File: nopq.yml

package info (click to toggle)
scap-security-guide 0.1.76-1
  • links: PTS, VCS
  • area: main
  • in suites: forky, sid, trixie
  • size: 110,644 kB
  • sloc: xml: 241,883; sh: 73,777; python: 32,527; makefile: 27
file content (55 lines) | stat: -rw-r--r-- 2,097 bytes parent folder | download | duplicates (2)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
policy: NOPQ Benchmark for securing Linux systems
title: NOPQ Benchmark for securing Linux systems
id: nopq
version: 1.2.3
source: https://www.example.com/nopq/linux.pdf
controls_dir: jklm
controls:
  - id: R2
    title: Minimization of configuration
    description: >-
      The features configured at the level of launched services
      should be limited to the strict minimum.
    rationale: >-
        Minimization of configuration helps to reduce attack surface.
    automated: no
    notes: >-
      This is individual depending on the system workload
      therefore needs to be audited manually.
    related_rules:
       - systemd_target_multi_use
  - id: R4
    title: Configure authentication
    description: >-
      Ensure authentication methods are functional to prevent
      unauthorized access to the system.
    controls:
      - id: R4.a
        title: Disable administrator accounts
        automated: yes
        rules:
          -  accounts_passwords_pam_faillock_deny_root
      - id: R4.b
        title: Enforce password quality standards
        automated: yes
        rules:
          - accounts_password_pam_minlen
          - accounts_password_pam_ocredit
          - var_password_pam_ocredit=1
      - id: R5
        title: The product must provide automated mechanisms for supporting account management functions.
        status: does not meet
        fixtext: There is no fixtext.
        check: There is no check.
        mitigation: |-
            Mitigate with third-party software.

            Although the listed mitigation is supporting the security function, it is not sufficient to reduce the residual risk of this requirement.
        description:
          The operating system must provide automated mechanisms for supporting account management functions.
        rationale:
          Enterprise environments make account management challenging and complex.
          A manual process for account management functions adds the risk of a potential oversight or other errors.
        status_justification:
          Mitigate with third-party software.