Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
All 30 checks on this page
- 1.1 Filesystem
- Ensure nodev option set on /tmp partition
- Ensure noexec option set on /tmp partition
- Ensure nosuid option set on /tmp partition
- Ensure /tmp is tmpfs or a separate partition
- Ensure nodev option set on /dev/shm partition
- Ensure noexec option set on /dev/shm partition
- Ensure nosuid option set on /dev/shm partition
- Ensure /dev/shm is tmpfs or a separate partition
- Ensure nodev option set on /home partition
- Ensure nosuid option set on /home partition
- Ensure separate partition exists for /home
- Ensure nodev option set on /var partition
- Ensure nosuid option set on /var partition
- Ensure separate partition exists for /var
- Ensure nodev option set on /var/tmp partition
- Ensure noexec option set on /var/tmp partition
- Ensure nosuid option set on /var/tmp partition
- Ensure separate partition exists for /var/tmp
- Ensure nodev option set on /var/log partition
- Ensure noexec option set on /var/log partition
- Ensure nosuid option set on /var/log partition
- Ensure separate partition exists for /var/log
- Ensure nodev option set on /var/log/audit partition
- Ensure noexec option set on /var/log/audit partition
- Ensure nosuid option set on /var/log/audit partition
- Ensure separate partition exists for /var/log/audit
- 1.3 Mandatory Access Control
- Ensure apparmor is installed
- Ensure apparmor-utils is installed
- 1.5 Configure Additional Process Hardening
- Ensure Automatic Error Reporting is configured
- Ensure prelink is not installed
1.1 Filesystem
Ensure nodev option set on /tmp partition
Finding: /tmp mount is missing the nodev option.
Checks that the /tmp mount is mounted with the nodev option so device files cannot be created there.
This rule fails when /tmp is mounted without the NO_DEV option.
Rationale: nodev prevents creation of device special files on /tmp, reducing an avenue for privilege escalation.
Impact: None for typical /tmp usage.
Remediation
From the command line:
# Add nodev to the /tmp entry in /etc/fstab (or tmp.mount Options), then:
mount -o remount /tmp
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure noexec option set on /tmp partition
Finding: /tmp mount is missing the noexec option.
Checks that the /tmp mount is mounted with the noexec option so binaries cannot be executed there.
This rule fails when /tmp is mounted without the NO_EXEC option.
Rationale: noexec blocks execution of programs staged in /tmp, a common malware drop location.
Impact: Software that executes from /tmp will fail.
Remediation
From the command line:
# Add noexec to the /tmp entry in /etc/fstab (or tmp.mount Options), then:
mount -o remount /tmp
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure nosuid option set on /tmp partition
Finding: /tmp mount is missing the nosuid option.
Checks that the /tmp mount is mounted with the nosuid option so setuid bits are ignored there.
This rule fails when /tmp is mounted without the NO_SUID option.
Rationale: nosuid prevents setuid/setgid programs from running with elevated rights out of /tmp.
Impact: None for typical /tmp usage.
Remediation
From the command line:
# Add nosuid to the /tmp entry in /etc/fstab (or tmp.mount Options), then:
mount -o remount /tmp
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure /tmp is tmpfs or a separate partition
Finding: /tmp is not a separate partition or tmpfs.
Checks that /tmp is mounted on its own partition or tmpfs rather than living under the root filesystem.
This rule fails when no mount exists at /tmp (not a separate partition).
Rationale: A dedicated /tmp lets nodev, nosuid and noexec be enforced and isolates temporary-file growth from the root filesystem.
Impact: Requires a partitioning or fstab/tmp.mount change; a reboot may be needed to take effect.
Scope: Ubuntu 24.04 and later endpoints.
Remediation
From the command line:
systemctl unmask tmp.mount
systemctl enable --now tmp.mount
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Impact (TA0040)
Ensure nodev option set on /dev/shm partition
Finding: /dev/shm mount is missing the nodev option.
Checks that /dev/shm is mounted with the nodev option.
This rule fails when /dev/shm is mounted without the NO_DEV option.
Rationale: nodev prevents device special files on shared memory.
Impact: None for typical usage.
Remediation
From the command line:
# Add nodev to the /dev/shm entry in /etc/fstab, then:
mount -o remount /dev/shm
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure noexec option set on /dev/shm partition
Finding: /dev/shm mount is missing the noexec option.
Checks that /dev/shm is mounted with the noexec option.
This rule fails when /dev/shm is mounted without the NO_EXEC option.
Rationale: noexec blocks execution of programs staged in shared memory.
Impact: Software that executes from /dev/shm will fail.
Remediation
From the command line:
# Add noexec to the /dev/shm entry in /etc/fstab, then:
mount -o remount /dev/shm
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure nosuid option set on /dev/shm partition
Finding: /dev/shm mount is missing the nosuid option.
Checks that /dev/shm is mounted with the nosuid option.
This rule fails when /dev/shm is mounted without the NO_SUID option.
Rationale: nosuid stops setuid programs from running with elevated rights out of shared memory.
Impact: None for typical usage.
Remediation
From the command line:
# Add nosuid to the /dev/shm entry in /etc/fstab, then:
mount -o remount /dev/shm
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure /dev/shm is tmpfs or a separate partition
Finding: /dev/shm is not a separate partition or tmpfs.
Checks that /dev/shm is mounted as its own tmpfs/partition.
This rule fails when no mount exists at /dev/shm (not a separate partition).
Rationale: A dedicated /dev/shm allows nodev, nosuid and noexec to be enforced on shared memory.
Impact: Requires an /etc/fstab entry for /dev/shm; a reboot may be needed.
Scope: Ubuntu 24.04 and later endpoints.
Remediation
From the command line:
grep -qE '^\S+\s+/dev/shm\s' /etc/fstab || echo 'tmpfs /dev/shm tmpfs defaults,rw,nosuid,nodev,noexec,relatime 0 0' >> /etc/fstab
mount /dev/shm
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Impact (TA0040)
Ensure nodev option set on /home partition
Finding: /home mount is missing the nodev option.
Checks that /home is mounted with the nodev option.
This rule fails when /home is mounted without the NO_DEV option.
Rationale: nodev prevents users from creating device special files under /home.
Impact: None for typical usage.
Remediation
From the command line:
# Add nodev to the /home entry in /etc/fstab, then:
mount -o remount /home
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure nosuid option set on /home partition
Finding: /home mount is missing the nosuid option.
Checks that /home is mounted with the nosuid option.
This rule fails when /home is mounted without the NO_SUID option.
Rationale: nosuid stops setuid programs from running with elevated rights out of user home directories.
Impact: None for typical usage.
Remediation
From the command line:
# Add nosuid to the /home entry in /etc/fstab, then:
mount -o remount /home
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure separate partition exists for /home
Finding: /home is not on a separate partition.
Checks that /home resides on its own partition.
This rule fails when no mount exists at /home (not a separate partition).
Rationale: Isolating /home limits the impact of user data growth and permits dedicated mount hardening.
Impact: Requires repartitioning and data migration.
Scope: Ubuntu 24.04 and later endpoints.
Remediation
Create a separate partition or volume for /home, add it to /etc/fstab, migrate the existing data, and mount it.
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Impact (TA0040)
Ensure nodev option set on /var partition
Finding: /var mount is missing the nodev option.
Checks that /var is mounted with the nodev option.
This rule fails when /var is mounted without the NO_DEV option.
Rationale: nodev prevents device special files under /var.
Impact: None for typical usage.
Remediation
From the command line:
# Add nodev to the /var entry in /etc/fstab, then:
mount -o remount /var
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure nosuid option set on /var partition
Finding: /var mount is missing the nosuid option.
Checks that /var is mounted with the nosuid option.
This rule fails when /var is mounted without the NO_SUID option.
Rationale: nosuid stops setuid programs from running with elevated rights out of /var.
Impact: None for typical usage.
Remediation
From the command line:
# Add nosuid to the /var entry in /etc/fstab, then:
mount -o remount /var
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure separate partition exists for /var
Finding: /var is not on a separate partition.
Checks that /var resides on its own partition.
This rule fails when no mount exists at /var (not a separate partition).
Rationale: Isolating /var prevents variable data growth from filling the root filesystem and permits mount hardening.
Impact: Requires repartitioning and data migration.
Scope: Ubuntu 24.04 and later endpoints.
Remediation
Create a separate partition or volume for /var, add it to /etc/fstab, migrate the existing data, and mount it.
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Impact (TA0040)
Ensure nodev option set on /var/tmp partition
Finding: /var/tmp mount is missing the nodev option.
Checks that /var/tmp is mounted with the nodev option.
This rule fails when /var/tmp is mounted without the NO_DEV option.
Rationale: nodev prevents device special files under /var/tmp.
Impact: None for typical usage.
Remediation
From the command line:
# Add nodev to the /var/tmp entry in /etc/fstab, then:
mount -o remount /var/tmp
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure noexec option set on /var/tmp partition
Finding: /var/tmp mount is missing the noexec option.
Checks that /var/tmp is mounted with the noexec option.
This rule fails when /var/tmp is mounted without the NO_EXEC option.
Rationale: noexec blocks execution of programs staged in /var/tmp.
Impact: Software that executes from /var/tmp will fail.
Remediation
From the command line:
# Add noexec to the /var/tmp entry in /etc/fstab, then:
mount -o remount /var/tmp
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure nosuid option set on /var/tmp partition
Finding: /var/tmp mount is missing the nosuid option.
Checks that /var/tmp is mounted with the nosuid option.
This rule fails when /var/tmp is mounted without the NO_SUID option.
Rationale: nosuid stops setuid programs from running with elevated rights out of /var/tmp.
Impact: None for typical usage.
Remediation
From the command line:
# Add nosuid to the /var/tmp entry in /etc/fstab, then:
mount -o remount /var/tmp
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure separate partition exists for /var/tmp
Finding: /var/tmp is not on a separate partition.
Checks that /var/tmp resides on its own partition.
This rule fails when no mount exists at /var/tmp (not a separate partition).
Rationale: A dedicated /var/tmp permits nodev, nosuid and noexec enforcement and isolates temporary data.
Impact: Requires repartitioning and data migration.
Scope: Ubuntu 24.04 and later endpoints.
Remediation
Create a separate partition or volume for /var/tmp, add it to /etc/fstab, migrate the existing data, and mount it.
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Impact (TA0040)
Ensure nodev option set on /var/log partition
Finding: /var/log mount is missing the nodev option.
Checks that /var/log is mounted with the nodev option.
This rule fails when /var/log is mounted without the NO_DEV option.
Rationale: nodev prevents device special files under /var/log.
Impact: None for typical usage.
Remediation
From the command line:
# Add nodev to the /var/log entry in /etc/fstab, then:
mount -o remount /var/log
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure noexec option set on /var/log partition
Finding: /var/log mount is missing the noexec option.
Checks that /var/log is mounted with the noexec option.
This rule fails when /var/log is mounted without the NO_EXEC option.
Rationale: noexec blocks execution of programs staged in /var/log.
Impact: Software that executes from /var/log will fail.
Remediation
From the command line:
# Add noexec to the /var/log entry in /etc/fstab, then:
mount -o remount /var/log
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure nosuid option set on /var/log partition
Finding: /var/log mount is missing the nosuid option.
Checks that /var/log is mounted with the nosuid option.
This rule fails when /var/log is mounted without the NO_SUID option.
Rationale: nosuid stops setuid programs from running with elevated rights out of /var/log.
Impact: None for typical usage.
Remediation
From the command line:
# Add nosuid to the /var/log entry in /etc/fstab, then:
mount -o remount /var/log
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure separate partition exists for /var/log
Finding: /var/log is not on a separate partition.
Checks that /var/log resides on its own partition.
This rule fails when no mount exists at /var/log (not a separate partition).
Rationale: Isolating /var/log protects logs and prevents log growth from filling the root filesystem.
Impact: Requires repartitioning and data migration.
Scope: Ubuntu 24.04 and later endpoints.
Remediation
Create a separate partition or volume for /var/log, add it to /etc/fstab, migrate the existing data, and mount it.
- Framework mappings
- CIS Controls v8: 8.3 Ensure Adequate Audit Log Storage
- NIST SP 800-53 Rev. 5: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Impact (TA0040)
Ensure nodev option set on /var/log/audit partition
Finding: /var/log/audit mount is missing the nodev option.
Checks that /var/log/audit is mounted with the nodev option.
This rule fails when /var/log/audit is mounted without the NO_DEV option.
Rationale: nodev prevents device special files under the audit-log partition.
Impact: None for typical usage.
Remediation
From the command line:
# Add nodev to the /var/log/audit entry in /etc/fstab, then:
mount -o remount /var/log/audit
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure noexec option set on /var/log/audit partition
Finding: /var/log/audit mount is missing the noexec option.
Checks that /var/log/audit is mounted with the noexec option.
This rule fails when /var/log/audit is mounted without the NO_EXEC option.
Rationale: noexec blocks execution of programs staged in the audit-log partition.
Impact: Software that executes from /var/log/audit will fail.
Remediation
From the command line:
# Add noexec to the /var/log/audit entry in /etc/fstab, then:
mount -o remount /var/log/audit
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure nosuid option set on /var/log/audit partition
Finding: /var/log/audit mount is missing the nosuid option.
Checks that /var/log/audit is mounted with the nosuid option.
This rule fails when /var/log/audit is mounted without the NO_SUID option.
Rationale: nosuid stops setuid programs from running with elevated rights out of the audit-log partition.
Impact: None for typical usage.
Remediation
From the command line:
# Add nosuid to the /var/log/audit entry in /etc/fstab, then:
mount -o remount /var/log/audit
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure separate partition exists for /var/log/audit
Finding: /var/log/audit is not on a separate partition.
Checks that /var/log/audit resides on its own partition.
This rule fails when no mount exists at /var/log/audit (not a separate partition).
Rationale: A dedicated audit-log partition protects audit records and prevents them from filling other filesystems.
Impact: Requires repartitioning and data migration.
Scope: Ubuntu 24.04 and later endpoints.
Remediation
Create a separate partition or volume for /var/log/audit, add it to /etc/fstab, migrate the existing data, and mount it.
- Framework mappings
- CIS Controls v8: 8.3 Ensure Adequate Audit Log Storage
- NIST SP 800-53 Rev. 5: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Impact (TA0040)
1.3 Mandatory Access Control
Ensure apparmor is installed
Finding: Apparmor package is not installed.
Checks that the apparmor package is installed.
This rule fails when the package is not installed.
Rationale: Without AppArmor installed only discretionary access control is available, weakening confinement of services.
Impact: None; installs supporting packages.
Scope: Ubuntu 24.04 and later endpoints.
Remediation
From the command line:
apt install apparmor
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure apparmor-utils is installed
Finding: apparmor-utils package is not installed.
Checks that the apparmor-utils package is installed.
This rule fails when the package is not installed.
Rationale: Without AppArmor installed only discretionary access control is available, weakening confinement of services.
Impact: None; installs supporting packages.
Scope: Ubuntu 24.04 and later endpoints.
Remediation
From the command line:
apt install apparmor-utils
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
1.5 Configure Additional Process Hardening
Ensure Automatic Error Reporting is configured
Finding: Automatic Error Reporting (apport) is active.
Checks that the apport automatic error-reporting service is stopped and masked.
This rule fails when the service unit is loaded (not masked) and RUNNING.
Rationale: Apport can transmit crash data, including memory contents, off the host, potentially disclosing sensitive information.
Impact: Automatic crash reporting will no longer be collected or sent.
Remediation
From the command line:
systemctl stop apport.service
systemctl mask apport.service
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure prelink is not installed
Finding: Prelink package is installed.
Checks that the prelink package is not installed, as it alters binaries and can interfere with integrity checking.
This rule fails when the installed package name is one of the prohibited packages.
Rationale: prelink modifies executables, which can break AIDE/library integrity verification and be abused to hide tampering.
Impact: Programs relying on prelink optimization lose it; run prelink -ua before removal.
Remediation
From the command line:
prelink -ua
apt purge prelink
- Framework mappings
- CIS Controls v8: 3.14 Log Sensitive Data Access
- NIST SP 800-53 Rev. 5: AC-6 Least Privilege; AU-2 Event Logging; AU-12 Audit Record Generation; SI-4 System Monitoring
- PCI DSS v4.0.1: 10.2.1.1 Record every individual user's cardholder data access
- Risk
- Insecure Application
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)