CIS_Amazon_Linux_2_Benchmarks

Ensure Audit Logging of Login and Logout Events
Profile Applicability:  • Level 2 Description:  Logging login and logout events is essential to monitor user access, track session activity, and detect una...
Wed, 21 May, 2025 at 1:26 AM
Disable hfsplus Kernel Module to Strengthen Linux Kernel Security
Profile Applicability:  • Level 1 Description:  The hfsplus kernel module provides support for the HFS Plus filesystem, used primarily by newer Apple Macin...
Wed, 21 May, 2025 at 1:27 AM
Disable jffs2 Kernel Module to Reduce Linux Attack Surface
Profile Applicability:  • Level 1 Description:  The jffs2 kernel module provides support for the Journaling Flash File System version 2 (JFFS2), used mainl...
Wed, 21 May, 2025 at 1:31 AM
Ensure Audit Logging of File Deletion Events by Users
Profile Applicability:  • Level 2 Description:  Tracking file deletion events provides visibility into potential unauthorized removal of files, which could...
Wed, 21 May, 2025 at 1:33 AM
Disable squashfs Kernel Module to Harden Linux Kernel
Profile Applicability:  • Level 2 Description:  The squashfs kernel module provides support for the SquashFS compressed read-only filesystem. SquashFS is o...
Wed, 21 May, 2025 at 1:36 AM
Ensure Audit Logging of Mandatory Access Control (MAC) Modification Events
Profile Applicability:  • Level 2 Description:  Mandatory Access Controls (MAC) such as SELinux or AppArmor enforce security policies restricting access to...
Wed, 21 May, 2025 at 1:40 AM
Disable udf Kernel Module to Harden Linux Kernel Security
Profile Applicability:  • Level 2 Description: The udf kernel module provides support for the Universal Disk Format (UDF) filesystem, commonly used on opti...
Wed, 21 May, 2025 at 1:41 AM
Disable usb-storage Kernel Module to Prevent Unauthorized USB Device Access
Profile Applicability:  • Level 1 Description:  The usb-storage kernel module provides support for USB mass storage devices, allowing the system to access ...
Wed, 21 May, 2025 at 1:46 AM
Ensure /tmp Directory is Mounted on a Separate Partition
Profile Applicability:  • Level 1 Description:  The /tmp directory is used for temporary files by system and user applications. Mounting /tmp on a separate...
Wed, 21 May, 2025 at 1:55 AM
Ensure nodev Mount Option is Set on /tmp Partition to Enhance Security
Profile Applicability:  • Level 1 Description:  The nodev mount option prevents device files from being interpreted on the mounted filesystem. Applying thi...
Wed, 21 May, 2025 at 2:18 AM