure source routed packets are not accepted
- oval:simp.cis.3.1.1.OracleLinux7.3.3.2_Ensure_ICMP_redirects_are_not_accepted:def:1
- Title: Ensure ICMP redirects are not accepted
- oval:simp.cis.3.1.1.OracleLinux7.3.3.3_Ensure_secure_ICMP_redirects_are_not_accepted:def:1
- Title: Ensure secure ICMP redirects are not accepted
- oval:simp.cis.3.1.1.OracleLinux7.3.3.5_Ensure_broadcast_ICMP_requests_are_ignored:def:1
- Title: Ensure broadcast ICMP requests are ignored
- oval:simp.cis.3.1.1.OracleLinux7.3.3.6_Ensure_bogus_ICMP_responses_are_ignored:def:1
- Title: Ensure bogus ICMP responses are ignored
- oval:simp.cis.3.1.1.OracleLinux7.3.3.7_Ensure_Reverse_Path_Filtering_is_enabled:def:1
- Title: Ensure Reverse Path Filtering is enabled
- oval:simp.cis.3.1.1.OracleLinux7.3.3.8_Ensure_TCP_SYN_Cookies_is_enabled:def:1
- Title: Ensure TCP SYN Cookies is enabled
- oval:simp.cis.3.1.1.OracleLinux7.3.3.9_Ensure_IPv6_router_advertisements_are_not_accepted:def:1
- Title: Ensure IPv6 router advertisements are not accepted
- oval:simp.cis.3.1.1.OracleLinux7.4.1.16_Ensure_kernel_module_loading_and_unloading_is_collected:def:1
- Title: Ensure kernel module loading and unloading is collected
- oval:simp.cis.3.1.1.OracleLinux7.4.2.1.3_Ensure_rsyslog_default_file_permissions_configured:def:1
- Title: Ensure rsyslog default file permissions configured
- oval:simp.cis.3.1.1.OracleLinux7.4.2.3_Ensure_permissions_on_all_logfiles_are_configured:def:1
- Title: Ensure permissions on all logfiles are configured
- oval:simp.cis.3.1.1.OracleLinux7.5.1.1_Ensure_cron_daemon_is_enabled_and_running:def:1
- Title: Ensure cron daemon is enabled and running
- oval:simp.cis.3.1.1.OracleLinux7.5.1.3_Ensure_permissions_on_etccron.hourly_are_configured:def:1
- Title: Ensure permissions on /etc/cron.hourly are configured
- oval:simp.cis.3.1.1.OracleLinux7.5.3.12_Ensure_SSH_PermitUserEnvironment_is_disabled:def:1
- Title: Ensure SSH PermitUserEnvironment is disabled
- oval:simp.cis.3.1.1.OracleLinux7.5.3.17_Ensure_SSH_LoginGraceTime_is_set_to_one_minute_or_less:def:1
- Title: Ensure SSH LoginGraceTime is set to one minute or less
- oval:simp.cis.3.1.1.OracleLinux7.5.3.18_Ensure_SSH_warning_banner_is_configured:def:1
- Title: Ensure SSH warning banner is configured
- oval:simp.cis.3.1.1.OracleLinux7.5.3.19_Ensure_SSH_PAM_is_enabled:def:1
- Title: Ensure SSH PAM is enabled
- oval:simp.cis.3.1.1.OracleLinux7.5.3.21_Ensure_SSH_MaxStartups_is_configured:def:1
- Title: Ensure SSH MaxStartups is configured
- oval:simp.cis.3.1.1.OracleLinux7.5.3.22_Ensure_SSH_MaxSessions_is_limited:def:1
- Title: Ensure SSH MaxSessions is limited
- oval:simp.cis.3.1.1.OracleLinux7.5.5.3_Ensure_default_group_for_the_root_account_is_GID_0:def:1
- Title: Ensure default group for the root account is GID 0
- oval:simp.cis.3.1.1.OracleLinux7.5.5.5_Ensure_default_user_umask_is_configured:def:1
- Title: Ensure default user umask is configured
- NOTE: The umask will be set to 027 within /etc/profile.d/simp.sh, however, this check still fails the scan.
- oval:simp.cis.3.1.1.OracleLinux7.5.6_Ensure_root_login_is_restricted_to_system_console:def:1
- Title: Ensure root login is restricted to system console
- oval:simp.cis.3.1.1.OracleLinux7.5.7_Ensure_access_to_the_su_command_is_restricted:def:1
- Title: Ensure access to the su command is restricted
- oval:simp.cis.3.1.1.OracleLinux7.6.2.4_Ensure_shadow_group_is_empty:def:1
- Title: Ensure shadow group is empty
- oval:simp.cis.3.1.1.OracleLinux7.6.2.9_Ensure_root_is_the_only_UID_0_account:def:1
- Title: Ensure root is the only UID 0 account
- oval:simp.cis.3.1.1.OracleLinux7.6.2.10_Ensure_root_PATH_Integrity:def:1
- Title: Ensure root PATH Integrity
- oval:simp.cis.3.1.1.OracleLinux7.6.2.11_Ensure_all_users_home_directories_exist:def:1
- Title: Ensure all users’ home directories exist
- oval:simp.cis.3.1.1.OracleLinux7.6.2.15Ensure_no_users_have.forward_files:def:1
- Title: Ensure no users have .forward files
- oval:simp.cis.3.1.1.OracleLinux7.1.6.1.1_Ensure_SELinux_is_installed:def:1
- Title: Ensure SELinux is installed
- oval:simp.cis.3.1.1.OracleLinux7.1.6.1.2_Ensure_SELinux_is_not_disabled_in_bootloader_configuration:def:1
- Title: Ensure SELinux is not disabled in bootloader configuration
- oval:simp.cis.3.1.1.OracleLinux7.1.6.1.3_Ensure_SELinux_policy_is_configured:def:1
- Title: Ensure SELinux policy is configured
- oval:simp.cis.3.1.1.OracleLinux7.1.6.1.4_Ensure_the_SELinux_mode_is_enforcing_or_permissive:def:1
- Title: Ensure the SELinux mode is enforcing or permissive
- oval:simp.cis.3.1.1.OracleLinux7.1.6.1.5_Ensure_the_SELinux_mode_is_enforcing:def:1
- Title: Ensure the SELinux mode is enforcing
- oval:simp.cis.3.1.1.OracleLinux7.1.6.1.7_Ensure_SETroubleshoot_is_not_installed:def:1
- Title: Ensure SETroubleshoot is not installed
- oval:simp.cis.3.1.1.OracleLinux7.1.7.4_Ensure_permissions_on_etcmotd_are_configured:def:1
- Title: Ensure permissions on /etc/motd are configured
- oval:simp.cis.3.1.1.OracleLinux7.1.7.5_Ensure_permissions_on_etcissue_are_configured:def:1
- Title: Ensure permissions on /etc/issue are configured
- oval:simp.cis.3.1.1.OracleLinux7.1.7.6_Ensure_permissions_on_etcissue.net_are_configured:def:1
- Title: Ensure permissions on /etc/issue.net are configured
- oval:simp.cis.3.1.1.OracleLinux7.5.1.2_Ensure_permissions_on_etccrontab_are_configured:def:1
- Title: Ensure permissions on /etc/crontab are configured
- oval:simp.cis.3.1.1.OracleLinux7.5.1.4_Ensure_permissions_on_etccron.daily_are_configured:def:1
- Title: Ensure permissions on /etc/cron.daily are configured
- oval:simp.cis.3.1.1.OracleLinux7.5.1.5_Ensure_permissions_on_etccron.weekly_are_configured:def:1
- Title: Ensure permissions on /etc/cron.weekly are configured
- oval:simp.cis.3.1.1.OracleLinux7.5.1.6_Ensure_permissions_on_etccron.monthly_are_configured:def:1
- Title: Ensure permissions on /etc/cron.monthly are configured
- oval:simp.cis.3.1.1.OracleLinux7.5.1.7_Ensure_permissions_on_etccron.d_are_configured:def:1
- Title: Ensure permissions on /etc/cron.d are configured
- oval:simp.cis.3.1.1.OracleLinux7.5.3.1_Ensure_permissions_on_etcsshsshd_config_are_configured:def:1
- Title: Ensure permissions on /etc/ssh/sshd_config are configured
- oval:simp.cis.3.1.1.OracleLinux7.5.3.2_Ensure_permissions_on_SSH_private_host_key_files_are_configured:def:1
- Title: Ensure permissions on SSH private host key files are configured
- oval:simp.cis.3.1.1.OracleLinux7.5.3.3_Ensure_permissions_on_SSH_public_host_key_files_are_configured:def:1
- Title: Ensure permissions on SSH public host key files are configured
- oval:simp.cis.3.1.1.OracleLinux7.6.1.2_Ensure_permissions_on_etcpasswd_are_configured:def:1
- Title: Ensure permissions on /etc/passwd are configured
- oval:simp.cis.3.1.1.OracleLinux7.6.1.3_Ensure_permissions_on_etcpasswd-_are_configured:def:1
- Title: Ensure permissions on /etc/passwd- are configured
- oval:simp.cis.3.1.1.OracleLinux7.6.1.4_Ensure_permissions_on_etcshadow_are_configured:def:1
- Title: Ensure permissions on /etc/shadow are configured
- oval:simp.cis.3.1.1.OracleLinux7.6.1.5_Ensure_permissions_on_etcshadow-_are_configured:def:1
- Title: Ensure permissions on /etc/shadow- are configured
- oval:simp.cis.3.1.1.OracleLinux7.6.1.7_Ensure_permissions_on_etcgshadow_are_configured:def:1
- Title: Ensure permissions on /etc/gshadow are configured
- oval:simp.cis.3.1.1.OracleLinux7.6.1.8_Ensure_permissions_on_etcgroup_are_configured:def:1
- Title: Ensure permissions on /etc/group are configured
- oval:simp.cis.3.1.1.OracleLinux7.6.1.9_Ensure_permissions_on_etcgroup-_are_configured:def:1
- Title: Ensure permissions on /etc/group- are configured
- oval:simp.cis.3.1.1.OracleLinux7.6.2.12_Ensure_users_own_their_home_directories:def:1
- Title: Ensure users own their home directories
- oval:simp.cis.3.1.1.OracleLinux7.6.2.13_Ensure_users_home_directories_permissions_are_750_or_more_restrictive:def:1
- Title: Ensure users’ home directories permissions are 750 or more restrictive
- oval:simp.cis.3.1.1.OracleLinux7.6.2.14_Ensure_users_dot_files_are_not_group_or_world_writable:def:1
- Title: Ensure users’ dot files are not group or world writable
- oval:simp.cis.3.1.1.OracleLinux7.5.5.1.4_Ensure_inactive_password_lock_is_30_days_or_less:def:1
- Title: Ensure inactive password lock is 30 days or less
- oval:simp.cis.3.1.1.OracleLinux7.4.1.7_Ensure_login_and_logout_events_are_collected:def:1
- Title: Ensure login and logout events are collected
- oval:simp.cis.3.1.1.OracleLinux7.4.1.8_Ensure_session_initiation_information_is_collected:def:1
- Title: Ensure session initiation information is collected
- oval:simp.cis.3.1.1.OracleLinux7.5.3.16_Ensure_SSH_Idle_Timeout_Interval_is_configured:def:1
- Title: Ensure SSH Idle Timeout Interval is configured
- oval:simp.cis.3.1.1.OracleLinux7.5.5.4_Ensure_default_user_shell_timeout_is_configured:def:1
- Title: Ensure default user shell timeout is configured
-
*NOTE: The scanner fails to pickup on the format the product uses for setting the timeout: [ $TMOUT ] |
|
export TMOUT=900. The setting is also set in a nonstandard location: /etc/profile.d/simp.sh.* |
- oval:simp.cis.3.1.1.OracleLinux7.1.1.23_Disable_Automounting:def:1
- Title: Disable Automounting
- oval:simp.cis.3.1.1.OracleLinux7.1.1.24_Disable_USB_Storage:def:1
- Title: Disable USB Storage
- oval:simp.cis.3.1.1.OracleLinux7.5.3.4_Ensure_SSH_access_is_limited:def:1
- Title: Ensure SSH access is limited
- oval:simp.cis.3.1.1.OracleLinux7.5.3.10_Ensure_SSH_root_login_is_disabled:def:1
- Title: Ensure SSH root login is disabled
- oval:simp.cis.3.1.1.OracleLinux7.3.1.2_Ensure_wireless_interfaces_are_disabled:def:1
- Title: Ensure wireless interfaces are disabled
- oval:simp.cis.3.1.1.OracleLinux7.3.3.4_Ensure_suspicious_packets_are_logged:def:1
- Title: Ensure suspicious packets are logged
- oval:simp.cis.3.1.1.OracleLinux7.4.1.1.1_Ensure_auditd_is_installed:def:1
- Title: Ensure auditd is installed
- oval:simp.cis.3.1.1.OracleLinux7.4.1.1.2_Ensure_auditd_service_is_enabled_and_running:def:1
- Title: Ensure auditd service is enabled and running
- oval:simp.cis.3.1.1.OracleLinux7.4.1.1.3_Ensure_auditing_for_processes_that_start_prior_to_auditd_is_enabled:def:1
- Title: Ensure auditing for processes that start prior to auditd is enabled
- oval:simp.cis.3.1.1.OracleLinux7.4.1.2.2_Ensure_audit_logs_are_not_automatically_deleted:def:1
- Title: Ensure audit logs are not automatically deleted
- oval:simp.cis.3.1.1.OracleLinux7.4.1.2.3_Ensure_system_is_disabled_when_audit_logs_are_full:def:1
- Title: Ensure system is disabled when audit logs are full
- oval:simp.cis.3.1.1.OracleLinux7.4.1.2.4_Ensure_audit_backlog_limit_is_sufficient:def:1
- Title: Ensure audit_backlog_limit is sufficient
- oval:simp.cis.3.1.1.OracleLinux7.4.1.5_Ensure_events_that_modify_the_systems_network_environment_are_collected:def:1
- Title: Ensure events that modify the system’s network environment are collected
- oval:simp.cis.3.1.1.OracleLinux7.4.1.11_Ensure_use_of_privileged_commands_is_collected:def:1
- Title: Ensure use of privileged commands is collected
- NOTE: The available setuid/setgid commands on a given system could vary greatly. Several of the more common commands are audited, but there is currently no automated way to identify and audit all possible setuid/setgid commands available on any given system.
- oval:simp.cis.3.1.1.OracleLinux7.4.1.12_Ensure_successful_file_system_mounts_are_collected:def:1
- Title: Ensure successful file system mounts are collected
- oval:simp.cis.3.1.1.OracleLinux7.4.1.13_Ensure_file_deletion_events_by_users_are_collected:def:1
- Title: Ensure file deletion events by users are collected
- oval:simp.cis.3.1.1.OracleLinux7.4.1.17_Ensure_the_audit_configuration_is_immutable:def:1
- Title: Ensure the audit configuration is immutable
- oval:simp.cis.3.1.1.OracleLinux7.4.2.1.1_Ensure_rsyslog_is_installed:def:1
- Title: Ensure rsyslog is installed
- oval:simp.cis.3.1.1.OracleLinux7.4.2.1.2_Ensure_rsyslog_Service_is_enabled_and_running:def:1
- Title: Ensure rsyslog Service is enabled and running
- oval:simp.cis.3.1.1.OracleLinux7.4.2.1.4_Ensure_logging_is_configured:def:1
- Title: Ensure logging is configured
- oval:simp.cis.3.1.1.OracleLinux7.4.2.2.3_Ensure_journald_is_configured_to_write_logfiles_to_persistent_disk:def:1
- Title: Ensure journald is configured to write logfiles to persistent disk
- oval:simp.cis.3.1.1.OracleLinux7.5.3.5_Ensure_SSH_LogLevel_is_appropriate:def:1
- Title: Ensure SSH LogLevel is appropriate
- oval:simp.cis.3.1.1.OracleLinux7.2.2.1.1_Ensure_time_synchronization_is_in_use:def:1
- Title: Ensure time synchronization is in use
- oval:simp.cis.3.1.1.OracleLinux7.2.2.1.2_Ensure_chrony_is_configured:def:1
- Title: Ensure chrony is configured
- NOTE: We are configuring the system to use ntpd instead of chrony.
- oval:simp.cis.3.1.1.OracleLinux7.2.2.1.3_Ensure_ntp_is_configured:def:1
- Title: Ensure ntp is configured
- oval:simp.cis.3.1.1.OracleLinux7.1.1.3_Ensure_noexec_option_set_on_tmp_partition:def:1
- Title: Ensure noexec option set on /tmp partition
- oval:simp.cis.3.1.1.OracleLinux7.1.1.7_Ensure_noexec_option_set_on_devshm_partition:def:1
- Title: Ensure noexec option set on /dev/shm partition
- oval:simp.cis.3.1.1.OracleLinux7.1.1.12_Ensure_vartmp_partition_includes_the_noexec_option:def:1
- Title: Ensure /var/tmp partition includes the noexec option
- oval:simp.cis.3.1.1.OracleLinux7.1.1.19_Ensure_removable_media_partitions_include_noexec_option:def:1
- Title: Ensure removable media partitions include noexec option
- oval:simp.cis.3.1.1.OracleLinux7.1.8.1_Ensure_GNOME_Display_Manager_is_removed:def:1
- Title: Ensure GNOME Display Manager is removed
- oval:simp.cis.3.1.1.OracleLinux7.2.1.1_Ensure_xinetd_is_not_installed:def:1
- Title: Ensure xinetd is not installed
- oval:simp.cis.3.1.1.OracleLinux7.2.2.2_Ensure_X11_Server_components_are_not_installed:def:1
- Title: Ensure X11 Server components are not installed
- oval:simp.cis.3.1.1.OracleLinux7.2.2.13_Ensure_net-snmp_is_not_installed:def:1
- Title: Ensure net-snmp is not installed
- oval:simp.cis.3.1.1.OracleLinux7.2.2.14_Ensure_NIS_server_is_not_installed:def:1
- Title: Ensure NIS server is not installed
- oval:simp.cis.3.1.1.OracleLinux7.2.2.15_Ensure_telnet-server_is_not_installed:def:1
- Title: Ensure telnet-server is not installed
- oval:simp.cis.3.1.1.OracleLinux7.2.3.1_Ensure_NIS_Client_is_not_installed:def:1
- Title: Ensure NIS Client is not installed
- oval:simp.cis.3.1.1.OracleLinux7.2.3.2_Ensure_rsh_client_is_not_installed:def:1
- Title: Ensure rsh client is not installed
- oval:simp.cis.3.1.1.OracleLinux7.2.3.3_Ensure_talk_client_is_not_installed:def:1
- Title: Ensure talk client is not installed
- oval:simp.cis.3.1.1.OracleLinux7.2.3.4_Ensure_telnet_client_is_not_installed:def:1
- Title: Ensure telnet client is not installed
- oval:simp.cis.3.1.1.OracleLinux7.2.3.5_Ensure_LDAP_client_is_not_installed:def:1
- Title: Ensure LDAP client is not installed
- oval:simp.cis.3.1.1.OracleLinux7.5.4.1_Ensure_password_creation_requirements_are_configured:def:1
- Title: Ensure password creation requirements are configured
- oval:simp.cis.3.1.1.OracleLinux7.5.5.1.1_Ensure_password_expiration_is_365_days_or_less:def:1
- Title: Ensure password expiration is 365 days or less
- NOTE: The product sets PASS_MAX_DAYS in /etc/login.defs, however, there is currently no mechanisme to enforce the setting for existing users in /etc/shadow.
- oval:simp.cis.3.1.1.OracleLinux7.5.5.1.2_Ensure_minimum_days_between_password_changes_is_configured:def:1
- Title: Ensure minimum days between password changes is configured
- NOTE: The product sets PASS_MIN_DAYS in /etc/login.defs, however, there is currently no mechanisme to enforce the setting for existing users in /etc/shadow.
- oval:simp.cis.3.1.1.OracleLinux7.5.5.1.3_Ensure_password_expiration_warning_days_is_7_or_more:def:1
- Title: Ensure password expiration warning days is 7 or more
- oval:simp.cis.3.1.1.OracleLinux7.5.5.1.5_Ensure_all_users_last_password_change_date_is_in_the_past:def:1
- Title: Ensure all users last password change date is in the past
- oval:simp.cis.3.1.1.OracleLinux7.6.2.1_Ensure_accounts_in_etcpasswd_use_shadowed_passwords:def:1
- Title: Ensure accounts in /etc/passwd use shadowed passwords
- oval:simp.cis.3.1.1.OracleLinux7.6.2.2_Ensure_etcshadow_password_fields_are_not_empty:def:1
- Title: Ensure /etc/shadow password fields are not empty
- oval:simp.cis.3.1.1.OracleLinux7.5.4.3_Ensure_password_hashing_algorithm_is_SHA-512:def:1
- Title: Ensure password hashing algorithm is SHA-512
- oval:simp.cis.3.1.1.OracleLinux7.6.1.6_Ensure_permissions_on_etcgshadow-_are_configured:def:1
- Title: Ensure permissions on /etc/gshadow- are configured
- oval:simp.cis.3.1.1.OracleLinux7.6.2.16Ensure_no_users_have.netrc_files:def:1
- Title: Ensure no users have .netrc files
- oval:simp.cis.3.1.1.OracleLinux7.6.2.17Ensure_no_users_have.rhosts_files:def:1
- Title: Ensure no users have .rhosts files
- oval:simp.cis.3.1.1.OracleLinux7.5.3.14_Ensure_only_strong_MAC_algorithms_are_used:def:1
- Title: Ensure only strong MAC algorithms are used
- oval:simp.cis.3.1.1.OracleLinux7.4.2.2.1_Ensure_journald_is_configured_to_send_logs_to_rsyslog:def:1
- Title: Ensure journald is configured to send logs to rsyslog
- oval:simp.cis.3.1.1.OracleLinux7.4.2.1.5_Ensure_rsyslog_is_configured_to_send_logs_to_a_remote_log_host:def:1
- Title: Ensure rsyslog is configured to send logs to a remote log host
- oval:simp.cis.3.1.1.OracleLinux7.5.4.2_Ensure_lockout_for_failed_password_attempts_is_configured:def:1
- Title: Ensure lockout for failed password attempts is configured
- oval:simp.cis.3.1.1.OracleLinux7.1.6.1.8_Ensure_the_MCS_Translation_Service_mcstrans_is_not_installed:def:1
- Title: Ensure the MCS Translation Service (mcstrans) is not installed
- oval:simp.cis.3.1.1.OracleLinux7.1.8.4_Ensure_XDCMP_is_not_enabled:def:1
- Title: Ensure XDCMP is not enabled
- oval:simp.cis.3.1.1.OracleLinux7.2.2.3_Ensure_Avahi_Server_is_not_installed:def:1
- Title: Ensure Avahi Server is not installed
- oval:simp.cis.3.1.1.OracleLinux7.2.2.4_Ensure_CUPS_is_not_installed:def:1
- Title: Ensure CUPS is not installed
- oval:simp.cis.3.1.1.OracleLinux7.2.2.5_Ensure_DHCP_Server_is_not_installed:def:1
- Title: Ensure DHCP Server is not installed
- oval:simp.cis.3.1.1.OracleLinux7.2.2.6_Ensure_LDAP_server_is_not_installed:def:1
- Title: Ensure LDAP server is not installed
- oval:simp.cis.3.1.1.OracleLinux7.2.2.7_Ensure_DNS_Server_is_not_installed:def:1
- Title: Ensure DNS Server is not installed
- oval:simp.cis.3.1.1.OracleLinux7.2.2.8_Ensure_FTP_Server_is_not_installed:def:1
- Title: Ensure FTP Server is not installed
- oval:simp.cis.3.1.1.OracleLinux7.2.2.9_Ensure_HTTP_server_is_not_installed:def:1
- Title: Ensure HTTP server is not installed
- oval:simp.cis.3.1.1.OracleLinux7.2.2.10_Ensure_IMAP_and_POP3_server_is_not_installed:def:1
- Title: Ensure IMAP and POP3 server is not installed
- oval:simp.cis.3.1.1.OracleLinux7.2.2.11_Ensure_Samba_is_not_installed:def:1
- Title: Ensure Samba is not installed
- oval:simp.cis.3.1.1.OracleLinux7.2.2.12_Ensure_HTTP_Proxy_Server_is_not_installed:def:1
- Title: Ensure HTTP Proxy Server is not installed
- oval:simp.cis.3.1.1.OracleLinux7.2.2.16_Ensure_mail_transfer_agent_is_configured_for_local-only_mode:def:1
- Title: Ensure mail transfer agent is configured for local-only mode
- oval:simp.cis.3.1.1.OracleLinux7.2.2.17_Ensure_nfs-utils_is_not_installed_or_the__nfs-server_service_is_masked:def:1
- Title: Ensure nfs-utils is not installed or the nfs-server service is masked
- oval:simp.cis.3.1.1.OracleLinux7.2.2.18_Ensure_rpcbind_is_not_installed_or_the__rpcbind_services_are_masked:def:1
- Title: Ensure rpcbind is not installed or the rpcbind services are masked
- oval:simp.cis.3.1.1.OracleLinux7.2.2.19_Ensure_rsync_is_not_installed_or_the_rsyncd_service_is_masked:def:1
- Title: Ensure rsync is not installed or the rsyncd service is masked
- oval:simp.cis.3.1.1.OracleLinux7.2.4_Ensure_nonessential_services_are_removed_or_masked:def:1
- Title: Ensure nonessential services are removed or masked
- oval:simp.cis.3.1.1.OracleLinux7.3.4.1_Ensure_DCCP_is_disabled:def:1
- Title: Ensure DCCP is disabled
- oval:simp.cis.3.1.1.OracleLinux7.3.4.2_Ensure_SCTP_is_disabled:def:1
- Title: Ensure SCTP is disabled
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.2.3_Ensure_iptables_rules_exist_for_all_open_ports:def:1
- Title: Ensure iptables rules exist for all open ports
- oval:simp.cis.3.1.1.OracleLinux7.4.2.1.6_Ensure_remote_rsyslog_messages_are_only_accepted_on_designated_log_hosts.:def:1
- Title: Ensure remote rsyslog messages are only accepted on designated log hosts.
- oval:simp.cis.3.1.1.OracleLinux7.5.3.6_Ensure_SSH_X11_forwarding_is_disabled:def:1
- Title: Ensure SSH X11 forwarding is disabled
- oval:simp.cis.3.1.1.OracleLinux7.5.3.8_Ensure_SSH_IgnoreRhosts_is_enabled:def:1
- Title: Ensure SSH IgnoreRhosts is enabled
- oval:simp.cis.3.1.1.OracleLinux7.5.3.20_Ensure_SSH_AllowTcpForwarding_is_disabled:def:1
- Title: Ensure SSH AllowTcpForwarding is disabled
- oval:simp.cis.3.1.1.OracleLinux7.1.1.2_Ensure_tmp_is_configured:def:1
- Title: Ensure /tmp is configured
- oval:simp.cis.3.1.1.OracleLinux7.3.1.1_Disable_IPv6:def:1
- oval:simp.cis.3.1.1.OracleLinux7.3.5.1.1_Ensure_firewalld_is_installed:def:1
- Title: Ensure firewalld is installed
- oval:simp.cis.3.1.1.OracleLinux7.3.5.1.2_Ensure_iptables-services_not_installed_with_firewalld:def:1
- Title: Ensure iptables-services not installed with firewalld
- oval:simp.cis.3.1.1.OracleLinux7.3.5.1.3_Ensure_nftables_either_not_installed_or_masked_with_firewalld:def:1
- Title: Ensure nftables either not installed or masked with firewalld
- oval:simp.cis.3.1.1.OracleLinux7.3.5.1.4_Ensure_firewalld_service_enabled_and_running:def:1
- Title: Ensure firewalld service enabled and running
- oval:simp.cis.3.1.1.OracleLinux7.3.5.1.5_Ensure_firewalld_default_zone_is_set:def:1
- Title: Ensure firewalld default zone is set
- oval:simp.cis.3.1.1.OracleLinux7.3.5.1.6_Ensure_network_interfaces_are_assigned_to_appropriate_zone:def:1
- Title: Ensure network interfaces are assigned to appropriate zone
- oval:simp.cis.3.1.1.OracleLinux7.3.5.1.7_Ensure_firewalld_drops_unnecessary_services_and_ports:def:1
- Title: Ensure firewalld drops unnecessary services and ports
- oval:simp.cis.3.1.1.OracleLinux7.3.5.2.1_Ensure_nftables_is_installed:def:1
- Title: Ensure nftables is installed
- oval:simp.cis.3.1.1.OracleLinux7.3.5.2.2_Ensure_firewalld_is_either_not_installed_or_masked_with_nftables:def:1
- Title: Ensure firewalld is either not installed or masked with nftables
- oval:simp.cis.3.1.1.OracleLinux7.3.5.2.3_Ensure_iptables-services_not_installed_with_nftables:def:1
- Title: Ensure iptables-services not installed with nftables
- oval:simp.cis.3.1.1.OracleLinux7.3.5.2.4_Ensure_iptables_are_flushed_with_nftables:def:1
- Title: Ensure iptables are flushed with nftables
- oval:simp.cis.3.1.1.OracleLinux7.3.5.2.5_Ensure_an_nftables_table_exists:def:1
- Title: Ensure an nftables table exists
- oval:simp.cis.3.1.1.OracleLinux7.3.5.2.6_Ensure_nftables_base_chains_exist:def:1
- Title: Ensure nftables base chains exist
- oval:simp.cis.3.1.1.OracleLinux7.3.5.2.7_Ensure_nftables_loopback_traffic_is_configured:def:1
- Title: Ensure nftables loopback traffic is configured
- oval:simp.cis.3.1.1.OracleLinux7.3.5.2.8_Ensure_nftables_outbound_and_established_connections_are_configured:def:1
- Title: Ensure nftables outbound and established connections are configured
- oval:simp.cis.3.1.1.OracleLinux7.3.5.2.9_Ensure_nftables_default_deny_firewall_policy:def:1
- Title: Ensure nftables default deny firewall policy
- oval:simp.cis.3.1.1.OracleLinux7.3.5.2.10_Ensure_nftables_service_is_enabled:def:1
- Title: Ensure nftables service is enabled
- oval:simp.cis.3.1.1.OracleLinux7.3.5.2.11_Ensure_nftables_rules_are_permanent:def:1
- Title: Ensure nftables rules are permanent
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.1.1_Ensure_iptables_packages_are_installed:def:1
- Title: Ensure iptables packages are installed
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.1.2_Ensure_nftables_is_not_installed_with_iptables:def:1
- Title: Ensure nftables is not installed with iptables
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.1.3_Ensure_firewalld_is_either_not_installed_or_masked_with_iptables:def:1
- Title: Ensure firewalld is either not installed or masked with iptables
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.2.1_Ensure_iptables_loopback_traffic_is_configured:def:1
- Title: Ensure iptables loopback traffic is configured
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.2.2_Ensure_iptables_outbound_and_established_connections_are_configured:def:1
- Title: Ensure iptables outbound and established connections are configured
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.2.4_Ensure_iptables_default_deny_firewall_policy:def:1
- Title: Ensure iptables default deny firewall policy
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.2.5_Ensure_iptables_rules_are_saved:def:1
- Title: Ensure iptables rules are saved
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.2.6_Ensure_iptables_is_enabled_and_running:def:1
- Title: Ensure iptables is enabled and running
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.3.1_Ensure_ip6tables_loopback_traffic_is_configured:def:1
- Title: Ensure ip6tables loopback traffic is configured
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.3.2_Ensure_ip6tables_outbound_and_established_connections_are_configured:def:1
- Title: Ensure ip6tables outbound and established connections are configured
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.3.3_Ensure_ip6tables_firewall_rules_exist_for_all_open_ports:def:1
- Title: Ensure ip6tables firewall rules exist for all open ports
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.3.4_Ensure_ip6tables_default_deny_firewall_policy:def:1
- Title: Ensure ip6tables default deny firewall policy
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.3.5_Ensure_ip6tables_rules_are_saved:def:1
- Title: Ensure ip6tables rules are saved
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.3.6_Ensure_ip6tables_is_enabled_and_running:def:1
- Title: Ensure ip6tables is enabled and running
- oval:simp.cis.3.1.1.OracleLinux7.5.3.13_Ensure_only_strong_Ciphers_are_used:def:1
- Title: Ensure only strong Ciphers are used
- oval:simp.cis.3.1.1.OracleLinux7.5.3.15_Ensure_only_strong_Key_Exchange_algorithms_are_used:def:1
- Title: Ensure only strong Key Exchange algorithms are used
- oval:simp.cis.3.1.1.OracleLinux7.5.3.7_Ensure_SSH_MaxAuthTries_is_set_to_4_or_less:def:1
- Title: Ensure SSH MaxAuthTries is set to 4 or less
OracleLinux 8 (213/231 [92%])
- oval:simp.cis.2.0.0.OracleLinux8.1.8.2_Ensure_GDM_login_banner_is_configured:def:1
- Title: Ensure GDM login banner is configured
- oval:simp.cis.2.0.0.OracleLinux8.1.8.3_Ensure_last_logged_in_user_display_is_disabled:def:1
- Title: Ensure last logged in user display is disabled
- oval:simp.cis.2.0.0.OracleLinux8.4.2.1.4_Ensure_rsyslog_default_file_permissions_are_configured:def:1
- Title: Ensure rsyslog default file permissions are configured
- oval:simp.cis.2.0.0.OracleLinux8.4.2.3_Ensure_permissions_on_all_logfiles_are_configured:def:1
- Title: Ensure permissions on all logfiles are configured
- NOTE: btmp, lastlog, and wtmp will not have any permissions stripped from them. Doing so could cause login issues for users.
- oval:simp.cis.2.0.0.OracleLinux8.5.2.1_Ensure_permissions_on_etcsshsshd_config_are_configured:def:1
- Title: Ensure permissions on /etc/ssh/sshd_config are configured
- oval:simp.cis.2.0.0.OracleLinux8.5.2.2_Ensure_permissions_on_SSH_private_host_key_files_are_configured:def:1
- Title: Ensure permissions on SSH private host key files are configured
- oval:simp.cis.2.0.0.OracleLinux8.5.2.3_Ensure_permissions_on_SSH_public_host_key_files_are_configured:def:1
- Title: Ensure permissions on SSH public host key files are configured
- oval:simp.cis.2.0.0.OracleLinux8.5.2.6_Ensure_SSH_PAM_is_enabled:def:1
- Title: Ensure SSH PAM is enabled
- oval:simp.cis.2.0.0.OracleLinux8.5.2.10_Ensure_SSH_PermitUserEnvironment_is_disabled:def:1
- Title: Ensure SSH PermitUserEnvironment is disabled
- oval:simp.cis.2.0.0.OracleLinux8.5.2.15_Ensure_SSH_warning_banner_is_configured:def:1
- Title: Ensure SSH warning banner is configured
- oval:simp.cis.2.0.0.OracleLinux8.5.2.17_Ensure_SSH_MaxStartups_is_configured:def:1
- Title: Ensure SSH MaxStartups is configured
- oval:simp.cis.2.0.0.OracleLinux8.5.2.18_Ensure_SSH_MaxSessions_is_set_to_10_or_less:def:1
- Title: Ensure SSH MaxSessions is set to 10 or less
- oval:simp.cis.2.0.0.OracleLinux8.5.2.19_Ensure_SSH_LoginGraceTime_is_set_to_one_minute_or_less:def:1
- Title: Ensure SSH LoginGraceTime is set to one minute or less
- oval:simp.cis.2.0.0.OracleLinux8.5.3.2_Ensure_sudo_commands_use_pty:def:1
- Title: Ensure sudo commands use pty
- oval:simp.cis.2.0.0.OracleLinux8.5.3.7_Ensure_access_to_the_su_command_is_restricted:def:1
- Title: Ensure access to the su command is restricted
- oval:simp.cis.2.0.0.OracleLinux8.5.6.4_Ensure_default_group_for_the_root_account_is_GID_0:def:1
- Title: Ensure default group for the root account is GID 0
- oval:simp.cis.2.0.0.OracleLinux8.6.1.2_Ensure_sticky_bit_is_set_on_all_world-writable_directories:def:1
- Title: Ensure sticky bit is set on all world-writable directories
- oval:simp.cis.2.0.0.OracleLinux8.6.2.7_Ensure_root_PATH_Integrity:def:1
- Title: Ensure root PATH Integrity
- oval:simp.cis.2.0.0.OracleLinux8.6.2.8_Ensure_root_is_the_only_UID_0_account:def:1
- Title: Ensure root is the only UID 0 account
- oval:simp.cis.2.0.0.OracleLinux8.6.2.9_Ensure_all_users_home_directories_exist:def:1
- Title: Ensure all users’ home directories exist
- oval:simp.cis.2.0.0.OracleLinux8.6.2.14Ensure_no_users_have.forward_files:def:1
- Title: Ensure no users have .forward files
- oval:simp.cis.2.0.0.OracleLinux8.1.1.2.3_Ensure_noexec_option_set_on_tmp_partition:def:1
- Title: Ensure noexec option set on /tmp partition
- oval:simp.cis.2.0.0.OracleLinux8.1.1.2.4_Ensure_nosuid_option_set_on_tmp_partition:def:1
- Title: Ensure nosuid option set on /tmp partition
- oval:simp.cis.2.0.0.OracleLinux8.1.1.3.2_Ensure_nodev_option_set_on_var_partition:def:1
- Title: Ensure nodev option set on /var partition
- oval:simp.cis.2.0.0.OracleLinux8.1.1.3.3_Ensure_noexec_option_set_on_var_partition:def:1
- Title: Ensure noexec option set on /var partition
- oval:simp.cis.2.0.0.OracleLinux8.1.1.3.4_Ensure_nosuid_option_set_on_var_partition:def:1
- Title: Ensure nosuid option set on /var partition
- oval:simp.cis.2.0.0.OracleLinux8.1.1.4.2_Ensure_noexec_option_set_on_vartmp_partition:def:1
- Title: Ensure noexec option set on /var/tmp partition
- oval:simp.cis.2.0.0.OracleLinux8.1.1.4.3_Ensure_nosuid_option_set_on_vartmp_partition:def:1
- Title: Ensure nosuid option set on /var/tmp partition
- oval:simp.cis.2.0.0.OracleLinux8.1.1.4.4_Ensure_nodev_option_set_on_vartmp_partition:def:1
- Title: Ensure nodev option set on /var/tmp partition
- oval:simp.cis.2.0.0.OracleLinux8.1.1.5.2_Ensure_nodev_option_set_on_varlog_partition:def:1
- Title: Ensure nodev option set on /var/log partition
- oval:simp.cis.2.0.0.OracleLinux8.1.1.5.3_Ensure_noexec_option_set_on_varlog_partition:def:1
- Title: Ensure noexec option set on /var/log partition
- oval:simp.cis.2.0.0.OracleLinux8.1.1.5.4_Ensure_nosuid_option_set_on_varlog_partition:def:1
- Title: Ensure nosuid option set on /var/log partition
- oval:simp.cis.2.0.0.OracleLinux8.1.1.6.2_Ensure_noexec_option_set_on_varlogaudit_partition:def:1
- Title: Ensure noexec option set on /var/log/audit partition
- oval:simp.cis.2.0.0.OracleLinux8.1.1.6.3_Ensure_nodev_option_set_on_varlogaudit_partition:def:1
- Title: Ensure nodev option set on /var/log/audit partition
- oval:simp.cis.2.0.0.OracleLinux8.1.1.6.4_Ensure_nosuid_option_set_on_varlogaudit_partition:def:1
- Title: Ensure nosuid option set on /var/log/audit partition
- oval:simp.cis.2.0.0.OracleLinux8.1.1.7.2_Ensure_nodev_option_set_on_home_partition:def:1
- Title: Ensure nodev option set on /home partition
- oval:simp.cis.2.0.0.OracleLinux8.1.1.7.3_Ensure_nosuid_option_set_on_home_partition:def:1
- Title: Ensure nosuid option set on /home partition
- oval:simp.cis.2.0.0.OracleLinux8.1.1.8.1_Ensure_nodev_option_set_on_devshm_partition:def:1
- Title: Ensure nodev option set on /dev/shm partition
- oval:simp.cis.2.0.0.OracleLinux8.1.1.8.2_Ensure_noexec_option_set_on_devshm_partition:def:1
- Title: Ensure noexec option set on /dev/shm partition
- oval:simp.cis.2.0.0.OracleLinux8.1.1.8.3_Ensure_nosuid_option_set_on_devshm_partition:def:1
- Title: Ensure nosuid option set on /dev/shm partition
- oval:simp.cis.2.0.0.OracleLinux8.1.4.1_Ensure_bootloader_password_is_set:def:1
- Title: Ensure bootloader password is set
- oval:simp.cis.2.0.0.OracleLinux8.1.4.2_Ensure_permissions_on_bootloader_config_are_configured:def:1
- Title: Ensure permissions on bootloader config are configured
- oval:simp.cis.2.0.0.OracleLinux8.1.6.1.1_Ensure_SELinux_is_installed:def:1
- Title: Ensure SELinux is installed
- oval:simp.cis.2.0.0.OracleLinux8.1.6.1.2_Ensure_SELinux_is_not_disabled_in_bootloader_configuration:def:1
- Title: Ensure SELinux is not disabled in bootloader configuration
- oval:simp.cis.2.0.0.OracleLinux8.1.6.1.3_Ensure_SELinux_policy_is_configured:def:1
- Title: Ensure SELinux policy is configured
- oval:simp.cis.2.0.0.OracleLinux8.1.6.1.4_Ensure_the_SELinux_mode_is_not_disabled:def:1
- Title: Ensure the SELinux mode is not disabled
- oval:simp.cis.2.0.0.OracleLinux8.1.6.1.5_Ensure_the_SELinux_mode_is_enforcing:def:1
- Title: Ensure the SELinux mode is enforcing
- oval:simp.cis.2.0.0.OracleLinux8.1.6.1.7_Ensure_SETroubleshoot_is_not_installed:def:1
- Title: Ensure SETroubleshoot is not installed
- oval:simp.cis.2.0.0.OracleLinux8.1.7.4_Ensure_permissions_on_etcmotd_are_configured:def:1
- Title: Ensure permissions on /etc/motd are configured
- oval:simp.cis.2.0.0.OracleLinux8.1.7.5_Ensure_permissions_on_etcissue_are_configured:def:1
- Title: Ensure permissions on /etc/issue are configured
- oval:simp.cis.2.0.0.OracleLinux8.1.7.6_Ensure_permissions_on_etcissue.net_are_configured:def:1
- Title: Ensure permissions on /etc/issue.net are configured
- oval:simp.cis.2.0.0.OracleLinux8.5.1.2_Ensure_permissions_on_etccrontab_are_configured:def:1
- Title: Ensure permissions on /etc/crontab are configured
- oval:simp.cis.2.0.0.OracleLinux8.5.1.3_Ensure_permissions_on_etccron.hourly_are_configured:def:1
- Title: Ensure permissions on /etc/cron.hourly are configured
- oval:simp.cis.2.0.0.OracleLinux8.5.1.4_Ensure_permissions_on_etccron.daily_are_configured:def:1
- Title: Ensure permissions on /etc/cron.daily are configured
- oval:simp.cis.2.0.0.OracleLinux8.5.1.5_Ensure_permissions_on_etccron.weekly_are_configured:def:1
- Title: Ensure permissions on /etc/cron.weekly are configured
- oval:simp.cis.2.0.0.OracleLinux8.5.1.6_Ensure_permissions_on_etccron.monthly_are_configured:def:1
- Title: Ensure permissions on /etc/cron.monthly are configured
- oval:simp.cis.2.0.0.OracleLinux8.5.1.7_Ensure_permissions_on_etccron.d_are_configured:def:1
- Title: Ensure permissions on /etc/cron.d are configured
- oval:simp.cis.2.0.0.OracleLinux8.5.1.8_Ensure_cron_is_restricted_to_authorized_users:def:1
- Title: Ensure cron is restricted to authorized users
- oval:simp.cis.2.0.0.OracleLinux8.5.1.9_Ensure_at_is_restricted_to_authorized_users:def:1
- Title: Ensure at is restricted to authorized users
- oval:simp.cis.2.0.0.OracleLinux8.5.6.2_Ensure_system_accounts_are_secured:def:1
- Title: Ensure system accounts are secured
- oval:simp.cis.2.0.0.OracleLinux8.5.6.5_Ensure_default_user_umask_is_027_or_more_restrictive:def:1
- Title: Ensure default user umask is 027 or more restrictive
- NOTE: The umask will be set to 027 within /etc/profile.d/simp.sh, however, this check still fails the scan.
- oval:simp.cis.2.0.0.OracleLinux8.6.2.10_Ensure_users_own_their_home_directories:def:1
- Title: Ensure users own their home directories
- oval:simp.cis.2.0.0.OracleLinux8.6.2.11_Ensure_users_home_directories_permissions_are_750_or_more_restrictive:def:1
- Title: Ensure users’ home directories permissions are 750 or more restrictive
- oval:simp.cis.2.0.0.OracleLinux8.6.2.12_Ensure_users_dot_files_are_not_group_or_world_writable:def:1
- Title: Ensure users’ dot files are not group or world writable
- oval:simp.cis.2.0.0.OracleLinux8.6.2.13Ensure_users.netrc_Files_are_not_group_or_world_accessible:def:1
- Title: Ensure users’ .netrc Files are not group or world accessible
- oval:simp.cis.2.0.0.OracleLinux8.4.1.3.12_Ensure_login_and_logout_events_are_collected:def:1
- Title: Ensure login and logout events are collected
- oval:simp.cis.2.0.0.OracleLinux8.5.2.20_Ensure_SSH_Idle_Timeout_Interval_is_configured:def:1
- Title: Ensure SSH Idle Timeout Interval is configured
- oval:simp.cis.2.0.0.OracleLinux8.5.6.3_Ensure_default_user_shell_timeout_is_900_seconds_or_less:def:1
- Title: Ensure default user shell timeout is 900 seconds or less
-
*NOTE: The scanner fails to pickup on the format the product uses for setting the timeout: [ $TMOUT ] |
|
export TMOUT=900. The setting is also set in a nonstandard location: /etc/profile.d/simp.sh.* |
- oval:simp.cis.2.0.0.OracleLinux8.1.1.9_Disable_Automounting:def:1
- Title: Disable Automounting
- oval:simp.cis.2.0.0.OracleLinux8.1.8.5_Ensure_automatic_mounting_of_removable_media_is_disabled:def:1
- Title: Ensure automatic mounting of removable media is disabled
- NOTE: This will remediate the rule as requested, however, the check will still fail because spacing is not aligned as expected in the rule.
- oval:simp.cis.2.0.0.OracleLinux8.5.2.7_Ensure_SSH_root_login_is_disabled:def:1
- Title: Ensure SSH root login is disabled
- oval:simp.cis.2.0.0.OracleLinux8.5.3.1_Ensure_sudo_is_installed:def:1
- Title: Ensure sudo is installed
- oval:simp.cis.2.0.0.OracleLinux8.5.3.6_Ensure_sudo_authentication_timeout_is_configured_correctly:def:1
- Title: Ensure sudo authentication timeout is configured correctly
- oval:simp.cis.2.0.0.OracleLinux8.1.1.10_Disable_USB_Storage:def:1
- Title: Disable USB Storage
- oval:simp.cis.2.0.0.OracleLinux8.3.1.4_Ensure_wireless_interfaces_are_disabled:def:1
- Title: Ensure wireless interfaces are disabled
- oval:simp.cis.2.0.0.OracleLinux8.3.3.4_Ensure_suspicious_packets_are_logged:def:1
- Title: Ensure suspicious packets are logged
- oval:simp.cis.2.0.0.OracleLinux8.4.1.1.1_Ensure_auditd_is_installed:def:1
- Title: Ensure auditd is installed
- oval:simp.cis.2.0.0.OracleLinux8.4.1.1.2_Ensure_auditd_service_is_enabled:def:1
- Title: Ensure auditd service is enabled
- oval:simp.cis.2.0.0.OracleLinux8.4.1.1.3_Ensure_auditing_for_processes_that_start_prior_to_auditd_is_enabled:def:1
- Title: Ensure auditing for processes that start prior to auditd is enabled
- oval:simp.cis.2.0.0.OracleLinux8.4.1.1.4_Ensure_audit_backlog_limit_is_sufficient:def:1
- Title: Ensure audit_backlog_limit is sufficient
- oval:simp.cis.2.0.0.OracleLinux8.4.1.3.6_Ensure_use_of_privileged_commands_are_collected:def:1
- Title: Ensure use of privileged commands are collected
- NOTE: The available setuid/setgid commands on a given system could vary greatly. Several of the more common commands are audited, but there is currently no automated way to identify and audit all possible setuid/setgid commands available on any given system.
- oval:simp.cis.2.0.0.OracleLinux8.4.1.3.13_Ensure_file_deletion_events_by_users_are_collected:def:1
- Title: Ensure file deletion events by users are collected
- oval:simp.cis.2.0.0.OracleLinux8.4.1.3.15_Ensure_successful_and_unsuccessful_attempts_to_use_the_chcon_command_are_recorded:def:1
- Title: Ensure successful and unsuccessful attempts to use the chcon command are recorded
- oval:simp.cis.2.0.0.OracleLinux8.4.1.3.16_Ensure_successful_and_unsuccessful_attempts_to_use_the_setfacl_command_are_recorded:def:1
- Title: Ensure successful and unsuccessful attempts to use the setfacl command are recorded
- oval:simp.cis.2.0.0.OracleLinux8.4.1.3.17_Ensure_successful_and_unsuccessful_attempts_to_use_the_chacl_command_are_recorded:def:1
- Title: Ensure successful and unsuccessful attempts to use the chacl command are recorded
- oval:simp.cis.2.0.0.OracleLinux8.4.1.3.18_Ensure_successful_and_unsuccessful_attempts_to_use_the_usermod_command_are_recorded:def:1
- Title: Ensure successful and unsuccessful attempts to use the usermod command are recorded
- oval:simp.cis.2.0.0.OracleLinux8.4.1.3.19_Ensure_kernel_module_loading_unloading_and_modification_is_collected:def:1
- Title: Ensure kernel module loading unloading and modification is collected
- oval:simp.cis.2.0.0.OracleLinux8.4.1.3.20_Ensure_the_audit_configuration_is_immutable:def:1
- Title: Ensure the audit configuration is immutable
- oval:simp.cis.2.0.0.OracleLinux8.4.2.1.1_Ensure_rsyslog_is_installed:def:1
- Title: Ensure rsyslog is installed
- oval:simp.cis.2.0.0.OracleLinux8.4.2.1.2_Ensure_rsyslog_service_is_enabled:def:1
- Title: Ensure rsyslog service is enabled
- oval:simp.cis.2.0.0.OracleLinux8.4.2.1.5_Ensure_logging_is_configured:def:1
- Title: Ensure logging is configured
- oval:simp.cis.2.0.0.OracleLinux8.4.2.1.7_Ensure_rsyslog_is_not_configured_to_receive_logs_from_a_remote_client:def:1
- Title: Ensure rsyslog is not configured to receive logs from a remote client
- NOTE: Including the product’s rsyslog class will purge any rsyslog configuration not specified by the user in hieradata or by other rules that require specific rsyslog configuration.
- oval:simp.cis.2.0.0.OracleLinux8.4.2.2.1.1_Ensure_systemd-journal-remote_is_installed:def:1
- Title: Ensure systemd-journal-remote is installed
- oval:simp.cis.2.0.0.OracleLinux8.4.2.2.1.4_Ensure_journald_is_not_configured_to_receive_logs_from_a_remote_client:def:1
- Title: Ensure journald is not configured to receive logs from a remote client
- oval:simp.cis.2.0.0.OracleLinux8.4.2.2.2_Ensure_journald_service_is_enabled:def:1
- Title: Ensure journald service is enabled
- NOTE: Simply including the journald class will include a default journald configuration and ensure the service is enabled.
- oval:simp.cis.2.0.0.OracleLinux8.4.2.2.3_Ensure_journald_is_configured_to_compress_large_log_files:def:1
- Title: Ensure journald is configured to compress large log files
- oval:simp.cis.2.0.0.OracleLinux8.4.2.2.4_Ensure_journald_is_configured_to_write_logfiles_to_persistent_disk:def:1
- Title: Ensure journald is configured to write logfiles to persistent disk
- oval:simp.cis.2.0.0.OracleLinux8.4.2.2.5_Ensure_journald_is_not_configured_to_send_logs_to_rsyslog:def:1
- Title: Ensure journald is not configured to send logs to rsyslog
- oval:simp.cis.2.0.0.OracleLinux8.4.2.2.6_Ensure_journald_log_rotation_is_configured_per_site_policy:def:1
- Title: Ensure journald log rotation is configured per site policy
- oval:simp.cis.2.0.0.OracleLinux8.5.2.5_Ensure_SSH_LogLevel_is_appropriate:def:1
- Title: Ensure SSH LogLevel is appropriate
- oval:simp.cis.2.0.0.OracleLinux8.2.1.1_Ensure_time_synchronization_is_in_use:def:1
- Title: Ensure time synchronization is in use
- oval:simp.cis.2.0.0.OracleLinux8.2.1.2_Ensure_chrony_is_configured:def:1
- Title: Ensure chrony is configured
- NOTE: We are configuring the system to use ntpd instead of chrony.
- oval:simp.cis.2.0.0.OracleLinux8.1.8.1_Ensure_GNOME_Display_Manager_is_removed:def:1
- Title: Ensure GNOME Display Manager is removed
- oval:simp.cis.2.0.0.OracleLinux8.2.2.1_Ensure_xinetd_is_not_installed:def:1
- Title: Ensure xinetd is not installed
- oval:simp.cis.2.0.0.OracleLinux8.2.2.14_Ensure_net-snmp_is_not_installed:def:1
- Title: Ensure net-snmp is not installed
- oval:simp.cis.2.0.0.OracleLinux8.2.2.15_Ensure_NIS_server_is_not_installed:def:1
- Title: Ensure NIS server is not installed
- oval:simp.cis.2.0.0.OracleLinux8.2.2.16_Ensure_telnet-server_is_not_installed:def:1
- Title: Ensure telnet-server is not installed
- oval:simp.cis.2.0.0.OracleLinux8.2.3.1_Ensure_NIS_Client_is_not_installed:def:1
- Title: Ensure NIS Client is not installed
- oval:simp.cis.2.0.0.OracleLinux8.2.3.2_Ensure_rsh_client_is_not_installed:def:1
- Title: Ensure rsh client is not installed
- oval:simp.cis.2.0.0.OracleLinux8.2.3.3_Ensure_talk_client_is_not_installed:def:1
- Title: Ensure talk client is not installed
- oval:simp.cis.2.0.0.OracleLinux8.2.3.4_Ensure_telnet_client_is_not_installed:def:1
- Title: Ensure telnet client is not installed
- oval:simp.cis.2.0.0.OracleLinux8.2.3.5_Ensure_LDAP_client_is_not_installed:def:1
- Title: Ensure LDAP client is not installed
- oval:simp.cis.2.0.0.OracleLinux8.1.4.3_Ensure_authentication_is_required_when_booting_into_rescue_mode:def:1
- Title: Ensure authentication is required when booting into rescue mode
- oval:simp.cis.2.0.0.OracleLinux8.5.5.1_Ensure_password_creation_requirements_are_configured:def:1
- Title: Ensure password creation requirements are configured
- oval:simp.cis.2.0.0.OracleLinux8.5.5.3_Ensure_password_reuse_is_limited:def:1
- Title: Ensure password reuse is limited
- NOTE: Password reuse will be limited through pam instead of authselect. The product will support authselect in a future release.
- oval:simp.cis.2.0.0.OracleLinux8.5.6.1.1_Ensure_password_expiration_is_365_days_or_less:def:1
- Title: Ensure password expiration is 365 days or less
- NOTE: The product sets PASS_MAX_DAYS in /etc/login.defs, however, there is currently no mechanism to enforce the setting for existing users in /etc/shadow.
- oval:simp.cis.2.0.0.OracleLinux8.5.6.1.2_Ensure_minimum_days_between_password_changes_is_7_or_more:def:1
- Title: Ensure minimum days between password changes is 7 or more
- NOTE: The PASS_MIN_DAYS value in /etc/login.defs will be set to 7 as requested, however, the product has no mechanism to change this value on all existing users.
- oval:simp.cis.2.0.0.OracleLinux8.5.6.1.3_Ensure_password_expiration_warning_days_is_7_or_more:def:1
- Title: Ensure password expiration warning days is 7 or more
- oval:simp.cis.2.0.0.OracleLinux8.5.6.1.4_Ensure_inactive_password_lock_is_30_days_or_less:def:1
- Title: Ensure inactive password lock is 30 days or less
- NOTE: The system will be configured to make accounts inactive after 30 days of inactivity, however, the product has no mechanism to change this value on existing users.
- oval:simp.cis.2.0.0.OracleLinux8.5.6.1.5_Ensure_all_users_last_password_change_date_is_in_the_past:def:1
- Title: Ensure all users last password change date is in the past
- oval:simp.cis.2.0.0.OracleLinux8.6.2.1_Ensure_password_fields_are_not_empty:def:1
- Title: Ensure password fields are not empty
- oval:simp.cis.2.0.0.OracleLinux8.5.5.4_Ensure_password_hashing_algorithm_is_SHA-512:def:1
- Title: Ensure password hashing algorithm is SHA-512
- oval:simp.cis.2.0.0.OracleLinux8.6.1.3_Ensure_permissions_on_etcpasswd_are_configured:def:1
- Title: Ensure permissions on /etc/passwd are configured
- oval:simp.cis.2.0.0.OracleLinux8.6.1.4_Ensure_permissions_on_etcshadow_are_configured:def:1
- Title: Ensure permissions on /etc/shadow are configured
- oval:simp.cis.2.0.0.OracleLinux8.6.1.5_Ensure_permissions_on_etcgroup_are_configured:def:1
- Title: Ensure permissions on /etc/group are configured
- oval:simp.cis.2.0.0.OracleLinux8.6.1.6_Ensure_permissions_on_etcgshadow_are_configured:def:1
- Title: Ensure permissions on /etc/gshadow are configured
- oval:simp.cis.2.0.0.OracleLinux8.6.1.7_Ensure_permissions_on_etcpasswd-_are_configured:def:1
- Title: Ensure permissions on /etc/passwd- are configured
- oval:simp.cis.2.0.0.OracleLinux8.6.1.8_Ensure_permissions_on_etcshadow-_are_configured:def:1
- Title: Ensure permissions on /etc/shadow- are configured
- oval:simp.cis.2.0.0.OracleLinux8.6.1.9_Ensure_permissions_on_etcgroup-_are_configured:def:1
- Title: Ensure permissions on /etc/group- are configured
- oval:simp.cis.2.0.0.OracleLinux8.6.1.10_Ensure_permissions_on_etcgshadow-_are_configured:def:1
- Title: Ensure permissions on /etc/gshadow- are configured
- oval:simp.cis.2.0.0.OracleLinux8.6.2.15Ensure_no_users_have.netrc_files:def:1
- Title: Ensure no users have .netrc files
- oval:simp.cis.2.0.0.OracleLinux8.6.2.16Ensure_no_users_have.rhosts_files:def:1
- Title: Ensure no users have .rhosts files
- oval:simp.cis.2.0.0.OracleLinux8.5.4.1_Ensure_custom_authselect_profile_is_used:def:1
- Title: Ensure custom authselect profile is used
- oval:simp.cis.2.0.0.OracleLinux8.5.4.2_Ensure_authselect_includes_with-faillock:def:1
- Title: Ensure authselect includes with-faillock
- oval:simp.cis.2.0.0.OracleLinux8.5.5.2_Ensure_lockout_for_failed_password_attempts_is_configured:def:1
- Title: Ensure lockout for failed password attempts is configured
- oval:simp.cis.2.0.0.OracleLinux8.1.1.1.1_Ensure_mounting_of_cramfs_filesystems_is_disabled:def:1
- Title: Ensure mounting of cramfs filesystems is disabled
- oval:simp.cis.2.0.0.OracleLinux8.1.1.1.2_Ensure_mounting_of_squashfs_filesystems_is_disabled:def:1
- Title: Ensure mounting of squashfs filesystems is disabled
- oval:simp.cis.2.0.0.OracleLinux8.1.1.1.3_Ensure_mounting_of_udf_filesystems_is_disabled:def:1
- Title: Ensure mounting of udf filesystems is disabled
- oval:simp.cis.2.0.0.OracleLinux8.1.1.2.1_Ensure_tmp_is_a_separate_partition:def:1
- Title: Ensure /tmp is a separate partition
- NOTE: /tmp will be configured as a bindmount with the following options: bind,nodev,noexec,nosuid. The test for this rule, however, is looking for /tmp in /etc/fstab.
- oval:simp.cis.2.0.0.OracleLinux8.1.1.2.2_Ensure_nodev_option_set_on_tmp_partition:def:1
- Title: Ensure nodev option set on /tmp partition
- oval:simp.cis.2.0.0.OracleLinux8.1.6.1.8_Ensure_the_MCS_Translation_Service_mcstrans_is_not_installed:def:1
- Title: Ensure the MCS Translation Service (mcstrans) is not installed
- oval:simp.cis.2.0.0.OracleLinux8.1.8.4_Ensure_XDMCP_is_not_enabled:def:1
- Title: Ensure XDMCP is not enabled
- oval:simp.cis.2.0.0.OracleLinux8.2.2.2_Ensure_xorg-x11-server-common_is_not_installed:def:1
- Title: Ensure xorg-x11-server-common is not installed
- oval:simp.cis.2.0.0.OracleLinux8.2.2.3_Ensure_Avahi_Server_is_not_installed:def:1
- Title: Ensure Avahi Server is not installed
- oval:simp.cis.2.0.0.OracleLinux8.2.2.4_Ensure_CUPS_is_not_installed:def:1
- Title: Ensure CUPS is not installed
- oval:simp.cis.2.0.0.OracleLinux8.2.2.5_Ensure_DHCP_Server_is_not_installed:def:1
- Title: Ensure DHCP Server is not installed
- oval:simp.cis.2.0.0.OracleLinux8.2.2.6_Ensure_DNS_Server_is_not_installed:def:1
- Title: Ensure DNS Server is not installed
- oval:simp.cis.2.0.0.OracleLinux8.2.2.7_Ensure_FTP_Server_is_not_installed:def:1
- Title: Ensure FTP Server is not installed
- oval:simp.cis.2.0.0.OracleLinux8.2.2.8_Ensure_VSFTP_Server_is_not_installed:def:1
- Title: Ensure VSFTP Server is not installed
- oval:simp.cis.2.0.0.OracleLinux8.2.2.9_Ensure_TFTP_Server_is_not_installed:def:1
- Title: Ensure TFTP Server is not installed
- oval:simp.cis.2.0.0.OracleLinux8.2.2.10_Ensure_a_web_server_is_not_installed:def:1
- Title: Ensure a web server is not installed
- oval:simp.cis.2.0.0.OracleLinux8.2.2.11_Ensure_IMAP_and_POP3_server_is_not_installed:def:1
- Title: Ensure IMAP and POP3 server is not installed
- oval:simp.cis.2.0.0.OracleLinux8.2.2.12_Ensure_Samba_is_not_installed:def:1
- Title: Ensure Samba is not installed
- oval:simp.cis.2.0.0.OracleLinux8.2.2.13_Ensure_HTTP_Proxy_Server_is_not_installed:def:1
- Title: Ensure HTTP Proxy Server is not installed
- oval:simp.cis.2.0.0.OracleLinux8.2.2.17_Ensure_mail_transfer_agent_is_configured_for_local-only_mode:def:1
- Title: Ensure mail transfer agent is configured for local-only mode
- oval:simp.cis.2.0.0.OracleLinux8.2.2.18_Ensure_nfs-utils_is_not_installed_or_the__nfs-server_service_is_masked:def:1
- Title: Ensure nfs-utils is not installed or the nfs-server service is masked
- oval:simp.cis.2.0.0.OracleLinux8.2.2.19_Ensure_rpcbind_is_not_installed_or_the__rpcbind_services_are_masked:def:1
- Title: Ensure rpcbind is not installed or the rpcbind services are masked
- oval:simp.cis.2.0.0.OracleLinux8.2.2.20_Ensure_rsync_is_not_installed_or_the_rsyncd_service_is_masked:def:1
- Title: Ensure rsync is not installed or the rsyncd service is masked
- oval:simp.cis.2.0.0.OracleLinux8.2.3.6_Ensure_TFTP_client_is_not_installed:def:1
- Title: Ensure TFTP client is not installed
- oval:simp.cis.2.0.0.OracleLinux8.2.4_Ensure_nonessential_services_are_removed_or_masked:def:1
- Title: Ensure nonessential services are removed or masked
- oval:simp.cis.2.0.0.OracleLinux8.3.1.1_Verify_if_IPv6_is_enabled_on_the_system:def:1
- Title: Verify if IPv6 is enabled on the system
- oval:simp.cis.2.0.0.OracleLinux8.3.1.2_Ensure_SCTP_is_disabled:def:1
- Title: Ensure SCTP is disabled
- oval:simp.cis.2.0.0.OracleLinux8.3.1.3_Ensure_DCCP_is_disabled:def:1
- Title: Ensure DCCP is disabled
- oval:simp.cis.2.0.0.OracleLinux8.3.2.1_Ensure_IP_forwarding_is_disabled:def:1
- Title: Ensure IP forwarding is disabled
- oval:simp.cis.2.0.0.OracleLinux8.3.2.2_Ensure_packet_redirect_sending_is_disabled:def:1
- Title: Ensure packet redirect sending is disabled
- oval:simp.cis.2.0.0.OracleLinux8.3.3.1_Ensure_source_routed_packets_are_not_accepted:def:1
- Title: Ensure source routed packets are not accepted
- oval:simp.cis.2.0.0.OracleLinux8.3.3.2_Ensure_ICMP_redirects_are_not_accepted:def:1
- Title: Ensure ICMP redirects are not accepted
- oval:simp.cis.2.0.0.OracleLinux8.3.3.3_Ensure_secure_ICMP_redirects_are_not_accepted:def:1
- Title: Ensure secure ICMP redirects are not accepted
- oval:simp.cis.2.0.0.OracleLinux8.3.3.5_Ensure_broadcast_ICMP_requests_are_ignored:def:1
- Title: Ensure broadcast ICMP requests are ignored
- oval:simp.cis.2.0.0.OracleLinux8.3.3.6_Ensure_bogus_ICMP_responses_are_ignored:def:1
- Title: Ensure bogus ICMP responses are ignored
- oval:simp.cis.2.0.0.OracleLinux8.3.3.7_Ensure_Reverse_Path_Filtering_is_enabled:def:1
- Title: Ensure Reverse Path Filtering is enabled
- oval:simp.cis.2.0.0.OracleLinux8.3.3.8_Ensure_TCP_SYN_Cookies_is_enabled:def:1
- Title: Ensure TCP SYN Cookies is enabled
- oval:simp.cis.2.0.0.OracleLinux8.3.3.9_Ensure_IPv6_router_advertisements_are_not_accepted:def:1
- Title: Ensure IPv6 router advertisements are not accepted
- oval:simp.cis.2.0.0.OracleLinux8.3.4.3.2.3_Ensure_iptables_rules_exist_for_all_open_ports:def:1
- Title: Ensure iptables rules exist for all open ports
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.OracleLinux8.5.2.11_Ensure_SSH_IgnoreRhosts_is_enabled:def:1
- Title: Ensure SSH IgnoreRhosts is enabled
- oval:simp.cis.2.0.0.OracleLinux8.5.2.12_Ensure_SSH_X11_forwarding_is_disabled:def:1
- Title: Ensure SSH X11 forwarding is disabled
- oval:simp.cis.2.0.0.OracleLinux8.5.2.13_Ensure_SSH_AllowTcpForwarding_is_disabled:def:1
- Title: Ensure SSH AllowTcpForwarding is disabled
- oval:simp.cis.2.0.0.OracleLinux8.3.4.1.1_Ensure_firewalld_is_installed:def:1
- Title: Ensure firewalld is installed
- oval:simp.cis.2.0.0.OracleLinux8.3.4.1.2_Ensure_iptables-services_not_installed_with_firewalld:def:1
- Title: Ensure iptables-services not installed with firewalld
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.OracleLinux8.3.4.1.3_Ensure_nftables_either_not_installed_or_masked_with_firewalld:def:1
- Title: Ensure nftables either not installed or masked with firewalld
- oval:simp.cis.2.0.0.OracleLinux8.3.4.1.4_Ensure_firewalld_service_enabled_and_running:def:1
- Title: Ensure firewalld service enabled and running
- oval:simp.cis.2.0.0.OracleLinux8.3.4.1.5_Ensure_firewalld_default_zone_is_set:def:1
- Title: Ensure firewalld default zone is set
- oval:simp.cis.2.0.0.OracleLinux8.3.4.1.6_Ensure_network_interfaces_are_assigned_to_appropriate_zone:def:1
- Title: Ensure network interfaces are assigned to appropriate zone
- oval:simp.cis.2.0.0.OracleLinux8.3.4.1.7_Ensure_firewalld_drops_unnecessary_services_and_ports:def:1
- Title: Ensure firewalld drops unnecessary services and ports
- oval:simp.cis.2.0.0.OracleLinux8.3.4.2.1_Ensure_nftables_is_installed:def:1
- Title: Ensure nftables is installed
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.OracleLinux8.3.4.2.2_Ensure_firewalld_is_either_not_installed_or_masked_with_nftables:def:1
- Title: Ensure firewalld is either not installed or masked with nftables
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.OracleLinux8.3.4.2.3_Ensure_iptables-services_not_installed_with_nftables:def:1
- Title: Ensure iptables-services not installed with nftables
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.OracleLinux8.3.4.2.4_Ensure_iptables_are_flushed_with_nftables:def:1
- Title: Ensure iptables are flushed with nftables
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.OracleLinux8.3.4.2.5_Ensure_an_nftables_table_exists:def:1
- Title: Ensure an nftables table exists
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.OracleLinux8.3.4.2.6_Ensure_nftables_base_chains_exist:def:1
- Title: Ensure nftables base chains exist
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.OracleLinux8.3.4.2.7_Ensure_nftables_loopback_traffic_is_configured:def:1
- Title: Ensure nftables loopback traffic is configured
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.OracleLinux8.3.4.2.8_Ensure_nftables_outbound_and_established_connections_are_configured:def:1
- Title: Ensure nftables outbound and established connections are configured
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.OracleLinux8.3.4.2.9_Ensure_nftables_default_deny_firewall_policy:def:1
- Title: Ensure nftables default deny firewall policy
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.OracleLinux8.3.4.2.10_Ensure_nftables_service_is_enabled:def:1
- Title: Ensure nftables service is enabled
- oval:simp.cis.2.0.0.OracleLinux8.3.4.2.11_Ensure_nftables_rules_are_permanent:def:1
- Title: Ensure nftables rules are permanent
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.OracleLinux8.3.4.3.1.1_Ensure_iptables_packages_are_installed:def:1
- Title: Ensure iptables packages are installed
- oval:simp.cis.2.0.0.OracleLinux8.3.4.3.1.2_Ensure_nftables_is_not_installed_with_iptables:def:1
- Title: Ensure nftables is not installed with iptables
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.OracleLinux8.3.4.3.1.3_Ensure_firewalld_is_either_not_installed_or_masked_with_iptables:def:1
- Title: Ensure firewalld is either not installed or masked with iptables
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.OracleLinux8.3.4.3.2.1_Ensure_iptables_loopback_traffic_is_configured:def:1
- Title: Ensure iptables loopback traffic is configured
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.OracleLinux8.3.4.3.2.2_Ensure_iptables_outbound_and_established_connections_are_configured:def:1
- Title: Ensure iptables outbound and established connections are configured
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.OracleLinux8.3.4.3.2.4_Ensure_iptables_default_deny_firewall_policy:def:1
- Title: Ensure iptables default deny firewall policy
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.OracleLinux8.3.4.3.2.5_Ensure_iptables_rules_are_saved:def:1
- Title: Ensure iptables rules are saved
- oval:simp.cis.2.0.0.OracleLinux8.3.4.3.2.6_Ensure_iptables_is_enabled_and_active:def:1
- Title: Ensure iptables is enabled and active
- oval:simp.cis.2.0.0.OracleLinux8.3.4.3.3.1_Ensure_ip6tables_loopback_traffic_is_configured:def:1
- Title: Ensure ip6tables loopback traffic is configured
- oval:simp.cis.2.0.0.OracleLinux8.3.4.3.3.2_Ensure_ip6tables_outbound_and_established_connections_are_configured:def:1
- Title: Ensure ip6tables outbound and established connections are configured
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.OracleLinux8.3.4.3.3.3_Ensure_ip6tables_firewall_rules_exist_for_all_open_ports:def:1
- Title: Ensure ip6tables firewall rules exist for all open ports
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.OracleLinux8.3.4.3.3.4_Ensure_ip6tables_default_deny_firewall_policy:def:1
- Title: Ensure ip6tables default deny firewall policy
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.OracleLinux8.3.4.3.3.5_Ensure_ip6tables_rules_are_saved:def:1
- Title: Ensure ip6tables rules are saved
- oval:simp.cis.2.0.0.OracleLinux8.3.4.3.3.6_Ensure_ip6tables_is_enabled_and_active:def:1
- Title: Ensure ip6tables is enabled and active
- oval:simp.cis.2.0.0.OracleLinux8.1.10_Ensure_system-wide_crypto_policy_is_not_legacy:def:1
- Title: Ensure system-wide crypto policy is not legacy
- oval:simp.cis.2.0.0.OracleLinux8.5.2.14_Ensure_system-wide_crypto_policy_is_not_over-ridden:def:1
- Title: Ensure system-wide crypto policy is not over-ridden
- oval:simp.cis.2.0.0.OracleLinux8.4.1.3.11_Ensure_session_initiation_information_is_collected:def:1
- Title: Ensure session initiation information is collected
- oval:simp.cis.2.0.0.OracleLinux8.5.2.16_Ensure_SSH_MaxAuthTries_is_set_to_4_or_less:def:1
- Title: Ensure SSH MaxAuthTries is set to 4 or less
RedHat 7 (202/210 [96%])
- oval:simp.cis.3.1.1.RedHat7.1.1.1.1_Ensure_mounting_of_cramfs_filesystems_is_disabled:def:1
- Title: Ensure mounting of cramfs filesystems is disabled
- oval:simp.cis.3.1.1.RedHat7.1.1.1.2_Ensure_mounting_of_squashfs_filesystems_is_disabled:def:1
- Title: Ensure mounting of squashfs filesystems is disabled
- oval:simp.cis.3.1.1.RedHat7.1.1.1.3_Ensure_mounting_of_udf_filesystems_is_disabled:def:1
- Title: Ensure mounting of udf filesystems is disabled
- oval:simp.cis.3.1.1.RedHat7.1.1.4_Ensure_nodev_option_set_on_tmp_partition:def:1
- Title: Ensure nodev option set on /tmp partition
- oval:simp.cis.3.1.1.RedHat7.1.1.5_Ensure_nosuid_option_set_on_tmp_partition:def:1
- Title: Ensure nosuid option set on /tmp partition
- oval:simp.cis.3.1.1.RedHat7.1.1.6_Ensure_devshm_is_configured:def:1
- Title: Ensure /dev/shm is configured
- oval:simp.cis.3.1.1.RedHat7.1.1.8_Ensure_nodev_option_set_on_devshm_partition:def:1
- Title: Ensure nodev option set on /dev/shm partition
- oval:simp.cis.3.1.1.RedHat7.1.1.9_Ensure_nosuid_option_set_on_devshm_partition:def:1
- Title: Ensure nosuid option set on /dev/shm partition
- oval:simp.cis.3.1.1.RedHat7.1.1.13_Ensure_vartmp_partition_includes_the_nodev_option:def:1
- Title: Ensure /var/tmp partition includes the nodev option
- oval:simp.cis.3.1.1.RedHat7.1.1.14_Ensure_vartmp_partition_includes_the_nosuid_option:def:1
- Title: Ensure /var/tmp partition includes the nosuid option
- oval:simp.cis.3.1.1.RedHat7.1.1.18_Ensure_home_partition_includes_the_nodev_option:def:1
- Title: Ensure /home partition includes the nodev option
- oval:simp.cis.3.1.1.RedHat7.1.1.20_Ensure_nodev_option_set_on_removable_media_partitions:def:1
- Title: Ensure nodev option set on removable media partitions
- oval:simp.cis.3.1.1.RedHat7.1.1.21_Ensure_nosuid_option_set_on_removable_media_partitions:def:1
- Title: Ensure nosuid option set on removable media partitions
- oval:simp.cis.3.1.1.RedHat7.1.1.22_Ensure_sticky_bit_is_set_on_all_world-writable_directories:def:1
- Title: Ensure sticky bit is set on all world-writable directories
- oval:simp.cis.3.1.1.RedHat7.1.4.1_Ensure_bootloader_password_is_set:def:1
- Title: Ensure bootloader password is set
- oval:simp.cis.3.1.1.RedHat7.1.4.2_Ensure_permissions_on_bootloader_config_are_configured:def:1
- Title: Ensure permissions on bootloader config are configured
- oval:simp.cis.3.1.1.RedHat7.1.4.3_Ensure_authentication_required_for_single_user_mode:def:1
- Title: Ensure authentication required for single user mode
- oval:simp.cis.3.1.1.RedHat7.1.5.1_Ensure_core_dumps_are_restricted:def:1
- Title: Ensure core dumps are restricted
- oval:simp.cis.3.1.1.RedHat7.1.7.1_Ensure_message_of_the_day_is_configured_properly:def:1
- Title: Ensure message of the day is configured properly
- oval:simp.cis.3.1.1.RedHat7.1.7.2_Ensure_local_login_warning_banner_is_configured_properly:def:1
- Title: Ensure local login warning banner is configured properly
- oval:simp.cis.3.1.1.RedHat7.1.7.3_Ensure_remote_login_warning_banner_is_configured_properly:def:1
- Title: Ensure remote login warning banner is configured properly
- oval:simp.cis.3.1.1.RedHat7.1.8.2_Ensure_GDM_login_banner_is_configured:def:1
- Title: Ensure GDM login banner is configured
- oval:simp.cis.3.1.1.RedHat7.1.8.3_Ensure_last_logged_in_user_display_is_disabled:def:1
- Title: Ensure last logged in user display is disabled
- oval:simp.cis.3.1.1.RedHat7.3.2.1_Ensure_IP_forwarding_is_disabled:def:1
- Title: Ensure IP forwarding is disabled
- oval:simp.cis.3.1.1.RedHat7.3.2.2_Ensure_packet_redirect_sending_is_disabled:def:1
- Title: Ensure packet redirect sending is disabled
- oval:simp.cis.3.1.1.RedHat7.3.3.1_Ensure_source_routed_packets_are_not_accepted:def:1
- Title: Ensure source routed packets are not accepted
- oval:simp.cis.3.1.1.RedHat7.3.3.2_Ensure_ICMP_redirects_are_not_accepted:def:1
- Title: Ensure ICMP redirects are not accepted
- oval:simp.cis.3.1.1.RedHat7.3.3.3_Ensure_secure_ICMP_redirects_are_not_accepted:def:1
- Title: Ensure secure ICMP redirects are not accepted
- oval:simp.cis.3.1.1.RedHat7.3.3.5_Ensure_broadcast_ICMP_requests_are_ignored:def:1
- Title: Ensure broadcast ICMP requests are ignored
- oval:simp.cis.3.1.1.RedHat7.3.3.6_Ensure_bogus_ICMP_responses_are_ignored:def:1
- Title: Ensure bogus ICMP responses are ignored
- oval:simp.cis.3.1.1.RedHat7.3.3.7_Ensure_Reverse_Path_Filtering_is_enabled:def:1
- Title: Ensure Reverse Path Filtering is enabled
- oval:simp.cis.3.1.1.RedHat7.3.3.8_Ensure_TCP_SYN_Cookies_is_enabled:def:1
- Title: Ensure TCP SYN Cookies is enabled
- oval:simp.cis.3.1.1.RedHat7.3.3.9_Ensure_IPv6_router_advertisements_are_not_accepted:def:1
- Title: Ensure IPv6 router advertisements are not accepted
- oval:simp.cis.3.1.1.RedHat7.4.1.16_Ensure_kernel_module_loading_and_unloading_is_collected:def:1
- Title: Ensure kernel module loading and unloading is collected
- oval:simp.cis.3.1.1.RedHat7.4.2.1.3_Ensure_rsyslog_default_file_permissions_configured:def:1
- Title: Ensure rsyslog default file permissions configured
- oval:simp.cis.3.1.1.RedHat7.4.2.3_Ensure_permissions_on_all_logfiles_are_configured:def:1
- Title: Ensure permissions on all logfiles are configured
- oval:simp.cis.3.1.1.RedHat7.5.1.1_Ensure_cron_daemon_is_enabled_and_running:def:1
- Title: Ensure cron daemon is enabled and running
- oval:simp.cis.3.1.1.RedHat7.5.1.3_Ensure_permissions_on_etccron.hourly_are_configured:def:1
- Title: Ensure permissions on /etc/cron.hourly are configured
- oval:simp.cis.3.1.1.RedHat7.5.3.12_Ensure_SSH_PermitUserEnvironment_is_disabled:def:1
- Title: Ensure SSH PermitUserEnvironment is disabled
- oval:simp.cis.3.1.1.RedHat7.5.3.17_Ensure_SSH_LoginGraceTime_is_set_to_one_minute_or_less:def:1
- Title: Ensure SSH LoginGraceTime is set to one minute or less
- oval:simp.cis.3.1.1.RedHat7.5.3.18_Ensure_SSH_warning_banner_is_configured:def:1
- Title: Ensure SSH warning banner is configured
- oval:simp.cis.3.1.1.RedHat7.5.3.19_Ensure_SSH_PAM_is_enabled:def:1
- Title: Ensure SSH PAM is enabled
- oval:simp.cis.3.1.1.RedHat7.5.3.21_Ensure_SSH_MaxStartups_is_configured:def:1
- Title: Ensure SSH MaxStartups is configured
- oval:simp.cis.3.1.1.RedHat7.5.3.22_Ensure_SSH_MaxSessions_is_limited:def:1
- Title: Ensure SSH MaxSessions is limited
- oval:simp.cis.3.1.1.RedHat7.5.5.3_Ensure_default_group_for_the_root_account_is_GID_0:def:1
- Title: Ensure default group for the root account is GID 0
- oval:simp.cis.3.1.1.RedHat7.5.5.5_Ensure_default_user_umask_is_configured:def:1
- Title: Ensure default user umask is configured
- NOTE: The umask will be set to 027 within /etc/profile.d/simp.sh, however, this check still fails the scan.
- oval:simp.cis.3.1.1.RedHat7.5.6_Ensure_root_login_is_restricted_to_system_console:def:1
- Title: Ensure root login is restricted to system console
- oval:simp.cis.3.1.1.RedHat7.5.7_Ensure_access_to_the_su_command_is_restricted:def:1
- Title: Ensure access to the su command is restricted
- oval:simp.cis.3.1.1.RedHat7.6.2.4_Ensure_shadow_group_is_empty:def:1
- Title: Ensure shadow group is empty
- oval:simp.cis.3.1.1.RedHat7.6.2.9_Ensure_root_is_the_only_UID_0_account:def:1
- Title: Ensure root is the only UID 0 account
- oval:simp.cis.3.1.1.RedHat7.6.2.10_Ensure_root_PATH_Integrity:def:1
- Title: Ensure root PATH Integrity
- oval:simp.cis.3.1.1.RedHat7.6.2.11_Ensure_all_users_home_directories_exist:def:1
- Title: Ensure all users’ home directories exist
- oval:simp.cis.3.1.1.RedHat7.6.2.15Ensure_no_users_have.forward_files:def:1
- Title: Ensure no users have .forward files
- oval:simp.cis.3.1.1.RedHat7.1.6.1.1_Ensure_SELinux_is_installed:def:1
- Title: Ensure SELinux is installed
- oval:simp.cis.3.1.1.RedHat7.1.6.1.2_Ensure_SELinux_is_not_disabled_in_bootloader_configuration:def:1
- Title: Ensure SELinux is not disabled in bootloader configuration
- oval:simp.cis.3.1.1.RedHat7.1.6.1.3_Ensure_SELinux_policy_is_configured:def:1
- Title: Ensure SELinux policy is configured
- oval:simp.cis.3.1.1.RedHat7.1.6.1.4_Ensure_the_SELinux_mode_is_enforcing_or_permissive:def:1
- Title: Ensure the SELinux mode is enforcing or permissive
- oval:simp.cis.3.1.1.RedHat7.1.6.1.5_Ensure_the_SELinux_mode_is_enforcing:def:1
- Title: Ensure the SELinux mode is enforcing
- oval:simp.cis.3.1.1.RedHat7.1.6.1.7_Ensure_SETroubleshoot_is_not_installed:def:1
- Title: Ensure SETroubleshoot is not installed
- oval:simp.cis.3.1.1.RedHat7.1.7.4_Ensure_permissions_on_etcmotd_are_configured:def:1
- Title: Ensure permissions on /etc/motd are configured
- oval:simp.cis.3.1.1.RedHat7.1.7.5_Ensure_permissions_on_etcissue_are_configured:def:1
- Title: Ensure permissions on /etc/issue are configured
- oval:simp.cis.3.1.1.RedHat7.1.7.6_Ensure_permissions_on_etcissue.net_are_configured:def:1
- Title: Ensure permissions on /etc/issue.net are configured
- oval:simp.cis.3.1.1.RedHat7.5.1.2_Ensure_permissions_on_etccrontab_are_configured:def:1
- Title: Ensure permissions on /etc/crontab are configured
- oval:simp.cis.3.1.1.RedHat7.5.1.4_Ensure_permissions_on_etccron.daily_are_configured:def:1
- Title: Ensure permissions on /etc/cron.daily are configured
- oval:simp.cis.3.1.1.RedHat7.5.1.5_Ensure_permissions_on_etccron.weekly_are_configured:def:1
- Title: Ensure permissions on /etc/cron.weekly are configured
- oval:simp.cis.3.1.1.RedHat7.5.1.6_Ensure_permissions_on_etccron.monthly_are_configured:def:1
- Title: Ensure permissions on /etc/cron.monthly are configured
- oval:simp.cis.3.1.1.RedHat7.5.1.7_Ensure_permissions_on_etccron.d_are_configured:def:1
- Title: Ensure permissions on /etc/cron.d are configured
- oval:simp.cis.3.1.1.RedHat7.5.3.1_Ensure_permissions_on_etcsshsshd_config_are_configured:def:1
- Title: Ensure permissions on /etc/ssh/sshd_config are configured
- oval:simp.cis.3.1.1.RedHat7.5.3.2_Ensure_permissions_on_SSH_private_host_key_files_are_configured:def:1
- Title: Ensure permissions on SSH private host key files are configured
- oval:simp.cis.3.1.1.RedHat7.5.3.3_Ensure_permissions_on_SSH_public_host_key_files_are_configured:def:1
- Title: Ensure permissions on SSH public host key files are configured
- oval:simp.cis.3.1.1.RedHat7.6.1.2_Ensure_permissions_on_etcpasswd_are_configured:def:1
- Title: Ensure permissions on /etc/passwd are configured
- oval:simp.cis.3.1.1.RedHat7.6.1.3_Ensure_permissions_on_etcpasswd-_are_configured:def:1
- Title: Ensure permissions on /etc/passwd- are configured
- oval:simp.cis.3.1.1.RedHat7.6.1.4_Ensure_permissions_on_etcshadow_are_configured:def:1
- Title: Ensure permissions on /etc/shadow are configured
- oval:simp.cis.3.1.1.RedHat7.6.1.5_Ensure_permissions_on_etcshadow-_are_configured:def:1
- Title: Ensure permissions on /etc/shadow- are configured
- oval:simp.cis.3.1.1.RedHat7.6.1.7_Ensure_permissions_on_etcgshadow_are_configured:def:1
- Title: Ensure permissions on /etc/gshadow are configured
- oval:simp.cis.3.1.1.RedHat7.6.1.8_Ensure_permissions_on_etcgroup_are_configured:def:1
- Title: Ensure permissions on /etc/group are configured
- oval:simp.cis.3.1.1.RedHat7.6.1.9_Ensure_permissions_on_etcgroup-_are_configured:def:1
- Title: Ensure permissions on /etc/group- are configured
- oval:simp.cis.3.1.1.RedHat7.6.2.12_Ensure_users_own_their_home_directories:def:1
- Title: Ensure users own their home directories
- oval:simp.cis.3.1.1.RedHat7.6.2.13_Ensure_users_home_directories_permissions_are_750_or_more_restrictive:def:1
- Title: Ensure users’ home directories permissions are 750 or more restrictive
- oval:simp.cis.3.1.1.RedHat7.6.2.14_Ensure_users_dot_files_are_not_group_or_world_writable:def:1
- Title: Ensure users’ dot files are not group or world writable
- oval:simp.cis.3.1.1.RedHat7.5.5.1.4_Ensure_inactive_password_lock_is_30_days_or_less:def:1
- Title: Ensure inactive password lock is 30 days or less
- oval:simp.cis.3.1.1.RedHat7.4.1.7_Ensure_login_and_logout_events_are_collected:def:1
- Title: Ensure login and logout events are collected
- oval:simp.cis.3.1.1.RedHat7.4.1.8_Ensure_session_initiation_information_is_collected:def:1
- Title: Ensure session initiation information is collected
- oval:simp.cis.3.1.1.RedHat7.5.3.16_Ensure_SSH_Idle_Timeout_Interval_is_configured:def:1
- Title: Ensure SSH Idle Timeout Interval is configured
- oval:simp.cis.3.1.1.RedHat7.5.5.4_Ensure_default_user_shell_timeout_is_configured:def:1
- Title: Ensure default user shell timeout is configured
-
*NOTE: The scanner fails to pickup on the format the product uses for setting the timeout: [ $TMOUT ] |
|
export TMOUT=900. The setting is also set in a nonstandard location: /etc/profile.d/simp.sh.* |
- oval:simp.cis.3.1.1.RedHat7.1.1.23_Disable_Automounting:def:1
- Title: Disable Automounting
- oval:simp.cis.3.1.1.RedHat7.1.1.24_Disable_USB_Storage:def:1
- Title: Disable USB Storage
- oval:simp.cis.3.1.1.RedHat7.5.3.4_Ensure_SSH_access_is_limited:def:1
- Title: Ensure SSH access is limited
- oval:simp.cis.3.1.1.RedHat7.5.3.10_Ensure_SSH_root_login_is_disabled:def:1
- Title: Ensure SSH root login is disabled
- oval:simp.cis.3.1.1.RedHat7.3.1.2_Ensure_wireless_interfaces_are_disabled:def:1
- Title: Ensure wireless interfaces are disabled
- oval:simp.cis.3.1.1.RedHat7.3.3.4_Ensure_suspicious_packets_are_logged:def:1
- Title: Ensure suspicious packets are logged
- oval:simp.cis.3.1.1.RedHat7.4.1.1.1_Ensure_auditd_is_installed:def:1
- Title: Ensure auditd is installed
- oval:simp.cis.3.1.1.RedHat7.4.1.1.2_Ensure_auditd_service_is_enabled_and_running:def:1
- Title: Ensure auditd service is enabled and running
- oval:simp.cis.3.1.1.RedHat7.4.1.1.3_Ensure_auditing_for_processes_that_start_prior_to_auditd_is_enabled:def:1
- Title: Ensure auditing for processes that start prior to auditd is enabled
- oval:simp.cis.3.1.1.RedHat7.4.1.2.2_Ensure_audit_logs_are_not_automatically_deleted:def:1
- Title: Ensure audit logs are not automatically deleted
- oval:simp.cis.3.1.1.RedHat7.4.1.2.3_Ensure_system_is_disabled_when_audit_logs_are_full:def:1
- Title: Ensure system is disabled when audit logs are full
- oval:simp.cis.3.1.1.RedHat7.4.1.2.4_Ensure_audit_backlog_limit_is_sufficient:def:1
- Title: Ensure audit_backlog_limit is sufficient
- oval:simp.cis.3.1.1.RedHat7.4.1.5_Ensure_events_that_modify_the_systems_network_environment_are_collected:def:1
- Title: Ensure events that modify the system’s network environment are collected
- oval:simp.cis.3.1.1.RedHat7.4.1.11_Ensure_use_of_privileged_commands_is_collected:def:1
- Title: Ensure use of privileged commands is collected
- NOTE: The available setuid/setgid commands on a given system could vary greatly. Several of the more common commands are audited, but there is currently no automated way to identify and audit all possible setuid/setgid commands available on any given system.
- oval:simp.cis.3.1.1.RedHat7.4.1.12_Ensure_successful_file_system_mounts_are_collected:def:1
- Title: Ensure successful file system mounts are collected
- oval:simp.cis.3.1.1.RedHat7.4.1.13_Ensure_file_deletion_events_by_users_are_collected:def:1
- Title: Ensure file deletion events by users are collected
- oval:simp.cis.3.1.1.RedHat7.4.1.17_Ensure_the_audit_configuration_is_immutable:def:1
- Title: Ensure the audit configuration is immutable
- oval:simp.cis.3.1.1.RedHat7.4.2.1.1_Ensure_rsyslog_is_installed:def:1
- Title: Ensure rsyslog is installed
- oval:simp.cis.3.1.1.RedHat7.4.2.1.2_Ensure_rsyslog_Service_is_enabled_and_running:def:1
- Title: Ensure rsyslog Service is enabled and running
- oval:simp.cis.3.1.1.RedHat7.4.2.1.4_Ensure_logging_is_configured:def:1
- Title: Ensure logging is configured
- oval:simp.cis.3.1.1.RedHat7.4.2.2.3_Ensure_journald_is_configured_to_write_logfiles_to_persistent_disk:def:1
- Title: Ensure journald is configured to write logfiles to persistent disk
- oval:simp.cis.3.1.1.RedHat7.5.3.5_Ensure_SSH_LogLevel_is_appropriate:def:1
- Title: Ensure SSH LogLevel is appropriate
- oval:simp.cis.3.1.1.RedHat7.2.2.1.1_Ensure_time_synchronization_is_in_use:def:1
- Title: Ensure time synchronization is in use
- oval:simp.cis.3.1.1.RedHat7.2.2.1.2_Ensure_chrony_is_configured:def:1
- Title: Ensure chrony is configured
- NOTE: We are configuring the system to use ntpd instead of chrony.
- oval:simp.cis.3.1.1.RedHat7.2.2.1.3_Ensure_ntp_is_configured:def:1
- Title: Ensure ntp is configured
- oval:simp.cis.3.1.1.RedHat7.1.1.3_Ensure_noexec_option_set_on_tmp_partition:def:1
- Title: Ensure noexec option set on /tmp partition
- oval:simp.cis.3.1.1.RedHat7.1.1.7_Ensure_noexec_option_set_on_devshm_partition:def:1
- Title: Ensure noexec option set on /dev/shm partition
- oval:simp.cis.3.1.1.RedHat7.1.1.12_Ensure_vartmp_partition_includes_the_noexec_option:def:1
- Title: Ensure /var/tmp partition includes the noexec option
- oval:simp.cis.3.1.1.RedHat7.1.1.19_Ensure_removable_media_partitions_include_noexec_option:def:1
- Title: Ensure removable media partitions include noexec option
- oval:simp.cis.3.1.1.RedHat7.1.8.1_Ensure_GNOME_Display_Manager_is_removed:def:1
- Title: Ensure GNOME Display Manager is removed
- oval:simp.cis.3.1.1.RedHat7.2.1.1_Ensure_xinetd_is_not_installed:def:1
- Title: Ensure xinetd is not installed
- oval:simp.cis.3.1.1.RedHat7.2.2.2_Ensure_X11_Server_components_are_not_installed:def:1
- Title: Ensure X11 Server components are not installed
- oval:simp.cis.3.1.1.RedHat7.2.2.13_Ensure_net-snmp_is_not_installed:def:1
- Title: Ensure net-snmp is not installed
- oval:simp.cis.3.1.1.RedHat7.2.2.14_Ensure_NIS_server_is_not_installed:def:1
- Title: Ensure NIS server is not installed
- oval:simp.cis.3.1.1.RedHat7.2.2.15_Ensure_telnet-server_is_not_installed:def:1
- Title: Ensure telnet-server is not installed
- oval:simp.cis.3.1.1.RedHat7.2.3.1_Ensure_NIS_Client_is_not_installed:def:1
- Title: Ensure NIS Client is not installed
- oval:simp.cis.3.1.1.RedHat7.2.3.2_Ensure_rsh_client_is_not_installed:def:1
- Title: Ensure rsh client is not installed
- oval:simp.cis.3.1.1.RedHat7.2.3.3_Ensure_talk_client_is_not_installed:def:1
- Title: Ensure talk client is not installed
- oval:simp.cis.3.1.1.RedHat7.2.3.4_Ensure_telnet_client_is_not_installed:def:1
- Title: Ensure telnet client is not installed
- oval:simp.cis.3.1.1.RedHat7.2.3.5_Ensure_LDAP_client_is_not_installed:def:1
- Title: Ensure LDAP client is not installed
- oval:simp.cis.3.1.1.RedHat7.5.4.1_Ensure_password_creation_requirements_are_configured:def:1
- Title: Ensure password creation requirements are configured
- oval:simp.cis.3.1.1.RedHat7.5.5.1.1_Ensure_password_expiration_is_365_days_or_less:def:1
- Title: Ensure password expiration is 365 days or less
- NOTE: The product sets PASS_MAX_DAYS in /etc/login.defs, however, there is currently no mechanisme to enforce the setting for existing users in /etc/shadow.
- oval:simp.cis.3.1.1.RedHat7.5.5.1.2_Ensure_minimum_days_between_password_changes_is_configured:def:1
- Title: Ensure minimum days between password changes is configured
- NOTE: The product sets PASS_MIN_DAYS in /etc/login.defs, however, there is currently no mechanisme to enforce the setting for existing users in /etc/shadow.
- oval:simp.cis.3.1.1.RedHat7.5.5.1.3_Ensure_password_expiration_warning_days_is_7_or_more:def:1
- Title: Ensure password expiration warning days is 7 or more
- oval:simp.cis.3.1.1.RedHat7.5.5.1.5_Ensure_all_users_last_password_change_date_is_in_the_past:def:1
- Title: Ensure all users last password change date is in the past
- oval:simp.cis.3.1.1.RedHat7.6.2.1_Ensure_accounts_in_etcpasswd_use_shadowed_passwords:def:1
- Title: Ensure accounts in /etc/passwd use shadowed passwords
- oval:simp.cis.3.1.1.RedHat7.6.2.2_Ensure_etcshadow_password_fields_are_not_empty:def:1
- Title: Ensure /etc/shadow password fields are not empty
- oval:simp.cis.3.1.1.RedHat7.5.4.3_Ensure_password_hashing_algorithm_is_SHA-512:def:1
- Title: Ensure password hashing algorithm is SHA-512
- oval:simp.cis.3.1.1.RedHat7.6.1.6_Ensure_permissions_on_etcgshadow-_are_configured:def:1
- Title: Ensure permissions on /etc/gshadow- are configured
- oval:simp.cis.3.1.1.RedHat7.6.2.16Ensure_no_users_have.netrc_files:def:1
- Title: Ensure no users have .netrc files
- oval:simp.cis.3.1.1.RedHat7.6.2.17Ensure_no_users_have.rhosts_files:def:1
- Title: Ensure no users have .rhosts files
- oval:simp.cis.3.1.1.RedHat7.5.3.14_Ensure_only_strong_MAC_algorithms_are_used:def:1
- Title: Ensure only strong MAC algorithms are used
- oval:simp.cis.3.1.1.RedHat7.4.2.2.1_Ensure_journald_is_configured_to_send_logs_to_rsyslog:def:1
- Title: Ensure journald is configured to send logs to rsyslog
- oval:simp.cis.3.1.1.RedHat7.4.2.1.5_Ensure_rsyslog_is_configured_to_send_logs_to_a_remote_log_host:def:1
- Title: Ensure rsyslog is configured to send logs to a remote log host
- oval:simp.cis.3.1.1.RedHat7.5.4.2_Ensure_lockout_for_failed_password_attempts_is_configured:def:1
- Title: Ensure lockout for failed password attempts is configured
- oval:simp.cis.3.1.1.RedHat7.1.2.5_Disable_the_rhnsd_Daemon:def:1
- Title: Disable the rhnsd Daemon
- NOTE: rhnsd should only be disabled if it is not in use.
- oval:simp.cis.3.1.1.RedHat7.1.6.1.8_Ensure_the_MCS_Translation_Service_mcstrans_is_not_installed:def:1
- Title: Ensure the MCS Translation Service (mcstrans) is not installed
- oval:simp.cis.3.1.1.RedHat7.1.8.4_Ensure_XDCMP_is_not_enabled:def:1
- Title: Ensure XDCMP is not enabled
- oval:simp.cis.3.1.1.RedHat7.2.2.3_Ensure_Avahi_Server_is_not_installed:def:1
- Title: Ensure Avahi Server is not installed
- oval:simp.cis.3.1.1.RedHat7.2.2.4_Ensure_CUPS_is_not_installed:def:1
- Title: Ensure CUPS is not installed
- oval:simp.cis.3.1.1.RedHat7.2.2.5_Ensure_DHCP_Server_is_not_installed:def:1
- Title: Ensure DHCP Server is not installed
- oval:simp.cis.3.1.1.RedHat7.2.2.6_Ensure_LDAP_server_is_not_installed:def:1
- Title: Ensure LDAP server is not installed
- oval:simp.cis.3.1.1.RedHat7.2.2.7_Ensure_DNS_Server_is_not_installed:def:1
- Title: Ensure DNS Server is not installed
- oval:simp.cis.3.1.1.RedHat7.2.2.8_Ensure_FTP_Server_is_not_installed:def:1
- Title: Ensure FTP Server is not installed
- oval:simp.cis.3.1.1.RedHat7.2.2.9_Ensure_HTTP_server_is_not_installed:def:1
- Title: Ensure HTTP server is not installed
- oval:simp.cis.3.1.1.RedHat7.2.2.10_Ensure_IMAP_and_POP3_server_is_not_installed:def:1
- Title: Ensure IMAP and POP3 server is not installed
- oval:simp.cis.3.1.1.RedHat7.2.2.11_Ensure_Samba_is_not_installed:def:1
- Title: Ensure Samba is not installed
- oval:simp.cis.3.1.1.RedHat7.2.2.12_Ensure_HTTP_Proxy_Server_is_not_installed:def:1
- Title: Ensure HTTP Proxy Server is not installed
- oval:simp.cis.3.1.1.RedHat7.2.2.16_Ensure_mail_transfer_agent_is_configured_for_local-only_mode:def:1
- Title: Ensure mail transfer agent is configured for local-only mode
- oval:simp.cis.3.1.1.RedHat7.2.2.17_Ensure_nfs-utils_is_not_installed_or_the__nfs-server_service_is_masked:def:1
- Title: Ensure nfs-utils is not installed or the nfs-server service is masked
- oval:simp.cis.3.1.1.RedHat7.2.2.18_Ensure_rpcbind_is_not_installed_or_the__rpcbind_services_are_masked:def:1
- Title: Ensure rpcbind is not installed or the rpcbind services are masked
- oval:simp.cis.3.1.1.RedHat7.2.2.19_Ensure_rsync_is_not_installed_or_the_rsyncd_service_is_masked:def:1
- Title: Ensure rsync is not installed or the rsyncd service is masked
- oval:simp.cis.3.1.1.RedHat7.2.4_Ensure_nonessential_services_are_removed_or_masked:def:1
- Title: Ensure nonessential services are removed or masked
- oval:simp.cis.3.1.1.RedHat7.3.4.1_Ensure_DCCP_is_disabled:def:1
- Title: Ensure DCCP is disabled
- oval:simp.cis.3.1.1.RedHat7.3.4.2_Ensure_SCTP_is_disabled:def:1
- Title: Ensure SCTP is disabled
- oval:simp.cis.3.1.1.RedHat7.3.5.3.2.3_Ensure_iptables_rules_exist_for_all_open_ports:def:1
- Title: Ensure iptables rules exist for all open ports
- oval:simp.cis.3.1.1.RedHat7.4.2.1.6_Ensure_remote_rsyslog_messages_are_only_accepted_on_designated_log_hosts.:def:1
- Title: Ensure remote rsyslog messages are only accepted on designated log hosts.
- oval:simp.cis.3.1.1.RedHat7.5.3.6_Ensure_SSH_X11_forwarding_is_disabled:def:1
- Title: Ensure SSH X11 forwarding is disabled
- oval:simp.cis.3.1.1.RedHat7.5.3.8_Ensure_SSH_IgnoreRhosts_is_enabled:def:1
- Title: Ensure SSH IgnoreRhosts is enabled
- oval:simp.cis.3.1.1.RedHat7.5.3.20_Ensure_SSH_AllowTcpForwarding_is_disabled:def:1
- Title: Ensure SSH AllowTcpForwarding is disabled
- oval:simp.cis.3.1.1.RedHat7.1.1.2_Ensure_tmp_is_configured:def:1
- Title: Ensure /tmp is configured
- oval:simp.cis.3.1.1.RedHat7.3.1.1_Disable_IPv6:def:1
- oval:simp.cis.3.1.1.RedHat7.3.5.1.1_Ensure_firewalld_is_installed:def:1
- Title: Ensure firewalld is installed
- oval:simp.cis.3.1.1.RedHat7.3.5.1.2_Ensure_iptables-services_not_installed_with_firewalld:def:1
- Title: Ensure iptables-services not installed with firewalld
- oval:simp.cis.3.1.1.RedHat7.3.5.1.3_Ensure_nftables_either_not_installed_or_masked_with_firewalld:def:1
- Title: Ensure nftables either not installed or masked with firewalld
- oval:simp.cis.3.1.1.RedHat7.3.5.1.4_Ensure_firewalld_service_enabled_and_running:def:1
- Title: Ensure firewalld service enabled and running
- oval:simp.cis.3.1.1.RedHat7.3.5.1.5_Ensure_firewalld_default_zone_is_set:def:1
- Title: Ensure firewalld default zone is set
- oval:simp.cis.3.1.1.RedHat7.3.5.1.6_Ensure_network_interfaces_are_assigned_to_appropriate_zone:def:1
- Title: Ensure network interfaces are assigned to appropriate zone
- oval:simp.cis.3.1.1.RedHat7.3.5.1.7_Ensure_firewalld_drops_unnecessary_services_and_ports:def:1
- Title: Ensure firewalld drops unnecessary services and ports
- oval:simp.cis.3.1.1.RedHat7.3.5.2.1_Ensure_nftables_is_installed:def:1
- Title: Ensure nftables is installed
- oval:simp.cis.3.1.1.RedHat7.3.5.2.2_Ensure_firewalld_is_either_not_installed_or_masked_with_nftables:def:1
- Title: Ensure firewalld is either not installed or masked with nftables
- oval:simp.cis.3.1.1.RedHat7.3.5.2.3_Ensure_iptables-services_not_installed_with_nftables:def:1
- Title: Ensure iptables-services not installed with nftables
- oval:simp.cis.3.1.1.RedHat7.3.5.2.4_Ensure_iptables_are_flushed_with_nftables:def:1
- Title: Ensure iptables are flushed with nftables
- oval:simp.cis.3.1.1.RedHat7.3.5.2.5_Ensure_an_nftables_table_exists:def:1
- Title: Ensure an nftables table exists
- oval:simp.cis.3.1.1.RedHat7.3.5.2.6_Ensure_nftables_base_chains_exist:def:1
- Title: Ensure nftables base chains exist
- oval:simp.cis.3.1.1.RedHat7.3.5.2.7_Ensure_nftables_loopback_traffic_is_configured:def:1
- Title: Ensure nftables loopback traffic is configured
- oval:simp.cis.3.1.1.RedHat7.3.5.2.8_Ensure_nftables_outbound_and_established_connections_are_configured:def:1
- Title: Ensure nftables outbound and established connections are configured
- oval:simp.cis.3.1.1.RedHat7.3.5.2.9_Ensure_nftables_default_deny_firewall_policy:def:1
- Title: Ensure nftables default deny firewall policy
- oval:simp.cis.3.1.1.RedHat7.3.5.2.10_Ensure_nftables_service_is_enabled:def:1
- Title: Ensure nftables service is enabled
- oval:simp.cis.3.1.1.RedHat7.3.5.2.11_Ensure_nftables_rules_are_permanent:def:1
- Title: Ensure nftables rules are permanent
- oval:simp.cis.3.1.1.RedHat7.3.5.3.1.1_Ensure_iptables_packages_are_installed:def:1
- Title: Ensure iptables packages are installed
- oval:simp.cis.3.1.1.RedHat7.3.5.3.1.2_Ensure_nftables_is_not_installed_with_iptables:def:1
- Title: Ensure nftables is not installed with iptables
- oval:simp.cis.3.1.1.RedHat7.3.5.3.1.3_Ensure_firewalld_is_either_not_installed_or_masked_with_iptables:def:1
- Title: Ensure firewalld is either not installed or masked with iptables
- oval:simp.cis.3.1.1.RedHat7.3.5.3.2.1_Ensure_iptables_loopback_traffic_is_configured:def:1
- Title: Ensure iptables loopback traffic is configured
- oval:simp.cis.3.1.1.RedHat7.3.5.3.2.2_Ensure_iptables_outbound_and_established_connections_are_configured:def:1
- Title: Ensure iptables outbound and established connections are configured
- oval:simp.cis.3.1.1.RedHat7.3.5.3.2.4_Ensure_iptables_default_deny_firewall_policy:def:1
- Title: Ensure iptables default deny firewall policy
- oval:simp.cis.3.1.1.RedHat7.3.5.3.2.5_Ensure_iptables_rules_are_saved:def:1
- Title: Ensure iptables rules are saved
- oval:simp.cis.3.1.1.RedHat7.3.5.3.2.6_Ensure_iptables_is_enabled_and_running:def:1
- Title: Ensure iptables is enabled and running
- oval:simp.cis.3.1.1.RedHat7.3.5.3.3.1_Ensure_ip6tables_loopback_traffic_is_configured:def:1
- Title: Ensure ip6tables loopback traffic is configured
- oval:simp.cis.3.1.1.RedHat7.3.5.3.3.2_Ensure_ip6tables_outbound_and_established_connections_are_configured:def:1
- Title: Ensure ip6tables outbound and established connections are configured
- oval:simp.cis.3.1.1.RedHat7.3.5.3.3.3_Ensure_ip6tables_firewall_rules_exist_for_all_open_ports:def:1
- Title: Ensure ip6tables firewall rules exist for all open ports
- oval:simp.cis.3.1.1.RedHat7.3.5.3.3.4_Ensure_ip6tables_default_deny_firewall_policy:def:1
- Title: Ensure ip6tables default deny firewall policy
- oval:simp.cis.3.1.1.RedHat7.3.5.3.3.5_Ensure_ip6tables_rules_are_saved:def:1
- Title: Ensure ip6tables rules are saved
- oval:simp.cis.3.1.1.RedHat7.3.5.3.3.6_Ensure_ip6tables_is_enabled_and_running:def:1
- Title: Ensure ip6tables is enabled and running
- oval:simp.cis.3.1.1.RedHat7.5.3.13_Ensure_only_strong_Ciphers_are_used:def:1
- Title: Ensure only strong Ciphers are used
- oval:simp.cis.3.1.1.RedHat7.5.3.15_Ensure_only_strong_Key_Exchange_algorithms_are_used:def:1
- Title: Ensure only strong Key Exchange algorithms are used
- oval:simp.cis.3.1.1.RedHat7.5.3.7_Ensure_SSH_MaxAuthTries_is_set_to_4_or_less:def:1
- Title: Ensure SSH MaxAuthTries is set to 4 or less
RedHat 8 (215/233 [92%])
- oval:simp.cis.2.0.0.RedHat8.1.7.1_Ensure_message_of_the_day_is_configured_properly:def:1
- Title: Ensure message of the day is configured properly
- oval:simp.cis.2.0.0.RedHat8.1.7.2_Ensure_local_login_warning_banner_is_configured_properly:def:1
- Title: Ensure local login warning banner is configured properly
- oval:simp.cis.2.0.0.RedHat8.1.7.3_Ensure_remote_login_warning_banner_is_configured_properly:def:1
- Title: Ensure remote login warning banner is configured properly
- oval:simp.cis.2.0.0.RedHat8.1.8.2_Ensure_GDM_login_banner_is_configured:def:1
- Title: Ensure GDM login banner is configured
- oval:simp.cis.2.0.0.RedHat8.1.8.3_Ensure_last_logged_in_user_display_is_disabled:def:1
- Title: Ensure last logged in user display is disabled
- oval:simp.cis.2.0.0.RedHat8.3.2.1_Ensure_IP_forwarding_is_disabled:def:1
- Title: Ensure IP forwarding is disabled
- oval:simp.cis.2.0.0.RedHat8.3.2.2_Ensure_packet_redirect_sending_is_disabled:def:1
- Title: Ensure packet redirect sending is disabled
- oval:simp.cis.2.0.0.RedHat8.3.3.1_Ensure_source_routed_packets_are_not_accepted:def:1
- Title: Ensure source routed packets are not accepted
- oval:simp.cis.2.0.0.RedHat8.3.3.2_Ensure_ICMP_redirects_are_not_accepted:def:1
- Title: Ensure ICMP redirects are not accepted
- oval:simp.cis.2.0.0.RedHat8.3.3.3_Ensure_secure_ICMP_redirects_are_not_accepted:def:1
- Title: Ensure secure ICMP redirects are not accepted
- oval:simp.cis.2.0.0.RedHat8.3.3.5_Ensure_broadcast_ICMP_requests_are_ignored:def:1
- Title: Ensure broadcast ICMP requests are ignored
- oval:simp.cis.2.0.0.RedHat8.3.3.6_Ensure_bogus_ICMP_responses_are_ignored:def:1
- Title: Ensure bogus ICMP responses are ignored
- oval:simp.cis.2.0.0.RedHat8.3.3.7_Ensure_Reverse_Path_Filtering_is_enabled:def:1
- Title: Ensure Reverse Path Filtering is enabled
- oval:simp.cis.2.0.0.RedHat8.3.3.8_Ensure_TCP_SYN_Cookies_is_enabled:def:1
- Title: Ensure TCP SYN Cookies is enabled
- oval:simp.cis.2.0.0.RedHat8.3.3.9_Ensure_IPv6_router_advertisements_are_not_accepted:def:1
- Title: Ensure IPv6 router advertisements are not accepted
- oval:simp.cis.2.0.0.RedHat8.4.1.3.10_Ensure_successful_file_system_mounts_are_collected:def:1
- Title: Ensure successful file system mounts are collected
- oval:simp.cis.2.0.0.RedHat8.4.1.3.19_Ensure_kernel_module_loading_unloading_and_modification_is_collected:def:1
- Title: Ensure kernel module loading unloading and modification is collected
- oval:simp.cis.2.0.0.RedHat8.4.2.1.4_Ensure_rsyslog_default_file_permissions_are_configured:def:1
- Title: Ensure rsyslog default file permissions are configured
- oval:simp.cis.2.0.0.RedHat8.4.2.3_Ensure_permissions_on_all_logfiles_are_configured:def:1
- Title: Ensure permissions on all logfiles are configured
- NOTE: btmp, lastlog, and wtmp will not have any permissions stripped from them. Doing so could cause login issues for users.
- oval:simp.cis.2.0.0.RedHat8.5.1.1_Ensure_cron_daemon_is_enabled:def:1
- Title: Ensure cron daemon is enabled
- oval:simp.cis.2.0.0.RedHat8.5.1.2_Ensure_permissions_on_etccrontab_are_configured:def:1
- Title: Ensure permissions on /etc/crontab are configured
- oval:simp.cis.2.0.0.RedHat8.5.1.3_Ensure_permissions_on_etccron.hourly_are_configured:def:1
- Title: Ensure permissions on /etc/cron.hourly are configured
- oval:simp.cis.2.0.0.RedHat8.5.1.4_Ensure_permissions_on_etccron.daily_are_configured:def:1
- Title: Ensure permissions on /etc/cron.daily are configured
- oval:simp.cis.2.0.0.RedHat8.5.1.5_Ensure_permissions_on_etccron.weekly_are_configured:def:1
- Title: Ensure permissions on /etc/cron.weekly are configured
- oval:simp.cis.2.0.0.RedHat8.5.1.6_Ensure_permissions_on_etccron.monthly_are_configured:def:1
- Title: Ensure permissions on /etc/cron.monthly are configured
- oval:simp.cis.2.0.0.RedHat8.5.1.7_Ensure_permissions_on_etccron.d_are_configured:def:1
- Title: Ensure permissions on /etc/cron.d are configured
- oval:simp.cis.2.0.0.RedHat8.5.2.1_Ensure_permissions_on_etcsshsshd_config_are_configured:def:1
- Title: Ensure permissions on /etc/ssh/sshd_config are configured
- oval:simp.cis.2.0.0.RedHat8.5.2.2_Ensure_permissions_on_SSH_private_host_key_files_are_configured:def:1
- Title: Ensure permissions on SSH private host key files are configured
- oval:simp.cis.2.0.0.RedHat8.5.2.3_Ensure_permissions_on_SSH_public_host_key_files_are_configured:def:1
- Title: Ensure permissions on SSH public host key files are configured
- oval:simp.cis.2.0.0.RedHat8.5.2.6_Ensure_SSH_PAM_is_enabled:def:1
- Title: Ensure SSH PAM is enabled
- oval:simp.cis.2.0.0.RedHat8.5.2.10_Ensure_SSH_PermitUserEnvironment_is_disabled:def:1
- Title: Ensure SSH PermitUserEnvironment is disabled
- oval:simp.cis.2.0.0.RedHat8.5.2.15_Ensure_SSH_warning_banner_is_configured:def:1
- Title: Ensure SSH warning banner is configured
- oval:simp.cis.2.0.0.RedHat8.5.2.17_Ensure_SSH_MaxStartups_is_configured:def:1
- Title: Ensure SSH MaxStartups is configured
- oval:simp.cis.2.0.0.RedHat8.5.2.18_Ensure_SSH_MaxSessions_is_set_to_10_or_less:def:1
- Title: Ensure SSH MaxSessions is set to 10 or less
- oval:simp.cis.2.0.0.RedHat8.5.2.19_Ensure_SSH_LoginGraceTime_is_set_to_one_minute_or_less:def:1
- Title: Ensure SSH LoginGraceTime is set to one minute or less
- oval:simp.cis.2.0.0.RedHat8.5.3.2_Ensure_sudo_commands_use_pty:def:1
- Title: Ensure sudo commands use pty
- oval:simp.cis.2.0.0.RedHat8.5.3.7_Ensure_access_to_the_su_command_is_restricted:def:1
- Title: Ensure access to the su command is restricted
- oval:simp.cis.2.0.0.RedHat8.5.6.4_Ensure_default_group_for_the_root_account_is_GID_0:def:1
- Title: Ensure default group for the root account is GID 0
- oval:simp.cis.2.0.0.RedHat8.6.1.2_Ensure_sticky_bit_is_set_on_all_world-writable_directories:def:1
- Title: Ensure sticky bit is set on all world-writable directories
- oval:simp.cis.2.0.0.RedHat8.6.2.7_Ensure_root_PATH_Integrity:def:1
- Title: Ensure root PATH Integrity
- oval:simp.cis.2.0.0.RedHat8.6.2.8_Ensure_root_is_the_only_UID_0_account:def:1
- Title: Ensure root is the only UID 0 account
- oval:simp.cis.2.0.0.RedHat8.6.2.9_Ensure_all_users_home_directories_exist:def:1
- Title: Ensure all users’ home directories exist
- oval:simp.cis.2.0.0.RedHat8.6.2.14Ensure_no_users_have.forward_files:def:1
- Title: Ensure no users have .forward files
- oval:simp.cis.2.0.0.RedHat8.1.1.2.3_Ensure_noexec_option_set_on_tmp_partition:def:1
- Title: Ensure noexec option set on /tmp partition
- oval:simp.cis.2.0.0.RedHat8.1.1.2.4_Ensure_nosuid_option_set_on_tmp_partition:def:1
- Title: Ensure nosuid option set on /tmp partition
- oval:simp.cis.2.0.0.RedHat8.1.1.3.2_Ensure_nodev_option_set_on_var_partition:def:1
- Title: Ensure nodev option set on /var partition
- oval:simp.cis.2.0.0.RedHat8.1.1.3.3_Ensure_noexec_option_set_on_var_partition:def:1
- Title: Ensure noexec option set on /var partition
- oval:simp.cis.2.0.0.RedHat8.1.1.3.4_Ensure_nosuid_option_set_on_var_partition:def:1
- Title: Ensure nosuid option set on /var partition
- oval:simp.cis.2.0.0.RedHat8.1.1.4.2_Ensure_noexec_option_set_on_vartmp_partition:def:1
- Title: Ensure noexec option set on /var/tmp partition
- oval:simp.cis.2.0.0.RedHat8.1.1.4.3_Ensure_nosuid_option_set_on_vartmp_partition:def:1
- Title: Ensure nosuid option set on /var/tmp partition
- oval:simp.cis.2.0.0.RedHat8.1.1.4.4_Ensure_nodev_option_set_on_vartmp_partition:def:1
- Title: Ensure nodev option set on /var/tmp partition
- oval:simp.cis.2.0.0.RedHat8.1.1.5.2_Ensure_nodev_option_set_on_varlog_partition:def:1
- Title: Ensure nodev option set on /var/log partition
- oval:simp.cis.2.0.0.RedHat8.1.1.5.3_Ensure_noexec_option_set_on_varlog_partition:def:1
- Title: Ensure noexec option set on /var/log partition
- oval:simp.cis.2.0.0.RedHat8.1.1.5.4_Ensure_nosuid_option_set_on_varlog_partition:def:1
- Title: Ensure nosuid option set on /var/log partition
- oval:simp.cis.2.0.0.RedHat8.1.1.6.2_Ensure_noexec_option_set_on_varlogaudit_partition:def:1
- Title: Ensure noexec option set on /var/log/audit partition
- oval:simp.cis.2.0.0.RedHat8.1.1.6.3_Ensure_nodev_option_set_on_varlogaudit_partition:def:1
- Title: Ensure nodev option set on /var/log/audit partition
- oval:simp.cis.2.0.0.RedHat8.1.1.6.4_Ensure_nosuid_option_set_on_varlogaudit_partition:def:1
- Title: Ensure nosuid option set on /var/log/audit partition
- oval:simp.cis.2.0.0.RedHat8.1.1.7.2_Ensure_nodev_option_set_on_home_partition:def:1
- Title: Ensure nodev option set on /home partition
- oval:simp.cis.2.0.0.RedHat8.1.1.7.3_Ensure_nosuid_option_set_on_home_partition:def:1
- Title: Ensure nosuid option set on /home partition
- oval:simp.cis.2.0.0.RedHat8.1.1.8.1_Ensure_nodev_option_set_on_devshm_partition:def:1
- Title: Ensure nodev option set on /dev/shm partition
- oval:simp.cis.2.0.0.RedHat8.1.1.8.2_Ensure_noexec_option_set_on_devshm_partition:def:1
- Title: Ensure noexec option set on /dev/shm partition
- oval:simp.cis.2.0.0.RedHat8.1.1.8.3_Ensure_nosuid_option_set_on_devshm_partition:def:1
- Title: Ensure nosuid option set on /dev/shm partition
- oval:simp.cis.2.0.0.RedHat8.1.4.1_Ensure_bootloader_password_is_set:def:1
- Title: Ensure bootloader password is set
- oval:simp.cis.2.0.0.RedHat8.1.4.2_Ensure_permissions_on_bootloader_config_are_configured:def:1
- Title: Ensure permissions on bootloader config are configured
- oval:simp.cis.2.0.0.RedHat8.1.6.1.1_Ensure_SELinux_is_installed:def:1
- Title: Ensure SELinux is installed
- oval:simp.cis.2.0.0.RedHat8.1.6.1.2_Ensure_SELinux_is_not_disabled_in_bootloader_configuration:def:1
- Title: Ensure SELinux is not disabled in bootloader configuration
- oval:simp.cis.2.0.0.RedHat8.1.6.1.3_Ensure_SELinux_policy_is_configured:def:1
- Title: Ensure SELinux policy is configured
- oval:simp.cis.2.0.0.RedHat8.1.6.1.4_Ensure_the_SELinux_mode_is_not_disabled:def:1
- Title: Ensure the SELinux mode is not disabled
- oval:simp.cis.2.0.0.RedHat8.1.6.1.5_Ensure_the_SELinux_mode_is_enforcing:def:1
- Title: Ensure the SELinux mode is enforcing
- oval:simp.cis.2.0.0.RedHat8.1.6.1.7_Ensure_SETroubleshoot_is_not_installed:def:1
- Title: Ensure SETroubleshoot is not installed
- oval:simp.cis.2.0.0.RedHat8.1.7.4_Ensure_permissions_on_etcmotd_are_configured:def:1
- Title: Ensure permissions on /etc/motd are configured
- oval:simp.cis.2.0.0.RedHat8.1.7.5_Ensure_permissions_on_etcissue_are_configured:def:1
- Title: Ensure permissions on /etc/issue are configured
- oval:simp.cis.2.0.0.RedHat8.1.7.6_Ensure_permissions_on_etcissue.net_are_configured:def:1
- Title: Ensure permissions on /etc/issue.net are configured
- oval:simp.cis.2.0.0.RedHat8.5.6.2_Ensure_system_accounts_are_secured:def:1
- Title: Ensure system accounts are secured
- oval:simp.cis.2.0.0.RedHat8.5.6.5_Ensure_default_user_umask_is_027_or_more_restrictive:def:1
- Title: Ensure default user umask is 027 or more restrictive
- NOTE: The umask will be set to 027 within /etc/profile.d/simp.sh, however, this check still fails the scan.
- oval:simp.cis.2.0.0.RedHat8.6.2.10_Ensure_users_own_their_home_directories:def:1
- Title: Ensure users own their home directories
- oval:simp.cis.2.0.0.RedHat8.6.2.11_Ensure_users_home_directories_permissions_are_750_or_more_restrictive:def:1
- Title: Ensure users’ home directories permissions are 750 or more restrictive
- oval:simp.cis.2.0.0.RedHat8.6.2.12_Ensure_users_dot_files_are_not_group_or_world_writable:def:1
- Title: Ensure users’ dot files are not group or world writable
- oval:simp.cis.2.0.0.RedHat8.6.2.13Ensure_users.netrc_Files_are_not_group_or_world_accessible:def:1
- Title: Ensure users’ .netrc Files are not group or world accessible
- oval:simp.cis.2.0.0.RedHat8.4.1.3.12_Ensure_login_and_logout_events_are_collected:def:1
- Title: Ensure login and logout events are collected
- oval:simp.cis.2.0.0.RedHat8.5.2.20_Ensure_SSH_Idle_Timeout_Interval_is_configured:def:1
- Title: Ensure SSH Idle Timeout Interval is configured
- oval:simp.cis.2.0.0.RedHat8.5.6.3_Ensure_default_user_shell_timeout_is_900_seconds_or_less:def:1
- Title: Ensure default user shell timeout is 900 seconds or less
-
*NOTE: The scanner fails to pickup on the format the product uses for setting the timeout: [ $TMOUT ] |
|
export TMOUT=900. The setting is also set in a nonstandard location: /etc/profile.d/simp.sh.* |
- oval:simp.cis.2.0.0.RedHat8.1.1.9_Disable_Automounting:def:1
- Title: Disable Automounting
- oval:simp.cis.2.0.0.RedHat8.1.8.5_Ensure_automatic_mounting_of_removable_media_is_disabled:def:1
- Title: Ensure automatic mounting of removable media is disabled
- NOTE: This has been remediated as requested, however, the product puts a space between the key/value pair in the dconf file and the check for the rule expects no spaces between the key/value and the ‘=’.
- oval:simp.cis.2.0.0.RedHat8.5.2.7_Ensure_SSH_root_login_is_disabled:def:1
- Title: Ensure SSH root login is disabled
- oval:simp.cis.2.0.0.RedHat8.5.3.1_Ensure_sudo_is_installed:def:1
- Title: Ensure sudo is installed
- oval:simp.cis.2.0.0.RedHat8.5.3.6_Ensure_sudo_authentication_timeout_is_configured_correctly:def:1
- Title: Ensure sudo authentication timeout is configured correctly
- oval:simp.cis.2.0.0.RedHat8.1.1.10_Disable_USB_Storage:def:1
- Title: Disable USB Storage
- oval:simp.cis.2.0.0.RedHat8.3.1.4_Ensure_wireless_interfaces_are_disabled:def:1
- Title: Ensure wireless interfaces are disabled
- oval:simp.cis.2.0.0.RedHat8.3.3.4_Ensure_suspicious_packets_are_logged:def:1
- Title: Ensure suspicious packets are logged
- oval:simp.cis.2.0.0.RedHat8.4.1.1.1_Ensure_auditd_is_installed:def:1
- Title: Ensure auditd is installed
- oval:simp.cis.2.0.0.RedHat8.4.1.1.2_Ensure_auditd_service_is_enabled:def:1
- Title: Ensure auditd service is enabled
- oval:simp.cis.2.0.0.RedHat8.4.1.1.3_Ensure_auditing_for_processes_that_start_prior_to_auditd_is_enabled:def:1
- Title: Ensure auditing for processes that start prior to auditd is enabled
- oval:simp.cis.2.0.0.RedHat8.4.1.1.4_Ensure_audit_backlog_limit_is_sufficient:def:1
- Title: Ensure audit_backlog_limit is sufficient
- oval:simp.cis.2.0.0.RedHat8.4.1.3.6_Ensure_use_of_privileged_commands_are_collected:def:1
- Title: Ensure use of privileged commands are collected
- NOTE: The available setuid/setgid commands on a given system could vary greatly. Several of the more common commands are audited, but there is currently no automated way to identify and audit all possible setuid/setgid commands available on any given system.
- oval:simp.cis.2.0.0.RedHat8.4.1.3.15_Ensure_successful_and_unsuccessful_attempts_to_use_the_chcon_command_are_recorded:def:1
- Title: Ensure successful and unsuccessful attempts to use the chcon command are recorded
- oval:simp.cis.2.0.0.RedHat8.4.1.3.16_Ensure_successful_and_unsuccessful_attempts_to_use_the_setfacl_command_are_recorded:def:1
- Title: Ensure successful and unsuccessful attempts to use the setfacl command are recorded
- oval:simp.cis.2.0.0.RedHat8.4.1.3.17_Ensure_successful_and_unsuccessful_attempts_to_use_the_chacl_command_are_recorded:def:1
- Title: Ensure successful and unsuccessful attempts to use the chacl command are recorded
- oval:simp.cis.2.0.0.RedHat8.4.1.3.18_Ensure_successful_and_unsuccessful_attempts_to_use_the_usermod_command_are_recorded:def:1
- Title: Ensure successful and unsuccessful attempts to use the usermod command are recorded
- oval:simp.cis.2.0.0.RedHat8.4.1.3.20_Ensure_the_audit_configuration_is_immutable:def:1
- Title: Ensure the audit configuration is immutable
- oval:simp.cis.2.0.0.RedHat8.4.2.1.1_Ensure_rsyslog_is_installed:def:1
- Title: Ensure rsyslog is installed
- oval:simp.cis.2.0.0.RedHat8.4.2.1.2_Ensure_rsyslog_service_is_enabled:def:1
- Title: Ensure rsyslog service is enabled
- oval:simp.cis.2.0.0.RedHat8.4.2.1.5_Ensure_logging_is_configured:def:1
- Title: Ensure logging is configured
- oval:simp.cis.2.0.0.RedHat8.4.2.1.7_Ensure_rsyslog_is_not_configured_to_recieve_logs_from_a_remote_client:def:1
- Title: Ensure rsyslog is not configured to recieve logs from a remote client
- NOTE: Including the product’s rsyslog class will purge any rsyslog configuration not specified by the user in hieradata or by other rules that require specific rsyslog configuration.
- oval:simp.cis.2.0.0.RedHat8.4.2.2.1.1_Ensure_systemd-journal-remote_is_installed:def:1
- Title: Ensure systemd-journal-remote is installed
- oval:simp.cis.2.0.0.RedHat8.4.2.2.1.4_Ensure_journald_is_not_configured_to_recieve_logs_from_a_remote_client:def:1
- Title: Ensure journald is not configured to recieve logs from a remote client
- oval:simp.cis.2.0.0.RedHat8.4.2.2.2_Ensure_journald_service_is_enabled:def:1
- Title: Ensure journald service is enabled
- NOTE: Simply including the journald class will include a default journald configuration and ensure the service is enabled.
- oval:simp.cis.2.0.0.RedHat8.4.2.2.3_Ensure_journald_is_configured_to_compress_large_log_files:def:1
- Title: Ensure journald is configured to compress large log files
- oval:simp.cis.2.0.0.RedHat8.4.2.2.4_Ensure_journald_is_configured_to_write_logfiles_to_persistent_disk:def:1
- Title: Ensure journald is configured to write logfiles to persistent disk
- oval:simp.cis.2.0.0.RedHat8.4.2.2.5_Ensure_journald_is_not_configured_to_send_logs_to_rsyslog:def:1
- Title: Ensure journald is not configured to send logs to rsyslog
- oval:simp.cis.2.0.0.RedHat8.4.2.2.6_Ensure_journald_log_rotation_is_configured_per_site_policy:def:1
- Title: Ensure journald log rotation is configured per site policy
- oval:simp.cis.2.0.0.RedHat8.5.2.5_Ensure_SSH_LogLevel_is_appropriate:def:1
- Title: Ensure SSH LogLevel is appropriate
- oval:simp.cis.2.0.0.RedHat8.2.1.1_Ensure_time_synchronization_is_in_use:def:1
- Title: Ensure time synchronization is in use
- oval:simp.cis.2.0.0.RedHat8.2.1.2_Ensure_chrony_is_configured:def:1
- Title: Ensure chrony is configured
- NOTE: We are configuring the system to use ntpd instead of chrony.
- oval:simp.cis.2.0.0.RedHat8.1.8.1_Ensure_GNOME_Display_Manager_is_removed:def:1
- Title: Ensure GNOME Display Manager is removed
- oval:simp.cis.2.0.0.RedHat8.2.2.1_Ensure_xinetd_is_not_installed:def:1
- Title: Ensure xinetd is not installed
- oval:simp.cis.2.0.0.RedHat8.2.2.14_Ensure_net-snmp_is_not_installed:def:1
- Title: Ensure net-snmp is not installed
- oval:simp.cis.2.0.0.RedHat8.2.2.15_Ensure_NIS_server_is_not_installed:def:1
- Title: Ensure NIS server is not installed
- oval:simp.cis.2.0.0.RedHat8.2.2.16_Ensure_telnet-server_is_not_installed:def:1
- Title: Ensure telnet-server is not installed
- oval:simp.cis.2.0.0.RedHat8.2.3.1_Ensure_NIS_Client_is_not_installed:def:1
- Title: Ensure NIS Client is not installed
- oval:simp.cis.2.0.0.RedHat8.2.3.2_Ensure_rsh_client_is_not_installed:def:1
- Title: Ensure rsh client is not installed
- oval:simp.cis.2.0.0.RedHat8.2.3.3_Ensure_talk_client_is_not_installed:def:1
- Title: Ensure talk client is not installed
- oval:simp.cis.2.0.0.RedHat8.2.3.4_Ensure_telnet_client_is_not_installed:def:1
- Title: Ensure telnet client is not installed
- oval:simp.cis.2.0.0.RedHat8.2.3.5_Ensure_LDAP_client_is_not_installed:def:1
- Title: Ensure LDAP client is not installed
- oval:simp.cis.2.0.0.RedHat8.1.4.3_Ensure_authentication_is_required_when_booting_into_rescue_mode:def:1
- Title: Ensure authentication is required when booting into rescue mode
- oval:simp.cis.2.0.0.RedHat8.5.5.1_Ensure_password_creation_requirements_are_configured:def:1
- Title: Ensure password creation requirements are configured
- oval:simp.cis.2.0.0.RedHat8.5.5.3_Ensure_password_reuse_is_limited:def:1
- Title: Ensure password reuse is limited
- NOTE: Password reuse will be limited through pam instead of authselect. The product will support authselect in a future release.
- oval:simp.cis.2.0.0.RedHat8.5.6.1.1_Ensure_password_expiration_is_365_days_or_less:def:1
- Title: Ensure password expiration is 365 days or less
- NOTE: The product sets PASS_MAX_DAYS in /etc/login.defs, however, there is currently no mechanism to enforce the setting for existing users in /etc/shadow.
- oval:simp.cis.2.0.0.RedHat8.5.6.1.2_Ensure_minimum_days_between_password_changes_is_7_or_more:def:1
- Title: Ensure minimum days between password changes is 7 or more
- NOTE: The PASS_MIN_DAYS value in /etc/login.defs will be set to 7 as requested, however, the product has no mechanism to change this value on all existing users.
- oval:simp.cis.2.0.0.RedHat8.5.6.1.3_Ensure_password_expiration_warning_days_is_7_or_more:def:1
- Title: Ensure password expiration warning days is 7 or more
- oval:simp.cis.2.0.0.RedHat8.5.6.1.4_Ensure_inactive_password_lock_is_30_days_or_less:def:1
- Title: Ensure inactive password lock is 30 days or less
- NOTE: The system will be configured to make accounts inactive after 30 days of inactivity, however, the product has no mechanism to change this value on existing users.
- oval:simp.cis.2.0.0.RedHat8.5.6.1.5_Ensure_all_users_last_password_change_date_is_in_the_past:def:1
- Title: Ensure all users last password change date is in the past
- oval:simp.cis.2.0.0.RedHat8.6.2.1_Ensure_password_fields_are_not_empty:def:1
- Title: Ensure password fields are not empty
- oval:simp.cis.2.0.0.RedHat8.5.5.4_Ensure_password_hashing_algorithm_is_SHA-512:def:1
- Title: Ensure password hashing algorithm is SHA-512
- oval:simp.cis.2.0.0.RedHat8.6.1.3_Ensure_permissions_on_etcpasswd_are_configured:def:1
- Title: Ensure permissions on /etc/passwd are configured
- oval:simp.cis.2.0.0.RedHat8.6.1.4_Ensure_permissions_on_etcshadow_are_configured:def:1
- Title: Ensure permissions on /etc/shadow are configured
- oval:simp.cis.2.0.0.RedHat8.6.1.5_Ensure_permissions_on_etcgroup_are_configured:def:1
- Title: Ensure permissions on /etc/group are configured
- oval:simp.cis.2.0.0.RedHat8.6.1.6_Ensure_permissions_on_etcgshadow_are_configured:def:1
- Title: Ensure permissions on /etc/gshadow are configured
- oval:simp.cis.2.0.0.RedHat8.6.1.7_Ensure_permissions_on_etcpasswd-_are_configured:def:1
- Title: Ensure permissions on /etc/passwd- are configured
- oval:simp.cis.2.0.0.RedHat8.6.1.8_Ensure_permissions_on_etcshadow-_are_configured:def:1
- Title: Ensure permissions on /etc/shadow- are configured
- oval:simp.cis.2.0.0.RedHat8.6.1.9_Ensure_permissions_on_etcgroup-_are_configured:def:1
- Title: Ensure permissions on /etc/group- are configured
- oval:simp.cis.2.0.0.RedHat8.6.1.10_Ensure_permissions_on_etcgshadow-_are_configured:def:1
- Title: Ensure permissions on /etc/gshadow- are configured
- oval:simp.cis.2.0.0.RedHat8.6.2.15Ensure_no_users_have.netrc_files:def:1
- Title: Ensure no users have .netrc files
- oval:simp.cis.2.0.0.RedHat8.6.2.16Ensure_no_users_have.rhosts_files:def:1
- Title: Ensure no users have .rhosts files
- oval:simp.cis.2.0.0.RedHat8.5.4.1_Ensure_custom_authselect_profile_is_used:def:1
- Title: Ensure custom authselect profile is used
- oval:simp.cis.2.0.0.RedHat8.5.4.2_Ensure_authselect_includes_with-faillock:def:1
- Title: Ensure authselect includes with-faillock
- oval:simp.cis.2.0.0.RedHat8.5.5.2_Ensure_lockout_for_failed_password_attempts_is_configured:def:1
- Title: Ensure lockout for failed password attempts is configured
- oval:simp.cis.2.0.0.RedHat8.1.1.1.1_Ensure_mounting_of_cramfs_filesystems_is_disabled:def:1
- Title: Ensure mounting of cramfs filesystems is disabled
- oval:simp.cis.2.0.0.RedHat8.1.1.1.2_Ensure_mounting_of_squashfs_filesystems_is_disabled:def:1
- Title: Ensure mounting of squashfs filesystems is disabled
- oval:simp.cis.2.0.0.RedHat8.1.1.1.3_Ensure_mounting_of_udf_filesystems_is_disabled:def:1
- Title: Ensure mounting of udf filesystems is disabled
- oval:simp.cis.2.0.0.RedHat8.1.1.2.1_Ensure_tmp_is_a_separate_partition:def:1
- Title: Ensure /tmp is a separate partition
- NOTE: /tmp will be configured as a bindmount with the following options: bind,nodev,noexec,nosuid. The test for this rule, however, is looking for /tmp in /etc/fstab.
- oval:simp.cis.2.0.0.RedHat8.1.1.2.2_Ensure_nodev_option_set_on_tmp_partition:def:1
- Title: Ensure nodev option set on /tmp partition
- oval:simp.cis.2.0.0.RedHat8.1.6.1.8_Ensure_the_MCS_Translation_Service_mcstrans_is_not_installed:def:1
- Title: Ensure the MCS Translation Service (mcstrans) is not installed
- oval:simp.cis.2.0.0.RedHat8.1.8.4_Ensure_XDMCP_is_not_enabled:def:1
- Title: Ensure XDMCP is not enabled
- oval:simp.cis.2.0.0.RedHat8.2.2.2_Ensure_xorg-x11-server-common_is_not_installed:def:1
- Title: Ensure xorg-x11-server-common is not installed
- oval:simp.cis.2.0.0.RedHat8.2.2.3_Ensure_Avahi_Server_is_not_installed:def:1
- Title: Ensure Avahi Server is not installed
- oval:simp.cis.2.0.0.RedHat8.2.2.4_Ensure_CUPS_is_not_installed:def:1
- Title: Ensure CUPS is not installed
- oval:simp.cis.2.0.0.RedHat8.2.2.5_Ensure_DHCP_Server_is_not_installed:def:1
- Title: Ensure DHCP Server is not installed
- oval:simp.cis.2.0.0.RedHat8.2.2.6_Ensure_DNS_Server_is_not_installed:def:1
- Title: Ensure DNS Server is not installed
- oval:simp.cis.2.0.0.RedHat8.2.2.7_Ensure_FTP_Server_is_not_installed:def:1
- Title: Ensure FTP Server is not installed
- oval:simp.cis.2.0.0.RedHat8.2.2.8_Ensure_VSFTP_Server_is_not_installed:def:1
- Title: Ensure VSFTP Server is not installed
- oval:simp.cis.2.0.0.RedHat8.2.2.9_Ensure_TFTP_Server_is_not_installed:def:1
- Title: Ensure TFTP Server is not installed
- oval:simp.cis.2.0.0.RedHat8.2.2.10_Ensure_a_web_server_is_not_installed:def:1
- Title: Ensure a web server is not installed
- oval:simp.cis.2.0.0.RedHat8.2.2.11_Ensure_IMAP_and_POP3_server_is_not_installed:def:1
- Title: Ensure IMAP and POP3 server is not installed
- oval:simp.cis.2.0.0.RedHat8.2.2.12_Ensure_Samba_is_not_installed:def:1
- Title: Ensure Samba is not installed
- oval:simp.cis.2.0.0.RedHat8.2.2.13_Ensure_HTTP_Proxy_Server_is_not_installed:def:1
- Title: Ensure HTTP Proxy Server is not installed
- oval:simp.cis.2.0.0.RedHat8.2.2.17_Ensure_mail_transfer_agent_is_configured_for_local-only_mode:def:1
- Title: Ensure mail transfer agent is configured for local-only mode
- oval:simp.cis.2.0.0.RedHat8.2.2.18_Ensure_nfs-utils_is_not_installed_or_the__nfs-server_service_is_masked:def:1
- Title: Ensure nfs-utils is not installed or the nfs-server service is masked
- oval:simp.cis.2.0.0.RedHat8.2.2.19_Ensure_rpcbind_is_not_installed_or_the__rpcbind_services_are_masked:def:1
- Title: Ensure rpcbind is not installed or the rpcbind services are masked
- oval:simp.cis.2.0.0.RedHat8.2.2.20_Ensure_rsync_is_not_installed_or_the_rsyncd_service_is_masked:def:1
- Title: Ensure rsync is not installed or the rsyncd service is masked
- oval:simp.cis.2.0.0.RedHat8.2.3.6_Ensure_TFTP_client_is_not_installed:def:1
- Title: Ensure TFTP client is not installed
- oval:simp.cis.2.0.0.RedHat8.2.4_Ensure_nonessential_services_are_removed_or_masked:def:1
- Title: Ensure nonessential services are removed or masked
- oval:simp.cis.2.0.0.RedHat8.3.1.2_Ensure_SCTP_is_disabled:def:1
- Title: Ensure SCTP is disabled
- oval:simp.cis.2.0.0.RedHat8.3.1.3_Ensure_DCCP_is_disabled:def:1
- Title: Ensure DCCP is disabled
- oval:simp.cis.2.0.0.RedHat8.3.4.3.2.3_Ensure_iptables_rules_exist_for_all_open_ports:def:1
- Title: Ensure iptables rules exist for all open ports
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.RedHat8.5.2.11_Ensure_SSH_IgnoreRhosts_is_enabled:def:1
- Title: Ensure SSH IgnoreRhosts is enabled
- oval:simp.cis.2.0.0.RedHat8.5.2.12_Ensure_SSH_X11_forwarding_is_disabled:def:1
- Title: Ensure SSH X11 forwarding is disabled
- oval:simp.cis.2.0.0.RedHat8.5.2.13_Ensure_SSH_AllowTcpForwarding_is_disabled:def:1
- Title: Ensure SSH AllowTcpForwarding is disabled
- oval:simp.cis.2.0.0.RedHat8.3.1.1_Verify_if_IPv6_is_enabled_on_the_system:def:1
- Title: Verify if IPv6 is enabled on the system
- oval:simp.cis.2.0.0.RedHat8.3.4.1.1_Ensure_firewalld_is_installed:def:1
- Title: Ensure firewalld is installed
- oval:simp.cis.2.0.0.RedHat8.3.4.1.2_Ensure_iptables-services_not_installed_with_firewalld:def:1
- Title: Ensure iptables-services not installed with firewalld
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.RedHat8.3.4.1.3_Ensure_nftables_either_not_installed_or_masked_with_firewalld:def:1
- Title: Ensure nftables either not installed or masked with firewalld
- oval:simp.cis.2.0.0.RedHat8.3.4.1.4_Ensure_firewalld_service_enabled_and_running:def:1
- Title: Ensure firewalld service enabled and running
- oval:simp.cis.2.0.0.RedHat8.3.4.1.5_Ensure_firewalld_default_zone_is_set:def:1
- Title: Ensure firewalld default zone is set
- oval:simp.cis.2.0.0.RedHat8.3.4.1.6_Ensure_network_interfaces_are_assigned_to_appropriate_zone:def:1
- Title: Ensure network interfaces are assigned to appropriate zone
- oval:simp.cis.2.0.0.RedHat8.3.4.1.7_Ensure_firewalld_drops_unnecessary_services_and_ports:def:1
- Title: Ensure firewalld drops unnecessary services and ports
- oval:simp.cis.2.0.0.RedHat8.3.4.2.1_Ensure_nftables_is_installed:def:1
- Title: Ensure nftables is installed
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.RedHat8.3.4.2.2_Ensure_firewalld_is_either_not_installed_or_masked_with_nftables:def:1
- Title: Ensure firewalld is either not installed or masked with nftables
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.RedHat8.3.4.2.3_Ensure_iptables-services_not_installed_with_nftables:def:1
- Title: Ensure iptables-services not installed with nftables
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.RedHat8.3.4.2.4_Ensure_iptables_are_flushed_with_nftables:def:1
- Title: Ensure iptables are flushed with nftables
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.RedHat8.3.4.2.5_Ensure_an_nftables_table_exists:def:1
- Title: Ensure an nftables table exists
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.RedHat8.3.4.2.6_Ensure_nftables_base_chains_exist:def:1
- Title: Ensure nftables base chains exist
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.RedHat8.3.4.2.7_Ensure_nftables_loopback_traffic_is_configured:def:1
- Title: Ensure nftables loopback traffic is configured
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.RedHat8.3.4.2.8_Ensure_nftables_outbound_and_established_connections_are_configured:def:1
- Title: Ensure nftables outbound and established connections are configured
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.RedHat8.3.4.2.9_Ensure_nftables_default_deny_firewall_policy:def:1
- Title: Ensure nftables default deny firewall policy
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.RedHat8.3.4.2.10_Ensure_nftables_service_is_enabled:def:1
- Title: Ensure nftables service is enabled
- oval:simp.cis.2.0.0.RedHat8.3.4.2.11_Ensure_nftables_rules_are_permanent:def:1
- Title: Ensure nftables rules are permanent
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.RedHat8.3.4.3.1.1_Ensure_iptables_packages_are_installed:def:1
- Title: Ensure iptables packages are installed
- oval:simp.cis.2.0.0.RedHat8.3.4.3.1.2_Ensure_nftables_is_not_installed_with_iptables:def:1
- Title: Ensure nftables is not installed with iptables
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.RedHat8.3.4.3.1.3_Ensure_firewalld_is_either_not_installed_or_masked_with_iptables:def:1
- Title: Ensure firewalld is either not installed or masked with iptables
- NOTE: Only applies when nftables is used for firewall provider
- oval:simp.cis.2.0.0.RedHat8.3.4.3.2.1_Ensure_iptables_loopback_traffic_is_configured:def:1
- Title: Ensure iptables loopback traffic is configured
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.RedHat8.3.4.3.2.2_Ensure_iptables_outbound_and_established_connections_are_configured:def:1
- Title: Ensure iptables outbound and established connections are configured
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.RedHat8.3.4.3.2.4_Ensure_iptables_default_deny_firewall_policy:def:1
- Title: Ensure iptables default deny firewall policy
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.RedHat8.3.4.3.2.5_Ensure_iptables_rules_are_saved:def:1
- Title: Ensure iptables rules are saved
- oval:simp.cis.2.0.0.RedHat8.3.4.3.2.6_Ensure_iptables_is_enabled_and_active:def:1
- Title: Ensure iptables is enabled and active
- oval:simp.cis.2.0.0.RedHat8.3.4.3.3.1_Ensure_ip6tables_loopback_traffic_is_configured:def:1
- Title: Ensure ip6tables loopback traffic is configured
- oval:simp.cis.2.0.0.RedHat8.3.4.3.3.2_Ensure_ip6tables_outbound_and_established_connections_are_configured:def:1
- Title: Ensure ip6tables outbound and established connections are configured
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.RedHat8.3.4.3.3.3_Ensure_ip6tables_firewall_rules_exist_for_all_open_ports:def:1
- Title: Ensure ip6tables firewall rules exist for all open ports
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.RedHat8.3.4.3.3.4_Ensure_ip6tables_default_deny_firewall_policy:def:1
- Title: Ensure ip6tables default deny firewall policy
- NOTE: Only applies when iptables is used for firewall provider
- oval:simp.cis.2.0.0.RedHat8.3.4.3.3.5_Ensure_ip6tables_rules_are_saved:def:1
- Title: Ensure ip6tables rules are saved
- oval:simp.cis.2.0.0.RedHat8.3.4.3.3.6_Ensure_ip6tables_is_enabled_and_active:def:1
- Title: Ensure ip6tables is enabled and active
- oval:simp.cis.2.0.0.RedHat8.1.10_Ensure_system-wide_crypto_policy_is_not_legacy:def:1
- Title: Ensure system-wide crypto policy is not legacy
- oval:simp.cis.2.0.0.RedHat8.5.2.14_Ensure_system-wide_crypto_policy_is_not_over-ridden:def:1
- Title: Ensure system-wide crypto policy is not over-ridden
- oval:simp.cis.2.0.0.RedHat8.4.1.3.11_Ensure_session_initiation_information_is_collected:def:1
- Title: Ensure session initiation information is collected
- oval:simp.cis.2.0.0.RedHat8.5.2.16_Ensure_SSH_MaxAuthTries_is_set_to_4_or_less:def:1
- Title: Ensure SSH MaxAuthTries is set to 4 or less