CIS_Amazon_Linux_2_Benchmarks

Ensure Only Authorized Groups Own Audit Log Files
Profile Applicability: Level 2 Description:  Audit log files contain sensitive information about system activity and security events. Ensuring that only au...
Fri, 30 May, 2025 at 6:24 AM
Ensure All Logfiles Have Appropriate Access Permissions Configured
Profile Applicability: Level 1 Description:  Logfiles contain sensitive system and security information. Proper access permissions on logfiles prevent unau...
Fri, 30 May, 2025 at 6:49 AM
Ensure Logrotate Is Properly Configured
Profile Applicability: Level 1 Description:  logrotate is a utility designed to manage the automatic rotation, compression, removal, and mailing of log fil...
Fri, 30 May, 2025 at 7:02 AM
Ensure sshd KexAlgorithms Are Configured
Profile Applicability:  • Level 1 Description:  The KexAlgorithms option in the SSH daemon (sshd) configuration specifies the key exchange algorithms used ...
Fri, 30 May, 2025 at 7:02 AM
Ensure journald Log Rotation Is Configured Per Site Policy
Profile Applicability: Level 1 Description:  The systemd journal (journald) collects and stores log data. Proper configuration of journald log rotation ens...
Fri, 30 May, 2025 at 7:11 AM
Ensure sshd LoginGraceTime Is Configured
Profile Applicability:  • Level 1 Description: The LoginGraceTime option in the SSH daemon (sshd) configuration specifies the time allowed for a user to su...
Fri, 30 May, 2025 at 7:51 AM
Ensure journald Is Not Configured to Forward Logs to rsyslog
Profile Applicability: Level 1 Description:  The systemd journal (journald) can forward log messages to the traditional syslog daemon (rsyslog). Disabling ...
Fri, 30 May, 2025 at 7:56 AM
Ensure journald Is Configured to Write Logfiles to Persistent Disk
Profile Applicability: Level 1 Description: By default, systemd’s journal (journald) stores logs in volatile memory, which means logs are lost on reboot. C...
Fri, 30 May, 2025 at 8:18 AM
Ensure sshd LogLevel Is Configured
Profile Applicability:  • Level 1 Description Setting an appropriate log level ensures that sufficient information is logged for auditing and troubleshooti...
Sun, 1 Jun, 2025 at 8:15 PM
Ensure sshd MACs Are Configured
Profile Applicability:  • Level 1 Description: The MACs option in the SSH daemon (sshd) configuration specifies the Message Authentication Codes used to v...
Sun, 1 Jun, 2025 at 8:27 PM