Skip to main content

Ubuntu 24.04 — Implemented CIS Rules

This page lists every CIS Benchmark rule ImageFactory automates for Ubuntu 24.04, exactly as implemented by the hardening tasks. See CIS Benchmarks for background on Level 1 vs. Level 2, and CIS Hardening Exceptions for rules that are intentionally not automated.

Level 1 (150 rules)​

Section 1 — Initial Setup​

Rule IDTitle
1.1.1.1Ensure mounting of cramfs filesystems is disabled
1.1.1.9Ensure usb-storage kernel module is not available
1.1.1.11Ensure firewire-core kernel module is not available
1.1.2.1Ensure /tmp is a separate partition
1.1.2.2Configure /dev/shm
1.1.2.3.2Ensure nodev option set on /home partition
1.3.1.1Ensure AppArmor is installed
1.3.1.2Ensure AppArmor is enabled in the bootloader configuration
1.3.1.3Ensure all AppArmor Profiles are in enforce or complain mode
1.4.2Ensure access to bootloader config is configured
1.5.1Ensure address space layout randomization is enabled
1.5.3Ensure core dumps are restricted
1.5.5Ensure kernel.dmesg_restrict is configured
1.5.7Ensure Automatic Error Reporting is not enabled
1.5.10Ensure systemd-coredump ProcessSizeMax is configured
1.5.11Ensure systemd-coredump Storage is configured
1.6.1Ensure message of the day is configured properly
1.6.2Ensure local login warning banner is configured properly
1.6.3Ensure remote login warning banner is configured properly
1.6.4Ensure access on /etc/motd are configured
1.6.5Ensure access on /etc/issue are configured
1.6.6Ensure access on /etc/issue.net are configured
1.6.7Ensure pam_motd is configured

Section 2 — Services​

Rule IDTitle
2.1.2avahi-daemon
2.1.3Ensure dhcp server services are not in use
2.1.4Ensure dns server services are not in use
2.1.6Ensure ftp server services are not in use
2.1.7Ensure ldap server services are not in use
2.1.8Ensure message access server services are not in use
2.1.10Ensure nis server services are not in use
2.1.11Ensure print server services are not in use
2.1.12Ensure rpcbind services are not in use
2.1.14Ensure samba file server services are not in use
2.1.15Ensure snmp services are not in use
2.1.16Ensure rsync service is not installed
2.1.17Ensure web proxy server services are not in use
2.1.18Ensure web server services are not in use
2.1.21Ensure mail transfer agent is configured for local-only mode
2.2.1Ensure NIS Client is not installed
2.2.2Ensure rsh client is not installed
2.2.3Ensure talk client is not installed
2.2.4Ensure telnet client is not installed
2.2.5Ensure LDAP client is not installed
2.2.6Ensure ftp client is not installed
2.3.1.1Ensure a single time synchronization daemon is in use
2.3.3.1Ensure chrony is configured
2.4.1Ensure cron daemon is enabled and running
2.4.1.2Ensure permissions on /etc/crontab are configured
2.4.1.3Ensure permissions on /etc/cron.hourly are configured
2.4.1.4Ensure permissions on /etc/cron.daily are configured
2.4.1.5Ensure permissions on /etc/cron.weekly are configured
2.4.1.6Ensure permissions on /etc/cron.monthly are configured
2.4.1.7Ensure permissions on /etc/cron.yearly are configured
2.4.1.8Ensure crontab is restricted to authorized users
2.4.2.1Ensure at is restricted to authorized users

Section 3 — Network Configuration​

Rule IDTitle
3.1.2Ensure wireless interfaces are disabled
3.2.1Ensure atm kernel module is not available
3.2.2Ensure can kernel module is not available
3.3.1Ensure IP forwarding is disabled
3.3.2Ensure packet redirect sending is disabled
3.3.3Ensure bogus icmp responses are ignored
3.3.4Ensure broadcast icmp requests are ignored
3.3.5Ensure icmp redirects are not accepted
3.3.6Ensure secure icmp redirects are not accepted
3.3.7Ensure Reverse Path Filtering is enabled
3.3.8Ensure source routed packets are not accepted
3.3.9Ensure suspicious packets are logged
3.3.10Ensure TCP SYN Cookies is enabled
3.3.11Ensure IPv6 router advertisements are not accepted

Section 4​

Rule IDTitle
4.2Remove ufw
4.3Ensure nftables is removed
4.4.1Configure iptables software
4.4.2Configure IPv4 iptables
4.4.3Configure IPv6 iptables

Section 5​

Rule IDTitle
5.1.1Ensure permissions on /etc/ssh/sshd_config are configured
5.1.2Ensure permissions on SSH private host key files are configured
5.1.3Ensure permissions on SSH public host key files are configured
5.1.4Ensure sshd access is configured
5.1.5Ensure sshd Banner is configured
5.1.6Ensure sshd Ciphers are configured
5.1.7Ensure sshd ClientAliveInterval and ClientAliveCountMax are configured
5.1.10Ensure sshd HostbasedAuthentication is disabled
5.1.11Ensure sshd IgnoreRhosts is enabled
5.1.12Ensure sshd KexAlgorithms is configured
5.1.13Ensure sshd LoginGraceTime is configured
5.1.14Ensure sshd LogLevel is configured
5.1.15Ensure sshd MACs are configured
5.1.16Ensure sshd MaxAuthTries is configured
5.1.18Ensure sshd MaxStartups is configured
5.1.19Ensure sshd PermitEmptyPasswords is disabled
5.1.20Ensure sshd PermitRootLogin is disabled
5.1.21Ensure sshd PermitUserEnvironment is disabled
5.1.22Ensure sshd UsePAM is enabled
5.2.1Ensure sudo is installed
5.2.2Ensure sudo commands use pty
5.2.3Ensure sudo log file exists
5.2.7Ensure access to the su command is restricted
5.3.1.3Ensure libpam-pwquality is installed
5.3.2.2Ensure pam_faillock module is enabled
5.3.3.1.1Ensure password failed attempts lockout is configured
5.3.3.1.2Ensure password unlock time is configured
5.3.3.2.1Ensure password creation requirements are configured
5.3.3.2.2Ensure lockout for failed password attempts is configured
5.3.3.2.3Ensure password hashing algorithm is SHA-512
5.3.3.2.4Ensure password reuse is limited
5.3.3.3.1Ensure password history remember is configured
5.3.3.3.2Ensure password history is enforced for the root user
5.3.3.3.3Ensure pam_pwhistory includes use_authtok
5.3.3.4.1Ensure pam_unix does not include nullok
5.4.2.4Ensure root password is set
5.4.2.5Ensure root path integrity
5.4.3.2Ensure default user shell timeout is configured
5.4.3.3Ensure default user umask is configured
5.4.4Ensure password hashing algorithm is up to date with the latest standards
5.5.1.1Ensure minimum days between password changes is configured (set PASS_MIN_DAYS {{ password['expiration']['min_days'] }} in /etc/login.defs) | OS independent
5.5.1.2Ensure password expiration is 365 days or less
5.5.1.3Ensure password expiration warning days is 7 or more
5.5.1.4Ensure inactive password lock is 30 days or less
5.5.2Ensure system accounts are secured
5.5.3Ensure default group for the root account is GID 0

Section 6​

Rule IDTitle
6.1.2.1.1Ensure systemd-journal-remote is installed
6.1.2.1.3Ensure systemd-journal-upload is enabled and active
6.1.2.2Ensure journald ForwardToSyslog is disabled
6.1.2.3Ensure journald Compress is configured
6.1.2.4Ensure journald Storage is configured
6.1.3.1Ensure rsyslog is installed
6.1.3.2Ensure rsyslog Service is enabled
6.1.3.4Ensure rsyslog default file permissions configured
6.1.4.1Ensure access to all logfiles has been configured
6.2.1.1Ensure audit log files are mode 0640 or less permissive
6.2.1.2Ensure only authorized users own audit log files
6.2.1.3Ensure only authorized groups are assigned ownership of audit log files
6.2.1.4Ensure the audit log directory is 0750 or more restrictive
6.2.1.5Ensure audit configuration files are 640 or more restrictive
6.2.1.6Ensure audit configuration files are owned by root
6.2.1.7Ensure audit configuration files belong to group root
6.2.1.8Ensure audit tools are 755 or more restrictive
6.2.1.9Ensure audit tools are owned by root
6.2.1.10Ensure audit tools belong to group root
6.2.1.11Ensure cryptographic mechanisms are used to protect the integrity of audit tools
6.3.1Ensure AIDE is installed
6.3.2Ensure filesystem integrity is regularly checked

Section 7​

Rule IDTitle
7.1.2Ensure permissions on /etc/passwd- are configured
7.1.3Ensure permissions on /etc/group are configured
7.1.4Ensure permissions on /etc/group- are configured
7.1.5Ensure permissions on /etc/shadow are configured
7.1.6Ensure permissions on /etc/shadow- are configured
7.1.7Ensure permissions on /etc/gshadow are configured
7.1.8Ensure permissions on /etc/gshadow- are configured
7.2.9Ensure users' home directories permissions are 750 or more restrictive

Level 2 (41 rules)​

Section 1 — Initial Setup​

Rule IDTitle
1.1.1.6Ensure overlayfs kernel module is not available
1.1.1.7Ensure squashfs kernel module is not available
1.1.1.8Ensure udf kernel module is not available
1.2.1.5Ensure weak dependencies are configured
1.3.1.2Ensure AppArmor is enabled in the bootloader configuration
1.3.1.3Ensure all AppArmor Profiles are enforcing
1.3.1.4Ensure apparmor_restrict_unprivileged_unconfined is enabled

Section 3 — Network Configuration​

Rule IDTitle
3.2.1Ensure dccp kernel module is not available
3.2.2Ensure tipc kernel module is not available
3.2.3Ensure rds kernel module is not available
3.2.4Ensure sctp kernel module is not available

Section 5​

Rule IDTitle
5.1.8Ensure sshd DisableForwarding is enabled
5.3.3.1.3Ensure password failed attempts lockout includes root account

Section 6​

Rule IDTitle
6.1.2.8Ensure rsyslog-gnutls is installed
6.2.1.1Ensure auditd packages are installed
6.2.1.2Ensure auditd service is enabled and active
6.2.1.4Ensure audit_backlog_limit is sufficient
6.2.2.1Ensure audit log storage size is configured
6.2.2.2Ensure audit logs are not automatically deleted
6.2.2.3Ensure system is disabled when audit logs are full
6.2.2.4Ensure system warns when audit logs are low on space
6.2.3.1Ensure changes to system administration scope (sudoers) is collected
6.2.3.2Ensure actions as another user are always logged
6.2.3.3Ensure events that modify the sudo log file are collected
6.2.3.4Ensure events that modify date and time information are collected
6.2.3.5Ensure events that modify the system's network environment are collected
6.2.3.6Ensure use of privileged commands are collected
6.2.3.7Ensure unsuccessful file access attempts are collected
6.2.3.8Ensure events that modify user/group information are collected
6.2.3.9Ensure discretionary access control permission modification events are collected
6.2.3.10Ensure successful file system mounts are collected
6.2.3.11Ensure session initiation information is collected
6.2.3.12Ensure login and logout events are collected
6.2.3.13Ensure file deletion events by users are collected
6.2.3.14Ensure events that modify the system's Mandatory Access Controls are collected
6.2.3.156.2.3.15 - 6.2.3.17 | Ensure successful and unsuccessful attempts to use the chcon command are recorded
6.2.3.166.2.3.15 - 6.2.3.17 | Ensure successful and unsuccessful attempts to use the chcon command are recorded
6.2.3.176.2.3.15 - 6.2.3.17 | Ensure successful and unsuccessful attempts to use the chcon command are recorded
6.2.3.18Ensure successful and unsuccessful attempts to use the usermod command are recorded
6.2.3.19Ensure kernel module loading unloading and modification is collected
6.2.3.20Ensure the audit configuration is immutable