Skip to main content

SLES 12 — Implemented CIS Rules

This page lists every CIS Benchmark rule ImageFactory automates for SLES 12, exactly as implemented by the hardening tasks. See CIS Benchmarks for background on Level 1 vs. Level 2, and CIS Hardening Exceptions for rules that are intentionally not automated.

Level 1 (137 rules)​

Section 1 — Initial Setup​

Rule IDTitle
1.1.1.2Ensure mounting of udf filesystems is disabled
1.1.2Ensure /tmp is configured
1.1.3Ensure noexec option set on /tmp partition
1.1.4Ensure nodev option set on /tmp partition
1.1.5Ensure nosuid option set on /tmp partition
1.1.7Ensure noexec option set on /dev/shm partition
1.1.8Ensure nodev option set on /dev/shm partition
1.1.9Ensure nosuid option set on /dev/shm partition
1.1.12Ensure noexec option set on /var/tmp partition
1.1.13Ensure nodev option set on /var/tmp partition
1.1.14Ensure nosuid option set on /var/tmp partition
1.1.18Ensure nodev option set on /home partition
1.1.22Ensure sticky bit is set on all world-writable directories
1.1.23Disable Automounting
1.2.3Ensure gpgcheck is globally activated
1.4.1Ensure AIDE is installed
1.4.2Ensure filesystem integrity is regularly checked
1.5.2Ensure permissions on bootloader config are configured
1.5.3Ensure authentication required for single user mode
1.6.1Ensure core dumps are restricted
1.6.2Ensure XD/NX support is enabled
1.6.3Ensure address space layout randomization (ASLR) is enabled
1.6.4Ensure prelink is disabled
1.7.1.1Ensure AppArmor is installed
1.7.1.2Ensure AppArmor is enabled in the bootloader configuration
1.7.1.3Ensure all AppArmor Profiles are in enforce or complain mode
1.8.1.1Ensure message of the day is configured properly
1.8.1.2Ensure local login warning banner is configured properly
1.8.1.3Ensure remote login warning banner is configured properly
1.8.1.4Ensure permissions on /etc/motd are configured
1.8.1.5Ensure permissions on /etc/issue are configured
1.8.1.6Ensure permissions on /etc/issue.net are configured
1.10Ensure GDM is removed or login is configured

Section 2 — Services​

Rule IDTitle
2.1.1Ensure xinetd is not installed
2.2.1.1Ensure time synchronization is in use
2.2.1.3Ensure chrony is configured
2.2.1.4Ensure ntp is configured
2.2.2Ensure X11 Server components are not installed
2.2.3Ensure Avahi Server is not installed
2.2.4Ensure CUPS is not installed
2.2.5Ensure DHCP Server is not installed
2.2.6Ensure LDAP server is not installed
2.2.7Ensure DNS Server is not installed
2.2.8Ensure FTP Server is not enabled
2.2.9Ensure HTTP server is not installed
2.2.10Ensure IMAP and POP3 server is not installed
2.2.11Ensure Samba is not installed
2.2.12Ensure HTTP Proxy Server is not installed
2.2.13Ensure net-snmp is not installed
2.2.14Ensure NIS server is not installed
2.2.15Ensure telnet-server is not installed
2.2.16Ensure nfs-utils is not installed or the nfs-server service is masked
2.2.17Ensure rpcbind is not installed or the rpcbind services are masked
2.2.18Ensure rsync is not installed or the rsyncd service is masked
2.2.19Ensure mail transfer agent is configured for local-only mode
2.3.1Ensure NIS Client is not installed
2.3.2Ensure rsh client is not installed
2.3.3Ensure talk client is not installed
2.3.4Ensure telnet client is not installed
2.3.5Ensure LDAP client is not installed

Section 3 — Network Configuration​

Rule IDTitle
3.2.1Ensure IP forwarding is disabled
3.3.1Ensure source routed packets are not accepted
3.3.2Ensure ICMP redirects are not accepted
3.3.3Ensure secure ICMP redirects are not accepted
3.3.4Ensure suspicious packets are logged
3.3.5Ensure broadcast ICMP requests are ignored
3.3.6Ensure bogus ICMP responses are ignored
3.3.7Ensure Reverse Path Filtering is enabled
3.3.8Ensure TCP SYN Cookies is enabled
3.3.9Ensure IPv6 router advertisements are not accepted
3.5.1.1Ensure iptables package is installed
3.5.2Configure IPv4 iptables
3.5.3Configure IPv6 ip6tables

Section 4​

Rule IDTitle
4.2.1.1Ensure rsyslog is installed
4.2.1.2Ensure rsyslog Service is enabled and running
4.2.1.3Ensure rsyslog default file permissions configured
4.2.1.5Ensure rsyslog is configured to send logs to a remote log host
4.2.1.6Ensure remote rsyslog messages are only accepted on designated log hosts.
4.2.2.1Ensure journald is configured to send logs to rsyslog
4.2.2.3Ensure journald is configured to compress large log files
4.2.3Ensure permissions on all logfiles are configured
4.2.4Ensure logrotate is configured

Section 5​

Rule IDTitle
5.1.1Ensure sudo is installed
5.1.2Ensure sudo commands use pty
5.1.3Ensure sudo log file exists
5.2.1Ensure cron daemon is enabled and running
5.2.2Ensure permissions on /etc/crontab are configured
5.2.3Ensure permissions on /etc/cron.hourly are configured
5.2.4Ensure permissions on /etc/cron.daily are configured
5.2.5Ensure permissions on /etc/cron.weekly are configured
5.2.6Ensure permissions on /etc/cron.monthly are configured
5.2.7Ensure permissions on /etc/cron.d are configured
5.2.8Ensure cron is restricted to authorized users
5.2.9Ensure at is restricted to authorized users
5.3.1Ensure permissions on /etc/ssh/sshd_config are configured
5.3.4Ensure SSH Protocol is set to 2
5.3.5Ensure SSH access is limited
5.3.6Ensure SSH LogLevel is appropriate
5.3.8Ensure SSH MaxAuthTries is set to 4 or less
5.3.9Ensure SSH IgnoreRhosts is enabled
5.3.10Ensure SSH HostbasedAuthentication is disabled
5.3.11Ensure SSH root login is disabled
5.3.12Ensure SSH PermitEmptyPasswords is disabled
5.3.13Ensure SSH PermitUserEnvironment is disabled
5.3.14Ensure only strong Ciphers are used
5.3.15Ensure only strong MAC algorithms are used
5.3.16Ensure only strong Key Exchange algorithms are used
5.3.17Ensure SSH Idle Timeout Interval is configured
5.3.18Ensure SSH LoginGraceTime is set to one minute or less
5.3.19Ensure SSH warning banner is configured
5.3.22Ensure SSH MaxStartups is configured
5.4.1Ensure password creation requirements are configured
5.4.2Ensure lockout for failed password attempts is configured
5.4.3Ensure password reuse is limited
5.5.1.1Ensure password hashing algorithm is SHA-512
5.5.1.2Ensure password expiration is 365 days or less
5.5.1.3Ensure minimum days between password changes is configured
5.5.1.4Ensure password expiration warning days is 7 or more
5.5.1.5Ensure inactive password lock is 30 days or less
5.5.2Ensure system accounts are secured
5.5.3Ensure default group for the root account is GID 0
5.5.4Ensure default user shell timeout is configured
5.5.5Ensure default user umask is configured
5.7Ensure access to the su command is restricted

Section 6​

Rule IDTitle
6.1.2Ensure permissions on /etc/passwd are configured
6.1.3Ensure permissions on /etc/shadow are configured
6.1.4Ensure permissions on /etc/group are configured
6.1.5Ensure permissions on /etc/passwd- are configured (Scored)
6.1.6Ensure permissions on /etc/shadow- are configured (Scored)
6.1.7Ensure permissions on /etc/group- are configured (Scored)
6.2.2Ensure /etc/shadow password fields are not empty
6.2.3Ensure root is the only UID 0 account
6.2.5Ensure all users' home directories exist
6.2.6Ensure users' home directories permissions are 750 or more restrictive
6.2.9Ensure no users have .forward files
6.2.10Ensure no users have .netrc files
6.2.12Ensure no users have .rhosts files

Level 2 (28 rules)​

Section 1 — Initial Setup​

Rule IDTitle
1.1.1.1Ensure mounting of squashfs filesystems is disabled

Section 3 — Network Configuration​

Rule IDTitle
3.1.1Disable IPv6
3.4.1Ensure DCCP is disabled
3.4.2Ensure SCTP is disabled

Section 4​

Rule IDTitle
4.1.1.1Ensure auditd is installed
4.1.1.2Ensure auditd service is enabled
4.1.1.3Ensure auditing for processes that start prior to auditd is enabled
4.1.2.1Ensure audit log storage size is configured
4.1.2.2Ensure audit logs are not automatically deleted
4.1.2.3Ensure system is disabled when audit logs are full
4.1.2.4Ensure audit_backlog_limit is sufficient
4.1.3Ensure events that modify date and time information are collected
4.1.4Ensure events that modify user/group information are collected
4.1.5Ensure events that modify the system's network environment are collected
4.1.6Ensure events that modify the system's Mandatory Access Controls are collected
4.1.7Ensure login and logout events are collected
4.1.8Ensure session initiation information is collected
4.1.9Ensure discretionary access control permission modification events are collected
4.1.10Ensure unsuccessful unauthorized file access attempts are collected
4.1.11Ensure use of privileged commands is collected
4.1.12Ensure successful file system mounts are collected
4.1.13Ensure file deletion events by users are collected
4.1.14Ensure changes to system administration scope (sudoers) is collected
4.1.15Ensure system administrator actions (sudolog) are collected
4.1.16Ensure kernel module loading and unloading is collected
4.1.17Ensure the audit configuration is immutable

Section 5​

Rule IDTitle
5.3.6Ensure SSH X11 forwarding is disabled
5.3.20Ensure SSH AllowTcpForwarding is disabled