Skip to main content

Amazon Linux 2023 — Implemented CIS Rules

This page lists every CIS Benchmark rule ImageFactory automates for Amazon Linux 2023, exactly as implemented by the hardening tasks. See CIS Benchmarks for background on Level 1 vs. Level 2, and CIS Hardening Exceptions for rules that are intentionally not automated.

Level 1 (113 rules)​

Section 1 — Initial Setup​

Rule IDTitle
1.1.1.3Ensure mounting of cramfs filesystems is disabled
1.1.2Ensure /tmp is configured
1.1.2.3Ensure nodev option set on /tmp partition
1.1.2.4Ensure noexec option set on /tmp partition
1.1.2.5Ensure nosuid option set on /tmp partition
1.1.4.2Ensure /var/tmp partition includes the noexec option
1.1.4.3Ensure /var/tmp partition includes the nosuid option
1.1.4.4Ensure /var/tmp partition includes the nodev option
1.1.7.2Ensure /home partition includes the nodev option
1.1.8.2Ensure nodev option set on /dev/shm partition
1.1.8.3Ensure noexec option set on /dev/shm partition
1.1.8.4Ensure nosuid option set on /dev/shm partition
1.1.9Ensure usb-storage is disabled
1.2.2Ensure gpgcheck is globally activated
1.3.1Ensure AIDE is installed
1.3.2Ensure filesystem integrity is regularly checked
1.3.3Ensure cryptographic mechanisms are used to protect the integrity of audit tools
1.4.1Ensure permissions on bootloader config are configured
1.5.1Ensure address space layout randomization (ASLR) is enabled
1.5.2Ensure ptrace_scope is restricted
1.5.3Ensure core dump storage is disabled
1.5.4Ensure core dump backtraces are disabled
1.6.1.1Ensure SELinux is installed
1.6.1.2Ensure SELinux is not disabled in bootloader configuration
1.6.1.3Ensure SELinux policy is configured
1.7.1Ensure message of the day is configured properly
1.7.2Ensure local login warning banner is configured properly
1.7.3Ensure remote login warning banner is configured properly
1.7.4Ensure permissions on /etc/motd are configured
1.7.5Ensure permissions on /etc/issue are configured
1.7.6Ensure permissions on /etc/issue.net are configured

Section 2 — Services​

Rule IDTitle
2.1.1Ensure time synchronization is in use
2.1.2Ensure chrony is configured
2.2.2Ensure Avahi Server is not installed
2.2.3Ensure a print server is not installed
2.2.4Ensure DHCP Server is not installed
2.2.5Ensure DNS Server is not installed
2.2.6Ensure FTP Server is not installed
2.2.8Ensure HTTP server is not installed
2.2.9Ensure IMAP and POP3 server is not installed
2.2.10Ensure Samba is not installed
2.2.11Ensure HTTP Proxy Server is not installed
2.2.12Ensure net-snmp is not installed
2.2.13Ensure telnet-server is not installed
2.2.15Ensure mail transfer agent is configured for local-only mode
2.2.16Ensure nfs-utils is not installed or the nfs-server service is masked
2.2.17Ensure rpcbind is not installed or the rpcbind services are masked
2.2.18Ensure rsync is not installed or the rsyncd service is masked
2.3.1Ensure telnet client is not installed
2.3.2Ensure LDAP client is not installed

Section 3 — Network Configuration​

Rule IDTitle
3.2.1Ensure IP forwarding is disabled
3.2.2Ensure packet redirect sending is disabled
3.3.1Ensure source routed packets are not accepted
3.3.2Ensure ICMP redirects are not accepted
3.3.3Ensure secure ICMP redirects are not accepted
3.3.4Ensure suspicious packets are logged
3.3.5Ensure broadcast ICMP requests are ignored
3.3.6Ensure bogus ICMP responses are ignored
3.3.7Ensure Reverse Path Filtering is enabled
3.3.8Ensure TCP SYN Cookies is enabled
3.3.9Ensure IPv6 router advertisements are not accepted
3.4.1Ensure a Firewall package is installed
3.4.2Configure firewall rules

Section 4​

Rule IDTitle
4.1.1Ensure cron daemon is enabled and running
4.1.2Ensure permissions on /etc/crontab are configured
4.1.3Ensure permissions on /etc/cron.hourly are configured
4.1.4Ensure permissions on /etc/cron.daily are configured
4.1.5Ensure permissions on /etc/cron.weekly are configured
4.1.6Ensure permissions on /etc/cron.monthly are configured
4.1.7Ensure permissions on /etc/cron.d are configured
4.1.84.1.8 - 5.1.9 | Ensure at/cron is restricted to authorized users
4.1.94.1.8 - 5.1.9 | Ensure at/cron is restricted to authorized users
4.2.1Ensure permissions on /etc/ssh/sshd_config are configured
4.2.2Ensure permissions on SSH private host key files are configured
4.2.3Ensure permissions on SSH public host key files are configured
4.2.4Ensure SSH access is limited
4.2.5Ensure SSH LogLevel is appropriate
4.2.6Ensure SSH PAM is enabled
4.2.7Ensure SSH root login is disabled
4.2.8Ensure SSH HostbasedAuthentication is disabled
4.2.9Ensure SSH PermitEmptyPasswords is disabled
4.2.10Ensure SSH PermitUserEnvironment is disabled
4.2.11Ensure SSH IgnoreRhosts is enabled
4.2.15Ensure SSH warning banner is configured
4.2.16Ensure SSH MaxAuthTries is set to 4 or less
4.2.17Ensure SSH MaxStartups is configured
4.2.18Ensure SSH MaxSessions is set to 4 or less
4.2.19Ensure SSH LoginGraceTime is set to one minute or less
4.2.20Ensure SSH Idle Timeout Interval is configured
4.3.1Ensure sudo is installed
4.3.2Ensure sudo commands use pty
4.3.3Ensure sudo log file exists
4.3.6Ensure access to the su command is restricted
4.5.1Ensure password creation requirements are configured
4.5.2Ensure lockout for failed password attempts is configured
4.5.3Ensure password hashing algorithm is SHA-512
4.5.4Ensure password reuse is limited
4.6.1.1Ensure password expiration is 365 days or less
4.6.1.2Ensure minimum days between password changes is 7 or more
4.6.1.3Ensure password expiration warning days is 7 or more
4.6.1.4Ensure inactive password lock is 30 days or less
4.6.3Ensure default user shell timeout is 900 seconds or less
4.6.4Ensure default group for the root account is GID 0
4.6.5Ensure default user umask is 027 or more restrictive

Section 5​

Rule IDTitle
5.1.1.1Ensure rsyslog is installed
5.1.1.2Ensure rsyslog Service is enabled and running
5.1.1.3Ensure journald is configured to send logs to rsyslog
5.1.1.4Ensure rsyslog default file permissions configured
5.1.2.3Ensure journald is configured to compress large log files
5.1.2.4Ensure journald is configured to write logfiles to persistent disk
5.1.3Ensure all logfiles have appropriate permissions and ownership

Section 6​

Rule IDTitle
6.1.11Ensure world writable files and directories are secured
6.2.13Ensure users' home directories permissions are 750 or more restrictive

Level 2 (34 rules)​

Section 1 — Initial Setup​

Rule IDTitle
1.1.1.1Ensure mounting of squashfs filesystems is disabled
1.1.1.2Ensure mounting of udf filesystems is disabled
1.6.1.5Ensure the SELinux mode is enforcing

Section 3 — Network Configuration​

Rule IDTitle
3.1.2Ensure DCCP is disabled
3.1.3Ensure SCTP is disabled
3.1.4Ensure RDS is disabled

Section 4​

Rule IDTitle
4.2.12Ensure SSH X11 forwarding is disabled
4.2.13Ensure SSH AllowTcpForwarding is disabled

Section 5​

Rule IDTitle
5.2.1.1Ensure auditd is installed
5.2.1.3Ensure audit_backlog_limit is sufficient
5.2.1.4Ensure auditd service is enabled
5.2.2.1Ensure audit log storage size is configured
5.2.2.2Ensure audit logs are not automatically deleted
5.2.2.3Ensure system is disabled when audit logs are full
5.2.3.1Ensure changes to system administration scope (sudoers) is collected
5.2.3.2Ensure actions as another user are always logged
5.2.3.3Ensure events that modify the sudo log file are collected
5.2.3.4Ensure events that modify date and time information are collected
5.2.3.5Ensure events that modify the system's network environment are collected
5.2.3.6Ensure use of privileged commands are collected
5.2.3.7Ensure unsuccessful file access attempts are collected
5.2.3.8Ensure events that modify user/group information are collected
5.2.3.9Ensure discretionary access control permission modification events are collected
5.2.3.10Ensure successful file system mounts are collected
5.2.3.11Ensure session initiation information is collected
5.2.3.12Ensure login and logout events are collected
5.2.3.13Ensure file deletion events by users are collected
5.2.3.14Ensure events that modify the system's Mandatory Access Controls are collected
5.2.3.15Ensure events that modify the system's Mandatory Access Controls are collected
5.2.3.16Ensure events that modify the system's Mandatory Access Controls are collected
5.2.3.17Ensure events that modify the system's Mandatory Access Controls are collected
5.2.3.18Ensure events that modify the system's Mandatory Access Controls are collected
5.2.3.19Ensure kernel module loading unloading and modification is collected
5.2.3.20Ensure the audit configuration is immutable