Skip to content

Commit

Permalink
Merge pull request #12675 from mpurg/ubuntu2404_cis_rules1
Browse files Browse the repository at this point in the history
Add rules to several ubuntu2404 CIS controls
  • Loading branch information
dodys authored Dec 10, 2024
2 parents 8f7ac0f + 3dd04b6 commit 93ba08a
Show file tree
Hide file tree
Showing 2 changed files with 13 additions and 13 deletions.
25 changes: 12 additions & 13 deletions controls/cis_ubuntu2404.yml
Original file line number Diff line number Diff line change
Expand Up @@ -1762,10 +1762,9 @@ controls:
levels:
- l1_server
- l1_workstation
related_rules:
rules:
- sudo_add_use_pty
status: planned
notes: TODO. Partial/incorrect implementation exists.See related rules. Analogous to ubuntu2204/5.3.2.
status: automated

- id: 5.2.3
title: Ensure sudo log file exists (Automated)
Expand Down Expand Up @@ -1836,8 +1835,9 @@ controls:
levels:
- l1_server
- l1_workstation
status: planned
notes: TODO. Rule does not seem to be implemented, nor does it map to any rules in ubuntu2204 profile.
rules:
- package_pam_pwquality_installed
status: automated

- id: 5.3.2.1
title: Ensure pam_unix module is enabled (Automated)
Expand Down Expand Up @@ -2289,20 +2289,18 @@ controls:
levels:
- l1_server
- l1_workstation
related_rules:
rules:
- journald_compress
status: planned
notes: TODO. Partial/incorrect implementation exists.See related rules. Analogous to ubuntu2204/4.2.1.3.
status: automated

- id: 6.1.2.4
title: Ensure journald Storage is configured (Automated)
levels:
- l1_server
- l1_workstation
related_rules:
rules:
- journald_storage
status: planned
notes: TODO. Partial/incorrect implementation exists.See related rules. Analogous to ubuntu2204/4.2.1.4.
status: automated

- id: 6.1.3.1
title: Ensure rsyslog is installed (Automated)
Expand All @@ -2327,8 +2325,9 @@ controls:
levels:
- l1_server
- l1_workstation
status: planned
notes: TODO. Rule does not seem to be implemented. Analogous to ubuntu2204/4.2.2.3.
rules:
- journald_forward_to_syslog
status: automated

- id: 6.1.3.4
title: Ensure rsyslog log file creation mode is configured (Automated)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,7 @@ template:
pkgname: libpwquality
pkgname@ubuntu2004: libpam-pwquality
pkgname@ubuntu2204: libpam-pwquality
pkgname@ubuntu2404: libpam-pwquality
pkgname@debian12: libpam-pwquality

platform: package[pam]

0 comments on commit 93ba08a

Please sign in to comment.