Skip to main content

Ubuntu 18.04 — Implemented CIS Rules

This page lists every CIS Benchmark rule ImageFactory automates for Ubuntu 18.04, exactly as implemented by the hardening tasks. See CIS Benchmarks for background on Level 1 vs. Level 2, and CIS Hardening Exceptions for rules that are intentionally not automated.

Level 1 (138 rules)​

Section 1 — Initial Setup​

Rule IDTitle
1.1.1.1Ensure mounting of cramfs filesystems is disabled
1.1.1.2Ensure mounting of freevxfs filesystems is disabled
1.1.1.3Ensure mounting of jffs2 filesystems is disabled
1.1.1.4Ensure mounting of hfs filesystems is disabled
1.1.1.5Ensure mounting of hfsplus filesystems is disabled
1.1.2.11.1.2.1 - 1.1.2.4 | Ensure /tmp is configured, Ensure noexec,nodev,nosuid option set on /tmp partition
1.1.2.21.1.2.1 - 1.1.2.4 | Ensure /tmp is configured, Ensure noexec,nodev,nosuid option set on /tmp partition
1.1.2.31.1.2.1 - 1.1.2.4 | Ensure /tmp is configured, Ensure noexec,nodev,nosuid option set on /tmp partition
1.1.2.41.1.2.1 - 1.1.2.4 | Ensure /tmp is configured, Ensure noexec,nodev,nosuid option set on /tmp partition
1.1.7.2Ensure nodev option set on /home partition
1.1.8.11.1.8.1 - 1.1.8.3 | Ensure nodev, nosuid, noexec option set on /dev/shm partition
1.1.8.21.1.8.1 - 1.1.8.3 | Ensure nodev, nosuid, noexec option set on /dev/shm partition
1.1.8.31.1.8.1 - 1.1.8.3 | Ensure nodev, nosuid, noexec option set on /dev/shm partition
1.1.10Disable USB Storage
1.2.1Ensure AIDE is installed
1.2.2Ensure filesystem integrity is regularly checked
1.4.1Ensure permissions on bootloader config are not overridden
1.4.2Ensure permissions on bootloader config are configured
1.5.2Ensure core dumps are restricted
1.5.3Ensure address space layout randomization (ASLR) is enabled
1.5.4Ensure prelink is disabled
1.5.5Ensure Automatic Error Reporting is not enabled
1.6.1.1Ensure AppArmor is installed
1.6.1.2Ensure AppArmor is enabled in the bootloader configuration
1.7.1Ensure message of the day is configured properly
1.7.2Ensure permissions on /etc/issue.net are configured
1.7.3Ensure permissions on /etc/issue are configured
1.7.4Ensure permissions on /etc/motd are configured
1.7.5Ensure remote login warning banner is configured properly
1.7.6Ensure local login warning banner is configured properly

Section 2 — Services​

Rule IDTitle
2.1.3.1Ensure systemd-timesyncd configured with authorized timeserver
2.1.3.2Ensure systemd-timesyncd is configured - GCP excluded
2.2.2avahi-daemon
2.2.3Ensure CUPS is not installed
2.2.4Ensure DHCP Server is not installed
2.2.5Ensure LDAP server is not installed
2.2.6Ensure NFS is not installed
2.2.7Ensure DNS Server is not installed
2.2.8Ensure FTP Server is not installed
2.2.9Ensure HTTP server is not installed
2.2.10Ensure IMAP and POP3 server are not installedd
2.2.11Ensure Samba is not installed
2.2.12Ensure HTTP Proxy Server is not installed
2.2.13Ensure SNMP Server is not installed
2.2.14Ensure NIS Server is not installed
2.2.16Ensure mail transfer agent is configured for local-only mode
2.2.17Ensure rsync service is not installed
2.3.1Ensure NIS Client is not installed
2.3.2Ensure rsh client is not installed
2.3.3Ensure talk client is not installed
2.3.4Ensure telnet client is not installed
2.3.5Ensure LDAP client is not installed
2.3.6Ensure RPC is not installed

Section 3 — Network Configuration​

Rule IDTitle
3.1.2Ensure wireless interfaces are disabled
3.3.1Ensure IP forwarding is disabled
3.3.2Ensure packet redirect sending is disabled
3.3.3Ensure bogus ICMP responses are ignored
3.3.4Ensure broadcast ICMP requests are ignored
3.3.5Ensure secure ICMP redirects are not accepted
3.3.6Ensure ICMP redirects are not accepted
3.3.7Ensure Reverse Path Filtering is enabled
3.3.8Ensure source routed packets are not accepted
3.3.9Ensure suspicious packets are logged
3.3.10Ensure TCP SYN Cookies is enabled
3.3.11Ensure IPv6 router advertisements are not accepted
3.5.1.1Ensure ufw is installed
3.5.1.2Ensure iptables-persistent is not installed with ufw
3.5.3.1.1Ensure iptables packages are installed
3.5.3.1.2Ensure nftables is not installed with iptables
3.5.3.2Configure IPv4 iptables | Create iptables directory
3.5.3.2.3Ensure iptables default deny firewall policy
3.5.3.3.3Ensure iptables default deny firewall policy

Section 4​

Rule IDTitle
4.1.1Ensure cron daemon is enabled and running
4.1.2Ensure permissions on /etc/crontab are configured
4.1.3Ensure permissions on /etc/cron.hourly are configured
4.1.4Ensure permissions on /etc/cron.daily are configured
4.1.5Ensure permissions on /etc/cron.weekly are configured
4.1.6Ensure permissions on /etc/cron.monthly are configured
4.1.7Ensure permissions on /etc/cron.d are configured
4.1.8Ensure cron is restricted to authorized users
4.1.9Ensure at is restricted to authorized users
4.2.1Ensure permissions on /etc/ssh/sshd_config are configured
4.2.2Ensure permissions on SSH private host key files are configured
4.2.3Ensure permissions on SSH public host key files are configured
4.2.4Ensure SSH access is limited
4.2.5Ensure SSH LogLevel is appropriate
4.2.6Ensure SSH PAM is enabled
4.2.7Ensure SSH root login is disabled
4.2.8Ensure SSH HostbasedAuthentication is disabled
4.2.9Ensure SSH PermitEmptyPasswords is disabled
4.2.10Ensure SSH PermitUserEnvironment is disabled
4.2.11Ensure SSH IgnoreRhosts is enabled
4.2.13Ensure only strong Ciphers are used
4.2.14Ensure only strong MAC algorithms are used
4.2.15Ensure only strong Key Exchange algorithms are used
4.2.17Ensure SSH warning banner is configured
4.2.18Ensure SSH MaxAuthTries is set to 4 or less
4.2.19Ensure SSH MaxStartups is configured
4.2.20Ensure SSH LoginGraceTime is set to one minute or less
4.2.21Ensure SSH MaxSessions is set to 10 or less
4.2.22Ensure SSH Idle Timeout Interval is configured
4.3.1Ensure sudo is installed
4.3.2Ensure sudo commands use pty
4.3.3Ensure sudo log file exists
4.4Ensure logrotate assigns appropriate permissions
4.4.1Ensure password creation requirements are configured
4.4.2Ensure lockout for failed password attempts is configured
4.4.3Ensure password reuse is limited
4.4.4Ensure strong password hashing algorithm is configured
4.5.1.1Ensure minimum days between password changes is configured
4.5.1.2Ensure password expiration is 365 days or less
4.5.1.3Ensure password expiration warning days is 7 or more
4.5.1.4Ensure inactive password lock is 30 days or less
4.5.2Ensure system accounts are secured
4.5.3Ensure default group for the root account is GID 0
4.5.4Ensure default user umask is 027 or more restrictive
4.5.5Ensure default user shell timeout is configured

Section 5​

Rule IDTitle
5.1.1.3Ensure journald is configured to compress large log files
5.1.2.1Ensure rsyslog is installed
5.1.2.2Ensure rsyslog Service is enabled
5.1.2.3Ensure journald is configured to send logs to rsyslog
5.1.2.4Ensure rsyslog default file permissions configured
5.1.3Ensure all logfiles have appropriate access configured
5.2.4.11Ensure cryptographic mechanisms are used to protect the integrity of audit tools
5.7Ensure access to the su command is restricted

Section 6​

Rule IDTitle
6.1.1Ensure permissions on /etc/passwd are configured
6.1.2Ensure permissions on /etc/passwd- are configured
6.1.3Ensure permissions on /etc/group are configured
6.1.4Ensure permissions on /etc/group- are configured
6.1.5Ensure permissions on /etc/shadow are configured
6.1.6Ensure permissions on /etc/shadow- are configured
6.1.7Ensure permissions on /etc/gshadow are configured
6.1.8Ensure permissions on /etc/gshadow- are configured
6.1.9Ensure permissions on /etc/opasswd are configured
6.1.10Ensure world writable files and directories are secured
6.1.11Ensure no unowned files or directories exist
6.1.12Ensure no ungrouped files or directories exist
6.2.6Ensure users' home directories permissions are 750 or more restrictive

Level 2 (34 rules)​

Section 1 — Initial Setup​

Rule IDTitle
1.1.1.7Ensure mounting of udf filesystems is disabled
1.6.4Ensure all AppArmor Profiles are enforcing

Section 3 — Network Configuration​

Rule IDTitle
3.2.1Ensure dccp kernel module is not available
3.2.2Ensure tipc kernel module is not available
3.2.3Ensure rds kernel module is not available
3.2.4Ensure sctp kernel module is not available

Section 4​

Rule IDTitle
4.2.7Ensure sshd DisableForwarding is enabled

Section 5​

Rule IDTitle
5.2.1.1Ensure auditd is installed
5.2.1.2Ensure auditd service is enabled
5.2.1.3Ensure auditing for processes that start prior to auditd is enabled
5.2.1.4Ensure audit_backlog_limit is sufficient
5.2.2.1Ensure audit log storage size is configured
5.2.2.2Ensure audit logs are not automatically deleted
5.2.2.3Ensure system is disabled when audit logs are full
5.2.3.1Ensure changes to system administration scope (sudoers) is collected
5.2.3.2Ensure actions as another user are always logged
5.2.3.3Ensure events that modify the sudo log file are collected
5.2.3.4Ensure events that modify date and time information are collected
5.2.3.5Ensure events that modify the system's network environment are collected
5.2.3.6Ensure use of privileged commands are collected
5.2.3.7Ensure unsuccessful file access attempts are collected
5.2.3.8Ensure events that modify user/group information are collected
5.2.3.9Ensure discretionary access control permission modification events are collected
5.2.3.10Ensure successful file system mounts are collected
5.2.3.11Ensure session initiation information is collected
5.2.3.12Ensure login and logout events are collected
5.2.3.13Ensure file deletion events by users are collected
5.2.3.14Ensure events that modify the system's Mandatory Access Controls are collected
5.2.3.155.2.3.15 - 5.2.3.17 | Ensure events that modify the system's Mandatory Access Controls are collected
5.2.3.165.2.3.15 - 5.2.3.17 | Ensure events that modify the system's Mandatory Access Controls are collected
5.2.3.175.2.3.15 - 5.2.3.17 | Ensure events that modify the system's Mandatory Access Controls are collected
5.2.3.18Ensure events that modify the system's Mandatory Access Controls are collected
5.2.3.19Ensure kernel module loading unloading and modification is collected
5.2.3.20Ensure the audit configuration is immutable