CIS_Amazon_Linux_2_Benchmarks

Ensure Core Dump Backtraces Are Disabled to Prevent Sensitive Data Exposure
Profile Applicability:  • Level 1 Description: Core dumps capture the memory state of a process when it crashes, including backtraces. Backtraces in core d...
Mon, 26 May, 2025 at 12:58 AM
Ensure Core Dump Storage is Disabled to Protect Sensitive Information
Profile Applicability:  • Level 1 Description:  Core dumps store the memory state of a process after a crash, which can contain sensitive information such ...
Mon, 26 May, 2025 at 1:05 AM
Ensure SELinux is Installed to Enforce Mandatory Access Control
Profile Applicability:  • Level 1 Description:  Security-Enhanced Linux (SELinux) provides a robust Mandatory Access Control (MAC) framework for Linux syst...
Mon, 26 May, 2025 at 1:11 AM
Ensure SELinux is Enabled in Bootloader Configuration
Profile Applicability:  • Level 1 Description:  SELinux can be disabled at boot time through bootloader parameters. Ensuring SELinux is not disabled in the...
Mon, 26 May, 2025 at 2:15 AM
Ensure SELinux Policy is Properly Configured and Enforced
Profile Applicability:  • Level 1 Description:  SELinux enforces mandatory access control policies on Linux systems to restrict programs’ capabilities and ...
Mon, 26 May, 2025 at 2:20 AM
Ensure SELinux Mode is Enabled and Not Disabled
Profile Applicability:  • Level 1 Description:  SELinux provides mandatory access control to enhance system security. Disabling SELinux mode reduces protec...
Mon, 26 May, 2025 at 2:24 AM
Ensure SELinux Mode is Set to Enforcing
Profile Applicability:  • Level 2 Description:  SELinux enforcing mode actively enforces the defined security policies, denying unauthorized actions and lo...
Mon, 26 May, 2025 at 2:30 AM
Ensure No Unconfined Services Are Running on the System
Profile Applicability:  • Level 1 Description:  Unconfined services run without SELinux policy enforcement, potentially increasing the risk of unauthorized...
Mon, 26 May, 2025 at 2:34 AM
Ensure the MCS Translation Service (mcstrans) is Not Installed
Profile Applicability:  • Level 1 Description:  The MCS Translation Service (mcstrans) is a daemon used by SELinux to manage multi-category security (MCS) ...
Mon, 26 May, 2025 at 2:38 AM
Ensure SETroubleshoot Package is Not Installed
Profile Applicability:  • Level 1 Description:  SETroubleshoot is a tool that provides detailed SELinux alerts and troubleshooting information. While usefu...
Mon, 26 May, 2025 at 2:43 AM