CIS_Amazon_Linux_2_Benchmarks

Ensure Password Expiration Warning Days Is 7 or More
Profile Applicability:  • Level 1 Description:  Configuring a password expiration warning period of 7 or more days alerts users in advance before their pas...
Fri, 30 May, 2025 at 2:30 AM
Ensure Inactive Password Lock Is 30 Days or Less
Profile Applicability:  • Level 1 Description:  The inactive password lock setting defines the number of days after a password expires before the account i...
Fri, 30 May, 2025 at 2:37 AM
Ensure All Users' Last Password Change Date Is in the Past
Profile Applicability:  • Level 1 Description:  Verifying that all users have a recorded last password change date in the past ensures that no user account...
Fri, 30 May, 2025 at 2:41 AM
Ensure Default Group for the Root Account Is GID 0
Profile Applicability:  • Level 1 Description:  The root account should have a default group with Group ID (GID) 0, typically the root group. Ensuring the ...
Fri, 30 May, 2025 at 2:46 AM
Ensure Root User umask Is Configured
Profile Applicability:  • Level 1 Description:  The umask setting determines the default file permission bits for newly created files and directories. Conf...
Fri, 30 May, 2025 at 2:50 AM
Ensure System Accounts Are Secured
Profile Applicability:  • Level 2 Description:  System accounts are accounts used by services and system processes. Securing these accounts by disabling lo...
Fri, 30 May, 2025 at 2:54 AM
Ensure Root Password Is Set
Profile Applicability:  • Level 1 Description:  Ensuring that the root account has a password set prevents unauthorized access to the highest-privilege acc...
Fri, 30 May, 2025 at 3:05 AM
Ensure nologin Is Not Listed in /etc/shells
Profile Applicability:  • Level 2 Description:  The /etc/shells file lists valid login shells on the system. Including /sbin/nologin or similar non-interac...
Fri, 30 May, 2025 at 3:09 AM
Ensure Audit Package Is Installed
Profile Applicability: Level 2 Description:  The audit package (auditd) provides the user-space component to the Linux Audit subsystem, allowing the system...
Fri, 30 May, 2025 at 3:13 AM
Ensure Default User Shell Timeout Is Configured
Profile Applicability:  • Level 1 Description:  Configuring a shell timeout automatically logs out users after a period of inactivity. This reduces the ris...
Fri, 30 May, 2025 at 3:13 AM