Cis Ubuntu1604 V200 1 2 2

Ensure GPG keys are configured

cyberstrikeus Updated

File contents

CIS Ubuntu Linux 16.04 LTS Benchmark v2.0.0 - 1.2.2

Profile Applicability

  • Level 1 - Server
  • Level 1 - Workstation

Description

Most packages managers implement GPG key signing to verify package integrity during installation.

Rationale

It is important to ensure that updates are obtained from a valid source to protect against spoofing that could lead to the inadvertent installation of malware on the system.

Audit Procedure

Command Line

Verify GPG keys are configured correctly for your package manager:

apt-key list

Expected Result

Verify GPG keys are configured correctly for your package manager.

Remediation

Command Line

Update your package manager GPG keys in accordance with site policy.

Default Value

Not applicable.

References

None.

CIS Controls

Controls Version Control
v7 3.4 Deploy Automated Operating System Patch Management Tools
v7 3.5 Deploy Automated Software Patch Management Tools

Assessment Status

Manual

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-linux-16-04-lts-benchmark-v2/cis-ubuntu1604-v200-1-2-2 commit dae9f74fcb

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu1604-v200-1-2-2