cyberstrikeus
- 7.2k skills
- 0 followers
- 1 day ago last updated
- ▌
- ▌ Cis Ubuntu1804 V220 5 1 2 6 · cyberstrikeusEnsure rsyslog is configured to send logs to a remote log host
- ▌ Cis Ubuntu1804 V220 5 1 2 7 · cyberstrikeusEnsure rsyslog is not configured to receive logs from a remote client
- ▌ Cis Ubuntu1804 V220 5 2 1 1 · cyberstrikeusVerify that auditd and audispd-plugins packages are installed
- ▌ Cis Ubuntu1804 V220 5 2 1 2 · cyberstrikeusVerify that the auditd daemon is enabled and running to record system events
- ▌ Cis Ubuntu1804 V220 5 2 1 3 · cyberstrikeusConfigure grub2 to enable auditing for processes that start prior to auditd daemon startup
- ▌ Cis Ubuntu1804 V220 5 2 1 4 · cyberstrikeusConfigure the audit_backlog_limit kernel parameter to prevent audit event loss
- ▌ Cis Ubuntu1804 V220 5 2 2 1 · cyberstrikeusConfigure the maximum size of audit log files to prevent system impact and audit data loss
- ▌ Cis Ubuntu1804 V220 5 2 2 2 · cyberstrikeusConfigure auditd to keep audit logs and never delete them automatically
- ▌ Cis Ubuntu1804 V220 5 2 2 3 · cyberstrikeusConfigure the system to halt when audit logs are full to prevent data loss
- ▌ Cis Ubuntu1804 V220 5 2 3 1 · cyberstrikeusEnsure changes to system administration scope (sudoers) is collected
- ▌
- ▌ Cis Ubuntu1804 V220 5 2 3 3 · cyberstrikeusEnsure events that modify the sudo log file are collected
- ▌ Cis Ubuntu1804 V220 5 2 3 4 · cyberstrikeusEnsure events that modify date and time information are collected
- ▌ Cis Ubuntu1804 V220 5 2 3 5 · cyberstrikeusEnsure events that modify the system's network environment are collected
- ▌
- ▌
- ▌ Cis Ubuntu1804 V220 5 2 3 8 · cyberstrikeusEnsure events that modify user/group information are collected
- ▌ Cis Ubuntu1804 V220 5 2 3 9 · cyberstrikeusEnsure discretionary access control permission modification events are collected
- ▌ Cis Ubuntu1804 V220 5 2 4 1 · cyberstrikeus5.2.4.1 Ensure audit log files are mode 0640 or less permissive
- ▌ Cis Ubuntu1804 V220 5 2 4 2 · cyberstrikeus5.2.4.2 Ensure only authorized users own audit log files
- ▌ Cis Ubuntu1804 V220 5 2 4 3 · cyberstrikeus5.2.4.3 Ensure only authorized groups are assigned ownership of audit log files
- ▌ Cis Ubuntu1804 V220 5 2 4 4 · cyberstrikeus5.2.4.4 Ensure the audit log directory is 0750 or more restrictive
- ▌ Cis Ubuntu1804 V220 5 2 4 5 · cyberstrikeus5.2.4.5 Ensure audit configuration files are 640 or more restrictive
- ▌ Cis Ubuntu1804 V220 5 2 4 6 · cyberstrikeus5.2.4.6 Ensure audit configuration files are owned by root
- ▌ Cis Ubuntu1804 V220 5 2 4 7 · cyberstrikeus5.2.4.7 Ensure audit configuration files belong to group root
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Ubuntu2004 V300 1 2 2 1 · cyberstrikeusEnsure updates, patches, and additional security software are installed
- ▌ Cis Ubuntu2004 V300 1 3 1 1 · cyberstrikeusEnsure latest versions of the apparmor packages are installed
- ▌ Cis Ubuntu2004 V300 1 3 1 2 · cyberstrikeusEnsure AppArmor is enabled in the bootloader configuration
- ▌
- ▌
- ▌
- ▌ Cis Ubuntu2004 V300 2 3 2 1 · cyberstrikeusEnsure systemd-timesyncd configured with authorized timeserver
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Ubuntu2004 V300 4 4 2 3 · cyberstrikeusEnsure iptables outbound and established connections are configured
- ▌
- ▌
- ▌
- ▌ Cis Ubuntu2004 V300 4 4 3 3 · cyberstrikeusEnsure ip6tables outbound and established connections are configured
- ▌ Cis Ubuntu2004 V300 4 4 3 4 · cyberstrikeusEnsure ip6tables firewall rules exist for all open ports
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Ubuntu2004 V300 5 4 1 6 · cyberstrikeusEnsure all users last password change date is in the past
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌