CIS_Amazon_Linux_2_Benchmarks

Ensure sshd MaxAuthTries Is Configured
Profile Applicability:  • Level 1 Description:  The MaxAuthTries option in the SSH daemon (sshd) configuration limits the number of authentication attempts...
Sun, 1 Jun, 2025 at 8:53 PM
Ensure sshd MaxSessions Is Configured
Profile Applicability:  • Level 1 Description:  The MaxSessions option in the SSH daemon (sshd) configuration limits the number of open sessions permitted ...
Sun, 1 Jun, 2025 at 9:08 PM
Ensure sshd MaxStartups Is Configured
Profile Applicability:  • Level 1 Description:  The MaxStartups option in the SSH daemon (sshd) configuration limits the maximum number of concurrent unaut...
Sun, 1 Jun, 2025 at 9:18 PM
Ensure journald Is Configured to Compress Large Log Files
Profile Applicability:  • Level 1 Description:  Compressing large log files in systemd’s journal (journald) reduces disk space usage by minimizing the stor...
Mon, 2 Jun, 2025 at 12:40 AM
Ensure Latest Version of PAM Is Installed
Profile Applicability:  • Level 1 Description:  Pluggable Authentication Modules (PAM) provide a flexible authentication framework for Linux systems. Insta...
Mon, 2 Jun, 2025 at 12:56 AM
Ensure libpwquality Is Installed
Profile Applicability:  • Level 1 Description: The libpwquality library provides password quality checking and enforcement for Linux systems. Installing li...
Mon, 2 Jun, 2025 at 1:01 AM
Ensure pam_faillock Module Is Enabled
Profile Applicability:  • Level 1 Description:  The pam_faillock module provides authentication failure tracking and account locking functionality. Enablin...
Mon, 2 Jun, 2025 at 1:06 AM
Ensure Password Failed Attempts Lockout Is Configured
Profile Applicability:  • Level 1 Description:  Configuring account lockout after a specified number of failed password attempts helps prevent brute-force ...
Mon, 2 Jun, 2025 at 1:10 AM
Ensure Password Unlock Time Is Configured
Profile Applicability:  • Level 1 Description:  Configuring the password unlock time determines how long a user account remains locked after exceeding the ...
Mon, 2 Jun, 2025 at 1:40 AM
Ensure Password Failed Attempts Lockout Includes Root Account
Profile Applicability:  • Level 1 Description:  Configuring the password failed attempts lockout to include the root account ensures that even the root use...
Mon, 2 Jun, 2025 at 1:45 AM