CIS Ubuntu Linux 24.04 LTS Benchmark · Section 1

Ubuntu 24.04 Initial Setup: 30 Checks

Wartiva runs 30 checks for section 1, Initial Setup, of the CIS Ubuntu Linux 24.04 LTS Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →

All 30 checks on this page

1.1 Filesystem

Ensure nodev option set on /tmp partition

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.1

Finding: /tmp mount is missing the nodev option.

Checks that the /tmp mount is mounted with the nodev option so device files cannot be created there.

This rule fails when /tmp is mounted without the NO_DEV option.

Rationale: nodev prevents creation of device special files on /tmp, reducing an avenue for privilege escalation.

Impact: None for typical /tmp usage.

Remediation

From the command line:

# Add nodev to the /tmp entry in /etc/fstab (or tmp.mount Options), then:
mount -o remount /tmp
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure noexec option set on /tmp partition

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.1

Finding: /tmp mount is missing the noexec option.

Checks that the /tmp mount is mounted with the noexec option so binaries cannot be executed there.

This rule fails when /tmp is mounted without the NO_EXEC option.

Rationale: noexec blocks execution of programs staged in /tmp, a common malware drop location.

Impact: Software that executes from /tmp will fail.

Remediation

From the command line:

# Add noexec to the /tmp entry in /etc/fstab (or tmp.mount Options), then:
mount -o remount /tmp
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure nosuid option set on /tmp partition

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.1

Finding: /tmp mount is missing the nosuid option.

Checks that the /tmp mount is mounted with the nosuid option so setuid bits are ignored there.

This rule fails when /tmp is mounted without the NO_SUID option.

Rationale: nosuid prevents setuid/setgid programs from running with elevated rights out of /tmp.

Impact: None for typical /tmp usage.

Remediation

From the command line:

# Add nosuid to the /tmp entry in /etc/fstab (or tmp.mount Options), then:
mount -o remount /tmp
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure /tmp is tmpfs or a separate partition

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.1

Finding: /tmp is not a separate partition or tmpfs.

Checks that /tmp is mounted on its own partition or tmpfs rather than living under the root filesystem.

This rule fails when no mount exists at /tmp (not a separate partition).

Rationale: A dedicated /tmp lets nodev, nosuid and noexec be enforced and isolates temporary-file growth from the root filesystem.

Impact: Requires a partitioning or fstab/tmp.mount change; a reboot may be needed to take effect.

Scope: Ubuntu 24.04 and later endpoints.

Remediation

From the command line:

systemctl unmask tmp.mount
systemctl enable --now tmp.mount
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Reliability Impact
MITRE ATT&CK tactic
Impact (TA0040)

Ensure nodev option set on /dev/shm partition

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.2

Finding: /dev/shm mount is missing the nodev option.

Checks that /dev/shm is mounted with the nodev option.

This rule fails when /dev/shm is mounted without the NO_DEV option.

Rationale: nodev prevents device special files on shared memory.

Impact: None for typical usage.

Remediation

From the command line:

# Add nodev to the /dev/shm entry in /etc/fstab, then:
mount -o remount /dev/shm
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure noexec option set on /dev/shm partition

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.2

Finding: /dev/shm mount is missing the noexec option.

Checks that /dev/shm is mounted with the noexec option.

This rule fails when /dev/shm is mounted without the NO_EXEC option.

Rationale: noexec blocks execution of programs staged in shared memory.

Impact: Software that executes from /dev/shm will fail.

Remediation

From the command line:

# Add noexec to the /dev/shm entry in /etc/fstab, then:
mount -o remount /dev/shm
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure nosuid option set on /dev/shm partition

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.2

Finding: /dev/shm mount is missing the nosuid option.

Checks that /dev/shm is mounted with the nosuid option.

This rule fails when /dev/shm is mounted without the NO_SUID option.

Rationale: nosuid stops setuid programs from running with elevated rights out of shared memory.

Impact: None for typical usage.

Remediation

From the command line:

# Add nosuid to the /dev/shm entry in /etc/fstab, then:
mount -o remount /dev/shm
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure /dev/shm is tmpfs or a separate partition

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.2

Finding: /dev/shm is not a separate partition or tmpfs.

Checks that /dev/shm is mounted as its own tmpfs/partition.

This rule fails when no mount exists at /dev/shm (not a separate partition).

Rationale: A dedicated /dev/shm allows nodev, nosuid and noexec to be enforced on shared memory.

Impact: Requires an /etc/fstab entry for /dev/shm; a reboot may be needed.

Scope: Ubuntu 24.04 and later endpoints.

Remediation

From the command line:

grep -qE '^\S+\s+/dev/shm\s' /etc/fstab || echo 'tmpfs /dev/shm tmpfs defaults,rw,nosuid,nodev,noexec,relatime 0 0' >> /etc/fstab
mount /dev/shm
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Reliability Impact
MITRE ATT&CK tactic
Impact (TA0040)

Ensure nodev option set on /home partition

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.3

Finding: /home mount is missing the nodev option.

Checks that /home is mounted with the nodev option.

This rule fails when /home is mounted without the NO_DEV option.

Rationale: nodev prevents users from creating device special files under /home.

Impact: None for typical usage.

Remediation

From the command line:

# Add nodev to the /home entry in /etc/fstab, then:
mount -o remount /home
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure nosuid option set on /home partition

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.3

Finding: /home mount is missing the nosuid option.

Checks that /home is mounted with the nosuid option.

This rule fails when /home is mounted without the NO_SUID option.

Rationale: nosuid stops setuid programs from running with elevated rights out of user home directories.

Impact: None for typical usage.

Remediation

From the command line:

# Add nosuid to the /home entry in /etc/fstab, then:
mount -o remount /home
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure separate partition exists for /home

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.3

Finding: /home is not on a separate partition.

Checks that /home resides on its own partition.

This rule fails when no mount exists at /home (not a separate partition).

Rationale: Isolating /home limits the impact of user data growth and permits dedicated mount hardening.

Impact: Requires repartitioning and data migration.

Scope: Ubuntu 24.04 and later endpoints.

Remediation

Create a separate partition or volume for /home, add it to /etc/fstab, migrate the existing data, and mount it.

Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Reliability Impact
MITRE ATT&CK tactic
Impact (TA0040)

Ensure nodev option set on /var partition

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.4

Finding: /var mount is missing the nodev option.

Checks that /var is mounted with the nodev option.

This rule fails when /var is mounted without the NO_DEV option.

Rationale: nodev prevents device special files under /var.

Impact: None for typical usage.

Remediation

From the command line:

# Add nodev to the /var entry in /etc/fstab, then:
mount -o remount /var
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure nosuid option set on /var partition

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.4

Finding: /var mount is missing the nosuid option.

Checks that /var is mounted with the nosuid option.

This rule fails when /var is mounted without the NO_SUID option.

Rationale: nosuid stops setuid programs from running with elevated rights out of /var.

Impact: None for typical usage.

Remediation

From the command line:

# Add nosuid to the /var entry in /etc/fstab, then:
mount -o remount /var
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure separate partition exists for /var

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.4

Finding: /var is not on a separate partition.

Checks that /var resides on its own partition.

This rule fails when no mount exists at /var (not a separate partition).

Rationale: Isolating /var prevents variable data growth from filling the root filesystem and permits mount hardening.

Impact: Requires repartitioning and data migration.

Scope: Ubuntu 24.04 and later endpoints.

Remediation

Create a separate partition or volume for /var, add it to /etc/fstab, migrate the existing data, and mount it.

Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Reliability Impact
MITRE ATT&CK tactic
Impact (TA0040)

Ensure nodev option set on /var/tmp partition

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.5

Finding: /var/tmp mount is missing the nodev option.

Checks that /var/tmp is mounted with the nodev option.

This rule fails when /var/tmp is mounted without the NO_DEV option.

Rationale: nodev prevents device special files under /var/tmp.

Impact: None for typical usage.

Remediation

From the command line:

# Add nodev to the /var/tmp entry in /etc/fstab, then:
mount -o remount /var/tmp
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure noexec option set on /var/tmp partition

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.5

Finding: /var/tmp mount is missing the noexec option.

Checks that /var/tmp is mounted with the noexec option.

This rule fails when /var/tmp is mounted without the NO_EXEC option.

Rationale: noexec blocks execution of programs staged in /var/tmp.

Impact: Software that executes from /var/tmp will fail.

Remediation

From the command line:

# Add noexec to the /var/tmp entry in /etc/fstab, then:
mount -o remount /var/tmp
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure nosuid option set on /var/tmp partition

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.5

Finding: /var/tmp mount is missing the nosuid option.

Checks that /var/tmp is mounted with the nosuid option.

This rule fails when /var/tmp is mounted without the NO_SUID option.

Rationale: nosuid stops setuid programs from running with elevated rights out of /var/tmp.

Impact: None for typical usage.

Remediation

From the command line:

# Add nosuid to the /var/tmp entry in /etc/fstab, then:
mount -o remount /var/tmp
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure separate partition exists for /var/tmp

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.5

Finding: /var/tmp is not on a separate partition.

Checks that /var/tmp resides on its own partition.

This rule fails when no mount exists at /var/tmp (not a separate partition).

Rationale: A dedicated /var/tmp permits nodev, nosuid and noexec enforcement and isolates temporary data.

Impact: Requires repartitioning and data migration.

Scope: Ubuntu 24.04 and later endpoints.

Remediation

Create a separate partition or volume for /var/tmp, add it to /etc/fstab, migrate the existing data, and mount it.

Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Reliability Impact
MITRE ATT&CK tactic
Impact (TA0040)

Ensure nodev option set on /var/log partition

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.6

Finding: /var/log mount is missing the nodev option.

Checks that /var/log is mounted with the nodev option.

This rule fails when /var/log is mounted without the NO_DEV option.

Rationale: nodev prevents device special files under /var/log.

Impact: None for typical usage.

Remediation

From the command line:

# Add nodev to the /var/log entry in /etc/fstab, then:
mount -o remount /var/log
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure noexec option set on /var/log partition

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.6

Finding: /var/log mount is missing the noexec option.

Checks that /var/log is mounted with the noexec option.

This rule fails when /var/log is mounted without the NO_EXEC option.

Rationale: noexec blocks execution of programs staged in /var/log.

Impact: Software that executes from /var/log will fail.

Remediation

From the command line:

# Add noexec to the /var/log entry in /etc/fstab, then:
mount -o remount /var/log
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure nosuid option set on /var/log partition

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.6

Finding: /var/log mount is missing the nosuid option.

Checks that /var/log is mounted with the nosuid option.

This rule fails when /var/log is mounted without the NO_SUID option.

Rationale: nosuid stops setuid programs from running with elevated rights out of /var/log.

Impact: None for typical usage.

Remediation

From the command line:

# Add nosuid to the /var/log entry in /etc/fstab, then:
mount -o remount /var/log
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure separate partition exists for /var/log

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.6

Finding: /var/log is not on a separate partition.

Checks that /var/log resides on its own partition.

This rule fails when no mount exists at /var/log (not a separate partition).

Rationale: Isolating /var/log protects logs and prevents log growth from filling the root filesystem.

Impact: Requires repartitioning and data migration.

Scope: Ubuntu 24.04 and later endpoints.

Remediation

Create a separate partition or volume for /var/log, add it to /etc/fstab, migrate the existing data, and mount it.

Framework mappings
  • CIS Controls v8: 8.3 Ensure Adequate Audit Log Storage
  • NIST SP 800-53 Rev. 5: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures
Risk
Reliability Impact
MITRE ATT&CK tactic
Impact (TA0040)

Ensure nodev option set on /var/log/audit partition

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.7

Finding: /var/log/audit mount is missing the nodev option.

Checks that /var/log/audit is mounted with the nodev option.

This rule fails when /var/log/audit is mounted without the NO_DEV option.

Rationale: nodev prevents device special files under the audit-log partition.

Impact: None for typical usage.

Remediation

From the command line:

# Add nodev to the /var/log/audit entry in /etc/fstab, then:
mount -o remount /var/log/audit
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure noexec option set on /var/log/audit partition

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.7

Finding: /var/log/audit mount is missing the noexec option.

Checks that /var/log/audit is mounted with the noexec option.

This rule fails when /var/log/audit is mounted without the NO_EXEC option.

Rationale: noexec blocks execution of programs staged in the audit-log partition.

Impact: Software that executes from /var/log/audit will fail.

Remediation

From the command line:

# Add noexec to the /var/log/audit entry in /etc/fstab, then:
mount -o remount /var/log/audit
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure nosuid option set on /var/log/audit partition

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.7

Finding: /var/log/audit mount is missing the nosuid option.

Checks that /var/log/audit is mounted with the nosuid option.

This rule fails when /var/log/audit is mounted without the NO_SUID option.

Rationale: nosuid stops setuid programs from running with elevated rights out of the audit-log partition.

Impact: None for typical usage.

Remediation

From the command line:

# Add nosuid to the /var/log/audit entry in /etc/fstab, then:
mount -o remount /var/log/audit
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure separate partition exists for /var/log/audit

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.1.2.7

Finding: /var/log/audit is not on a separate partition.

Checks that /var/log/audit resides on its own partition.

This rule fails when no mount exists at /var/log/audit (not a separate partition).

Rationale: A dedicated audit-log partition protects audit records and prevents them from filling other filesystems.

Impact: Requires repartitioning and data migration.

Scope: Ubuntu 24.04 and later endpoints.

Remediation

Create a separate partition or volume for /var/log/audit, add it to /etc/fstab, migrate the existing data, and mount it.

Framework mappings
  • CIS Controls v8: 8.3 Ensure Adequate Audit Log Storage
  • NIST SP 800-53 Rev. 5: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures
Risk
Reliability Impact
MITRE ATT&CK tactic
Impact (TA0040)

1.3 Mandatory Access Control

Ensure apparmor is installed

High severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.3.1

Finding: Apparmor package is not installed.

Checks that the apparmor package is installed.

This rule fails when the package is not installed.

Rationale: Without AppArmor installed only discretionary access control is available, weakening confinement of services.

Impact: None; installs supporting packages.

Scope: Ubuntu 24.04 and later endpoints.

Remediation

From the command line:

apt install apparmor
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Reliability Impact
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure apparmor-utils is installed

High severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.3.1

Finding: apparmor-utils package is not installed.

Checks that the apparmor-utils package is installed.

This rule fails when the package is not installed.

Rationale: Without AppArmor installed only discretionary access control is available, weakening confinement of services.

Impact: None; installs supporting packages.

Scope: Ubuntu 24.04 and later endpoints.

Remediation

From the command line:

apt install apparmor-utils
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Reliability Impact
MITRE ATT&CK tactic
Defense Evasion (TA0005)

1.5 Configure Additional Process Hardening

Ensure Automatic Error Reporting is configured

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 1.5

Finding: Automatic Error Reporting (apport) is active.

Checks that the apport automatic error-reporting service is stopped and masked.

This rule fails when the service unit is loaded (not masked) and RUNNING.

Rationale: Apport can transmit crash data, including memory contents, off the host, potentially disclosing sensitive information.

Impact: Automatic crash reporting will no longer be collected or sent.

Remediation

From the command line:

systemctl stop apport.service
systemctl mask apport.service
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)