File: rule.yml

package info (click to toggle)
scap-security-guide 0.1.76-1
  • links: PTS, VCS
  • area: main
  • in suites: trixie
  • size: 110,644 kB
  • sloc: xml: 241,883; sh: 73,777; python: 32,527; makefile: 27
file content (35 lines) | stat: -rw-r--r-- 1,060 bytes parent folder | download
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
documentation_complete: true

title: 'Install the ntp service'

description: 'The ntpd service should be installed.'

rationale: 'Time synchronization (using NTP) is required by almost all network and administrative tasks (syslog, cryptographic based services (authentication, etc.), etc.). Ntpd is regulary maintained and updated, supporting security features such as RFC 5906.'

severity: high

identifiers:
    cce@sle12: CCE-91656-9
    cce@sle15: CCE-91293-1

references:
    cis-csc: 1,14,15,16,3,5,6
    cis@ubuntu2004: 2.2.1.1
    cis@ubuntu2204: 2.1.1.1
    cobit5: APO11.04,BAI03.05,DSS05.04,DSS05.07,MEA02.01
    disa: CCI-000160
    isa-62443-2009: 4.3.3.3.9,4.3.3.5.8,4.3.4.4.7,4.4.2.1,4.4.2.2,4.4.2.4
    isa-62443-2013: 'SR 2.10,SR 2.11,SR 2.12,SR 2.8,SR 2.9'
    iso27001-2013: A.12.4.1,A.12.4.2,A.12.4.3,A.12.4.4,A.12.7.1
    nist: CM-6(a)
    nist-csf: PR.PT-1
    pcidss: Req-10.4

ocil_clause: 'the package is not installed'

ocil: '{{{ ocil_package(package="ntp") }}}'

template:
    name: package_installed
    vars:
        pkgname: ntp