File: rule.yml

package info (click to toggle)
scap-security-guide 0.1.78-1
  • links: PTS, VCS
  • area: main
  • in suites: forky, sid
  • size: 114,600 kB
  • sloc: xml: 245,305; sh: 84,381; python: 33,093; makefile: 27
file content (38 lines) | stat: -rw-r--r-- 1,128 bytes parent folder | download
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
documentation_complete: true

title: 'Install the ntp service'

description: 'The ntpd service should be installed.'

rationale: 'Time synchronization (using NTP) is required by almost all network and administrative tasks (syslog, cryptographic based services (authentication, etc.), etc.). Ntpd is regulary maintained and updated, supporting security features such as RFC 5906.'

severity: high

identifiers:
    cce@sle12: CCE-91656-9
    cce@sle15: CCE-91293-1

references:
    cis-csc: 1,14,15,16,3,5,6
    cobit5: APO11.04,BAI03.05,DSS05.04,DSS05.07,MEA02.01
    isa-62443-2009: 4.3.3.3.9,4.3.3.5.8,4.3.4.4.7,4.4.2.1,4.4.2.2,4.4.2.4
    isa-62443-2013: 'SR 2.10,SR 2.11,SR 2.12,SR 2.8,SR 2.9'
    iso27001-2013: A.12.4.1,A.12.4.2,A.12.4.3,A.12.4.4,A.12.7.1
    nist: CM-6(a)
    nist-csf: PR.PT-1
    pcidss: Req-10.4

ocil_clause: 'the package is not installed'

ocil: |-
  {{% if product == "debian13" %}}
  {{{ ocil_package(package="ntpsec") }}}
  {{% else %}}
  {{{ ocil_package(package="ntp") }}}
  {{% endif %}}
  
template:
    name: package_installed
    vars:
        pkgname: ntp
        pkgname@debian13: ntpsec