Skip to main content

Ubuntu 20.04 — Implemented CIS Rules

This page lists every CIS Benchmark rule ImageFactory automates for Ubuntu 20.04, exactly as implemented by the hardening tasks. See CIS Benchmarks for background on Level 1 vs. Level 2, and CIS Hardening Exceptions for rules that are intentionally not automated.

Level 1 (153 rules)​

Section 1 — Initial Setup​

Rule IDTitle
1.1.1.1Ensure mounting of cramfs filesystems is disabled
1.1.1.2Ensure mounting of freevxfs filesystems is disabled
1.1.1.3Ensure mounting of jffs2 filesystems is disabled
1.1.1.4Ensure mounting of hfs filesystems is disabled
1.1.1.5Ensure mounting of hfsplus filesystems is disabled
1.1.21.1.2 - 1.1.5 | Ensure /tmp is configured, Ensure noexec,nodev,nosuid option set on /tmp partition
1.1.31.1.2 - 1.1.5 | Ensure /tmp is configured, Ensure noexec,nodev,nosuid option set on /tmp partition
1.1.41.1.2 - 1.1.5 | Ensure /tmp is configured, Ensure noexec,nodev,nosuid option set on /tmp partition
1.1.51.1.2 - 1.1.5 | Ensure /tmp is configured, Ensure noexec,nodev,nosuid option set on /tmp partition
1.1.71.1.7 - 1.1.9 | Ensure nodev, nosuid, noexec option set on /dev/shm partition
1.1.81.1.7 - 1.1.9 | Ensure nodev, nosuid, noexec option set on /dev/shm partition
1.1.91.1.7 - 1.1.9 | Ensure nodev, nosuid, noexec option set on /dev/shm partition
1.1.10Disable USB Storage
1.1.18Ensure /home partition includes the nodev option
1.1.22Ensure sticky bit is set on all world-writable directories
1.1.24Disable USB Storage
1.3.1Ensure AIDE is installed
1.3.2Ensure filesystem integrity is regularly checked
1.4Check if /boot/grub/grub.cfg
1.4.2Ensure permissions on bootloader config are configured
1.5.1Ensure prelink is not installed
1.5.2Ensure address space layout randomization (ASLR) is enabled
1.5.3Ensure core dumps are restricted
1.5.4Ensure Automatic Error Reporting is not enabled
1.6.1.1Ensure AppArmor is installed
1.6.1.2Ensure AppArmor is enabled in the bootloader configuration
1.6.3Ensure all AppArmor Profiles are in enforce or complain mode
1.7.1Ensure message of the day is configured properly
1.7.2Ensure local login warning banner is configured properly
1.7.3Ensure remote login warning banner is configured properly
1.7.4Ensure permissions on /etc/motd are configured
1.7.5Ensure permissions on /etc/issue are configured
1.7.6Ensure permissions on /etc/issue.net are configured

Section 2 — Services​

Rule IDTitle
2.1.1.1Ensure time synchronization is in use | DEB family
2.1.1.3Ensure chrony is configured
2.1.2Ensure X Window System is not installed
2.1.3avahi-daemon
2.1.4Ensure CUPS is not installed
2.1.5Ensure DHCP Server is not installed
2.1.6Ensure LDAP server is not installed
2.1.7Ensure NFS is not installed
2.1.8Ensure DNS Server is not installed
2.1.9Ensure FTP Server is not installed
2.1.10Ensure HTTP server is not installed
2.1.11Ensure IMAP and POP3 server are not installedd
2.1.12Ensure Samba is not installed
2.1.13Ensure HTTP Proxy Server is not installed
2.1.14Ensure SNMP Server is not installed
2.1.15Ensure mail transfer agent is configured for local-only mode
2.1.16Ensure rsync service is not installed
2.1.17Ensure NIS Server is not installed
2.2.1Ensure NIS Client is not installed
2.2.2Ensure rsh client is not installed
2.2.3Ensure talk client is not installed
2.2.4Ensure telnet client is not installed
2.2.5Ensure LDAP client is not installed
2.2.6Ensure RPC is not installed
2.2.7Ensure ftp client is not installed

Section 3 — Network Configuration​

Rule IDTitle
3.1.2Ensure wireless interfaces are disabled
3.2.1Ensure packet redirect sending is disabled
3.2.2Ensure IP forwarding is disabled
3.3.1Ensure source routed packets are not accepted
3.3.2Ensure ICMP redirects are not accepted
3.3.3Ensure secure ICMP redirects are not accepted
3.3.4Ensure suspicious packets are logged
3.3.5Ensure broadcast ICMP requests are ignored
3.3.6Ensure bogus ICMP responses are ignored
3.3.7Ensure Reverse Path Filtering is enabled
3.3.8Ensure TCP SYN Cookies is enabled
3.3.9Ensure IPv6 router advertisements are not accepted
3.4.1.1Ensure ufw is installed
3.4.1.2Ensure iptables-persistent is not installed with ufw
3.5.3.1.1Ensure iptables packages are installed
3.5.3.1.2Ensure nftables is not installed with iptables
3.5.3.2Configure IPv4 iptables | Create iptables directory
3.5.3.2.3Ensure iptables default deny firewall policy
3.5.3.3.3Ensure iptables default deny firewall policy

Section 4​

Rule IDTitle
4.1.1Ensure cron daemon is enabled and running
4.1.2Ensure permissions on /etc/crontab are configured
4.1.3Ensure permissions on /etc/cron.hourly are configured
4.1.4Ensure permissions on /etc/cron.daily are configured
4.1.5Ensure permissions on /etc/cron.weekly are configured
4.1.6Ensure permissions on /etc/cron.monthly are configured
4.1.7Ensure permissions on /etc/cron.d are configured
4.1.84.1.8 - 4.1.9 | Ensure at/cron is restricted to authorized users
4.1.94.1.8 - 4.1.9 | Ensure at/cron is restricted to authorized users
4.2.1Ensure permissions on /etc/ssh/sshd_config are configured
4.2.2Ensure permissions on SSH private host key files are configured
4.2.3Ensure permissions on SSH public host key files are configured
4.2.4Ensure SSH access is limited
4.2.5Ensure SSH LogLevel is appropriate
4.2.6Ensure SSH PAM is enabled
4.2.7Ensure SSH root login is disabled
4.2.8Ensure SSH HostbasedAuthentication is disabled
4.2.9Ensure SSH PermitEmptyPasswords is disabled
4.2.10Ensure SSH PermitUserEnvironment is disabled
4.2.11Ensure SSH IgnoreRhosts is enabled
4.2.13Ensure only strong Ciphers are used
4.2.14Ensure only strong MAC algorithms are used
4.2.15Ensure only strong Key Exchange algorithms are used
4.2.17Ensure SSH warning banner is configured
4.2.18Ensure SSH MaxAuthTries is set to 4 or less
4.2.19Ensure SSH MaxStartups is configured
4.2.20Ensure SSH LoginGraceTime is set to one minute or less
4.2.21Ensure SSH MaxSessions is set to 10 or less
4.2.22Ensure SSH Idle Timeout Interval is configured
4.3.1Ensure sudo is installed
4.3.2Ensure sudo commands use pty
4.3.3Ensure sudo log file exists
4.4Ensure logrotate assigns appropriate permissions
4.4.1Ensure password creation requirements are configured
4.4.2Ensure lockout for failed password attempts is configured
4.4.3Ensure password reuse is limited
4.4.4Ensure strong password hashing algorithm is configured
4.5.1.1Ensure minimum days between password changes is configured
4.5.1.2Ensure password expiration is 365 days or less
4.5.1.3Ensure password expiration warning days is 7 or more
4.5.1.4Ensure inactive password lock is 30 days or less
4.5.2Ensure system accounts are secured
4.5.3Ensure default group for the root account is GID 0
4.5.4Ensure default user umask is 027 or more restrictive
4.5.5Ensure default user shell timeout is configured

Section 5​

Rule IDTitle
5.1.1.3Ensure journald is configured to compress large log files
5.1.2.1Ensure rsyslog is installed
5.1.2.2Ensure rsyslog Service is enabled
5.1.2.3Ensure journald is configured to send logs to rsyslog
5.1.2.4Ensure rsyslog default file permissions configured
5.1.3Ensure all logfiles have appropriate access configured
5.2.4.11Ensure cryptographic mechanisms are used to protect the integrity of audit tools
5.3.2.2Ensure pam_faillock module is enabled
5.3.3.1.1Ensure password failed attempts lockout is configured
5.3.3.1.2Ensure password unlock time is configured
5.3.3.2.1Ensure password creation requirements are configured
5.3.3.2.2Ensure lockout for failed password attempts is configured
5.3.3.2.3Ensure password hashing algorithm is SHA-512
5.3.3.2.4Ensure password reuse is limited
5.3.3.3.1Ensure password history remember is configured
5.3.3.3.2Ensure password history is enforced for the root user
5.3.3.3.3Ensure pam_pwhistory includes use_authtok
5.3.3.4.1Ensure pam_unix does not include nullok
5.7Ensure access to the su command is restricted

Section 6​

Rule IDTitle
6.1.1Ensure permissions on /etc/passwd are configured
6.1.2Ensure permissions on /etc/passwd- are configured
6.1.3Ensure permissions on /etc/group are configured
6.1.4Ensure permissions on /etc/group- are configured
6.1.5Ensure permissions on /etc/shadow are configured
6.1.6Ensure permissions on /etc/shadow- are configured
6.1.7Ensure permissions on /etc/gshadow are configured
6.1.8Ensure permissions on /etc/gshadow- are configured
6.1.10Ensure permissions on /etc/opasswd are configured
6.1.11Ensure no unowned files or directories exist
6.1.12Ensure no ungrouped files or directories exist
6.2.6Ensure users' home directories permissions are 750 or more restrictive

Level 2 (38 rules)​

Section 1 — Initial Setup​

Rule IDTitle
1.1.1.6Ensure overlay kernel module is not available
1.1.1.7Ensure mounting of udf filesystems is disabled
1.6.1.4Ensure all AppArmor Profiles are enforcing

Section 3 — Network Configuration​

Rule IDTitle
3.1.4Ensure DCCP is disabled
3.1.5Ensure SCTP is disabled
3.1.6Ensure RDS is disabled
3.1.7Ensure TIPC is disabled

Section 4​

Rule IDTitle
4.2.12Ensure SSH X11 forwarding is disabled
4.2.16Ensure SSH AllowTcpForwarding is disabled

Section 5​

Rule IDTitle
5.1.8Ensure sshd DisableForwarding is enabled
5.2.1.1Ensure auditd is installed
5.2.1.2Ensure auditd service is enabled
5.2.1.3Ensure AppArmor is enabled in the bootloader configuration
5.2.1.4Ensure audit_backlog_limit is sufficient
5.2.2.1Ensure audit log storage size is configured
5.2.2.2Ensure audit logs are not automatically deleted
5.2.2.3Ensure system is disabled when audit logs are full
5.2.3.1Ensure changes to system administration scope (sudoers) is collected
5.2.3.2Ensure actions as another user are always logged
5.2.3.3Ensure events that modify the sudo log file are collected
5.2.3.4Ensure events that modify date and time information are collected
5.2.3.5Ensure events that modify the system's network environment are collected
5.2.3.6Ensure use of privileged commands are collected
5.2.3.7Ensure unsuccessful file access attempts are collected
5.2.3.8Ensure events that modify user/group information are collected
5.2.3.9Ensure discretionary access control permission modification events are collected
5.2.3.10Ensure successful file system mounts are collected
5.2.3.11Ensure session initiation information is collected
5.2.3.12Ensure login and logout events are collected
5.2.3.13Ensure file deletion events by users are collected
5.2.3.14Ensure events that modify the system's Mandatory Access Controls are collected
5.2.3.155.2.3.15 - 5.2.3.17 | Ensure events that modify the system's Mandatory Access Controls are collected
5.2.3.165.2.3.15 - 5.2.3.17 | Ensure events that modify the system's Mandatory Access Controls are collected
5.2.3.175.2.3.15 - 5.2.3.17 | Ensure events that modify the system's Mandatory Access Controls are collected
5.2.3.18Ensure events that modify the system's Mandatory Access Controls are collected
5.2.3.19Ensure kernel module loading unloading and modification is collected
5.2.3.20Ensure the audit configuration is immutable
5.3.3.1.3Ensure password failed attempts lockout includes root account