Ensure AppArmor is installed – libapparmor1 Details AppArmor provides Mandatory Access Controls. Rationale: Without a Mandatory Access Control system installed only the default Discretionary Access Control...
Ensure authentication required for single user mode – rescue.emergency Details Single user mode (rescue mode) is used for recovery when the system detects an issue during boot or by...
Ensure authentication required for single user mode – rescue.service Details Single user mode (rescue mode) is used for recovery when the system detects an issue during boot or by...
Ensure bootloader password is set – password Details Setting the boot loader password will require that anyone rebooting the system must enter a password before being able...
Ensure bootloader password is set – superusers Details Setting the boot loader password will require that anyone rebooting the system must enter a password before being able...
Ensure core dumps are restricted – fs.suid_dumpable sysctl.conf Details A core dump is the memory of an executable program. It is generally used to determine why a program...
Ensure core dumps are restricted – limits.conf Details A core dump is the memory of an executable program. It is generally used to determine why a program...
Ensure core dumps are restricted – sysctl fs.suid_dumpable Details A core dump is the memory of an executable program. It is generally used to determine why a program...
Ensure core dumps are restricted – systemd-coredump ProcessSizeMax Details A core dump is the memory of an executable program. It is generally used to determine why a program...
Ensure core dumps are restricted – systemd-coredump Storage Details A core dump is the memory of an executable program. It is generally used to determine why a program...