@@ -62,6 +62,13 @@ controls:
6262 - sysctl_net_ipv6_conf_default_accept_ra
6363 - sysctl_net_ipv6_conf_default_accept_redirects
6464 - sysctl_net_ipv6_conf_default_accept_source_route
65+ - sshd_idle_timeout_value=5_minutes
66+ - sysctl_net_ipv4_tcp_syncookies_value=enabled
67+ - var_accounts_maximum_age_login_defs=365
68+ - var_sshd_max_sessions=10
69+ - var_sshd_set_keepalive=1
70+ - var_sshd_set_maxstartups=10:30:60
71+ - var_user_initialization_files_regex=all_dotfiles
6572 status : automated
6673 - id : cm-2
6774 title : Baseline Configuration
@@ -220,6 +227,7 @@ controls:
220227 - banner_etc_motd_cis
221228 - coredump_disable_backtraces
222229 - coredump_disable_storage
230+ - dconf_db_up_to_date
223231 - dconf_gnome_disable_user_list
224232 - disable_host_auth
225233 - disable_users_coredumps
@@ -248,6 +256,7 @@ controls:
248256 - service_rpcbind_disabled
249257 - sshd_disable_gssapi_auth
250258 - sshd_set_login_grace_time
259+ - sysctl_fs_suid_dumpable
251260 - sysctl_kernel_kptr_restrict
252261 - sysctl_kernel_randomize_va_space
253262 - sysctl_kernel_yama_ptrace_scope
@@ -276,6 +285,32 @@ controls:
276285 - sysctl_net_ipv6_conf_default_accept_redirects
277286 - sysctl_net_ipv6_conf_default_accept_source_route
278287 - sysctl_net_ipv6_conf_default_forwarding
288+ - cis_banner_text=cis
289+ - dconf_login_banner_contents=cis_default
290+ - dconf_login_banner_text=cis_banners
291+ - sysctl_net_ipv4_conf_all_accept_redirects_value=disabled
292+ - sysctl_net_ipv4_conf_all_accept_source_route_value=disabled
293+ - sysctl_net_ipv4_conf_all_log_martians_value=enabled
294+ - sysctl_net_ipv4_conf_all_rp_filter_value=enabled
295+ - sysctl_net_ipv4_conf_all_secure_redirects_value=disabled
296+ - sysctl_net_ipv4_conf_default_accept_redirects_value=disabled
297+ - sysctl_net_ipv4_conf_default_accept_source_route_value=disabled
298+ - sysctl_net_ipv4_conf_default_forwarding_value=disabled
299+ - sysctl_net_ipv4_conf_default_log_martians_value=enabled
300+ - sysctl_net_ipv4_conf_default_rp_filter_value=enabled
301+ - sysctl_net_ipv4_conf_default_secure_redirects_value=disabled
302+ - sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value=enabled
303+ - sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value=enabled
304+ - sysctl_net_ipv6_conf_all_accept_ra_value=disabled
305+ - sysctl_net_ipv6_conf_all_accept_redirects_value=disabled
306+ - sysctl_net_ipv6_conf_all_accept_source_route_value=disabled
307+ - sysctl_net_ipv6_conf_all_forwarding_value=disabled
308+ - sysctl_net_ipv6_conf_default_accept_ra_value=disabled
309+ - sysctl_net_ipv6_conf_default_accept_redirects_value=disabled
310+ - sysctl_net_ipv6_conf_default_accept_source_route_value=disabled
311+ - sysctl_net_ipv6_conf_default_forwarding_value=disabled
312+ - var_accounts_user_umask=027
313+ - var_sshd_set_login_grace_time=60
279314 status : automated
280315 - id : cm-6.1
281316 title : Automated Management, Application, and Verification
@@ -303,6 +338,7 @@ controls:
303338 - low
304339 rules :
305340 - dconf_gnome_disable_autorun
341+ - disable_weak_deps
306342 - file_ownership_var_log_audit_stig
307343 - has_nonlocal_mta
308344 - kernel_module_atm_disabled
@@ -330,11 +366,14 @@ controls:
330366 - package_cyrus-imapd_removed
331367 - package_dovecot_removed
332368 - package_ftp_removed
369+ - package_gdm_removed
333370 - package_httpd_removed
334371 - package_kea_removed
335372 - package_net-snmp_removed
336373 - package_nginx_removed
337374 - package_openldap-clients_removed
375+ - package_postfix_installed
376+ - package_sequoia-sq_installed
338377 - package_telnet-server_removed
339378 - package_telnet_removed
340379 - package_tftp-server_removed
@@ -354,6 +393,8 @@ controls:
354393 - service_dnsmasq_disabled
355394 - sshd_disable_forwarding
356395 - wireless_disable_interfaces
396+ - xwayland_disabled
397+ - var_postfix_inet_interfaces=loopback-only
357398 status : automated
358399 - id : cm-7.1
359400 title : Periodic Review
0 commit comments