Skip to main content

Ubuntu 16.04 — Implemented CIS Rules

This page lists every CIS Benchmark rule ImageFactory automates for Ubuntu 16.04, exactly as implemented by the hardening tasks. See CIS Benchmarks for background on Level 1 vs. Level 2, and CIS Hardening Exceptions for rules that are intentionally not automated.

Level 1 (101 rules)​

Section 1 — Initial Setup​

Rule IDTitle
1.1.1.1Ensure mounting of cramfs filesystems is disabled
1.1.1.2Ensure mounting of freevxfs filesystems is disabled
1.1.1.3Ensure mounting of jffs2 filesystems is disabled
1.1.1.4Ensure mounting of hfs filesystems is disabled
1.1.1.5Ensure mounting of hfsplus filesystems is disabled
1.1.1.6Ensure mounting of squashfs filesystems is disabled
1.1.31.1.3 - 1.1.4 | Ensure nodev,nosuid option set on /tmp partition
1.1.41.1.3 - 1.1.4 | Ensure nodev,nosuid option set on /tmp partition
1.1.71.1.7 - 1.1.9 | Ensure nodev, nosuid, noexec option set on /dev/shm partition
1.1.81.1.7 - 1.1.9 | Ensure nodev, nosuid, noexec option set on /dev/shm partition
1.1.91.1.7 - 1.1.9 | Ensure nodev, nosuid, noexec option set on /dev/shm partition
1.1.121.1.12 - 1.1.14 | Ensure nodev,nosuid,noexec option set on /var/tmp partition
1.1.131.1.12 - 1.1.14 | Ensure nodev,nosuid,noexec option set on /var/tmp partition
1.1.141.1.12 - 1.1.14 | Ensure nodev,nosuid,noexec option set on /var/tmp partition
1.1.18Ensure /home partition includes the nodev option
1.1.22Ensure sticky bit is set on all world-writable directories
1.1.23Disable Automounting
1.3.1Ensure AIDE is installed
1.3.2Ensure filesystem integrity is regularly checked
1.5.1Ensure XD/NX support is enabled
1.5.2Ensure address space layout randomization (ASLR) is enabled
1.5.3Ensure prelink is disabled
1.5.4Ensure core dumps are restricted
1.7.1Ensure message of the day is configured properly
1.7.2Ensure local login warning banner is configured properly
1.7.3Ensure remote login warning banner is configured properly
1.7.4Ensure permissions on /etc/motd are configured
1.7.5Ensure permissions on /etc/issue are configured
1.7.6Ensure permissions on /etc/issue.net are configured

Section 2 — Services​

Rule IDTitle
2.1.100Ensure chargen services are not enabled
2.1.101Ensure daytime services are not enabled
2.1.102Ensure discard services are not enabled
2.1.103Ensure echo services are not enabled
2.1.104Ensure time services are not enabled
2.2.4Ensure telnet client is not installed
2.2.16Ensure mail transfer agent is configured for local-only mode

Section 3 — Network Configuration​

Rule IDTitle
3.2.1Ensure packet redirect sending is disabled
3.2.2Ensure IP forwarding is disabled
3.3.1Ensure source routed packets are not accepted
3.3.2Ensure ICMP redirects are not accepted
3.3.3Ensure secure ICMP redirects are not accepted
3.3.4Ensure suspicious packets are logged
3.3.5Ensure broadcast ICMP requests are ignored
3.3.6Ensure bogus ICMP responses are ignored
3.3.7Ensure Reverse Path Filtering is enabled
3.3.8Ensure TCP SYN Cookies is enabled
3.4.2Ensure /etc/hosts.allow is configured
3.4.100Ensure /etc/hosts.deny is configured
3.4.101Ensure permissions on /etc/hosts.allow are configured
3.4.102Ensure permissions on /etc/hosts.deny are 644
3.5.3.1.1Ensure iptables packages are installed
3.5.3.2.1Ensure iptables default deny firewall policy
3.5.3.3.1Ensure ip6tables default deny firewall policy
3.5.100Ensure DCCP is disabled
3.5.101Ensure SCTP is disabled
3.5.102Ensure RDS is disabled
3.5.103Ensure TIPC is disabled

Section 4​

Rule IDTitle
4.2.1.1Ensure rsyslog Service is enabled
4.2.1.4Ensure rsyslog default file permissions configured
4.2.3Ensure rsyslog is installed

Section 5​

Rule IDTitle
5.1.1Ensure cron daemon is enabled and running
5.1.2Ensure permissions on /etc/crontab are configured
5.1.3Ensure permissions on /etc/cron.hourly are configured
5.1.4Ensure permissions on /etc/cron.daily are configured
5.1.5Ensure permissions on /etc/cron.weekly are configured
5.1.6Ensure permissions on /etc/cron.monthly are configured
5.1.7Ensure permissions on /etc/cron.d are configured
5.1.8Ensure cron is restricted to authorized users
5.1.9Ensure at is restricted to authorized users
5.2.100Ensure SSH KerberosAuthentication is enabled
5.2.101Ensure SSH X11 forwarding is disabled
5.3.1Ensure permissions on /etc/ssh/sshd_config are configured
5.3.4Ensure SSH Protocol is set to 2
5.3.6Ensure SSH LogLevel is appropriate
5.3.8Ensure SSH MaxAuthTries is set to 4 or less
5.3.9Ensure SSH IgnoreRhosts is enabled
5.3.10Ensure SSH HostbasedAuthentication is disabled
5.3.11Ensure SSH root login is disabled
5.3.12Ensure SSH PermitEmptyPasswords is disabled
5.3.13Ensure SSH PermitUserEnvironment is disabled
5.3.15Ensure only strong MAC algorithms are used
5.3.17Ensure SSH Idle Timeout Interval is configured
5.3.18Ensure SSH LoginGraceTime is set to one minute or less
5.3.19Ensure SSH warning banner is configured
5.4.1Ensure password creation requirements are configured
5.4.3Ensure password reuse is limited
5.4.4Ensure password hashing algorithm is SHA-512
5.5.1.1Ensure minimum days between password changes is configured
5.5.1.2Ensure password expiration is 365 days or less
5.5.1.3Ensure password expiration warning days is 7 or more
5.5.1.4Ensure inactive password lock is 30 days or less
5.5.3Ensure default group for the root account is GID 0
5.5.4Ensure default user umask is 027 or more restrictive
5.5.100Fetch system account names
5.5.101Ensure system accounts are non-login
5.5.102Ensure default group for the root account is root
5.6Ensure access to the su command is restricted

Section 6​

Rule IDTitle
6.2.12Ensure root PATH Integrity
6.2.100Ensure no legacy '+' entries exist in /etc/passwd
6.2.101Ensure no legacy '+' entries exist in /etc/shadow
6.2.102Ensure no legacy '+' entries exist in /etc/group