CIS_Amazon_Linux_2_Benchmarks

Ensure Password History Remember Is Configured
Profile Applicability:  • Level 1 Description:  Configuring password history remember enforces that users cannot reuse a specified number of their previous...
Fri, 30 May, 2025 at 12:34 AM
Ensure Password History Is Enforced for the Root User
Profile Applicability:  • Level 1 Description:  Enforcing password history for the root user prevents reuse of recently used passwords, enhancing the secur...
Fri, 30 May, 2025 at 12:38 AM
Ensure pam_pwhistory Includes use_authtok Option
Profile Applicability:  • Level 1 Description:  The use_authtok option in the pam_pwhistory module ensures that the module uses the password token obtained...
Fri, 30 May, 2025 at 12:42 AM
Ensure pam_unix Module Does Not Include Nullok Option
Profile Applicability:  • Level 1 Description:  The nullok option in the pam_unix module allows users to authenticate with empty (null) passwords. Removing...
Fri, 30 May, 2025 at 12:46 AM
Ensure pam_unix Module Does Not Include Nullok Option
Profile Applicability:  • Level 1 Description:  The nullok option in the pam_unix module allows users to authenticate with empty (null) passwords. Removing...
Fri, 30 May, 2025 at 12:55 AM
Ensure pam_unix Includes a Strong Password Hashing Algorithm
Profile Applicability:  • Level 1 Description:  The pam_unix module handles authentication using UNIX passwords. Configuring it to use a strong hashing alg...
Fri, 30 May, 2025 at 12:59 AM
Ensure pam_unix Includes use_authtok Option
Profile Applicability:  • Level 1 Description:  The use_authtok option in the pam_unix module ensures that the module uses the authentication token obtaine...
Fri, 30 May, 2025 at 1:04 AM
Ensure Strong Password Hashing Algorithm Is Configured
Profile Applicability:  • Level 1 Description:  Configuring a strong password hashing algorithm (e.g., SHA-512) strengthens password storage security by ma...
Fri, 30 May, 2025 at 1:11 AM
Ensure Password Expiration Is 365 Days or Less
Profile Applicability:  • Level 1 Description:  Setting a maximum password age of 365 days or less enforces regular password changes, reducing the risk of ...
Fri, 30 May, 2025 at 1:19 AM
Ensure sshd DisableForwarding Is Enabled
Profile Applicability:  • Level 1 Description:  The DisableForwarding option in the SSH daemon configuration disables all port forwarding (including TCP, X...
Fri, 30 May, 2025 at 2:19 AM