Skip to content

Commit c2f84ff

Browse files
authored
Merge pull request #13072 from mpurg/ubuntu2404_cis_release
Release Ubuntu 24.04 CIS v1.0.0 profiles
2 parents e9f26b6 + da5a43f commit c2f84ff

File tree

5 files changed

+27
-20
lines changed

5 files changed

+27
-20
lines changed

controls/cis_ubuntu2404.yml

Lines changed: 19 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
policy: CIS Benchmark for Ubuntu 24.04 LTS
22
title: CIS Benchmark for Ubuntu 24.04 LTS
33
id: cis_ubuntu2404
4-
version: Draft
4+
version: '1.0.0'
55
source: https://www.cisecurity.org/cis-benchmarks
66
levels:
77
- id: l1_server
@@ -389,11 +389,13 @@ controls:
389389
rules:
390390
- var_apparmor_mode=enforce
391391
- all_apparmor_profiles_in_enforce_complain_mode
392-
status: partial
392+
status: automated
393393
notes: |
394-
Current implementation does not adequately address the nuances
395-
of various profiles, including snap, disabled, force-complain,
396-
and unconfined.
394+
CIS recommendation does not adequately address the nuances
395+
of various profiles, including disabled, force-complain,
396+
and unconfined. Currently, the control changes the default apparmor
397+
mode for all profiles in /etc/apparmor.d which can
398+
break certain applications.
397399
398400
- id: 1.3.1.4
399401
title: Ensure all AppArmor Profiles are enforcing (Automated)
@@ -403,11 +405,13 @@ controls:
403405
rules:
404406
- var_apparmor_mode=enforce
405407
- all_apparmor_profiles_enforced
406-
status: partial
408+
status: automated
407409
notes: |
408-
Current implementation does not adequately address the nuances
409-
of various profiles, including snap, disabled, force-complain,
410-
and unconfined.
410+
CIS recommendation does not adequately address the nuances
411+
of various profiles, including disabled, force-complain,
412+
and unconfined. Currently, the control changes the default apparmor
413+
mode for all profiles in /etc/apparmor.d which can
414+
break certain applications.
411415
412416
- id: 1.4.1
413417
title: Ensure bootloader password is set (Automated)
@@ -1445,11 +1449,14 @@ controls:
14451449
levels:
14461450
- l1_server
14471451
- l1_workstation
1448-
related_rules:
1452+
rules:
14491453
- var_nftables_master_config_file=etc
14501454
- nftables_rules_permanent
1451-
status: planned
1452-
notes: TODO. Partial/incorrect implementation exists.See related rules. Analogous to ubuntu2204/3.5.2.10.
1455+
status: automated
1456+
notes: |
1457+
Audit procedure for 4.3.10 depends on local site policy thus
1458+
it cannot be fully automated. Upstream ticket:
1459+
https://workbench.cisecurity.org/benchmarks/18959/tickets/23190
14531460
14541461
- id: 4.4.1.1
14551462
title: Ensure iptables packages are installed (Automated)

products/ubuntu2404/profiles/cis_level1_server.profile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,15 @@
11
documentation_complete: true
22

33
metadata:
4-
version: draft
4+
version: 1.0.0
55
SMEs:
66
- mpurg
77
- dodys
88
- alanmcanonical
99

1010
reference: https://www.cisecurity.org/benchmark/ubuntu_linux
1111

12-
title: 'DRAFT - CIS Ubuntu Linux 24.04 LTS Benchmark for Level 1 - Server'
12+
title: 'CIS Ubuntu Linux 24.04 LTS Benchmark for Level 1 - Server'
1313

1414
description: |-
1515
This profile defines a baseline that aligns to the "Level 1 - Server"

products/ubuntu2404/profiles/cis_level1_workstation.profile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,15 @@
11
documentation_complete: true
22

33
metadata:
4-
version: draft
4+
version: 1.0.0
55
SMEs:
66
- mpurg
77
- dodys
88
- alanmcanonical
99

1010
reference: https://www.cisecurity.org/benchmark/ubuntu_linux
1111

12-
title: 'DRAFT - CIS Ubuntu Linux 24.04 LTS Benchmark for Level 1 - Workstation'
12+
title: 'CIS Ubuntu Linux 24.04 LTS Benchmark for Level 1 - Workstation'
1313

1414
description: |-
1515
This profile defines a baseline that aligns to the "Level 1 - Workstation"

products/ubuntu2404/profiles/cis_level2_server.profile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,15 @@
11
documentation_complete: true
22

33
metadata:
4-
version: draft
4+
version: 1.0.0
55
SMEs:
66
- mpurg
77
- dodys
88
- alanmcanonical
99

1010
reference: https://www.cisecurity.org/benchmark/ubuntu_linux
1111

12-
title: 'DRAFT - CIS Ubuntu Linux 24.04 LTS Benchmark for Level 2 - Server'
12+
title: 'CIS Ubuntu Linux 24.04 LTS Benchmark for Level 2 - Server'
1313

1414
description: |-
1515
This profile defines a baseline that aligns to the "Level 2 - Server"

products/ubuntu2404/profiles/cis_level2_workstation.profile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,15 @@
11
documentation_complete: true
22

33
metadata:
4-
version: draft
4+
version: 1.0.0
55
SMEs:
66
- mpurg
77
- dodys
88
- alanmcanonical
99

1010
reference: https://www.cisecurity.org/benchmark/ubuntu_linux
1111

12-
title: 'DRAFT - CIS Ubuntu Linux 24.04 LTS Benchmark for Level 2 - Workstation'
12+
title: 'CIS Ubuntu Linux 24.04 LTS Benchmark for Level 2 - Workstation'
1313

1414
description: |-
1515
This profile defines a baseline that aligns to the "Level 2 - Workstation"

0 commit comments

Comments
 (0)