SLES 12 — Implemented CIS Rules
This page lists every CIS Benchmark rule ImageFactory automates for SLES 12, exactly as implemented by the hardening tasks. See CIS Benchmarks for background on Level 1 vs. Level 2, and CIS Hardening Exceptions for rules that are intentionally not automated.
Level 1 (137 rules)
Section 1 — Initial Setup
| Rule ID | Title |
|---|---|
| 1.1.1.2 | Ensure mounting of udf filesystems is disabled |
| 1.1.2 | Ensure /tmp is configured |
| 1.1.3 | Ensure noexec option set on /tmp partition |
| 1.1.4 | Ensure nodev option set on /tmp partition |
| 1.1.5 | Ensure nosuid option set on /tmp partition |
| 1.1.7 | Ensure noexec option set on /dev/shm partition |
| 1.1.8 | Ensure nodev option set on /dev/shm partition |
| 1.1.9 | Ensure nosuid option set on /dev/shm partition |
| 1.1.12 | Ensure noexec option set on /var/tmp partition |
| 1.1.13 | Ensure nodev option set on /var/tmp partition |
| 1.1.14 | Ensure nosuid option set on /var/tmp partition |
| 1.1.18 | Ensure nodev option set on /home partition |
| 1.1.22 | Ensure sticky bit is set on all world-writable directories |
| 1.1.23 | Disable Automounting |
| 1.2.3 | Ensure gpgcheck is globally activated |
| 1.4.1 | Ensure AIDE is installed |
| 1.4.2 | Ensure filesystem integrity is regularly checked |
| 1.5.2 | Ensure permissions on bootloader config are configured |
| 1.5.3 | Ensure authentication required for single user mode |
| 1.6.1 | Ensure core dumps are restricted |
| 1.6.2 | Ensure XD/NX support is enabled |
| 1.6.3 | Ensure address space layout randomization (ASLR) is enabled |
| 1.6.4 | Ensure prelink is disabled |
| 1.7.1.1 | Ensure AppArmor is installed |
| 1.7.1.2 | Ensure AppArmor is enabled in the bootloader configuration |
| 1.7.1.3 | Ensure all AppArmor Profiles are in enforce or complain mode |
| 1.8.1.1 | Ensure message of the day is configured properly |
| 1.8.1.2 | Ensure local login warning banner is configured properly |
| 1.8.1.3 | Ensure remote login warning banner is configured properly |
| 1.8.1.4 | Ensure permissions on /etc/motd are configured |
| 1.8.1.5 | Ensure permissions on /etc/issue are configured |
| 1.8.1.6 | Ensure permissions on /etc/issue.net are configured |
| 1.10 | Ensure GDM is removed or login is configured |
Section 2 — Services
| Rule ID | Title |
|---|---|
| 2.1.1 | Ensure xinetd is not installed |
| 2.2.1.1 | Ensure time synchronization is in use |
| 2.2.1.3 | Ensure chrony is configured |
| 2.2.1.4 | Ensure ntp is configured |
| 2.2.2 | Ensure X11 Server components are not installed |
| 2.2.3 | Ensure Avahi Server is not installed |
| 2.2.4 | Ensure CUPS is not installed |
| 2.2.5 | Ensure DHCP Server is not installed |
| 2.2.6 | Ensure LDAP server is not installed |
| 2.2.7 | Ensure DNS Server is not installed |
| 2.2.8 | Ensure FTP Server is not enabled |
| 2.2.9 | Ensure HTTP server is not installed |
| 2.2.10 | Ensure IMAP and POP3 server is not installed |
| 2.2.11 | Ensure Samba is not installed |
| 2.2.12 | Ensure HTTP Proxy Server is not installed |
| 2.2.13 | Ensure net-snmp is not installed |
| 2.2.14 | Ensure NIS server is not installed |
| 2.2.15 | Ensure telnet-server is not installed |
| 2.2.16 | Ensure nfs-utils is not installed or the nfs-server service is masked |
| 2.2.17 | Ensure rpcbind is not installed or the rpcbind services are masked |
| 2.2.18 | Ensure rsync is not installed or the rsyncd service is masked |
| 2.2.19 | Ensure mail transfer agent is configured for local-only mode |
| 2.3.1 | Ensure NIS Client is not installed |
| 2.3.2 | Ensure rsh client is not installed |
| 2.3.3 | Ensure talk client is not installed |
| 2.3.4 | Ensure telnet client is not installed |
| 2.3.5 | Ensure LDAP client is not installed |
Section 3 — Network Configuration
| Rule ID | Title |
|---|---|
| 3.2.1 | Ensure IP forwarding is disabled |
| 3.3.1 | Ensure source routed packets are not accepted |
| 3.3.2 | Ensure ICMP redirects are not accepted |
| 3.3.3 | Ensure secure ICMP redirects are not accepted |
| 3.3.4 | Ensure suspicious packets are logged |
| 3.3.5 | Ensure broadcast ICMP requests are ignored |
| 3.3.6 | Ensure bogus ICMP responses are ignored |
| 3.3.7 | Ensure Reverse Path Filtering is enabled |
| 3.3.8 | Ensure TCP SYN Cookies is enabled |
| 3.3.9 | Ensure IPv6 router advertisements are not accepted |
| 3.5.1.1 | Ensure iptables package is installed |
| 3.5.2 | Configure IPv4 iptables |
| 3.5.3 | Configure IPv6 ip6tables |
Section 4
| Rule ID | Title |
|---|---|
| 4.2.1.1 | Ensure rsyslog is installed |
| 4.2.1.2 | Ensure rsyslog Service is enabled and running |
| 4.2.1.3 | Ensure rsyslog default file permissions configured |
| 4.2.1.5 | Ensure rsyslog is configured to send logs to a remote log host |
| 4.2.1.6 | Ensure remote rsyslog messages are only accepted on designated log hosts. |
| 4.2.2.1 | Ensure journald is configured to send logs to rsyslog |
| 4.2.2.3 | Ensure journald is configured to compress large log files |
| 4.2.3 | Ensure permissions on all logfiles are configured |
| 4.2.4 | Ensure logrotate is configured |
Section 5
| Rule ID | Title |
|---|---|
| 5.1.1 | Ensure sudo is installed |
| 5.1.2 | Ensure sudo commands use pty |
| 5.1.3 | Ensure sudo log file exists |
| 5.2.1 | Ensure cron daemon is enabled and running |
| 5.2.2 | Ensure permissions on /etc/crontab are configured |
| 5.2.3 | Ensure permissions on /etc/cron.hourly are configured |
| 5.2.4 | Ensure permissions on /etc/cron.daily are configured |
| 5.2.5 | Ensure permissions on /etc/cron.weekly are configured |
| 5.2.6 | Ensure permissions on /etc/cron.monthly are configured |
| 5.2.7 | Ensure permissions on /etc/cron.d are configured |
| 5.2.8 | Ensure cron is restricted to authorized users |
| 5.2.9 | Ensure at is restricted to authorized users |
| 5.3.1 | Ensure permissions on /etc/ssh/sshd_config are configured |
| 5.3.4 | Ensure SSH Protocol is set to 2 |
| 5.3.5 | Ensure SSH access is limited |
| 5.3.6 | Ensure SSH LogLevel is appropriate |
| 5.3.8 | Ensure SSH MaxAuthTries is set to 4 or less |
| 5.3.9 | Ensure SSH IgnoreRhosts is enabled |
| 5.3.10 | Ensure SSH HostbasedAuthentication is disabled |
| 5.3.11 | Ensure SSH root login is disabled |
| 5.3.12 | Ensure SSH PermitEmptyPasswords is disabled |
| 5.3.13 | Ensure SSH PermitUserEnvironment is disabled |
| 5.3.14 | Ensure only strong Ciphers are used |
| 5.3.15 | Ensure only strong MAC algorithms are used |
| 5.3.16 | Ensure only strong Key Exchange algorithms are used |
| 5.3.17 | Ensure SSH Idle Timeout Interval is configured |
| 5.3.18 | Ensure SSH LoginGraceTime is set to one minute or less |
| 5.3.19 | Ensure SSH warning banner is configured |
| 5.3.22 | Ensure SSH MaxStartups is configured |
| 5.4.1 | Ensure password creation requirements are configured |
| 5.4.2 | Ensure lockout for failed password attempts is configured |
| 5.4.3 | Ensure password reuse is limited |
| 5.5.1.1 | Ensure password hashing algorithm is SHA-512 |
| 5.5.1.2 | Ensure password expiration is 365 days or less |
| 5.5.1.3 | Ensure minimum days between password changes is configured |
| 5.5.1.4 | Ensure password expiration warning days is 7 or more |
| 5.5.1.5 | Ensure inactive password lock is 30 days or less |
| 5.5.2 | Ensure system accounts are secured |
| 5.5.3 | Ensure default group for the root account is GID 0 |
| 5.5.4 | Ensure default user shell timeout is configured |
| 5.5.5 | Ensure default user umask is configured |
| 5.7 | Ensure access to the su command is restricted |
Section 6
| Rule ID | Title |
|---|---|
| 6.1.2 | Ensure permissions on /etc/passwd are configured |
| 6.1.3 | Ensure permissions on /etc/shadow are configured |
| 6.1.4 | Ensure permissions on /etc/group are configured |
| 6.1.5 | Ensure permissions on /etc/passwd- are configured (Scored) |
| 6.1.6 | Ensure permissions on /etc/shadow- are configured (Scored) |
| 6.1.7 | Ensure permissions on /etc/group- are configured (Scored) |
| 6.2.2 | Ensure /etc/shadow password fields are not empty |
| 6.2.3 | Ensure root is the only UID 0 account |
| 6.2.5 | Ensure all users' home directories exist |
| 6.2.6 | Ensure users' home directories permissions are 750 or more restrictive |
| 6.2.9 | Ensure no users have .forward files |
| 6.2.10 | Ensure no users have .netrc files |
| 6.2.12 | Ensure no users have .rhosts files |
Level 2 (28 rules)
Section 1 — Initial Setup
| Rule ID | Title |
|---|---|
| 1.1.1.1 | Ensure mounting of squashfs filesystems is disabled |
Section 3 — Network Configuration
| Rule ID | Title |
|---|---|
| 3.1.1 | Disable IPv6 |
| 3.4.1 | Ensure DCCP is disabled |
| 3.4.2 | Ensure SCTP is disabled |
Section 4
| Rule ID | Title |
|---|---|
| 4.1.1.1 | Ensure auditd is installed |
| 4.1.1.2 | Ensure auditd service is enabled |
| 4.1.1.3 | Ensure auditing for processes that start prior to auditd is enabled |
| 4.1.2.1 | Ensure audit log storage size is configured |
| 4.1.2.2 | Ensure audit logs are not automatically deleted |
| 4.1.2.3 | Ensure system is disabled when audit logs are full |
| 4.1.2.4 | Ensure audit_backlog_limit is sufficient |
| 4.1.3 | Ensure events that modify date and time information are collected |
| 4.1.4 | Ensure events that modify user/group information are collected |
| 4.1.5 | Ensure events that modify the system's network environment are collected |
| 4.1.6 | Ensure events that modify the system's Mandatory Access Controls are collected |
| 4.1.7 | Ensure login and logout events are collected |
| 4.1.8 | Ensure session initiation information is collected |
| 4.1.9 | Ensure discretionary access control permission modification events are collected |
| 4.1.10 | Ensure unsuccessful unauthorized file access attempts are collected |
| 4.1.11 | Ensure use of privileged commands is collected |
| 4.1.12 | Ensure successful file system mounts are collected |
| 4.1.13 | Ensure file deletion events by users are collected |
| 4.1.14 | Ensure changes to system administration scope (sudoers) is collected |
| 4.1.15 | Ensure system administrator actions (sudolog) are collected |
| 4.1.16 | Ensure kernel module loading and unloading is collected |
| 4.1.17 | Ensure the audit configuration is immutable |
Section 5
| Rule ID | Title |
|---|---|
| 5.3.6 | Ensure SSH X11 forwarding is disabled |
| 5.3.20 | Ensure SSH AllowTcpForwarding is disabled |