Coverage - CIS, Linux
CIS CAT Assessor scan results
The following scans were performed on a default installation of the noted Operating System with the SIMP Enterprise profile enforced.
  
    
      | OS | EE Profile | Scan Type | Benchmark Version | Pass | Fail | Total % | Certification Status | 
  
  
    
      | CentOS 7 | cis:level:1:server | Level 1 - Server | 3.1.1 | 182 | 10 | 95% | Certified | 
    
      | CentOS 7 | cis:level:2:server | Level 2 - Server | 3.1.1 | 210 | 15 | 93% | Certified | 
    
      | CentOS 8 | cis:level:1:server | Level 1 - Server | 1.0.1 | 154 | 18 | 90% | Certified | 
    
      | CentOS 8 | cis:level:2:server | Level 2 - Server | 1.0.1 | 190 | 23 | 89% | Certified | 
    
      | Oracle Linux 7 | cis:level:1:server | Level 1 - Server | 3.1.1 | 183 | 9 | 95% | Certified | 
    
      | Oracle Linux 7 | cis:level:2:server | Level 2 - Server | 3.1.1 | 211 | 14 | 94% | Certified | 
    
      | Oracle Linux 8 | cis:level:1:server | Level 1 - Server | 1.0.1 | 152 | 19 | 89% | Certified | 
    
      | Oracle Linux 8 | cis:level:2:server | Level 2 - Server | 1.0.1 | 186 | 26 | 88% | Certified | 
    
      | Red Hat Enterprise 7 | cis:level:1:server | Level 1 - Server | 3.1.1 | 183 | 9 | 95% | Certified | 
    
      | Red Hat Enterprise 7 | cis:level:2:server | Level 2 - Server | 3.1.1 | 211 | 14 | 94% | Certified | 
    
      | Red Hat Enterprise 8 | cis:level:1:server | Level 1 - Server | 1.0.1 | 153 | 18 | 89% | Certified | 
    
      | Red Hat Enterprise 8 | cis:level:2:server | Level 2 - Server | 1.0.1 | 187 | 25 | 88% | Certified | 
  
Control Coverage
The following report details the status of each CIS recommendation in the SIMP EE compliance data.
  - Paper policycontrols refer to organizational policy requirements and cannot be reasonably enforced by SIMP at this time.
- Mappedcontrols have enforcement and reporting support.
- Unmappedcontrols are not supported at this time.  A reason for the lack of support is provided for each unmapped control.
Summary
Detail
Paper Policy
The following controls require administrative documentation:
CentOS 8 (12/235 [5%])
  - oval:simp.cis.1.0.1.CentOS8.1.1.11_Ensure_separate_partition_exists_for_varlog:def:1
    
      - Title: Ensure separate partition exists for /var/log
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.1.0.1.CentOS8.1.1.12_Ensure_separate_partition_exists_for_varlogaudit:def:1
    
      - Title: Ensure separate partition exists for /var/log/audit
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.1.0.1.CentOS8.1.1.13_Ensure_separate_partition_exists_for_home:def:1
    
      - Title: Ensure separate partition exists for /home
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.1.0.1.CentOS8.1.1.6_Ensure_separate_partition_exists_for_var:def:1
    
      - Title: Ensure separate partition exists for /var
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.1.0.1.CentOS8.1.2.3_Ensure_package_manager_repositories_are_configured:def:1
    
      - Title: Ensure package manager repositories are configured
- NOTE: Package manager configuration is site-specific.
 
- oval:simp.cis.1.0.1.CentOS8.1.7.1.5_Ensure_no_unconfined_services_exist:def:1
    
      - Title: Ensure no unconfined services exist
- NOTE: We have no viable method of remediation.
 
- oval:simp.cis.1.0.1.CentOS8.6.1.10_Ensure_no_world_writable_files_exist:def:1
    
      - Title: Ensure no world writable files exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.1.0.1.CentOS8.6.1.11_Ensure_no_unowned_files_or_directories_exist:def:1
    
      - Title: Ensure no unowned files or directories exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.1.0.1.CentOS8.6.1.12_Ensure_no_ungrouped_files_or_directories_exist:def:1
    
      - Title: Ensure no ungrouped files or directories exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.1.0.1.CentOS8.6.1.13_Audit_SUID_executables:def:1
    
      - Title: Audit SUID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.1.0.1.CentOS8.6.1.14_Audit_SGID_executables:def:1
    
      - Title: Audit SGID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.1.0.1.CentOS8.6.1.1_Audit_system_file_permissions:def:1
    
      - Title: Audit system file permissions
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
        OracleLinux 8 (12/234 [5%])
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.11_Ensure_separate_partition_exists_for_varlog:def:1
    
      - Title: Ensure separate partition exists for /var/log
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.12_Ensure_separate_partition_exists_for_varlogaudit:def:1
    
      - Title: Ensure separate partition exists for /var/log/audit
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.13_Ensure_separate_partition_exists_for_home:def:1
    
      - Title: Ensure separate partition exists for /home
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.6_Ensure_separate_partition_exists_for_var:def:1
    
      - Title: Ensure separate partition exists for /var
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.1.0.1.OracleLinux8.1.2.3_Ensure_package_manager_repositories_are_configured:def:1
    
      - Title: Ensure package manager repositories are configured
- NOTE: Package manager configuration is site-specific.
 
- oval:simp.cis.1.0.1.OracleLinux8.1.7.1.5_Ensure_no_unconfined_services_exist:def:1
    
      - Title: Ensure no unconfined services exist
- NOTE: We have no viable method of remediation.
 
- oval:simp.cis.1.0.1.OracleLinux8.6.1.10_Ensure_no_world_writable_files_exist:def:1
    
      - Title: Ensure no world writable files exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.1.0.1.OracleLinux8.6.1.11_Ensure_no_unowned_files_or_directories_exist:def:1
    
      - Title: Ensure no unowned files or directories exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.1.0.1.OracleLinux8.6.1.12_Ensure_no_ungrouped_files_or_directories_exist:def:1
    
      - Title: Ensure no ungrouped files or directories exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.1.0.1.OracleLinux8.6.1.13_Audit_SUID_executables:def:1
    
      - Title: Audit SUID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.1.0.1.OracleLinux8.6.1.14_Audit_SGID_executables:def:1
    
      - Title: Audit SGID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.1.0.1.OracleLinux8.6.1.1_Audit_system_file_permissions:def:1
    
      - Title: Audit system file permissions
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
        RedHat 8 (13/236 [5%])
 
- oval:simp.cis.1.0.1.RedHat8.1.1.11_Ensure_separate_partition_exists_for_varlog:def:1
    
      - Title: Ensure separate partition exists for /var/log
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.1.0.1.RedHat8.1.1.12_Ensure_separate_partition_exists_for_varlogaudit:def:1
    
      - Title: Ensure separate partition exists for /var/log/audit
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.1.0.1.RedHat8.1.1.13_Ensure_separate_partition_exists_for_home:def:1
    
      - Title: Ensure separate partition exists for /home
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.1.0.1.RedHat8.1.1.6_Ensure_separate_partition_exists_for_var:def:1
    
      - Title: Ensure separate partition exists for /var
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.1.0.1.RedHat8.1.2.1_Ensure_Red_Hat_Subscription_Manager_connection_is_configured:def:1
    
      - Title: Ensure Red Hat Subscription Manager connection is configured
- NOTE: Package manager configuration is site-specific.
 
- oval:simp.cis.1.0.1.RedHat8.1.2.5_Ensure_package_manager_repositories_are_configured:def:1
    
      - Title: Ensure package manager repositories are configured
- NOTE: Package manager configuration is site-specific.
 
- oval:simp.cis.1.0.1.RedHat8.1.7.1.5_Ensure_no_unconfined_services_exist:def:1
    
      - Title: Ensure no unconfined services exist
- NOTE: We have no viable method of remediation.
 
- oval:simp.cis.1.0.1.RedHat8.6.1.10_Ensure_no_world_writable_files_exist:def:1
    
      - Title: Ensure no world writable files exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.1.0.1.RedHat8.6.1.11_Ensure_no_unowned_files_or_directories_exist:def:1
    
      - Title: Ensure no unowned files or directories exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.1.0.1.RedHat8.6.1.12_Ensure_no_ungrouped_files_or_directories_exist:def:1
    
      - Title: Ensure no ungrouped files or directories exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.1.0.1.RedHat8.6.1.13_Audit_SUID_executables:def:1
    
      - Title: Audit SUID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.1.0.1.RedHat8.6.1.14_Audit_SGID_executables:def:1
    
      - Title: Audit SGID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.1.0.1.RedHat8.6.1.1_Audit_system_file_permissions:def:1
    
      - Title: Audit system file permissions
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
        CentOS 7 (14/246 [5%])
 
- oval:simp.cis.3.1.1.CentOS7.1.1.10_Ensure_separate_partition_exists_for_var:def:1
    
      - Title: Ensure separate partition exists for /var
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.3.1.1.CentOS7.1.1.11_Ensure_separate_partition_exists_for_vartmp:def:1
    
      - Title: Ensure separate partition exists for /var/tmp
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.3.1.1.CentOS7.1.1.15_Ensure_separate_partition_exists_for_varlog:def:1
    
      - Title: Ensure separate partition exists for /var/log
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.3.1.1.CentOS7.1.1.16_Ensure_separate_partition_exists_for_varlogaudit:def:1
    
      - Title: Ensure separate partition exists for /var/log/audit
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.3.1.1.CentOS7.1.1.17_Ensure_separate_partition_exists_for_home:def:1
    
      - Title: Ensure separate partition exists for /home
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.3.1.1.CentOS7.1.2.2_Ensure_package_manager_repositories_are_configured:def:1
    
      - Title: Ensure package manager repositories are configured
- NOTE: Package manager configuration is site-specific.
 
- oval:simp.cis.3.1.1.CentOS7.1.5.2_Ensure_XDNX_support_is_enabled:def:1
    
      - Title: Ensure XD/NX support is enabled
- NOTE: We do not support 32-bit kernels.  Any additional remediation is at the hardware/BIOS level.
 
- oval:simp.cis.3.1.1.CentOS7.1.6.1.6_Ensure_no_unconfined_services_exist:def:1
    
      - Title: Ensure no unconfined services exist
- NOTE: We have no viable method of remediation.
 
- oval:simp.cis.3.1.1.CentOS7.6.1.10_Ensure_no_world_writable_files_exist:def:1
    
      - Title: Ensure no world writable files exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.3.1.1.CentOS7.6.1.11_Ensure_no_unowned_files_or_directories_exist:def:1
    
      - Title: Ensure no unowned files or directories exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.3.1.1.CentOS7.6.1.12_Ensure_no_ungrouped_files_or_directories_exist:def:1
    
      - Title: Ensure no ungrouped files or directories exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.3.1.1.CentOS7.6.1.13_Audit_SUID_executables:def:1
    
      - Title: Audit SUID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.3.1.1.CentOS7.6.1.14_Audit_SGID_executables:def:1
    
      - Title: Audit SGID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.3.1.1.CentOS7.6.1.1_Audit_system_file_permissions:def:1
    
      - Title: Audit system file permissions
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
        OracleLinux 7 (14/246 [5%])
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.10_Ensure_separate_partition_exists_for_var:def:1
    
      - Title: Ensure separate partition exists for /var
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.11_Ensure_separate_partition_exists_for_vartmp:def:1
    
      - Title: Ensure separate partition exists for /var/tmp
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.15_Ensure_separate_partition_exists_for_varlog:def:1
    
      - Title: Ensure separate partition exists for /var/log
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.16_Ensure_separate_partition_exists_for_varlogaudit:def:1
    
      - Title: Ensure separate partition exists for /var/log/audit
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.17_Ensure_separate_partition_exists_for_home:def:1
    
      - Title: Ensure separate partition exists for /home
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.3.1.1.OracleLinux7.1.2.2_Ensure_package_manager_repositories_are_configured:def:1
    
      - Title: Ensure package manager repositories are configured
- NOTE: Package manager configuration is site-specific.
 
- oval:simp.cis.3.1.1.OracleLinux7.1.5.2_Ensure_XDNX_support_is_enabled:def:1
    
      - Title: Ensure XD/NX support is enabled
- NOTE: We do not support 32-bit kernels.  Any additional remediation is at the hardware/BIOS level.
 
- oval:simp.cis.3.1.1.OracleLinux7.1.6.1.6_Ensure_no_unconfined_services_exist:def:1
    
      - Title: Ensure no unconfined services exist
- NOTE: We have no viable method of remediation.
 
- oval:simp.cis.3.1.1.OracleLinux7.6.1.10_Ensure_no_world_writable_files_exist:def:1
    
      - Title: Ensure no world writable files exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.3.1.1.OracleLinux7.6.1.11_Ensure_no_unowned_files_or_directories_exist:def:1
    
      - Title: Ensure no unowned files or directories exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.3.1.1.OracleLinux7.6.1.12_Ensure_no_ungrouped_files_or_directories_exist:def:1
    
      - Title: Ensure no ungrouped files or directories exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.3.1.1.OracleLinux7.6.1.13_Audit_SUID_executables:def:1
    
      - Title: Audit SUID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.3.1.1.OracleLinux7.6.1.14_Audit_SGID_executables:def:1
    
      - Title: Audit SGID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.3.1.1.OracleLinux7.6.1.1_Audit_system_file_permissions:def:1
    
      - Title: Audit system file permissions
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
        RedHat 7 (15/248 [6%])
 
- oval:simp.cis.3.1.1.RedHat7.1.1.10_Ensure_separate_partition_exists_for_var:def:1
    
      - Title: Ensure separate partition exists for /var
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.3.1.1.RedHat7.1.1.11_Ensure_separate_partition_exists_for_vartmp:def:1
    
      - Title: Ensure separate partition exists for /var/tmp
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.3.1.1.RedHat7.1.1.15_Ensure_separate_partition_exists_for_varlog:def:1
    
      - Title: Ensure separate partition exists for /var/log
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.3.1.1.RedHat7.1.1.16_Ensure_separate_partition_exists_for_varlogaudit:def:1
    
      - Title: Ensure separate partition exists for /var/log/audit
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.3.1.1.RedHat7.1.1.17_Ensure_separate_partition_exists_for_home:def:1
    
      - Title: Ensure separate partition exists for /home
- NOTE: There is no way to safely change this on a running system.
 
- oval:simp.cis.3.1.1.RedHat7.1.2.2_Ensure_package_manager_repositories_are_configured:def:1
    
      - Title: Ensure package manager repositories are configured
- NOTE: Package manager configuration is site-specific.
 
- oval:simp.cis.3.1.1.RedHat7.1.2.4_Ensure_Red_Hat_Subscription_Manager_connection_is_configured:def:1
    
      - Title: Ensure Red Hat Subscription Manager connection is configured
- NOTE: Package manager configuration is site-specific.
 
- oval:simp.cis.3.1.1.RedHat7.1.5.2_Ensure_XDNX_support_is_enabled:def:1
    
      - Title: Ensure XD/NX support is enabled
- NOTE: We do not support 32-bit kernels.  Any additional remediation is at the hardware/BIOS level.
 
- oval:simp.cis.3.1.1.RedHat7.1.6.1.6_Ensure_no_unconfined_services_exist:def:1
    
      - Title: Ensure no unconfined services exist
- NOTE: We have no viable method of remediation.
 
- oval:simp.cis.3.1.1.RedHat7.6.1.10_Ensure_no_world_writable_files_exist:def:1
    
      - Title: Ensure no world writable files exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.3.1.1.RedHat7.6.1.11_Ensure_no_unowned_files_or_directories_exist:def:1
    
      - Title: Ensure no unowned files or directories exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.3.1.1.RedHat7.6.1.12_Ensure_no_ungrouped_files_or_directories_exist:def:1
    
      - Title: Ensure no ungrouped files or directories exist
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.3.1.1.RedHat7.6.1.13_Audit_SUID_executables:def:1
    
      - Title: Audit SUID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.3.1.1.RedHat7.6.1.14_Audit_SGID_executables:def:1
    
      - Title: Audit SGID executables
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
- oval:simp.cis.3.1.1.RedHat7.6.1.1_Audit_system_file_permissions:def:1
    
      - Title: Audit system file permissions
- NOTE: We do not currently have a mechanism for scanning the filesystem for enforcement.
 
Mapped
The following controls are mapped:
CentOS 8 (223/235 [94%])
  - oval:simp.cis.1.0.1.CentOS8.1.1.1.1_Ensure_mounting_of_cramfs_filesystems_is_disabled:def:1
    
      - Title: Ensure mounting of cramfs filesystems is disabled
 
- oval:simp.cis.1.0.1.CentOS8.1.1.1.2_Ensure_mounting_of_vFAT_filesystems_is_limited:def:1
    
      - Title: Ensure mounting of vFAT filesystems is limited
 
- oval:simp.cis.1.0.1.CentOS8.1.1.1.3_Ensure_mounting_of_squashfs_filesystems_is_disabled:def:1
    
      - Title: Ensure mounting of squashfs filesystems is disabled
 
- oval:simp.cis.1.0.1.CentOS8.1.1.1.4_Ensure_mounting_of_udf_filesystems_is_disabled:def:1
    
      - Title: Ensure mounting of udf filesystems is disabled
 
- oval:simp.cis.1.0.1.CentOS8.1.1.10_Ensure_noexec_option_set_on_vartmp_partition:def:1
    
      - Title: Ensure noexec option set on /var/tmp partition
 
- oval:simp.cis.1.0.1.CentOS8.1.1.14_Ensure_nodev_option_set_on_home_partition:def:1
    
      - Title: Ensure nodev option set on /home partition
 
- oval:simp.cis.1.0.1.CentOS8.1.1.15_Ensure_nodev_option_set_on_devshm_partition:def:1
    
      - Title: Ensure nodev option set on /dev/shm partition
 
- oval:simp.cis.1.0.1.CentOS8.1.1.16_Ensure_nosuid_option_set_on_devshm_partition:def:1
    
      - Title: Ensure nosuid option set on /dev/shm partition
 
- oval:simp.cis.1.0.1.CentOS8.1.1.17_Ensure_noexec_option_set_on_devshm_partition:def:1
    
      - Title: Ensure noexec option set on /dev/shm partition
 
- oval:simp.cis.1.0.1.CentOS8.1.1.18_Ensure_nodev_option_set_on_removable_media_partitions:def:1
    
      - Title: Ensure nodev option set on removable media partitions
 
- oval:simp.cis.1.0.1.CentOS8.1.1.19_Ensure_nosuid_option_set_on_removable_media_partitions:def:1
    
      - Title: Ensure nosuid option set on removable media partitions
 
- oval:simp.cis.1.0.1.CentOS8.1.1.20_Ensure_noexec_option_set_on_removable_media_partitions:def:1
    
      - Title: Ensure noexec option set on removable media partitions
 
- oval:simp.cis.1.0.1.CentOS8.1.1.21_Ensure_sticky_bit_is_set_on_all_world-writable_directories:def:1
    
      - Title: Ensure sticky bit is set on all world-writable directories
 
- oval:simp.cis.1.0.1.CentOS8.1.1.22_Disable_Automounting:def:1
    
      - Title: Disable Automounting
 
- oval:simp.cis.1.0.1.CentOS8.1.1.23_Disable_USB_Storage:def:1
    
      - Title: Disable USB Storage
 
- oval:simp.cis.1.0.1.CentOS8.1.1.2_Ensure_tmp_is_configured:def:1
    
      - Title: Ensure /tmp is configured
 
- oval:simp.cis.1.0.1.CentOS8.1.1.3_Ensure_nodev_option_set_on_tmp_partition:def:1
    
      - Title: Ensure nodev option set on /tmp partition
 
- oval:simp.cis.1.0.1.CentOS8.1.1.4_Ensure_nosuid_option_set_on_tmp_partition:def:1
    
      - Title: Ensure nosuid option set on /tmp partition
 
- oval:simp.cis.1.0.1.CentOS8.1.1.5_Ensure_noexec_option_set_on_tmp_partition:def:1
    
      - Title: Ensure noexec option set on /tmp partition
 
- oval:simp.cis.1.0.1.CentOS8.1.1.7_Ensure_separate_partition_exists_for_vartmp:def:1
    
      - Title: Ensure separate partition exists for /var/tmp
 
- oval:simp.cis.1.0.1.CentOS8.1.1.8_Ensure_nodev_option_set_on_vartmp_partition:def:1
    
      - Title: Ensure nodev option set on /var/tmp partition
 
- oval:simp.cis.1.0.1.CentOS8.1.1.9_Ensure_nosuid_option_set_on_vartmp_partition:def:1
    
      - Title: Ensure nosuid option set on /var/tmp partition
 
- oval:simp.cis.1.0.1.CentOS8.1.10_Ensure_system-wide_crypto_policy_is_not_legacy:def:1
    
      - Title: Ensure system-wide crypto policy is not legacy
 
- oval:simp.cis.1.0.1.CentOS8.1.11_Ensure_system-wide_crypto_policy_is_FUTURE_or_FIPS:def:1
    
      - Title: Ensure system-wide crypto policy is FUTURE or FIPS
 
- oval:simp.cis.1.0.1.CentOS8.1.2.1_Ensure_GPG_keys_are_configured:def:1
    
      - Title: Ensure GPG keys are configured
 
- oval:simp.cis.1.0.1.CentOS8.1.2.2_Ensure_gpgcheck_is_globally_activated:def:1
    
      - Title: Ensure gpgcheck is globally activated
 
- oval:simp.cis.1.0.1.CentOS8.1.3.1_Ensure_sudo_is_installed:def:1
    
      - Title: Ensure sudo is installed
 
- oval:simp.cis.1.0.1.CentOS8.1.3.2_Ensure_sudo_commands_use_pty:def:1
    
      - Title: Ensure sudo commands use pty
 
- oval:simp.cis.1.0.1.CentOS8.1.3.3_Ensure_sudo_log_file_exists:def:1
    
      - Title: Ensure sudo log file exists
 
- oval:simp.cis.1.0.1.CentOS8.1.4.1_Ensure_AIDE_is_installed:def:1
    
      - Title: Ensure AIDE is installed
 
- oval:simp.cis.1.0.1.CentOS8.1.4.2_Ensure_filesystem_integrity_is_regularly_checked:def:1
    
      - Title: Ensure filesystem integrity is regularly checked
 
- oval:simp.cis.1.0.1.CentOS8.1.5.1_Ensure_permissions_on_bootloader_config_are_configured:def:1
    
      - Title: Ensure permissions on bootloader config are configured
 
- oval:simp.cis.1.0.1.CentOS8.1.5.2_Ensure_bootloader_password_is_set:def:1
    
      - Title: Ensure bootloader password is set
 
- oval:simp.cis.1.0.1.CentOS8.1.5.3_Ensure_authentication_required_for_single_user_mode:def:1
    
      - Title: Ensure authentication required for single user mode
 
- oval:simp.cis.1.0.1.CentOS8.1.6.1_Ensure_core_dumps_are_restricted:def:1
    
      - Title: Ensure core dumps are restricted
 
- oval:simp.cis.1.0.1.CentOS8.1.6.2_Ensure_address_space_layout_randomization_ASLR_is_enabled:def:1
    
      - Title: Ensure address space layout randomization (ASLR) is enabled
 
- oval:simp.cis.1.0.1.CentOS8.1.7.1.1_Ensure_SELinux_is_installed:def:1
    
      - Title: Ensure SELinux is installed
 
- oval:simp.cis.1.0.1.CentOS8.1.7.1.2_Ensure_SELinux_is_not_disabled_in_bootloader_configuration:def:1
    
      - Title: Ensure SELinux is not disabled in bootloader configuration
 
- oval:simp.cis.1.0.1.CentOS8.1.7.1.3_Ensure_SELinux_policy_is_configured:def:1
    
      - Title: Ensure SELinux policy is configured
 
- oval:simp.cis.1.0.1.CentOS8.1.7.1.4_Ensure_the_SELinux_state_is_enforcing:def:1
    
      - Title: Ensure the SELinux state is enforcing
 
- oval:simp.cis.1.0.1.CentOS8.1.7.1.6_Ensure_SETroubleshoot_is_not_installed:def:1
    
      - Title: Ensure SETroubleshoot is not installed
 
- oval:simp.cis.1.0.1.CentOS8.1.7.1.7_Ensure_the_MCS_Translation_Service_mcstrans_is_not_installed:def:1
    
      - Title: Ensure the MCS Translation Service (mcstrans) is not installed
 
- oval:simp.cis.1.0.1.CentOS8.1.8.1.1_Ensure_message_of_the_day_is_configured_properly:def:1
    
      - Title: Ensure message of the day is configured properly
 
- oval:simp.cis.1.0.1.CentOS8.1.8.1.2_Ensure_local_login_warning_banner_is_configured_properly:def:1
    
      - Title: Ensure local login warning banner is configured properly
 
- oval:simp.cis.1.0.1.CentOS8.1.8.1.3_Ensure_remote_login_warning_banner_is_configured_properly:def:1
    
      - Title: Ensure remote login warning banner is configured properly
 
- oval:simp.cis.1.0.1.CentOS8.1.8.1.4_Ensure_permissions_on_etcmotd_are_configured:def:1
    
      - Title: Ensure permissions on /etc/motd are configured
 
- oval:simp.cis.1.0.1.CentOS8.1.8.1.5_Ensure_permissions_on_etcissue_are_configured:def:1
    
      - Title: Ensure permissions on /etc/issue are configured
 
- oval:simp.cis.1.0.1.CentOS8.1.8.1.6_Ensure_permissions_on_etcissue.net_are_configured:def:1
    
      - Title: Ensure permissions on /etc/issue.net are configured
 
- oval:simp.cis.1.0.1.CentOS8.1.8.2_Ensure_GDM_login_banner_is_configured:def:1
    
      - Title: Ensure GDM login banner is configured
 
- oval:simp.cis.1.0.1.CentOS8.1.9_Ensure_updates_patches_and_additional_security_software_are_installed:def:1
    
      - Title: Ensure updates, patches, and additional security software are installed
 
- oval:simp.cis.1.0.1.CentOS8.2.1.1_Ensure_xinetd_is_not_installed:def:1
    
      - Title: Ensure xinetd is not installed
 
- oval:simp.cis.1.0.1.CentOS8.2.2.1.1_Ensure_time_synchronization_is_in_use:def:1
    
      - Title: Ensure time synchronization is in use
 
- oval:simp.cis.1.0.1.CentOS8.2.2.1.2_Ensure_chrony_is_configured:def:1
    
      - Title: Ensure chrony is configured
 
- oval:simp.cis.1.0.1.CentOS8.2.2.10_Ensure_FTP_Server_is_not_enabled:def:1
    
      - Title: Ensure FTP Server is not enabled
 
- oval:simp.cis.1.0.1.CentOS8.2.2.11_Ensure_DNS_Server_is_not_enabled:def:1
    
      - Title: Ensure DNS Server is not enabled
 
- oval:simp.cis.1.0.1.CentOS8.2.2.12_Ensure_NFS_is_not_enabled:def:1
    
      - Title: Ensure NFS is not enabled
 
- oval:simp.cis.1.0.1.CentOS8.2.2.13_Ensure__RPC_is_not_enabled:def:1
    
      - Title: Ensure RPC is not enabled
 
- oval:simp.cis.1.0.1.CentOS8.2.2.14_Ensure_LDAP_server_is_not_enabled:def:1
    
      - Title: Ensure LDAP server is not enabled
 
- oval:simp.cis.1.0.1.CentOS8.2.2.15_Ensure_DHCP_Server_is_not_enabled:def:1
    
      - Title: Ensure DHCP Server is not enabled
 
- oval:simp.cis.1.0.1.CentOS8.2.2.16_Ensure_CUPS_is_not_enabled:def:1
    
      - Title: Ensure CUPS is not enabled
 
- oval:simp.cis.1.0.1.CentOS8.2.2.17_Ensure_NIS_Server_is_not_enabled:def:1
    
      - Title: Ensure NIS Server is not enabled
 
- oval:simp.cis.1.0.1.CentOS8.2.2.18_Ensure_mail_transfer_agent_is_configured_for_local-only_mode:def:1
    
      - Title: Ensure mail transfer agent is configured for local-only mode
 
- oval:simp.cis.1.0.1.CentOS8.2.2.2_Ensure_X_Window_System_is_not_installed:def:1
    
      - Title: Ensure X Window System is not installed
 
- oval:simp.cis.1.0.1.CentOS8.2.2.3_Ensure_rsync_service_is_not_enabled:def:1
    
      - Title: Ensure rsync service is not enabled
 
- oval:simp.cis.1.0.1.CentOS8.2.2.4_Ensure_Avahi_Server_is_not_enabled:def:1
    
      - Title: Ensure Avahi Server is not enabled
 
- oval:simp.cis.1.0.1.CentOS8.2.2.5_Ensure_SNMP_Server_is_not_enabled:def:1
    
      - Title: Ensure SNMP Server is not enabled
 
- oval:simp.cis.1.0.1.CentOS8.2.2.6_Ensure_HTTP_Proxy_Server_is_not_enabled:def:1
    
      - Title: Ensure HTTP Proxy Server is not enabled
 
- oval:simp.cis.1.0.1.CentOS8.2.2.7_Ensure_Samba_is_not_enabled:def:1
    
      - Title: Ensure Samba is not enabled
 
- oval:simp.cis.1.0.1.CentOS8.2.2.8_Ensure_IMAP_and_POP3_server_is_not_enabled:def:1
    
      - Title: Ensure IMAP and POP3 server is not enabled
 
- oval:simp.cis.1.0.1.CentOS8.2.2.9_Ensure_HTTP_server_is_not_enabled:def:1
    
      - Title: Ensure HTTP server is not enabled
 
- oval:simp.cis.1.0.1.CentOS8.2.3.1_Ensure_NIS_Client_is_not_installed:def:1
    
      - Title: Ensure NIS Client is not installed
 
- oval:simp.cis.1.0.1.CentOS8.2.3.2_Ensure_telnet_client_is_not_installed:def:1
    
      - Title: Ensure telnet client is not installed
 
- oval:simp.cis.1.0.1.CentOS8.2.3.3_Ensure_LDAP_client_is_not_installed:def:1
    
      - Title: Ensure LDAP client is not installed
 
- oval:simp.cis.1.0.1.CentOS8.3.1.1_Ensure_IP_forwarding_is_disabled:def:1
    
      - Title: Ensure IP forwarding is disabled
 
- oval:simp.cis.1.0.1.CentOS8.3.1.2_Ensure_packet_redirect_sending_is_disabled:def:1
    
      - Title: Ensure packet redirect sending is disabled
 
- oval:simp.cis.1.0.1.CentOS8.3.2.1_Ensure_source_routed_packets_are_not_accepted:def:1
    
      - Title: Ensure source routed packets are not accepted
 
- oval:simp.cis.1.0.1.CentOS8.3.2.2_Ensure_ICMP_redirects_are_not_accepted:def:1
    
      - Title: Ensure ICMP redirects are not accepted
 
- oval:simp.cis.1.0.1.CentOS8.3.2.3_Ensure_secure_ICMP_redirects_are_not_accepted:def:1
    
      - Title: Ensure secure ICMP redirects are not accepted
 
- oval:simp.cis.1.0.1.CentOS8.3.2.4_Ensure_suspicious_packets_are_logged:def:1
    
      - Title: Ensure suspicious packets are logged
 
- oval:simp.cis.1.0.1.CentOS8.3.2.5_Ensure_broadcast_ICMP_requests_are_ignored:def:1
    
      - Title: Ensure broadcast ICMP requests are ignored
 
- oval:simp.cis.1.0.1.CentOS8.3.2.6_Ensure_bogus_ICMP_responses_are_ignored:def:1
    
      - Title: Ensure bogus ICMP responses are ignored
 
- oval:simp.cis.1.0.1.CentOS8.3.2.7_Ensure_Reverse_Path_Filtering_is_enabled:def:1
    
      - Title: Ensure Reverse Path Filtering is enabled
 
- oval:simp.cis.1.0.1.CentOS8.3.2.8_Ensure_TCP_SYN_Cookies_is_enabled:def:1
    
      - Title: Ensure TCP SYN Cookies is enabled
 
- oval:simp.cis.1.0.1.CentOS8.3.2.9_Ensure_IPv6_router_advertisements_are_not_accepted:def:1
    
      - Title: Ensure IPv6 router advertisements are not accepted
 
- oval:simp.cis.1.0.1.CentOS8.3.3.1_Ensure_DCCP_is_disabled:def:1
    
      - Title: Ensure DCCP is disabled
 
- oval:simp.cis.1.0.1.CentOS8.3.3.2_Ensure_SCTP_is_disabled:def:1
    
      - Title: Ensure SCTP is disabled
 
- oval:simp.cis.1.0.1.CentOS8.3.3.3_Ensure_RDS_is_disabled:def:1
    
      - Title: Ensure RDS is disabled
 
- oval:simp.cis.1.0.1.CentOS8.3.3.4_Ensure_TIPC_is_disabled:def:1
    
      - Title: Ensure TIPC is disabled
 
- oval:simp.cis.1.0.1.CentOS8.3.4.1.1_Ensure_a_Firewall_package_is_installed:def:1
    
      - Title: Ensure a Firewall package is installed
 
- oval:simp.cis.1.0.1.CentOS8.3.4.2.1_Ensure_firewalld_service_is_enabled_and_running:def:1
    
      - Title: Ensure firewalld service is enabled and running
 
- oval:simp.cis.1.0.1.CentOS8.3.4.2.2_Ensure_iptables_service_is_not_enabled_with_firewalld:def:1
    
      - Title: Ensure iptables service is not enabled with firewalld
 
- oval:simp.cis.1.0.1.CentOS8.3.4.2.3_Ensure_nftables_is_not_enabled_with_firewalld:def:1
    
      - Title: Ensure nftables is not enabled with firewalld
 
- oval:simp.cis.1.0.1.CentOS8.3.4.2.4_Ensure_firewalld_default_zone_is_set:def:1
    
      - Title: Ensure firewalld default zone is set
 
- oval:simp.cis.1.0.1.CentOS8.3.4.2.5_Ensure_network_interfaces_are_assigned_to_appropriate_zone:def:1
    
      - Title: Ensure network interfaces are assigned to appropriate zone
 
- oval:simp.cis.1.0.1.CentOS8.3.4.2.6_Ensure_firewalld_drops_unnecessary_services_and_ports:def:1
    
      - Title: Ensure firewalld drops unnecessary services and ports
 
- oval:simp.cis.1.0.1.CentOS8.3.4.3.1_Ensure_iptables_are_flushed_with_nftables:def:1
    
      - Title: Ensure iptables are flushed with nftables
 
- oval:simp.cis.1.0.1.CentOS8.3.4.3.2_Ensure_an_nftables_table_exists:def:1
    
      - Title: Ensure an nftables table exists
 
- oval:simp.cis.1.0.1.CentOS8.3.4.3.3_Ensure_nftables_base_chains_exist:def:1
    
      - Title: Ensure nftables base chains exist
 
- oval:simp.cis.1.0.1.CentOS8.3.4.3.4_Ensure_nftables_loopback_traffic_is_configured:def:1
    
      - Title: Ensure nftables loopback traffic is configured
 
- oval:simp.cis.1.0.1.CentOS8.3.4.3.5_Ensure_nftables_outbound_and_established_connections_are_configured:def:1
    
      - Title: Ensure nftables outbound and established connections are configured
 
- oval:simp.cis.1.0.1.CentOS8.3.4.3.6_Ensure_nftables_default_deny_firewall_policy:def:1
    
      - Title: Ensure nftables default deny firewall policy
 
- oval:simp.cis.1.0.1.CentOS8.3.4.3.7_Ensure_nftables_service_is_enabled:def:1
    
      - Title: Ensure nftables service is enabled
 
- oval:simp.cis.1.0.1.CentOS8.3.4.3.8_Ensure_nftables_rules_are_permanent:def:1
    
      - Title: Ensure nftables rules are permanent
 
- oval:simp.cis.1.0.1.CentOS8.3.4.4.1.1_Ensure_iptables_default_deny_firewall_policy:def:1
    
      - Title: Ensure iptables default deny firewall policy
 
- oval:simp.cis.1.0.1.CentOS8.3.4.4.1.2_Ensure_iptables_loopback_traffic_is_configured:def:1
    
      - Title: Ensure iptables loopback traffic is configured
 
- oval:simp.cis.1.0.1.CentOS8.3.4.4.1.3_Ensure_iptables_outbound_and_established_connections_are_configured:def:1
    
      - Title: Ensure iptables outbound and established connections are configured
 
- oval:simp.cis.1.0.1.CentOS8.3.4.4.1.4_Ensure_iptables_firewall_rules_exist_for_all_open_ports:def:1
    
      - Title: Ensure iptables firewall rules exist for all open ports
 
- oval:simp.cis.1.0.1.CentOS8.3.4.4.1.5_Ensure_iptables_is_enabled_and_active:def:1
    
      - Title: Ensure iptables is enabled and active
 
- oval:simp.cis.1.0.1.CentOS8.3.4.4.1.6_Ensure_iptables_is_enabled_and_active:def:1
    
      - Title: Ensure iptables is enabled and active
 
- oval:simp.cis.1.0.1.CentOS8.3.4.4.2.1_Ensure_ip6tables_default_deny_firewall_policy:def:1
    
      - Title: Ensure ip6tables default deny firewall policy
 
- oval:simp.cis.1.0.1.CentOS8.3.4.4.2.2_Ensure_ip6tables_loopback_traffic_is_configured:def:1
    
      - Title: Ensure ip6tables loopback traffic is configured
 
- oval:simp.cis.1.0.1.CentOS8.3.4.4.2.3_Ensure_ip6tables_outbound_and_established_connections_are_configured:def:1
    
      - Title: Ensure ip6tables outbound and established connections are configured
 
- oval:simp.cis.1.0.1.CentOS8.3.4.4.2.4_Ensure_ip6tables_firewall_rules_exist_for_all_open_ports:def:1
    
      - Title: Ensure ip6tables firewall rules exist for all open ports
 
- oval:simp.cis.1.0.1.CentOS8.3.4.4.2.5_Ensure_ip6tables_is_enabled_and_active:def:1
    
      - Title: Ensure ip6tables is enabled and active
 
- oval:simp.cis.1.0.1.CentOS8.3.5_Ensure_wireless_interfaces_are_disabled:def:1
    
      - Title: Ensure wireless interfaces are disabled
 
- oval:simp.cis.1.0.1.CentOS8.3.6_Disable_IPv6:def:1
    
      - Title: Disable IPv6
- NOTE: Disabled via sysctl instead of kernel command line
 
- oval:simp.cis.1.0.1.CentOS8.4.1.1.1_Ensure_auditd_is_installed:def:1
    
      - Title: Ensure auditd is installed
 
- oval:simp.cis.1.0.1.CentOS8.4.1.1.2_Ensure_auditd_service_is_enabled:def:1
    
      - Title: Ensure auditd service is enabled
 
- oval:simp.cis.1.0.1.CentOS8.4.1.1.3_Ensure_auditing_for_processes_that_start_prior_to_auditd_is_enabled:def:1
    
      - Title: Ensure auditing for processes that start prior to auditd is enabled
 
- oval:simp.cis.1.0.1.CentOS8.4.1.1.4_Ensure_audit_backlog_limit_is_sufficient:def:1
    
      - Title: Ensure audit_backlog_limit is sufficient
 
- oval:simp.cis.1.0.1.CentOS8.4.1.10_Ensure_unsuccessful_unauthorized_file_access_attempts_are_collected:def:1
    
      - Title: Ensure unsuccessful unauthorized file access attempts are collected
 
- oval:simp.cis.1.0.1.CentOS8.4.1.11_Ensure_events_that_modify_usergroup_information_are_collected:def:1
    
      - Title: Ensure events that modify user/group information are collected
 
- oval:simp.cis.1.0.1.CentOS8.4.1.12_Ensure_successful_file_system_mounts_are_collected:def:1
    
      - Title: Ensure successful file system mounts are collected
 
- oval:simp.cis.1.0.1.CentOS8.4.1.13_Ensure_use_of_privileged_commands_is_collected:def:1
    
      - Title: Ensure use of privileged commands is collected
 
- oval:simp.cis.1.0.1.CentOS8.4.1.14_Ensure_file_deletion_events_by_users_are_collected:def:1
    
      - Title: Ensure file deletion events by users are collected
 
- oval:simp.cis.1.0.1.CentOS8.4.1.15_Ensure_kernel_module_loading_and_unloading_is_collected:def:1
    
      - Title: Ensure kernel module loading and unloading is collected
 
- oval:simp.cis.1.0.1.CentOS8.4.1.16_Ensure_system_administrator_actions_sudolog_are_collected:def:1
    
      - Title: Ensure system administrator actions (sudolog) are collected
 
- oval:simp.cis.1.0.1.CentOS8.4.1.17_Ensure_the_audit_configuration_is_immutable:def:1
    
      - Title: Ensure the audit configuration is immutable
 
- oval:simp.cis.1.0.1.CentOS8.4.1.2.1_Ensure_audit_log_storage_size_is_configured:def:1
    
      - Title: Ensure audit log storage size is configured
 
- oval:simp.cis.1.0.1.CentOS8.4.1.2.2_Ensure_audit_logs_are_not_automatically_deleted:def:1
    
      - Title: Ensure audit logs are not automatically deleted
 
- oval:simp.cis.1.0.1.CentOS8.4.1.2.3_Ensure_system_is_disabled_when_audit_logs_are_full:def:1
    
      - Title: Ensure system is disabled when audit logs are full
 
- oval:simp.cis.1.0.1.CentOS8.4.1.3_Ensure_changes_to_system_administration_scope_sudoers_is_collected:def:1
    
      - Title: Ensure changes to system administration scope (sudoers) is collected
 
- oval:simp.cis.1.0.1.CentOS8.4.1.4_Ensure_login_and_logout_events_are_collected:def:1
    
      - Title: Ensure login and logout events are collected
 
- oval:simp.cis.1.0.1.CentOS8.4.1.5_Ensure_session_initiation_information_is_collected:def:1
    
      - Title: Ensure session initiation information is collected
 
- oval:simp.cis.1.0.1.CentOS8.4.1.6_Ensure_events_that_modify_date_and_time_information_are_collected:def:1
    
      - Title: Ensure events that modify date and time information are collected
 
- oval:simp.cis.1.0.1.CentOS8.4.1.7_Ensure_events_that_modify_the_systems_Mandatory_Access_Controls_are_collected:def:1
    
      - Title: Ensure events that modify the system’s Mandatory Access Controls are collected
 
- oval:simp.cis.1.0.1.CentOS8.4.1.8_Ensure_events_that_modify_the_systems_network_environment_are_collected:def:1
    
      - Title: Ensure events that modify the system’s network environment are collected
 
- oval:simp.cis.1.0.1.CentOS8.4.1.9_Ensure_discretionary_access_control_permission_modification_events_are_collected:def:1
    
      - Title: Ensure discretionary access control permission modification events are collected
 
- oval:simp.cis.1.0.1.CentOS8.4.2.1.1_Ensure_rsyslog_is_installed:def:1
    
      - Title: Ensure rsyslog is installed
 
- oval:simp.cis.1.0.1.CentOS8.4.2.1.2_Ensure_rsyslog_Service_is_enabled:def:1
    
      - Title: Ensure rsyslog Service is enabled
 
- oval:simp.cis.1.0.1.CentOS8.4.2.1.3_Ensure_rsyslog_default_file_permissions_configured:def:1
    
      - Title: Ensure rsyslog default file permissions configured
 
- oval:simp.cis.1.0.1.CentOS8.4.2.1.4_Ensure_logging_is_configured:def:1
    
      - Title: Ensure logging is configured
 
- oval:simp.cis.1.0.1.CentOS8.4.2.1.5_Ensure_rsyslog_is_configured_to_send_logs_to_a_remote_log_host:def:1
    
      - Title: Ensure rsyslog is configured to send logs to a remote log host
 
- oval:simp.cis.1.0.1.CentOS8.4.2.1.6_Ensure_remote_rsyslog_messages_are_only_accepted_on_designated_log_hosts.:def:1
    
      - Title: Ensure remote rsyslog messages are only accepted on designated log hosts.
 
- oval:simp.cis.1.0.1.CentOS8.4.2.2.1_Ensure_journald_is_configured_to_send_logs_to_rsyslog:def:1
    
      - Title: Ensure journald is configured to send logs to rsyslog
 
- oval:simp.cis.1.0.1.CentOS8.4.2.2.2_Ensure_journald_is_configured_to_compress_large_log_files:def:1
    
      - Title: Ensure journald is configured to compress large log files
 
- oval:simp.cis.1.0.1.CentOS8.4.2.2.3_Ensure_journald_is_configured_to_write_logfiles_to_persistent_disk:def:1
    
      - Title: Ensure journald is configured to write logfiles to persistent disk
 
- oval:simp.cis.1.0.1.CentOS8.4.2.3_Ensure_permissions_on_all_logfiles_are_configured:def:1
    
      - Title: Ensure permissions on all logfiles are configured
 
- oval:simp.cis.1.0.1.CentOS8.4.3_Ensure_logrotate_is_configured:def:1
    
      - Title: Ensure logrotate is configured
 
- oval:simp.cis.1.0.1.CentOS8.5.1.1_Ensure_cron_daemon_is_enabled:def:1
    
      - Title: Ensure cron daemon is enabled
 
- oval:simp.cis.1.0.1.CentOS8.5.1.2_Ensure_permissions_on_etccrontab_are_configured:def:1
    
      - Title: Ensure permissions on /etc/crontab are configured
 
- oval:simp.cis.1.0.1.CentOS8.5.1.3_Ensure_permissions_on_etccron.hourly_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.hourly are configured
 
- oval:simp.cis.1.0.1.CentOS8.5.1.4_Ensure_permissions_on_etccron.daily_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.daily are configured
 
- oval:simp.cis.1.0.1.CentOS8.5.1.5_Ensure_permissions_on_etccron.weekly_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.weekly are configured
 
- oval:simp.cis.1.0.1.CentOS8.5.1.6_Ensure_permissions_on_etccron.monthly_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.monthly are configured
 
- oval:simp.cis.1.0.1.CentOS8.5.1.7_Ensure_permissions_on_etccron.d_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.d are configured
 
- oval:simp.cis.1.0.1.CentOS8.5.1.8_Ensure_atcron_is_restricted_to_authorized_users:def:1
    
      - Title: Ensure at/cron is restricted to authorized users
 
- oval:simp.cis.1.0.1.CentOS8.5.2.10_Ensure_SSH_root_login_is_disabled:def:1
    
      - Title: Ensure SSH root login is disabled
 
- oval:simp.cis.1.0.1.CentOS8.5.2.11_Ensure_SSH_PermitEmptyPasswords_is_disabled:def:1
    
      - Title: Ensure SSH PermitEmptyPasswords is disabled
 
- oval:simp.cis.1.0.1.CentOS8.5.2.12_Ensure_SSH_PermitUserEnvironment_is_disabled:def:1
    
      - Title: Ensure SSH PermitUserEnvironment is disabled
 
- oval:simp.cis.1.0.1.CentOS8.5.2.13_Ensure_SSH_Idle_Timeout_Interval_is_configured:def:1
    
      - Title: Ensure SSH Idle Timeout Interval is configured
 
- oval:simp.cis.1.0.1.CentOS8.5.2.14_Ensure_SSH_LoginGraceTime_is_set_to_one_minute_or_less:def:1
    
      - Title: Ensure SSH LoginGraceTime is set to one minute or less
 
- oval:simp.cis.1.0.1.CentOS8.5.2.15_Ensure_SSH_warning_banner_is_configured:def:1
    
      - Title: Ensure SSH warning banner is configured
 
- oval:simp.cis.1.0.1.CentOS8.5.2.16_Ensure_SSH_PAM_is_enabled:def:1
    
      - Title: Ensure SSH PAM is enabled
 
- oval:simp.cis.1.0.1.CentOS8.5.2.17_Ensure_SSH_AllowTcpForwarding_is_disabled:def:1
    
      - Title: Ensure SSH AllowTcpForwarding is disabled
 
- oval:simp.cis.1.0.1.CentOS8.5.2.18_Ensure_SSH_MaxStartups_is_configured:def:1
    
      - Title: Ensure SSH MaxStartups is configured
 
- oval:simp.cis.1.0.1.CentOS8.5.2.19_Ensure_SSH_MaxSessions_is_set_to_4_or_less:def:1
    
      - Title: Ensure SSH MaxSessions is set to 4 or less
 
- oval:simp.cis.1.0.1.CentOS8.5.2.1_Ensure_permissions_on_etcsshsshd_config_are_configured:def:1
    
      - Title: Ensure permissions on /etc/ssh/sshd_config are configured
 
- oval:simp.cis.1.0.1.CentOS8.5.2.20_Ensure_system-wide_crypto_policy_is_not_over-ridden:def:1
    
      - Title: Ensure system-wide crypto policy is not over-ridden
 
- oval:simp.cis.1.0.1.CentOS8.5.2.2_Ensure_SSH_access_is_limited:def:1
    
      - Title: Ensure SSH access is limited
 
- oval:simp.cis.1.0.1.CentOS8.5.2.3_Ensure_permissions_on_SSH_private_host_key_files_are_configured:def:1
    
      - Title: Ensure permissions on SSH private host key files are configured
 
- oval:simp.cis.1.0.1.CentOS8.5.2.4_Ensure_permissions_on_SSH_public_host_key_files_are_configured:def:1
    
      - Title: Ensure permissions on SSH public host key files are configured
 
- oval:simp.cis.1.0.1.CentOS8.5.2.5_Ensure_SSH_LogLevel_is_appropriate:def:1
    
      - Title: Ensure SSH LogLevel is appropriate
 
- oval:simp.cis.1.0.1.CentOS8.5.2.6_Ensure_SSH_X11_forwarding_is_disabled:def:1
    
      - Title: Ensure SSH X11 forwarding is disabled
 
- oval:simp.cis.1.0.1.CentOS8.5.2.7_Ensure_SSH_MaxAuthTries_is_set_to_4_or_less:def:1
    
      - Title: Ensure SSH MaxAuthTries is set to 4 or less
 
- oval:simp.cis.1.0.1.CentOS8.5.2.8_Ensure_SSH_IgnoreRhosts_is_enabled:def:1
    
      - Title: Ensure SSH IgnoreRhosts is enabled
 
- oval:simp.cis.1.0.1.CentOS8.5.2.9_Ensure_SSH_HostbasedAuthentication_is_disabled:def:1
    
      - Title: Ensure SSH HostbasedAuthentication is disabled
 
- oval:simp.cis.1.0.1.CentOS8.5.3.1_Create_custom_authselect_profile:def:1
    
      - Title: Create custom authselect profile
 
- oval:simp.cis.1.0.1.CentOS8.5.3.2_Select_authselect_profile:def:1
    
      - Title: Select authselect profile
 
- oval:simp.cis.1.0.1.CentOS8.5.3.3_Ensure_authselect_includes_with-faillock:def:1
    
      - Title: Ensure authselect includes with-faillock
 
- oval:simp.cis.1.0.1.CentOS8.5.4.1_Ensure_password_creation_requirements_are_configured:def:1
    
      - Title: Ensure password creation requirements are configured
 
- oval:simp.cis.1.0.1.CentOS8.5.4.2_Ensure_lockout_for_failed_password_attempts_is_configured:def:1
    
      - Title: Ensure lockout for failed password attempts is configured
 
- oval:simp.cis.1.0.1.CentOS8.5.4.3_Ensure_password_reuse_is_limited:def:1
    
      - Title: Ensure password reuse is limited
 
- oval:simp.cis.1.0.1.CentOS8.5.4.4_Ensure_password_hashing_algorithm_is_SHA-512:def:1
    
      - Title: Ensure password hashing algorithm is SHA-512
 
- oval:simp.cis.1.0.1.CentOS8.5.5.1.1_Ensure_password_expiration_is_365_days_or_less:def:1
    
      - Title: Ensure password expiration is 365 days or less
 
- oval:simp.cis.1.0.1.CentOS8.5.5.1.2_Ensure_minimum_days_between_password_changes_is_7_or_more:def:1
    
      - Title: Ensure minimum days between password changes is 7 or more
 
- oval:simp.cis.1.0.1.CentOS8.5.5.1.3_Ensure_password_expiration_warning_days_is_7_or_more:def:1
    
      - Title: Ensure password expiration warning days is 7 or more
 
- oval:simp.cis.1.0.1.CentOS8.5.5.1.4_Ensure_inactive_password_lock_is_30_days_or_less:def:1
    
      - Title: Ensure inactive password lock is 30 days or less
 
- oval:simp.cis.1.0.1.CentOS8.5.5.1.5_Ensure_all_users_last_password_change_date_is_in_the_past:def:1
    
      - Title: Ensure all users last password change date is in the past
 
- oval:simp.cis.1.0.1.CentOS8.5.5.2_Ensure_system_accounts_are_secured:def:1
    
      - Title: Ensure system accounts are secured
 
- oval:simp.cis.1.0.1.CentOS8.5.5.3_Ensure_default_user_shell_timeout_is_900_seconds_or_less:def:1
    
      - Title: Ensure default user shell timeout is 900 seconds or less
 
- oval:simp.cis.1.0.1.CentOS8.5.5.4_Ensure_default_group_for_the_root_account_is_GID_0:def:1
    
      - Title: Ensure default group for the root account is GID 0
 
- oval:simp.cis.1.0.1.CentOS8.5.5.5_Ensure_default_user_umask_is_027_or_more_restrictive:def:1
    
      - Title: Ensure default user umask is 027 or more restrictive
 
- oval:simp.cis.1.0.1.CentOS8.5.6_Ensure_root_login_is_restricted_to_system_console:def:1
    
      - Title: Ensure root login is restricted to system console
 
- oval:simp.cis.1.0.1.CentOS8.5.7_Ensure_access_to_the_su_command_is_restricted:def:1
    
      - Title: Ensure access to the su command is restricted
 
- oval:simp.cis.1.0.1.CentOS8.6.1.2_Ensure_permissions_on_etcpasswd_are_configured:def:1
    
      - Title: Ensure permissions on /etc/passwd are configured
 
- oval:simp.cis.1.0.1.CentOS8.6.1.3_Ensure_permissions_on_etcpasswd-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/passwd- are configured
 
- oval:simp.cis.1.0.1.CentOS8.6.1.4_Ensure_permissions_on_etcshadow_are_configured:def:1
    
      - Title: Ensure permissions on /etc/shadow are configured
 
- oval:simp.cis.1.0.1.CentOS8.6.1.5_Ensure_permissions_on_etcshadow-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/shadow- are configured
 
- oval:simp.cis.1.0.1.CentOS8.6.1.6_Ensure_permissions_on_etcgshadow_are_configured:def:1
    
      - Title: Ensure permissions on /etc/gshadow are configured
 
- oval:simp.cis.1.0.1.CentOS8.6.1.7_Ensure_permissions_on_etcgshadow-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/gshadow- are configured
 
- oval:simp.cis.1.0.1.CentOS8.6.1.8_Ensure_permissions_on_etcgroup_are_configured:def:1
    
      - Title: Ensure permissions on /etc/group are configured
 
- oval:simp.cis.1.0.1.CentOS8.6.1.9_Ensure_permissions_on_etcgroup-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/group- are configured
 
- oval:simp.cis.1.0.1.CentOS8.6.2.10Ensure_no_users_have.forward_files:def:1
    
      - Title: Ensure no users have .forward files
 
- oval:simp.cis.1.0.1.CentOS8.6.2.11Ensure_no_users_have.netrc_files:def:1
    
      - Title: Ensure no users have .netrc files
 
- oval:simp.cis.1.0.1.CentOS8.6.2.12Ensure_users.netrc_Files_are_not_group_or_world_accessible:def:1
    
      - Title: Ensure users’ .netrc Files are not group or world accessible
 
- oval:simp.cis.1.0.1.CentOS8.6.2.13Ensure_no_users_have.rhosts_files:def:1
    
      - Title: Ensure no users have .rhosts files
 
- oval:simp.cis.1.0.1.CentOS8.6.2.14_Ensure_all_groups_in_etcpasswd_exist_in_etcgroup:def:1
    
      - Title: Ensure all groups in /etc/passwd exist in /etc/group
 
- oval:simp.cis.1.0.1.CentOS8.6.2.15_Ensure_no_duplicate_UIDs_exist:def:1
    
      - Title: Ensure no duplicate UIDs exist
 
- oval:simp.cis.1.0.1.CentOS8.6.2.16_Ensure_no_duplicate_GIDs_exist:def:1
    
      - Title: Ensure no duplicate GIDs exist
 
- oval:simp.cis.1.0.1.CentOS8.6.2.17_Ensure_no_duplicate_user_names_exist:def:1
    
      - Title: Ensure no duplicate user names exist
 
- oval:simp.cis.1.0.1.CentOS8.6.2.18_Ensure_no_duplicate_group_names_exist:def:1
    
      - Title: Ensure no duplicate group names exist
 
- oval:simp.cis.1.0.1.CentOS8.6.2.19_Ensure_shadow_group_is_empty:def:1
    
      - Title: Ensure shadow group is empty
 
- oval:simp.cis.1.0.1.CentOS8.6.2.1_Ensure_password_fields_are_not_empty:def:1
    
      - Title: Ensure password fields are not empty
 
- oval:simp.cis.1.0.1.CentOS8.6.2.20_Ensure_all_users_home_directories_exist:def:1
    
      - Title: Ensure all users’ home directories exist
 
- oval:simp.cis.1.0.1.CentOS8.6.2.2_Ensure_no_legacy__entries_exist_in_etcpasswd:def:1
    
      - Title: Ensure no legacy “+” entries exist in /etc/passwd
 
- oval:simp.cis.1.0.1.CentOS8.6.2.3_Ensure_root_PATH_Integrity:def:1
    
      - Title: Ensure root PATH Integrity
 
- oval:simp.cis.1.0.1.CentOS8.6.2.4_Ensure_no_legacy__entries_exist_in_etcshadow:def:1
    
      - Title: Ensure no legacy “+” entries exist in /etc/shadow
 
- oval:simp.cis.1.0.1.CentOS8.6.2.5_Ensure_no_legacy__entries_exist_in_etcgroup:def:1
    
      - Title: Ensure no legacy “+” entries exist in /etc/group
 
- oval:simp.cis.1.0.1.CentOS8.6.2.6_Ensure_root_is_the_only_UID_0_account:def:1
    
      - Title: Ensure root is the only UID 0 account
 
- oval:simp.cis.1.0.1.CentOS8.6.2.7_Ensure_users_home_directories_permissions_are_750_or_more_restrictive:def:1
    
      - Title: Ensure users’ home directories permissions are 750 or more restrictive
 
- oval:simp.cis.1.0.1.CentOS8.6.2.8_Ensure_users_own_their_home_directories:def:1
    
      - Title: Ensure users own their home directories
 
- oval:simp.cis.1.0.1.CentOS8.6.2.9_Ensure_users_dot_files_are_not_group_or_world_writable:def:1
    
      - Title: Ensure users’ dot files are not group or world writable
        OracleLinux 8 (222/234 [94%])
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.1.1_Ensure_mounting_of_cramfs_filesystems_is_disabled:def:1
    
      - Title: Ensure mounting of cramfs filesystems is disabled
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.1.2_Ensure_mounting_of_vFAT_filesystems_is_limited:def:1
    
      - Title: Ensure mounting of vFAT filesystems is limited
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.1.3_Ensure_mounting_of_squashfs_filesystems_is_disabled:def:1
    
      - Title: Ensure mounting of squashfs filesystems is disabled
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.1.4_Ensure_mounting_of_udf_filesystems_is_disabled:def:1
    
      - Title: Ensure mounting of udf filesystems is disabled
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.10_Ensure_noexec_option_set_on_vartmp_partition:def:1
    
      - Title: Ensure noexec option set on /var/tmp partition
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.14_Ensure_nodev_option_set_on_home_partition:def:1
    
      - Title: Ensure nodev option set on /home partition
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.15_Ensure_nodev_option_set_on_devshm_partition:def:1
    
      - Title: Ensure nodev option set on /dev/shm partition
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.16_Ensure_nosuid_option_set_on_devshm_partition:def:1
    
      - Title: Ensure nosuid option set on /dev/shm partition
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.17_Ensure_noexec_option_set_on_devshm_partition:def:1
    
      - Title: Ensure noexec option set on /dev/shm partition
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.18_Ensure_nodev_option_set_on_removable_media_partitions:def:1
    
      - Title: Ensure nodev option set on removable media partitions
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.19_Ensure_nosuid_option_set_on_removable_media_partitions:def:1
    
      - Title: Ensure nosuid option set on removable media partitions
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.20_Ensure_noexec_option_set_on_removable_media_partitions:def:1
    
      - Title: Ensure noexec option set on removable media partitions
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.21_Ensure_sticky_bit_is_set_on_all_world-writable_directories:def:1
    
      - Title: Ensure sticky bit is set on all world-writable directories
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.22_Disable_Automounting:def:1
    
      - Title: Disable Automounting
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.23_Disable_USB_Storage:def:1
    
      - Title: Disable USB Storage
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.2_Ensure_tmp_is_configured:def:1
    
      - Title: Ensure /tmp is configured
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.3_Ensure_nodev_option_set_on_tmp_partition:def:1
    
      - Title: Ensure nodev option set on /tmp partition
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.4_Ensure_nosuid_option_set_on_tmp_partition:def:1
    
      - Title: Ensure nosuid option set on /tmp partition
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.5_Ensure_noexec_option_set_on_tmp_partition:def:1
    
      - Title: Ensure noexec option set on /tmp partition
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.7_Ensure_separate_partition_exists_for_vartmp:def:1
    
      - Title: Ensure separate partition exists for /var/tmp
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.8_Ensure_nodev_option_set_on_vartmp_partition:def:1
    
      - Title: Ensure nodev option set on /var/tmp partition
 
- oval:simp.cis.1.0.1.OracleLinux8.1.1.9_Ensure_nosuid_option_set_on_vartmp_partition:def:1
    
      - Title: Ensure nosuid option set on /var/tmp partition
 
- oval:simp.cis.1.0.1.OracleLinux8.1.10_Ensure_system-wide_crypto_policy_is_not_legacy:def:1
    
      - Title: Ensure system-wide crypto policy is not legacy
 
- oval:simp.cis.1.0.1.OracleLinux8.1.11_Ensure_system-wide_crypto_policy_is_FUTURE_or_FIPS:def:1
    
      - Title: Ensure system-wide crypto policy is FUTURE or FIPS
 
- oval:simp.cis.1.0.1.OracleLinux8.1.2.1_Ensure_GPG_keys_are_configured:def:1
    
      - Title: Ensure GPG keys are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.1.2.2_Ensure_gpgcheck_is_globally_activated:def:1
    
      - Title: Ensure gpgcheck is globally activated
 
- oval:simp.cis.1.0.1.OracleLinux8.1.3.1_Ensure_sudo_is_installed:def:1
    
      - Title: Ensure sudo is installed
 
- oval:simp.cis.1.0.1.OracleLinux8.1.3.2_Ensure_sudo_commands_use_pty:def:1
    
      - Title: Ensure sudo commands use pty
 
- oval:simp.cis.1.0.1.OracleLinux8.1.3.3_Ensure_sudo_log_file_exists:def:1
    
      - Title: Ensure sudo log file exists
 
- oval:simp.cis.1.0.1.OracleLinux8.1.4.1_Ensure_AIDE_is_installed:def:1
    
      - Title: Ensure AIDE is installed
 
- oval:simp.cis.1.0.1.OracleLinux8.1.4.2_Ensure_filesystem_integrity_is_regularly_checked:def:1
    
      - Title: Ensure filesystem integrity is regularly checked
 
- oval:simp.cis.1.0.1.OracleLinux8.1.5.1_Ensure_permissions_on_bootloader_config_are_configured:def:1
    
      - Title: Ensure permissions on bootloader config are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.1.5.2_Ensure_bootloader_password_is_set:def:1
    
      - Title: Ensure bootloader password is set
 
- oval:simp.cis.1.0.1.OracleLinux8.1.5.3_Ensure_authentication_required_for_single_user_mode:def:1
    
      - Title: Ensure authentication required for single user mode
 
- oval:simp.cis.1.0.1.OracleLinux8.1.6.1_Ensure_core_dumps_are_restricted:def:1
    
      - Title: Ensure core dumps are restricted
 
- oval:simp.cis.1.0.1.OracleLinux8.1.6.2_Ensure_address_space_layout_randomization_ASLR_is_enabled:def:1
    
      - Title: Ensure address space layout randomization (ASLR) is enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.1.7.1.1_Ensure_SELinux_is_installed:def:1
    
      - Title: Ensure SELinux is installed
 
- oval:simp.cis.1.0.1.OracleLinux8.1.7.1.2_Ensure_SELinux_is_not_disabled_in_bootloader_configuration:def:1
    
      - Title: Ensure SELinux is not disabled in bootloader configuration
 
- oval:simp.cis.1.0.1.OracleLinux8.1.7.1.3_Ensure_SELinux_policy_is_configured:def:1
    
      - Title: Ensure SELinux policy is configured
 
- oval:simp.cis.1.0.1.OracleLinux8.1.7.1.4_Ensure_the_SELinux_state_is_enforcing:def:1
    
      - Title: Ensure the SELinux state is enforcing
 
- oval:simp.cis.1.0.1.OracleLinux8.1.7.1.6_Ensure_SETroubleshoot_is_not_installed:def:1
    
      - Title: Ensure SETroubleshoot is not installed
 
- oval:simp.cis.1.0.1.OracleLinux8.1.7.1.7_Ensure_the_MCS_Translation_Service_mcstrans_is_not_installed:def:1
    
      - Title: Ensure the MCS Translation Service (mcstrans) is not installed
 
- oval:simp.cis.1.0.1.OracleLinux8.1.8.1.1_Ensure_message_of_the_day_is_configured_properly:def:1
    
      - Title: Ensure message of the day is configured properly
 
- oval:simp.cis.1.0.1.OracleLinux8.1.8.1.2_Ensure_local_login_warning_banner_is_configured_properly:def:1
    
      - Title: Ensure local login warning banner is configured properly
 
- oval:simp.cis.1.0.1.OracleLinux8.1.8.1.3_Ensure_remote_login_warning_banner_is_configured_properly:def:1
    
      - Title: Ensure remote login warning banner is configured properly
 
- oval:simp.cis.1.0.1.OracleLinux8.1.8.1.4_Ensure_permissions_on_etcmotd_are_configured:def:1
    
      - Title: Ensure permissions on /etc/motd are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.1.8.1.5_Ensure_permissions_on_etcissue_are_configured:def:1
    
      - Title: Ensure permissions on /etc/issue are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.1.8.1.6_Ensure_permissions_on_etcissue.net_are_configured:def:1
    
      - Title: Ensure permissions on /etc/issue.net are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.1.8.2_Ensure_GDM_login_banner_is_configured:def:1
    
      - Title: Ensure GDM login banner is configured
 
- oval:simp.cis.1.0.1.OracleLinux8.1.9_Ensure_updates_patches_and_additional_security_software_are_installed:def:1
    
      - Title: Ensure updates, patches, and additional security software are installed
 
- oval:simp.cis.1.0.1.OracleLinux8.2.1.1_Ensure_xinetd_is_not_installed:def:1
    
      - Title: Ensure xinetd is not installed
 
- oval:simp.cis.1.0.1.OracleLinux8.2.2.1.1_Ensure_time_synchronization_is_in_use:def:1
    
      - Title: Ensure time synchronization is in use
 
- oval:simp.cis.1.0.1.OracleLinux8.2.2.1.2_Ensure_chrony_is_configured:def:1
    
      - Title: Ensure chrony is configured
 
- oval:simp.cis.1.0.1.OracleLinux8.2.2.10_Ensure_FTP_Server_is_not_enabled:def:1
    
      - Title: Ensure FTP Server is not enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.2.2.11_Ensure_DNS_Server_is_not_enabled:def:1
    
      - Title: Ensure DNS Server is not enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.2.2.12_Ensure_NFS_is_not_enabled:def:1
    
      - Title: Ensure NFS is not enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.2.2.13_Ensure__RPC_is_not_enabled:def:1
    
      - Title: Ensure RPC is not enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.2.2.14_Ensure_LDAP_server_is_not_enabled:def:1
    
      - Title: Ensure LDAP server is not enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.2.2.15_Ensure_DHCP_Server_is_not_enabled:def:1
    
      - Title: Ensure DHCP Server is not enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.2.2.16_Ensure_CUPS_is_not_enabled:def:1
    
      - Title: Ensure CUPS is not enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.2.2.17_Ensure_NIS_Server_is_not_enabled:def:1
    
      - Title: Ensure NIS Server is not enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.2.2.18_Ensure_mail_transfer_agent_is_configured_for_local-only_mode:def:1
    
      - Title: Ensure mail transfer agent is configured for local-only mode
 
- oval:simp.cis.1.0.1.OracleLinux8.2.2.2_Ensure_X_Window_System_is_not_installed:def:1
    
      - Title: Ensure X Window System is not installed
 
- oval:simp.cis.1.0.1.OracleLinux8.2.2.3_Ensure_rsync_service_is_not_enabled:def:1
    
      - Title: Ensure rsync service is not enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.2.2.4_Ensure_Avahi_Server_is_not_enabled:def:1
    
      - Title: Ensure Avahi Server is not enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.2.2.5_Ensure_SNMP_Server_is_not_enabled:def:1
    
      - Title: Ensure SNMP Server is not enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.2.2.6_Ensure_HTTP_Proxy_Server_is_not_enabled:def:1
    
      - Title: Ensure HTTP Proxy Server is not enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.2.2.7_Ensure_Samba_is_not_enabled:def:1
    
      - Title: Ensure Samba is not enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.2.2.8_Ensure_IMAP_and_POP3_server_is_not_enabled:def:1
    
      - Title: Ensure IMAP and POP3 server is not enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.2.2.9_Ensure_HTTP_server_is_not_enabled:def:1
    
      - Title: Ensure HTTP server is not enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.2.3.1_Ensure_NIS_Client_is_not_installed:def:1
    
      - Title: Ensure NIS Client is not installed
 
- oval:simp.cis.1.0.1.OracleLinux8.2.3.2_Ensure_telnet_client_is_not_installed:def:1
    
      - Title: Ensure telnet client is not installed
 
- oval:simp.cis.1.0.1.OracleLinux8.2.3.3_Ensure_LDAP_client_is_not_installed:def:1
    
      - Title: Ensure LDAP client is not installed
 
- oval:simp.cis.1.0.1.OracleLinux8.3.1.1_Ensure_IP_forwarding_is_disabled:def:1
    
      - Title: Ensure IP forwarding is disabled
 
- oval:simp.cis.1.0.1.OracleLinux8.3.1.2_Ensure_packet_redirect_sending_is_disabled:def:1
    
      - Title: Ensure packet redirect sending is disabled
 
- oval:simp.cis.1.0.1.OracleLinux8.3.2.1_Ensure_source_routed_packets_are_not_accepted:def:1
    
      - Title: Ensure source routed packets are not accepted
 
- oval:simp.cis.1.0.1.OracleLinux8.3.2.2_Ensure_ICMP_redirects_are_not_accepted:def:1
    
      - Title: Ensure ICMP redirects are not accepted
 
- oval:simp.cis.1.0.1.OracleLinux8.3.2.3_Ensure_secure_ICMP_redirects_are_not_accepted:def:1
    
      - Title: Ensure secure ICMP redirects are not accepted
 
- oval:simp.cis.1.0.1.OracleLinux8.3.2.4_Ensure_suspicious_packets_are_logged:def:1
    
      - Title: Ensure suspicious packets are logged
 
- oval:simp.cis.1.0.1.OracleLinux8.3.2.5_Ensure_broadcast_ICMP_requests_are_ignored:def:1
    
      - Title: Ensure broadcast ICMP requests are ignored
 
- oval:simp.cis.1.0.1.OracleLinux8.3.2.6_Ensure_bogus_ICMP_responses_are_ignored:def:1
    
      - Title: Ensure bogus ICMP responses are ignored
 
- oval:simp.cis.1.0.1.OracleLinux8.3.2.7_Ensure_Reverse_Path_Filtering_is_enabled:def:1
    
      - Title: Ensure Reverse Path Filtering is enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.3.2.8_Ensure_TCP_SYN_Cookies_is_enabled:def:1
    
      - Title: Ensure TCP SYN Cookies is enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.3.2.9_Ensure_IPv6_router_advertisements_are_not_accepted:def:1
    
      - Title: Ensure IPv6 router advertisements are not accepted
 
- oval:simp.cis.1.0.1.OracleLinux8.3.3.1_Ensure_DCCP_is_disabled:def:1
    
      - Title: Ensure DCCP is disabled
 
- oval:simp.cis.1.0.1.OracleLinux8.3.3.2_Ensure_SCTP_is_disabled:def:1
    
      - Title: Ensure SCTP is disabled
 
- oval:simp.cis.1.0.1.OracleLinux8.3.3.3_Ensure_RDS_is_disabled:def:1
    
      - Title: Ensure RDS is disabled
 
- oval:simp.cis.1.0.1.OracleLinux8.3.3.4_Ensure_TIPC_is_disabled:def:1
    
      - Title: Ensure TIPC is disabled
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.1.1_Ensure_a_Firewall_package_is_installed:def:1
    
      - Title: Ensure a Firewall package is installed
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.2.1_Ensure_firewalld_service_is_enabled_and_running:def:1
    
      - Title: Ensure firewalld service is enabled and running
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.2.2_Ensure_iptables_service_is_not_enabled_with_firewalld:def:1
    
      - Title: Ensure iptables service is not enabled with firewalld
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.2.3_Ensure_nftables_is_not_enabled_with_firewalld:def:1
    
      - Title: Ensure nftables is not enabled with firewalld
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.2.4_Ensure_firewalld_default_zone_is_set:def:1
    
      - Title: Ensure firewalld default zone is set
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.2.5_Ensure_network_interfaces_are_assigned_to_appropriate_zone:def:1
    
      - Title: Ensure network interfaces are assigned to appropriate zone
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.2.6_Ensure_firewalld_drops_unnecessary_services_and_ports:def:1
    
      - Title: Ensure firewalld drops unnecessary services and ports
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.3.1_Ensure_iptables_are_flushed_with_nftables:def:1
    
      - Title: Ensure iptables are flushed with nftables
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.3.2_Ensure_an_nftables_table_exists:def:1
    
      - Title: Ensure an nftables table exists
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.3.3_Ensure_nftables_base_chains_exist:def:1
    
      - Title: Ensure nftables base chains exist
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.3.4_Ensure_nftables_loopback_traffic_is_configured:def:1
    
      - Title: Ensure nftables loopback traffic is configured
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.3.5_Ensure_nftables_outbound_and_established_connections_are_configured:def:1
    
      - Title: Ensure nftables outbound and established connections are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.3.6_Ensure_nftables_default_deny_firewall_policy:def:1
    
      - Title: Ensure nftables default deny firewall policy
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.3.7_Ensure_nftables_service_is_enabled:def:1
    
      - Title: Ensure nftables service is enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.3.8_Ensure_nftables_rules_are_permanent:def:1
    
      - Title: Ensure nftables rules are permanent
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.4.1.1_Ensure_iptables_default_deny_firewall_policy:def:1
    
      - Title: Ensure iptables default deny firewall policy
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.4.1.2_Ensure_iptables_loopback_traffic_is_configured:def:1
    
      - Title: Ensure iptables loopback traffic is configured
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.4.1.3_Ensure_iptables_outbound_and_established_connections_are_configured:def:1
    
      - Title: Ensure iptables outbound and established connections are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.4.1.4_Ensure_iptables_firewall_rules_exist_for_all_open_ports:def:1
    
      - Title: Ensure iptables firewall rules exist for all open ports
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.4.1.5_Ensure_iptables_is_enabled_and_active:def:1
    
      - Title: Ensure iptables is enabled and active
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.4.2.1_Ensure_ip6tables_default_deny_firewall_policy:def:1
    
      - Title: Ensure ip6tables default deny firewall policy
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.4.2.2_Ensure_ip6tables_loopback_traffic_is_configured:def:1
    
      - Title: Ensure ip6tables loopback traffic is configured
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.4.2.3_Ensure_ip6tables_outbound_and_established_connections_are_configured:def:1
    
      - Title: Ensure ip6tables outbound and established connections are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.4.2.4_Ensure_ip6tables_firewall_rules_exist_for_all_open_ports:def:1
    
      - Title: Ensure ip6tables firewall rules exist for all open ports
 
- oval:simp.cis.1.0.1.OracleLinux8.3.4.4.2.5_Ensure_ip6tables_is_enabled_and_active:def:1
    
      - Title: Ensure ip6tables is enabled and active
 
- oval:simp.cis.1.0.1.OracleLinux8.3.5_Ensure_wireless_interfaces_are_disabled:def:1
    
      - Title: Ensure wireless interfaces are disabled
 
- oval:simp.cis.1.0.1.OracleLinux8.3.6_Disable_IPv6:def:1
    
  
- oval:simp.cis.1.0.1.OracleLinux8.4.1.1.1_Ensure_auditd_is_installed:def:1
    
      - Title: Ensure auditd is installed
 
- oval:simp.cis.1.0.1.OracleLinux8.4.1.1.2_Ensure_auditd_service_is_enabled:def:1
    
      - Title: Ensure auditd service is enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.4.1.1.3_Ensure_auditing_for_processes_that_start_prior_to_auditd_is_enabled:def:1
    
      - Title: Ensure auditing for processes that start prior to auditd is enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.4.1.1.4_Ensure_audit_backlog_limit_is_sufficient:def:1
    
      - Title: Ensure audit_backlog_limit is sufficient
 
- oval:simp.cis.1.0.1.OracleLinux8.4.1.10_Ensure_unsuccessful_unauthorized_file_access_attempts_are_collected:def:1
    
      - Title: Ensure unsuccessful unauthorized file access attempts are collected
 
- oval:simp.cis.1.0.1.OracleLinux8.4.1.11_Ensure_events_that_modify_usergroup_information_are_collected:def:1
    
      - Title: Ensure events that modify user/group information are collected
 
- oval:simp.cis.1.0.1.OracleLinux8.4.1.12_Ensure_successful_file_system_mounts_are_collected:def:1
    
      - Title: Ensure successful file system mounts are collected
 
- oval:simp.cis.1.0.1.OracleLinux8.4.1.13_Ensure_use_of_privileged_commands_is_collected:def:1
    
      - Title: Ensure use of privileged commands is collected
 
- oval:simp.cis.1.0.1.OracleLinux8.4.1.14_Ensure_file_deletion_events_by_users_are_collected:def:1
    
      - Title: Ensure file deletion events by users are collected
 
- oval:simp.cis.1.0.1.OracleLinux8.4.1.15_Ensure_kernel_module_loading_and_unloading_is_collected:def:1
    
      - Title: Ensure kernel module loading and unloading is collected
 
- oval:simp.cis.1.0.1.OracleLinux8.4.1.16_Ensure_system_administrator_actions_sudolog_are_collected:def:1
    
      - Title: Ensure system administrator actions (sudolog) are collected
 
- oval:simp.cis.1.0.1.OracleLinux8.4.1.17_Ensure_the_audit_configuration_is_immutable:def:1
    
      - Title: Ensure the audit configuration is immutable
 
- oval:simp.cis.1.0.1.OracleLinux8.4.1.2.1_Ensure_audit_log_storage_size_is_configured:def:1
    
      - Title: Ensure audit log storage size is configured
 
- oval:simp.cis.1.0.1.OracleLinux8.4.1.2.2_Ensure_audit_logs_are_not_automatically_deleted:def:1
    
      - Title: Ensure audit logs are not automatically deleted
 
- oval:simp.cis.1.0.1.OracleLinux8.4.1.2.3_Ensure_system_is_disabled_when_audit_logs_are_full:def:1
    
      - Title: Ensure system is disabled when audit logs are full
 
- oval:simp.cis.1.0.1.OracleLinux8.4.1.3_Ensure_changes_to_system_administration_scope_sudoers_is_collected:def:1
    
      - Title: Ensure changes to system administration scope (sudoers) is collected
 
- oval:simp.cis.1.0.1.OracleLinux8.4.1.4_Ensure_login_and_logout_events_are_collected:def:1
    
      - Title: Ensure login and logout events are collected
 
- oval:simp.cis.1.0.1.OracleLinux8.4.1.5_Ensure_session_initiation_information_is_collected:def:1
    
      - Title: Ensure session initiation information is collected
 
- oval:simp.cis.1.0.1.OracleLinux8.4.1.6_Ensure_events_that_modify_date_and_time_information_are_collected:def:1
    
      - Title: Ensure events that modify date and time information are collected
 
- oval:simp.cis.1.0.1.OracleLinux8.4.1.7_Ensure_events_that_modify_the_systems_Mandatory_Access_Controls_are_collected:def:1
    
      - Title: Ensure events that modify the system’s Mandatory Access Controls are collected
 
- oval:simp.cis.1.0.1.OracleLinux8.4.1.8_Ensure_events_that_modify_the_systems_network_environment_are_collected:def:1
    
      - Title: Ensure events that modify the system’s network environment are collected
 
- oval:simp.cis.1.0.1.OracleLinux8.4.1.9_Ensure_discretionary_access_control_permission_modification_events_are_collected:def:1
    
      - Title: Ensure discretionary access control permission modification events are collected
 
- oval:simp.cis.1.0.1.OracleLinux8.4.2.1.1_Ensure_rsyslog_is_installed:def:1
    
      - Title: Ensure rsyslog is installed
 
- oval:simp.cis.1.0.1.OracleLinux8.4.2.1.2_Ensure_rsyslog_Service_is_enabled:def:1
    
      - Title: Ensure rsyslog Service is enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.4.2.1.3_Ensure_rsyslog_default_file_permissions_configured:def:1
    
      - Title: Ensure rsyslog default file permissions configured
 
- oval:simp.cis.1.0.1.OracleLinux8.4.2.1.4_Ensure_logging_is_configured:def:1
    
      - Title: Ensure logging is configured
 
- oval:simp.cis.1.0.1.OracleLinux8.4.2.1.5_Ensure_rsyslog_is_configured_to_send_logs_to_a_remote_log_host:def:1
    
      - Title: Ensure rsyslog is configured to send logs to a remote log host
 
- oval:simp.cis.1.0.1.OracleLinux8.4.2.1.6_Ensure_remote_rsyslog_messages_are_only_accepted_on_designated_log_hosts.:def:1
    
      - Title: Ensure remote rsyslog messages are only accepted on designated log hosts.
 
- oval:simp.cis.1.0.1.OracleLinux8.4.2.2.1_Ensure_journald_is_configured_to_send_logs_to_rsyslog:def:1
    
      - Title: Ensure journald is configured to send logs to rsyslog
 
- oval:simp.cis.1.0.1.OracleLinux8.4.2.2.2_Ensure_journald_is_configured_to_compress_large_log_files:def:1
    
      - Title: Ensure journald is configured to compress large log files
 
- oval:simp.cis.1.0.1.OracleLinux8.4.2.2.3_Ensure_journald_is_configured_to_write_logfiles_to_persistent_disk:def:1
    
      - Title: Ensure journald is configured to write logfiles to persistent disk
 
- oval:simp.cis.1.0.1.OracleLinux8.4.2.3_Ensure_permissions_on_all_logfiles_are_configured:def:1
    
      - Title: Ensure permissions on all logfiles are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.4.3_Ensure_logrotate_is_configured:def:1
    
      - Title: Ensure logrotate is configured
 
- oval:simp.cis.1.0.1.OracleLinux8.5.1.1_Ensure_cron_daemon_is_enabled:def:1
    
      - Title: Ensure cron daemon is enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.5.1.2_Ensure_permissions_on_etccrontab_are_configured:def:1
    
      - Title: Ensure permissions on /etc/crontab are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.5.1.3_Ensure_permissions_on_etccron.hourly_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.hourly are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.5.1.4_Ensure_permissions_on_etccron.daily_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.daily are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.5.1.5_Ensure_permissions_on_etccron.weekly_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.weekly are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.5.1.6_Ensure_permissions_on_etccron.monthly_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.monthly are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.5.1.7_Ensure_permissions_on_etccron.d_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.d are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.5.1.8_Ensure_atcron_is_restricted_to_authorized_users:def:1
    
      - Title: Ensure at/cron is restricted to authorized users
 
- oval:simp.cis.1.0.1.OracleLinux8.5.2.10_Ensure_SSH_root_login_is_disabled:def:1
    
      - Title: Ensure SSH root login is disabled
 
- oval:simp.cis.1.0.1.OracleLinux8.5.2.11_Ensure_SSH_PermitEmptyPasswords_is_disabled:def:1
    
      - Title: Ensure SSH PermitEmptyPasswords is disabled
 
- oval:simp.cis.1.0.1.OracleLinux8.5.2.12_Ensure_SSH_PermitUserEnvironment_is_disabled:def:1
    
      - Title: Ensure SSH PermitUserEnvironment is disabled
 
- oval:simp.cis.1.0.1.OracleLinux8.5.2.13_Ensure_SSH_Idle_Timeout_Interval_is_configured:def:1
    
      - Title: Ensure SSH Idle Timeout Interval is configured
 
- oval:simp.cis.1.0.1.OracleLinux8.5.2.14_Ensure_SSH_LoginGraceTime_is_set_to_one_minute_or_less:def:1
    
      - Title: Ensure SSH LoginGraceTime is set to one minute or less
 
- oval:simp.cis.1.0.1.OracleLinux8.5.2.15_Ensure_SSH_warning_banner_is_configured:def:1
    
      - Title: Ensure SSH warning banner is configured
 
- oval:simp.cis.1.0.1.OracleLinux8.5.2.16_Ensure_SSH_PAM_is_enabled:def:1
    
      - Title: Ensure SSH PAM is enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.5.2.17_Ensure_SSH_AllowTcpForwarding_is_disabled:def:1
    
      - Title: Ensure SSH AllowTcpForwarding is disabled
 
- oval:simp.cis.1.0.1.OracleLinux8.5.2.18_Ensure_SSH_MaxStartups_is_configured:def:1
    
      - Title: Ensure SSH MaxStartups is configured
 
- oval:simp.cis.1.0.1.OracleLinux8.5.2.19_Ensure_SSH_MaxSessions_is_set_to_4_or_less:def:1
    
      - Title: Ensure SSH MaxSessions is set to 4 or less
 
- oval:simp.cis.1.0.1.OracleLinux8.5.2.1_Ensure_permissions_on_etcsshsshd_config_are_configured:def:1
    
      - Title: Ensure permissions on /etc/ssh/sshd_config are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.5.2.20_Ensure_system-wide_crypto_policy_is_not_over-ridden:def:1
    
      - Title: Ensure system-wide crypto policy is not over-ridden
 
- oval:simp.cis.1.0.1.OracleLinux8.5.2.2_Ensure_SSH_access_is_limited:def:1
    
      - Title: Ensure SSH access is limited
 
- oval:simp.cis.1.0.1.OracleLinux8.5.2.3_Ensure_permissions_on_SSH_private_host_key_files_are_configured:def:1
    
      - Title: Ensure permissions on SSH private host key files are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.5.2.4_Ensure_permissions_on_SSH_public_host_key_files_are_configured:def:1
    
      - Title: Ensure permissions on SSH public host key files are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.5.2.5_Ensure_SSH_LogLevel_is_appropriate:def:1
    
      - Title: Ensure SSH LogLevel is appropriate
 
- oval:simp.cis.1.0.1.OracleLinux8.5.2.6_Ensure_SSH_X11_forwarding_is_disabled:def:1
    
      - Title: Ensure SSH X11 forwarding is disabled
 
- oval:simp.cis.1.0.1.OracleLinux8.5.2.7_Ensure_SSH_MaxAuthTries_is_set_to_4_or_less:def:1
    
      - Title: Ensure SSH MaxAuthTries is set to 4 or less
 
- oval:simp.cis.1.0.1.OracleLinux8.5.2.8_Ensure_SSH_IgnoreRhosts_is_enabled:def:1
    
      - Title: Ensure SSH IgnoreRhosts is enabled
 
- oval:simp.cis.1.0.1.OracleLinux8.5.2.9_Ensure_SSH_HostbasedAuthentication_is_disabled:def:1
    
      - Title: Ensure SSH HostbasedAuthentication is disabled
 
- oval:simp.cis.1.0.1.OracleLinux8.5.3.1_Create_custom_authselect_profile:def:1
    
      - Title: Create custom authselect profile
 
- oval:simp.cis.1.0.1.OracleLinux8.5.3.2_Select_authselect_profile:def:1
    
      - Title: Select authselect profile
 
- oval:simp.cis.1.0.1.OracleLinux8.5.3.3_Ensure_authselect_includes_with-faillock:def:1
    
      - Title: Ensure authselect includes with-faillock
 
- oval:simp.cis.1.0.1.OracleLinux8.5.4.1_Ensure_password_creation_requirements_are_configured:def:1
    
      - Title: Ensure password creation requirements are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.5.4.2_Ensure_lockout_for_failed_password_attempts_is_configured:def:1
    
      - Title: Ensure lockout for failed password attempts is configured
 
- oval:simp.cis.1.0.1.OracleLinux8.5.4.3_Ensure_password_reuse_is_limited:def:1
    
      - Title: Ensure password reuse is limited
 
- oval:simp.cis.1.0.1.OracleLinux8.5.4.4_Ensure_password_hashing_algorithm_is_SHA-512:def:1
    
      - Title: Ensure password hashing algorithm is SHA-512
 
- oval:simp.cis.1.0.1.OracleLinux8.5.5.1.1_Ensure_password_expiration_is_365_days_or_less:def:1
    
      - Title: Ensure password expiration is 365 days or less
 
- oval:simp.cis.1.0.1.OracleLinux8.5.5.1.2_Ensure_minimum_days_between_password_changes_is_7_or_more:def:1
    
      - Title: Ensure minimum days between password changes is 7 or more
 
- oval:simp.cis.1.0.1.OracleLinux8.5.5.1.3_Ensure_password_expiration_warning_days_is_7_or_more:def:1
    
      - Title: Ensure password expiration warning days is 7 or more
 
- oval:simp.cis.1.0.1.OracleLinux8.5.5.1.4_Ensure_inactive_password_lock_is_30_days_or_less:def:1
    
      - Title: Ensure inactive password lock is 30 days or less
 
- oval:simp.cis.1.0.1.OracleLinux8.5.5.1.5_Ensure_all_users_last_password_change_date_is_in_the_past:def:1
    
      - Title: Ensure all users last password change date is in the past
 
- oval:simp.cis.1.0.1.OracleLinux8.5.5.2_Ensure_system_accounts_are_secured:def:1
    
      - Title: Ensure system accounts are secured
 
- oval:simp.cis.1.0.1.OracleLinux8.5.5.3_Ensure_default_user_shell_timeout_is_900_seconds_or_less:def:1
    
      - Title: Ensure default user shell timeout is 900 seconds or less
 
- oval:simp.cis.1.0.1.OracleLinux8.5.5.4_Ensure_default_group_for_the_root_account_is_GID_0:def:1
    
      - Title: Ensure default group for the root account is GID 0
 
- oval:simp.cis.1.0.1.OracleLinux8.5.5.5_Ensure_default_user_umask_is_027_or_more_restrictive:def:1
    
      - Title: Ensure default user umask is 027 or more restrictive
 
- oval:simp.cis.1.0.1.OracleLinux8.5.6_Ensure_root_login_is_restricted_to_system_console:def:1
    
      - Title: Ensure root login is restricted to system console
 
- oval:simp.cis.1.0.1.OracleLinux8.5.7_Ensure_access_to_the_su_command_is_restricted:def:1
    
      - Title: Ensure access to the su command is restricted
 
- oval:simp.cis.1.0.1.OracleLinux8.6.1.2_Ensure_permissions_on_etcpasswd_are_configured:def:1
    
      - Title: Ensure permissions on /etc/passwd are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.6.1.3_Ensure_permissions_on_etcpasswd-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/passwd- are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.6.1.4_Ensure_permissions_on_etcshadow_are_configured:def:1
    
      - Title: Ensure permissions on /etc/shadow are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.6.1.5_Ensure_permissions_on_etcshadow-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/shadow- are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.6.1.6_Ensure_permissions_on_etcgshadow_are_configured:def:1
    
      - Title: Ensure permissions on /etc/gshadow are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.6.1.7_Ensure_permissions_on_etcgshadow-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/gshadow- are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.6.1.8_Ensure_permissions_on_etcgroup_are_configured:def:1
    
      - Title: Ensure permissions on /etc/group are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.6.1.9_Ensure_permissions_on_etcgroup-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/group- are configured
 
- oval:simp.cis.1.0.1.OracleLinux8.6.2.10Ensure_no_users_have.forward_files:def:1
    
      - Title: Ensure no users have .forward files
 
- oval:simp.cis.1.0.1.OracleLinux8.6.2.11Ensure_no_users_have.netrc_files:def:1
    
      - Title: Ensure no users have .netrc files
 
- oval:simp.cis.1.0.1.OracleLinux8.6.2.12Ensure_users.netrc_Files_are_not_group_or_world_accessible:def:1
    
      - Title: Ensure users’ .netrc Files are not group or world accessible
 
- oval:simp.cis.1.0.1.OracleLinux8.6.2.13Ensure_no_users_have.rhosts_files:def:1
    
      - Title: Ensure no users have .rhosts files
 
- oval:simp.cis.1.0.1.OracleLinux8.6.2.14_Ensure_all_groups_in_etcpasswd_exist_in_etcgroup:def:1
    
      - Title: Ensure all groups in /etc/passwd exist in /etc/group
 
- oval:simp.cis.1.0.1.OracleLinux8.6.2.15_Ensure_no_duplicate_UIDs_exist:def:1
    
      - Title: Ensure no duplicate UIDs exist
 
- oval:simp.cis.1.0.1.OracleLinux8.6.2.16_Ensure_no_duplicate_GIDs_exist:def:1
    
      - Title: Ensure no duplicate GIDs exist
 
- oval:simp.cis.1.0.1.OracleLinux8.6.2.17_Ensure_no_duplicate_user_names_exist:def:1
    
      - Title: Ensure no duplicate user names exist
 
- oval:simp.cis.1.0.1.OracleLinux8.6.2.18_Ensure_no_duplicate_group_names_exist:def:1
    
      - Title: Ensure no duplicate group names exist
 
- oval:simp.cis.1.0.1.OracleLinux8.6.2.19_Ensure_shadow_group_is_empty:def:1
    
      - Title: Ensure shadow group is empty
 
- oval:simp.cis.1.0.1.OracleLinux8.6.2.1_Ensure_password_fields_are_not_empty:def:1
    
      - Title: Ensure password fields are not empty
 
- oval:simp.cis.1.0.1.OracleLinux8.6.2.20_Ensure_all_users_home_directories_exist:def:1
    
      - Title: Ensure all users’ home directories exist
 
- oval:simp.cis.1.0.1.OracleLinux8.6.2.2_Ensure_no_legacy__entries_exist_in_etcpasswd:def:1
    
      - Title: Ensure no legacy “+” entries exist in /etc/passwd
 
- oval:simp.cis.1.0.1.OracleLinux8.6.2.3_Ensure_root_PATH_Integrity:def:1
    
      - Title: Ensure root PATH Integrity
 
- oval:simp.cis.1.0.1.OracleLinux8.6.2.4_Ensure_no_legacy__entries_exist_in_etcshadow:def:1
    
      - Title: Ensure no legacy “+” entries exist in /etc/shadow
 
- oval:simp.cis.1.0.1.OracleLinux8.6.2.5_Ensure_no_legacy__entries_exist_in_etcgroup:def:1
    
      - Title: Ensure no legacy “+” entries exist in /etc/group
 
- oval:simp.cis.1.0.1.OracleLinux8.6.2.6_Ensure_root_is_the_only_UID_0_account:def:1
    
      - Title: Ensure root is the only UID 0 account
 
- oval:simp.cis.1.0.1.OracleLinux8.6.2.7_Ensure_users_home_directories_permissions_are_750_or_more_restrictive:def:1
    
      - Title: Ensure users’ home directories permissions are 750 or more restrictive
 
- oval:simp.cis.1.0.1.OracleLinux8.6.2.8_Ensure_users_own_their_home_directories:def:1
    
      - Title: Ensure users own their home directories
 
- oval:simp.cis.1.0.1.OracleLinux8.6.2.9_Ensure_users_dot_files_are_not_group_or_world_writable:def:1
    
      - Title: Ensure users’ dot files are not group or world writable
        RedHat 8 (223/236 [94%])
 
- oval:simp.cis.1.0.1.RedHat8.1.1.1.1_Ensure_mounting_of_cramfs_filesystems_is_disabled:def:1
    
      - Title: Ensure mounting of cramfs filesystems is disabled
 
- oval:simp.cis.1.0.1.RedHat8.1.1.1.2_Ensure_mounting_of_vFAT_filesystems_is_limited:def:1
    
      - Title: Ensure mounting of vFAT filesystems is limited
 
- oval:simp.cis.1.0.1.RedHat8.1.1.1.3_Ensure_mounting_of_squashfs_filesystems_is_disabled:def:1
    
      - Title: Ensure mounting of squashfs filesystems is disabled
 
- oval:simp.cis.1.0.1.RedHat8.1.1.1.4_Ensure_mounting_of_udf_filesystems_is_disabled:def:1
    
      - Title: Ensure mounting of udf filesystems is disabled
 
- oval:simp.cis.1.0.1.RedHat8.1.1.10_Ensure_noexec_option_set_on_vartmp_partition:def:1
    
      - Title: Ensure noexec option set on /var/tmp partition
 
- oval:simp.cis.1.0.1.RedHat8.1.1.14_Ensure_nodev_option_set_on_home_partition:def:1
    
      - Title: Ensure nodev option set on /home partition
 
- oval:simp.cis.1.0.1.RedHat8.1.1.15_Ensure_nodev_option_set_on_devshm_partition:def:1
    
      - Title: Ensure nodev option set on /dev/shm partition
 
- oval:simp.cis.1.0.1.RedHat8.1.1.16_Ensure_nosuid_option_set_on_devshm_partition:def:1
    
      - Title: Ensure nosuid option set on /dev/shm partition
 
- oval:simp.cis.1.0.1.RedHat8.1.1.17_Ensure_noexec_option_set_on_devshm_partition:def:1
    
      - Title: Ensure noexec option set on /dev/shm partition
 
- oval:simp.cis.1.0.1.RedHat8.1.1.18_Ensure_nodev_option_set_on_removable_media_partitions:def:1
    
      - Title: Ensure nodev option set on removable media partitions
 
- oval:simp.cis.1.0.1.RedHat8.1.1.19_Ensure_nosuid_option_set_on_removable_media_partitions:def:1
    
      - Title: Ensure nosuid option set on removable media partitions
 
- oval:simp.cis.1.0.1.RedHat8.1.1.20_Ensure_noexec_option_set_on_removable_media_partitions:def:1
    
      - Title: Ensure noexec option set on removable media partitions
 
- oval:simp.cis.1.0.1.RedHat8.1.1.21_Ensure_sticky_bit_is_set_on_all_world-writable_directories:def:1
    
      - Title: Ensure sticky bit is set on all world-writable directories
 
- oval:simp.cis.1.0.1.RedHat8.1.1.22_Disable_Automounting:def:1
    
      - Title: Disable Automounting
 
- oval:simp.cis.1.0.1.RedHat8.1.1.23_Disable_USB_Storage:def:1
    
      - Title: Disable USB Storage
 
- oval:simp.cis.1.0.1.RedHat8.1.1.2_Ensure_tmp_is_configured:def:1
    
      - Title: Ensure /tmp is configured
 
- oval:simp.cis.1.0.1.RedHat8.1.1.3_Ensure_nodev_option_set_on_tmp_partition:def:1
    
      - Title: Ensure nodev option set on /tmp partition
 
- oval:simp.cis.1.0.1.RedHat8.1.1.4_Ensure_nosuid_option_set_on_tmp_partition:def:1
    
      - Title: Ensure nosuid option set on /tmp partition
 
- oval:simp.cis.1.0.1.RedHat8.1.1.5_Ensure_noexec_option_set_on_tmp_partition:def:1
    
      - Title: Ensure noexec option set on /tmp partition
 
- oval:simp.cis.1.0.1.RedHat8.1.1.7_Ensure_separate_partition_exists_for_vartmp:def:1
    
      - Title: Ensure separate partition exists for /var/tmp
 
- oval:simp.cis.1.0.1.RedHat8.1.1.8_Ensure_nodev_option_set_on_vartmp_partition:def:1
    
      - Title: Ensure nodev option set on /var/tmp partition
 
- oval:simp.cis.1.0.1.RedHat8.1.1.9_Ensure_nosuid_option_set_on_vartmp_partition:def:1
    
      - Title: Ensure nosuid option set on /var/tmp partition
 
- oval:simp.cis.1.0.1.RedHat8.1.10_Ensure_system-wide_crypto_policy_is_not_legacy:def:1
    
      - Title: Ensure system-wide crypto policy is not legacy
 
- oval:simp.cis.1.0.1.RedHat8.1.11_Ensure_system-wide_crypto_policy_is_FUTURE_or_FIPS:def:1
    
      - Title: Ensure system-wide crypto policy is FUTURE or FIPS
 
- oval:simp.cis.1.0.1.RedHat8.1.2.2_Disable_the_rhnsd_Daemon:def:1
    
      - Title: Disable the rhnsd Daemon
- NOTE: rhnsd should only be disabled if it is not in use.
 
- oval:simp.cis.1.0.1.RedHat8.1.2.3_Ensure_GPG_keys_are_configured:def:1
    
      - Title: Ensure GPG keys are configured
 
- oval:simp.cis.1.0.1.RedHat8.1.2.4_Ensure_gpgcheck_is_globally_activated:def:1
    
      - Title: Ensure gpgcheck is globally activated
 
- oval:simp.cis.1.0.1.RedHat8.1.3.1_Ensure_sudo_is_installed:def:1
    
      - Title: Ensure sudo is installed
 
- oval:simp.cis.1.0.1.RedHat8.1.3.2_Ensure_sudo_commands_use_pty:def:1
    
      - Title: Ensure sudo commands use pty
 
- oval:simp.cis.1.0.1.RedHat8.1.3.3_Ensure_sudo_log_file_exists:def:1
    
      - Title: Ensure sudo log file exists
 
- oval:simp.cis.1.0.1.RedHat8.1.4.1_Ensure_AIDE_is_installed:def:1
    
      - Title: Ensure AIDE is installed
 
- oval:simp.cis.1.0.1.RedHat8.1.4.2_Ensure_filesystem_integrity_is_regularly_checked:def:1
    
      - Title: Ensure filesystem integrity is regularly checked
 
- oval:simp.cis.1.0.1.RedHat8.1.5.1_Ensure_permissions_on_bootloader_config_are_configured:def:1
    
      - Title: Ensure permissions on bootloader config are configured
 
- oval:simp.cis.1.0.1.RedHat8.1.5.2_Ensure_bootloader_password_is_set:def:1
    
      - Title: Ensure bootloader password is set
 
- oval:simp.cis.1.0.1.RedHat8.1.5.3_Ensure_authentication_required_for_single_user_mode:def:1
    
      - Title: Ensure authentication required for single user mode
 
- oval:simp.cis.1.0.1.RedHat8.1.6.1_Ensure_core_dumps_are_restricted:def:1
    
      - Title: Ensure core dumps are restricted
 
- oval:simp.cis.1.0.1.RedHat8.1.6.2_Ensure_address_space_layout_randomization_ASLR_is_enabled:def:1
    
      - Title: Ensure address space layout randomization (ASLR) is enabled
 
- oval:simp.cis.1.0.1.RedHat8.1.7.1.1_Ensure_SELinux_is_installed:def:1
    
      - Title: Ensure SELinux is installed
 
- oval:simp.cis.1.0.1.RedHat8.1.7.1.2_Ensure_SELinux_is_not_disabled_in_bootloader_configuration:def:1
    
      - Title: Ensure SELinux is not disabled in bootloader configuration
 
- oval:simp.cis.1.0.1.RedHat8.1.7.1.3_Ensure_SELinux_policy_is_configured:def:1
    
      - Title: Ensure SELinux policy is configured
 
- oval:simp.cis.1.0.1.RedHat8.1.7.1.4_Ensure_the_SELinux_state_is_enforcing:def:1
    
      - Title: Ensure the SELinux state is enforcing
 
- oval:simp.cis.1.0.1.RedHat8.1.7.1.6_Ensure_SETroubleshoot_is_not_installed:def:1
    
      - Title: Ensure SETroubleshoot is not installed
 
- oval:simp.cis.1.0.1.RedHat8.1.7.1.7_Ensure_the_MCS_Translation_Service_mcstrans_is_not_installed:def:1
    
      - Title: Ensure the MCS Translation Service (mcstrans) is not installed
 
- oval:simp.cis.1.0.1.RedHat8.1.8.1.1_Ensure_message_of_the_day_is_configured_properly:def:1
    
      - Title: Ensure message of the day is configured properly
 
- oval:simp.cis.1.0.1.RedHat8.1.8.1.2_Ensure_local_login_warning_banner_is_configured_properly:def:1
    
      - Title: Ensure local login warning banner is configured properly
 
- oval:simp.cis.1.0.1.RedHat8.1.8.1.3_Ensure_remote_login_warning_banner_is_configured_properly:def:1
    
      - Title: Ensure remote login warning banner is configured properly
 
- oval:simp.cis.1.0.1.RedHat8.1.8.1.4_Ensure_permissions_on_etcmotd_are_configured:def:1
    
      - Title: Ensure permissions on /etc/motd are configured
 
- oval:simp.cis.1.0.1.RedHat8.1.8.1.5_Ensure_permissions_on_etcissue_are_configured:def:1
    
      - Title: Ensure permissions on /etc/issue are configured
 
- oval:simp.cis.1.0.1.RedHat8.1.8.1.6_Ensure_permissions_on_etcissue.net_are_configured:def:1
    
      - Title: Ensure permissions on /etc/issue.net are configured
 
- oval:simp.cis.1.0.1.RedHat8.1.8.2_Ensure_GDM_login_banner_is_configured:def:1
    
      - Title: Ensure GDM login banner is configured
 
- oval:simp.cis.1.0.1.RedHat8.1.9_Ensure_updates_patches_and_additional_security_software_are_installed:def:1
    
      - Title: Ensure updates, patches, and additional security software are installed
 
- oval:simp.cis.1.0.1.RedHat8.2.1.1_Ensure_xinetd_is_not_installed:def:1
    
      - Title: Ensure xinetd is not installed
 
- oval:simp.cis.1.0.1.RedHat8.2.2.1.1_Ensure_time_synchronization_is_in_use:def:1
    
      - Title: Ensure time synchronization is in use
 
- oval:simp.cis.1.0.1.RedHat8.2.2.1.2_Ensure_chrony_is_configured:def:1
    
      - Title: Ensure chrony is configured
 
- oval:simp.cis.1.0.1.RedHat8.2.2.10_Ensure_FTP_Server_is_not_enabled:def:1
    
      - Title: Ensure FTP Server is not enabled
 
- oval:simp.cis.1.0.1.RedHat8.2.2.11_Ensure_DNS_Server_is_not_enabled:def:1
    
      - Title: Ensure DNS Server is not enabled
 
- oval:simp.cis.1.0.1.RedHat8.2.2.12_Ensure_NFS_is_not_enabled:def:1
    
      - Title: Ensure NFS is not enabled
 
- oval:simp.cis.1.0.1.RedHat8.2.2.13_Ensure__RPC_is_not_enabled:def:1
    
      - Title: Ensure RPC is not enabled
 
- oval:simp.cis.1.0.1.RedHat8.2.2.14_Ensure_LDAP_server_is_not_enabled:def:1
    
      - Title: Ensure LDAP server is not enabled
 
- oval:simp.cis.1.0.1.RedHat8.2.2.15_Ensure_DHCP_Server_is_not_enabled:def:1
    
      - Title: Ensure DHCP Server is not enabled
 
- oval:simp.cis.1.0.1.RedHat8.2.2.16_Ensure_CUPS_is_not_enabled:def:1
    
      - Title: Ensure CUPS is not enabled
 
- oval:simp.cis.1.0.1.RedHat8.2.2.17_Ensure_NIS_Server_is_not_enabled:def:1
    
      - Title: Ensure NIS Server is not enabled
 
- oval:simp.cis.1.0.1.RedHat8.2.2.18_Ensure_mail_transfer_agent_is_configured_for_local-only_mode:def:1
    
      - Title: Ensure mail transfer agent is configured for local-only mode
 
- oval:simp.cis.1.0.1.RedHat8.2.2.2_Ensure_X_Window_System_is_not_installed:def:1
    
      - Title: Ensure X Window System is not installed
 
- oval:simp.cis.1.0.1.RedHat8.2.2.3_Ensure_rsync_service_is_not_enabled:def:1
    
      - Title: Ensure rsync service is not enabled
 
- oval:simp.cis.1.0.1.RedHat8.2.2.4_Ensure_Avahi_Server_is_not_enabled:def:1
    
      - Title: Ensure Avahi Server is not enabled
 
- oval:simp.cis.1.0.1.RedHat8.2.2.5_Ensure_SNMP_Server_is_not_enabled:def:1
    
      - Title: Ensure SNMP Server is not enabled
 
- oval:simp.cis.1.0.1.RedHat8.2.2.6_Ensure_HTTP_Proxy_Server_is_not_enabled:def:1
    
      - Title: Ensure HTTP Proxy Server is not enabled
 
- oval:simp.cis.1.0.1.RedHat8.2.2.7_Ensure_Samba_is_not_enabled:def:1
    
      - Title: Ensure Samba is not enabled
 
- oval:simp.cis.1.0.1.RedHat8.2.2.8_Ensure_IMAP_and_POP3_server_is_not_enabled:def:1
    
      - Title: Ensure IMAP and POP3 server is not enabled
 
- oval:simp.cis.1.0.1.RedHat8.2.2.9_Ensure_HTTP_server_is_not_enabled:def:1
    
      - Title: Ensure HTTP server is not enabled
 
- oval:simp.cis.1.0.1.RedHat8.2.3.1_Ensure_NIS_Client_is_not_installed:def:1
    
      - Title: Ensure NIS Client is not installed
 
- oval:simp.cis.1.0.1.RedHat8.2.3.2_Ensure_telnet_client_is_not_installed:def:1
    
      - Title: Ensure telnet client is not installed
 
- oval:simp.cis.1.0.1.RedHat8.2.3.3_Ensure_LDAP_client_is_not_installed:def:1
    
      - Title: Ensure LDAP client is not installed
 
- oval:simp.cis.1.0.1.RedHat8.3.1.1_Ensure_IP_forwarding_is_disabled:def:1
    
      - Title: Ensure IP forwarding is disabled
 
- oval:simp.cis.1.0.1.RedHat8.3.1.2_Ensure_packet_redirect_sending_is_disabled:def:1
    
      - Title: Ensure packet redirect sending is disabled
 
- oval:simp.cis.1.0.1.RedHat8.3.2.1_Ensure_source_routed_packets_are_not_accepted:def:1
    
      - Title: Ensure source routed packets are not accepted
 
- oval:simp.cis.1.0.1.RedHat8.3.2.2_Ensure_ICMP_redirects_are_not_accepted:def:1
    
      - Title: Ensure ICMP redirects are not accepted
 
- oval:simp.cis.1.0.1.RedHat8.3.2.3_Ensure_secure_ICMP_redirects_are_not_accepted:def:1
    
      - Title: Ensure secure ICMP redirects are not accepted
 
- oval:simp.cis.1.0.1.RedHat8.3.2.4_Ensure_suspicious_packets_are_logged:def:1
    
      - Title: Ensure suspicious packets are logged
 
- oval:simp.cis.1.0.1.RedHat8.3.2.5_Ensure_broadcast_ICMP_requests_are_ignored:def:1
    
      - Title: Ensure broadcast ICMP requests are ignored
 
- oval:simp.cis.1.0.1.RedHat8.3.2.6_Ensure_bogus_ICMP_responses_are_ignored:def:1
    
      - Title: Ensure bogus ICMP responses are ignored
 
- oval:simp.cis.1.0.1.RedHat8.3.2.7_Ensure_Reverse_Path_Filtering_is_enabled:def:1
    
      - Title: Ensure Reverse Path Filtering is enabled
 
- oval:simp.cis.1.0.1.RedHat8.3.2.8_Ensure_TCP_SYN_Cookies_is_enabled:def:1
    
      - Title: Ensure TCP SYN Cookies is enabled
 
- oval:simp.cis.1.0.1.RedHat8.3.2.9_Ensure_IPv6_router_advertisements_are_not_accepted:def:1
    
      - Title: Ensure IPv6 router advertisements are not accepted
 
- oval:simp.cis.1.0.1.RedHat8.3.3.1_Ensure_DCCP_is_disabled:def:1
    
      - Title: Ensure DCCP is disabled
 
- oval:simp.cis.1.0.1.RedHat8.3.3.2_Ensure_SCTP_is_disabled:def:1
    
      - Title: Ensure SCTP is disabled
 
- oval:simp.cis.1.0.1.RedHat8.3.3.3_Ensure_RDS_is_disabled:def:1
    
      - Title: Ensure RDS is disabled
 
- oval:simp.cis.1.0.1.RedHat8.3.3.4_Ensure_TIPC_is_disabled:def:1
    
      - Title: Ensure TIPC is disabled
 
- oval:simp.cis.1.0.1.RedHat8.3.4.1.1_Ensure_a_Firewall_package_is_installed:def:1
    
      - Title: Ensure a Firewall package is installed
 
- oval:simp.cis.1.0.1.RedHat8.3.4.2.1_Ensure_firewalld_service_is_enabled_and_running:def:1
    
      - Title: Ensure firewalld service is enabled and running
 
- oval:simp.cis.1.0.1.RedHat8.3.4.2.2_Ensure_iptables_service_is_not_enabled_with_firewalld:def:1
    
      - Title: Ensure iptables service is not enabled with firewalld
 
- oval:simp.cis.1.0.1.RedHat8.3.4.2.3_Ensure_nftables_is_not_enabled_with_firewalld:def:1
    
      - Title: Ensure nftables is not enabled with firewalld
 
- oval:simp.cis.1.0.1.RedHat8.3.4.2.4_Ensure_firewalld_default_zone_is_set:def:1
    
      - Title: Ensure firewalld default zone is set
 
- oval:simp.cis.1.0.1.RedHat8.3.4.2.5_Ensure_network_interfaces_are_assigned_to_appropriate_zone:def:1
    
      - Title: Ensure network interfaces are assigned to appropriate zone
 
- oval:simp.cis.1.0.1.RedHat8.3.4.2.6_Ensure_firewalld_drops_unnecessary_services_and_ports:def:1
    
      - Title: Ensure firewalld drops unnecessary services and ports
 
- oval:simp.cis.1.0.1.RedHat8.3.4.3.1_Ensure_iptables_are_flushed_with_nftables:def:1
    
      - Title: Ensure iptables are flushed with nftables
 
- oval:simp.cis.1.0.1.RedHat8.3.4.3.2_Ensure_an_nftables_table_exists:def:1
    
      - Title: Ensure an nftables table exists
 
- oval:simp.cis.1.0.1.RedHat8.3.4.3.3_Ensure_nftables_base_chains_exist:def:1
    
      - Title: Ensure nftables base chains exist
 
- oval:simp.cis.1.0.1.RedHat8.3.4.3.4_Ensure_nftables_loopback_traffic_is_configured:def:1
    
      - Title: Ensure nftables loopback traffic is configured
 
- oval:simp.cis.1.0.1.RedHat8.3.4.3.5_Ensure_nftables_outbound_and_established_connections_are_configured:def:1
    
      - Title: Ensure nftables outbound and established connections are configured
 
- oval:simp.cis.1.0.1.RedHat8.3.4.3.6_Ensure_nftables_default_deny_firewall_policy:def:1
    
      - Title: Ensure nftables default deny firewall policy
 
- oval:simp.cis.1.0.1.RedHat8.3.4.3.7_Ensure_nftables_service_is_enabled:def:1
    
      - Title: Ensure nftables service is enabled
 
- oval:simp.cis.1.0.1.RedHat8.3.4.3.8_Ensure_nftables_rules_are_permanent:def:1
    
      - Title: Ensure nftables rules are permanent
 
- oval:simp.cis.1.0.1.RedHat8.3.4.4.1.1_Ensure_iptables_default_deny_firewall_policy:def:1
    
      - Title: Ensure iptables default deny firewall policy
 
- oval:simp.cis.1.0.1.RedHat8.3.4.4.1.2_Ensure_iptables_loopback_traffic_is_configured:def:1
    
      - Title: Ensure iptables loopback traffic is configured
 
- oval:simp.cis.1.0.1.RedHat8.3.4.4.1.3_Ensure_iptables_outbound_and_established_connections_are_configured:def:1
    
      - Title: Ensure iptables outbound and established connections are configured
 
- oval:simp.cis.1.0.1.RedHat8.3.4.4.1.4_Ensure_iptables_firewall_rules_exist_for_all_open_ports:def:1
    
      - Title: Ensure iptables firewall rules exist for all open ports
 
- oval:simp.cis.1.0.1.RedHat8.3.4.4.1.5_Ensure_iptables_is_enabled_and_active:def:1
    
      - Title: Ensure iptables is enabled and active
 
- oval:simp.cis.1.0.1.RedHat8.3.4.4.2.1_Ensure_ip6tables_default_deny_firewall_policy:def:1
    
      - Title: Ensure ip6tables default deny firewall policy
 
- oval:simp.cis.1.0.1.RedHat8.3.4.4.2.2_Ensure_ip6tables_loopback_traffic_is_configured:def:1
    
      - Title: Ensure ip6tables loopback traffic is configured
 
- oval:simp.cis.1.0.1.RedHat8.3.4.4.2.3_Ensure_ip6tables_outbound_and_established_connections_are_configured:def:1
    
      - Title: Ensure ip6tables outbound and established connections are configured
 
- oval:simp.cis.1.0.1.RedHat8.3.4.4.2.4_Ensure_ip6tables_firewall_rules_exist_for_all_open_ports:def:1
    
      - Title: Ensure ip6tables firewall rules exist for all open ports
 
- oval:simp.cis.1.0.1.RedHat8.3.4.4.2.5_Ensure_ip6tables_is_enabled_and_active:def:1
    
      - Title: Ensure ip6tables is enabled and active
 
- oval:simp.cis.1.0.1.RedHat8.3.5_Ensure_wireless_interfaces_are_disabled:def:1
    
      - Title: Ensure wireless interfaces are disabled
 
- oval:simp.cis.1.0.1.RedHat8.3.6_Disable_IPv6:def:1
    
  
- oval:simp.cis.1.0.1.RedHat8.4.1.1.1_Ensure_auditd_is_installed:def:1
    
      - Title: Ensure auditd is installed
 
- oval:simp.cis.1.0.1.RedHat8.4.1.1.2_Ensure_auditd_service_is_enabled:def:1
    
      - Title: Ensure auditd service is enabled
 
- oval:simp.cis.1.0.1.RedHat8.4.1.1.3_Ensure_auditing_for_processes_that_start_prior_to_auditd_is_enabled:def:1
    
      - Title: Ensure auditing for processes that start prior to auditd is enabled
 
- oval:simp.cis.1.0.1.RedHat8.4.1.1.4_Ensure_audit_backlog_limit_is_sufficient:def:1
    
      - Title: Ensure audit_backlog_limit is sufficient
 
- oval:simp.cis.1.0.1.RedHat8.4.1.10_Ensure_unsuccessful_unauthorized_file_access_attempts_are_collected:def:1
    
      - Title: Ensure unsuccessful unauthorized file access attempts are collected
 
- oval:simp.cis.1.0.1.RedHat8.4.1.11_Ensure_events_that_modify_usergroup_information_are_collected:def:1
    
      - Title: Ensure events that modify user/group information are collected
 
- oval:simp.cis.1.0.1.RedHat8.4.1.12_Ensure_successful_file_system_mounts_are_collected:def:1
    
      - Title: Ensure successful file system mounts are collected
 
- oval:simp.cis.1.0.1.RedHat8.4.1.13_Ensure_use_of_privileged_commands_is_collected:def:1
    
      - Title: Ensure use of privileged commands is collected
 
- oval:simp.cis.1.0.1.RedHat8.4.1.14_Ensure_file_deletion_events_by_users_are_collected:def:1
    
      - Title: Ensure file deletion events by users are collected
 
- oval:simp.cis.1.0.1.RedHat8.4.1.15_Ensure_kernel_module_loading_and_unloading_is_collected:def:1
    
      - Title: Ensure kernel module loading and unloading is collected
 
- oval:simp.cis.1.0.1.RedHat8.4.1.16_Ensure_system_administrator_actions_sudolog_are_collected:def:1
    
      - Title: Ensure system administrator actions (sudolog) are collected
 
- oval:simp.cis.1.0.1.RedHat8.4.1.17_Ensure_the_audit_configuration_is_immutable:def:1
    
      - Title: Ensure the audit configuration is immutable
 
- oval:simp.cis.1.0.1.RedHat8.4.1.2.1_Ensure_audit_log_storage_size_is_configured:def:1
    
      - Title: Ensure audit log storage size is configured
 
- oval:simp.cis.1.0.1.RedHat8.4.1.2.2_Ensure_audit_logs_are_not_automatically_deleted:def:1
    
      - Title: Ensure audit logs are not automatically deleted
 
- oval:simp.cis.1.0.1.RedHat8.4.1.2.3_Ensure_system_is_disabled_when_audit_logs_are_full:def:1
    
      - Title: Ensure system is disabled when audit logs are full
 
- oval:simp.cis.1.0.1.RedHat8.4.1.3_Ensure_changes_to_system_administration_scope_sudoers_is_collected:def:1
    
      - Title: Ensure changes to system administration scope (sudoers) is collected
 
- oval:simp.cis.1.0.1.RedHat8.4.1.4_Ensure_login_and_logout_events_are_collected:def:1
    
      - Title: Ensure login and logout events are collected
 
- oval:simp.cis.1.0.1.RedHat8.4.1.5_Ensure_session_initiation_information_is_collected:def:1
    
      - Title: Ensure session initiation information is collected
 
- oval:simp.cis.1.0.1.RedHat8.4.1.6_Ensure_events_that_modify_date_and_time_information_are_collected:def:1
    
      - Title: Ensure events that modify date and time information are collected
 
- oval:simp.cis.1.0.1.RedHat8.4.1.7_Ensure_events_that_modify_the_systems_Mandatory_Access_Controls_are_collected:def:1
    
      - Title: Ensure events that modify the system’s Mandatory Access Controls are collected
 
- oval:simp.cis.1.0.1.RedHat8.4.1.8_Ensure_events_that_modify_the_systems_network_environment_are_collected:def:1
    
      - Title: Ensure events that modify the system’s network environment are collected
 
- oval:simp.cis.1.0.1.RedHat8.4.1.9_Ensure_discretionary_access_control_permission_modification_events_are_collected:def:1
    
      - Title: Ensure discretionary access control permission modification events are collected
 
- oval:simp.cis.1.0.1.RedHat8.4.2.1.1_Ensure_rsyslog_is_installed:def:1
    
      - Title: Ensure rsyslog is installed
 
- oval:simp.cis.1.0.1.RedHat8.4.2.1.2_Ensure_rsyslog_Service_is_enabled:def:1
    
      - Title: Ensure rsyslog Service is enabled
 
- oval:simp.cis.1.0.1.RedHat8.4.2.1.3_Ensure_rsyslog_default_file_permissions_configured:def:1
    
      - Title: Ensure rsyslog default file permissions configured
 
- oval:simp.cis.1.0.1.RedHat8.4.2.1.4_Ensure_logging_is_configured:def:1
    
      - Title: Ensure logging is configured
 
- oval:simp.cis.1.0.1.RedHat8.4.2.1.5_Ensure_rsyslog_is_configured_to_send_logs_to_a_remote_log_host:def:1
    
      - Title: Ensure rsyslog is configured to send logs to a remote log host
 
- oval:simp.cis.1.0.1.RedHat8.4.2.1.6_Ensure_remote_rsyslog_messages_are_only_accepted_on_designated_log_hosts.:def:1
    
      - Title: Ensure remote rsyslog messages are only accepted on designated log hosts.
 
- oval:simp.cis.1.0.1.RedHat8.4.2.2.1_Ensure_journald_is_configured_to_send_logs_to_rsyslog:def:1
    
      - Title: Ensure journald is configured to send logs to rsyslog
 
- oval:simp.cis.1.0.1.RedHat8.4.2.2.2_Ensure_journald_is_configured_to_compress_large_log_files:def:1
    
      - Title: Ensure journald is configured to compress large log files
 
- oval:simp.cis.1.0.1.RedHat8.4.2.2.3_Ensure_journald_is_configured_to_write_logfiles_to_persistent_disk:def:1
    
      - Title: Ensure journald is configured to write logfiles to persistent disk
 
- oval:simp.cis.1.0.1.RedHat8.4.2.3_Ensure_permissions_on_all_logfiles_are_configured:def:1
    
      - Title: Ensure permissions on all logfiles are configured
 
- oval:simp.cis.1.0.1.RedHat8.4.3_Ensure_logrotate_is_configured:def:1
    
      - Title: Ensure logrotate is configured
 
- oval:simp.cis.1.0.1.RedHat8.5.1.1_Ensure_cron_daemon_is_enabled:def:1
    
      - Title: Ensure cron daemon is enabled
 
- oval:simp.cis.1.0.1.RedHat8.5.1.2_Ensure_permissions_on_etccrontab_are_configured:def:1
    
      - Title: Ensure permissions on /etc/crontab are configured
 
- oval:simp.cis.1.0.1.RedHat8.5.1.3_Ensure_permissions_on_etccron.hourly_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.hourly are configured
 
- oval:simp.cis.1.0.1.RedHat8.5.1.4_Ensure_permissions_on_etccron.daily_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.daily are configured
 
- oval:simp.cis.1.0.1.RedHat8.5.1.5_Ensure_permissions_on_etccron.weekly_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.weekly are configured
 
- oval:simp.cis.1.0.1.RedHat8.5.1.6_Ensure_permissions_on_etccron.monthly_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.monthly are configured
 
- oval:simp.cis.1.0.1.RedHat8.5.1.7_Ensure_permissions_on_etccron.d_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.d are configured
 
- oval:simp.cis.1.0.1.RedHat8.5.1.8_Ensure_atcron_is_restricted_to_authorized_users:def:1
    
      - Title: Ensure at/cron is restricted to authorized users
 
- oval:simp.cis.1.0.1.RedHat8.5.2.10_Ensure_SSH_root_login_is_disabled:def:1
    
      - Title: Ensure SSH root login is disabled
 
- oval:simp.cis.1.0.1.RedHat8.5.2.11_Ensure_SSH_PermitEmptyPasswords_is_disabled:def:1
    
      - Title: Ensure SSH PermitEmptyPasswords is disabled
 
- oval:simp.cis.1.0.1.RedHat8.5.2.12_Ensure_SSH_PermitUserEnvironment_is_disabled:def:1
    
      - Title: Ensure SSH PermitUserEnvironment is disabled
 
- oval:simp.cis.1.0.1.RedHat8.5.2.13_Ensure_SSH_Idle_Timeout_Interval_is_configured:def:1
    
      - Title: Ensure SSH Idle Timeout Interval is configured
 
- oval:simp.cis.1.0.1.RedHat8.5.2.14_Ensure_SSH_LoginGraceTime_is_set_to_one_minute_or_less:def:1
    
      - Title: Ensure SSH LoginGraceTime is set to one minute or less
 
- oval:simp.cis.1.0.1.RedHat8.5.2.15_Ensure_SSH_warning_banner_is_configured:def:1
    
      - Title: Ensure SSH warning banner is configured
 
- oval:simp.cis.1.0.1.RedHat8.5.2.16_Ensure_SSH_PAM_is_enabled:def:1
    
      - Title: Ensure SSH PAM is enabled
 
- oval:simp.cis.1.0.1.RedHat8.5.2.17_Ensure_SSH_AllowTcpForwarding_is_disabled:def:1
    
      - Title: Ensure SSH AllowTcpForwarding is disabled
 
- oval:simp.cis.1.0.1.RedHat8.5.2.18_Ensure_SSH_MaxStartups_is_configured:def:1
    
      - Title: Ensure SSH MaxStartups is configured
 
- oval:simp.cis.1.0.1.RedHat8.5.2.19_Ensure_SSH_MaxSessions_is_set_to_4_or_less:def:1
    
      - Title: Ensure SSH MaxSessions is set to 4 or less
 
- oval:simp.cis.1.0.1.RedHat8.5.2.1_Ensure_permissions_on_etcsshsshd_config_are_configured:def:1
    
      - Title: Ensure permissions on /etc/ssh/sshd_config are configured
 
- oval:simp.cis.1.0.1.RedHat8.5.2.20_Ensure_system-wide_crypto_policy_is_not_over-ridden:def:1
    
      - Title: Ensure system-wide crypto policy is not over-ridden
 
- oval:simp.cis.1.0.1.RedHat8.5.2.2_Ensure_SSH_access_is_limited:def:1
    
      - Title: Ensure SSH access is limited
 
- oval:simp.cis.1.0.1.RedHat8.5.2.3_Ensure_permissions_on_SSH_private_host_key_files_are_configured:def:1
    
      - Title: Ensure permissions on SSH private host key files are configured
 
- oval:simp.cis.1.0.1.RedHat8.5.2.4_Ensure_permissions_on_SSH_public_host_key_files_are_configured:def:1
    
      - Title: Ensure permissions on SSH public host key files are configured
 
- oval:simp.cis.1.0.1.RedHat8.5.2.5_Ensure_SSH_LogLevel_is_appropriate:def:1
    
      - Title: Ensure SSH LogLevel is appropriate
 
- oval:simp.cis.1.0.1.RedHat8.5.2.6_Ensure_SSH_X11_forwarding_is_disabled:def:1
    
      - Title: Ensure SSH X11 forwarding is disabled
 
- oval:simp.cis.1.0.1.RedHat8.5.2.7_Ensure_SSH_MaxAuthTries_is_set_to_4_or_less:def:1
    
      - Title: Ensure SSH MaxAuthTries is set to 4 or less
 
- oval:simp.cis.1.0.1.RedHat8.5.2.8_Ensure_SSH_IgnoreRhosts_is_enabled:def:1
    
      - Title: Ensure SSH IgnoreRhosts is enabled
 
- oval:simp.cis.1.0.1.RedHat8.5.2.9_Ensure_SSH_HostbasedAuthentication_is_disabled:def:1
    
      - Title: Ensure SSH HostbasedAuthentication is disabled
 
- oval:simp.cis.1.0.1.RedHat8.5.3.1_Create_custom_authselect_profile:def:1
    
      - Title: Create custom authselect profile
 
- oval:simp.cis.1.0.1.RedHat8.5.3.2_Select_authselect_profile:def:1
    
      - Title: Select authselect profile
 
- oval:simp.cis.1.0.1.RedHat8.5.3.3_Ensure_authselect_includes_with-faillock:def:1
    
      - Title: Ensure authselect includes with-faillock
 
- oval:simp.cis.1.0.1.RedHat8.5.4.1_Ensure_password_creation_requirements_are_configured:def:1
    
      - Title: Ensure password creation requirements are configured
 
- oval:simp.cis.1.0.1.RedHat8.5.4.2_Ensure_lockout_for_failed_password_attempts_is_configured:def:1
    
      - Title: Ensure lockout for failed password attempts is configured
 
- oval:simp.cis.1.0.1.RedHat8.5.4.3_Ensure_password_reuse_is_limited:def:1
    
      - Title: Ensure password reuse is limited
 
- oval:simp.cis.1.0.1.RedHat8.5.4.4_Ensure_password_hashing_algorithm_is_SHA-512:def:1
    
      - Title: Ensure password hashing algorithm is SHA-512
 
- oval:simp.cis.1.0.1.RedHat8.5.5.1.1_Ensure_password_expiration_is_365_days_or_less:def:1
    
      - Title: Ensure password expiration is 365 days or less
 
- oval:simp.cis.1.0.1.RedHat8.5.5.1.2_Ensure_minimum_days_between_password_changes_is_7_or_more:def:1
    
      - Title: Ensure minimum days between password changes is 7 or more
 
- oval:simp.cis.1.0.1.RedHat8.5.5.1.3_Ensure_password_expiration_warning_days_is_7_or_more:def:1
    
      - Title: Ensure password expiration warning days is 7 or more
 
- oval:simp.cis.1.0.1.RedHat8.5.5.1.4_Ensure_inactive_password_lock_is_30_days_or_less:def:1
    
      - Title: Ensure inactive password lock is 30 days or less
 
- oval:simp.cis.1.0.1.RedHat8.5.5.1.5_Ensure_all_users_last_password_change_date_is_in_the_past:def:1
    
      - Title: Ensure all users last password change date is in the past
 
- oval:simp.cis.1.0.1.RedHat8.5.5.2_Ensure_system_accounts_are_secured:def:1
    
      - Title: Ensure system accounts are secured
 
- oval:simp.cis.1.0.1.RedHat8.5.5.3_Ensure_default_user_shell_timeout_is_900_seconds_or_less:def:1
    
      - Title: Ensure default user shell timeout is 900 seconds or less
 
- oval:simp.cis.1.0.1.RedHat8.5.5.4_Ensure_default_group_for_the_root_account_is_GID_0:def:1
    
      - Title: Ensure default group for the root account is GID 0
 
- oval:simp.cis.1.0.1.RedHat8.5.5.5_Ensure_default_user_umask_is_027_or_more_restrictive:def:1
    
      - Title: Ensure default user umask is 027 or more restrictive
 
- oval:simp.cis.1.0.1.RedHat8.5.6_Ensure_root_login_is_restricted_to_system_console:def:1
    
      - Title: Ensure root login is restricted to system console
 
- oval:simp.cis.1.0.1.RedHat8.5.7_Ensure_access_to_the_su_command_is_restricted:def:1
    
      - Title: Ensure access to the su command is restricted
 
- oval:simp.cis.1.0.1.RedHat8.6.1.2_Ensure_permissions_on_etcpasswd_are_configured:def:1
    
      - Title: Ensure permissions on /etc/passwd are configured
 
- oval:simp.cis.1.0.1.RedHat8.6.1.3_Ensure_permissions_on_etcpasswd-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/passwd- are configured
 
- oval:simp.cis.1.0.1.RedHat8.6.1.4_Ensure_permissions_on_etcshadow_are_configured:def:1
    
      - Title: Ensure permissions on /etc/shadow are configured
 
- oval:simp.cis.1.0.1.RedHat8.6.1.5_Ensure_permissions_on_etcshadow-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/shadow- are configured
 
- oval:simp.cis.1.0.1.RedHat8.6.1.6_Ensure_permissions_on_etcgshadow_are_configured:def:1
    
      - Title: Ensure permissions on /etc/gshadow are configured
 
- oval:simp.cis.1.0.1.RedHat8.6.1.7_Ensure_permissions_on_etcgshadow-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/gshadow- are configured
 
- oval:simp.cis.1.0.1.RedHat8.6.1.8_Ensure_permissions_on_etcgroup_are_configured:def:1
    
      - Title: Ensure permissions on /etc/group are configured
 
- oval:simp.cis.1.0.1.RedHat8.6.1.9_Ensure_permissions_on_etcgroup-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/group- are configured
 
- oval:simp.cis.1.0.1.RedHat8.6.2.10Ensure_no_users_have.forward_files:def:1
    
      - Title: Ensure no users have .forward files
 
- oval:simp.cis.1.0.1.RedHat8.6.2.11Ensure_no_users_have.netrc_files:def:1
    
      - Title: Ensure no users have .netrc files
 
- oval:simp.cis.1.0.1.RedHat8.6.2.12Ensure_users.netrc_Files_are_not_group_or_world_accessible:def:1
    
      - Title: Ensure users’ .netrc Files are not group or world accessible
 
- oval:simp.cis.1.0.1.RedHat8.6.2.13Ensure_no_users_have.rhosts_files:def:1
    
      - Title: Ensure no users have .rhosts files
 
- oval:simp.cis.1.0.1.RedHat8.6.2.14_Ensure_all_groups_in_etcpasswd_exist_in_etcgroup:def:1
    
      - Title: Ensure all groups in /etc/passwd exist in /etc/group
 
- oval:simp.cis.1.0.1.RedHat8.6.2.15_Ensure_no_duplicate_UIDs_exist:def:1
    
      - Title: Ensure no duplicate UIDs exist
 
- oval:simp.cis.1.0.1.RedHat8.6.2.16_Ensure_no_duplicate_GIDs_exist:def:1
    
      - Title: Ensure no duplicate GIDs exist
 
- oval:simp.cis.1.0.1.RedHat8.6.2.17_Ensure_no_duplicate_user_names_exist:def:1
    
      - Title: Ensure no duplicate user names exist
 
- oval:simp.cis.1.0.1.RedHat8.6.2.18_Ensure_no_duplicate_group_names_exist:def:1
    
      - Title: Ensure no duplicate group names exist
 
- oval:simp.cis.1.0.1.RedHat8.6.2.19_Ensure_shadow_group_is_empty:def:1
    
      - Title: Ensure shadow group is empty
 
- oval:simp.cis.1.0.1.RedHat8.6.2.1_Ensure_password_fields_are_not_empty:def:1
    
      - Title: Ensure password fields are not empty
 
- oval:simp.cis.1.0.1.RedHat8.6.2.20_Ensure_all_users_home_directories_exist:def:1
    
      - Title: Ensure all users’ home directories exist
 
- oval:simp.cis.1.0.1.RedHat8.6.2.2_Ensure_no_legacy__entries_exist_in_etcpasswd:def:1
    
      - Title: Ensure no legacy “+” entries exist in /etc/passwd
 
- oval:simp.cis.1.0.1.RedHat8.6.2.3_Ensure_root_PATH_Integrity:def:1
    
      - Title: Ensure root PATH Integrity
 
- oval:simp.cis.1.0.1.RedHat8.6.2.4_Ensure_no_legacy__entries_exist_in_etcshadow:def:1
    
      - Title: Ensure no legacy “+” entries exist in /etc/shadow
 
- oval:simp.cis.1.0.1.RedHat8.6.2.5_Ensure_no_legacy__entries_exist_in_etcgroup:def:1
    
      - Title: Ensure no legacy “+” entries exist in /etc/group
 
- oval:simp.cis.1.0.1.RedHat8.6.2.6_Ensure_root_is_the_only_UID_0_account:def:1
    
      - Title: Ensure root is the only UID 0 account
 
- oval:simp.cis.1.0.1.RedHat8.6.2.7_Ensure_users_home_directories_permissions_are_750_or_more_restrictive:def:1
    
      - Title: Ensure users’ home directories permissions are 750 or more restrictive
 
- oval:simp.cis.1.0.1.RedHat8.6.2.8_Ensure_users_own_their_home_directories:def:1
    
      - Title: Ensure users own their home directories
 
- oval:simp.cis.1.0.1.RedHat8.6.2.9_Ensure_users_dot_files_are_not_group_or_world_writable:def:1
    
      - Title: Ensure users’ dot files are not group or world writable
        CentOS 7 (232/246 [94%])
 
- oval:simp.cis.3.1.1.CentOS7.1.1.1.1_Ensure_mounting_of_cramfs_filesystems_is_disabled:def:1
    
      - Title: Ensure mounting of cramfs filesystems is disabled
 
- oval:simp.cis.3.1.1.CentOS7.1.1.1.2_Ensure_mounting_of_squashfs_filesystems_is_disabled:def:1
    
      - Title: Ensure mounting of squashfs filesystems is disabled
 
- oval:simp.cis.3.1.1.CentOS7.1.1.1.3_Ensure_mounting_of_udf_filesystems_is_disabled:def:1
    
      - Title: Ensure mounting of udf filesystems is disabled
 
- oval:simp.cis.3.1.1.CentOS7.1.1.12_Ensure_vartmp_partition_includes_the_noexec_option:def:1
    
      - Title: Ensure /var/tmp partition includes the noexec option
 
- oval:simp.cis.3.1.1.CentOS7.1.1.13_Ensure_vartmp_partition_includes_the_nodev_option:def:1
    
      - Title: Ensure /var/tmp partition includes the nodev option
 
- oval:simp.cis.3.1.1.CentOS7.1.1.14_Ensure_vartmp_partition_includes_the_nosuid_option:def:1
    
      - Title: Ensure /var/tmp partition includes the nosuid option
 
- oval:simp.cis.3.1.1.CentOS7.1.1.18_Ensure_home_partition_includes_the_nodev_option:def:1
    
      - Title: Ensure /home partition includes the nodev option
 
- oval:simp.cis.3.1.1.CentOS7.1.1.19_Ensure_removable_media_partitions_include_noexec_option:def:1
    
      - Title: Ensure removable media partitions include noexec option
 
- oval:simp.cis.3.1.1.CentOS7.1.1.20_Ensure_nodev_option_set_on_removable_media_partitions:def:1
    
      - Title: Ensure nodev option set on removable media partitions
 
- oval:simp.cis.3.1.1.CentOS7.1.1.21_Ensure_nosuid_option_set_on_removable_media_partitions:def:1
    
      - Title: Ensure nosuid option set on removable media partitions
 
- oval:simp.cis.3.1.1.CentOS7.1.1.22_Ensure_sticky_bit_is_set_on_all_world-writable_directories:def:1
    
      - Title: Ensure sticky bit is set on all world-writable directories
 
- oval:simp.cis.3.1.1.CentOS7.1.1.23_Disable_Automounting:def:1
    
      - Title: Disable Automounting
 
- oval:simp.cis.3.1.1.CentOS7.1.1.24_Disable_USB_Storage:def:1
    
      - Title: Disable USB Storage
 
- oval:simp.cis.3.1.1.CentOS7.1.1.2_Ensure_tmp_is_configured:def:1
    
      - Title: Ensure /tmp is configured
 
- oval:simp.cis.3.1.1.CentOS7.1.1.3_Ensure_noexec_option_set_on_tmp_partition:def:1
    
      - Title: Ensure noexec option set on /tmp partition
 
- oval:simp.cis.3.1.1.CentOS7.1.1.4_Ensure_nodev_option_set_on_tmp_partition:def:1
    
      - Title: Ensure nodev option set on /tmp partition
 
- oval:simp.cis.3.1.1.CentOS7.1.1.5_Ensure_nosuid_option_set_on_tmp_partition:def:1
    
      - Title: Ensure nosuid option set on /tmp partition
 
- oval:simp.cis.3.1.1.CentOS7.1.1.6_Ensure_devshm_is_configured:def:1
    
      - Title: Ensure /dev/shm is configured
 
- oval:simp.cis.3.1.1.CentOS7.1.1.7_Ensure_noexec_option_set_on_devshm_partition:def:1
    
      - Title: Ensure noexec option set on /dev/shm partition
 
- oval:simp.cis.3.1.1.CentOS7.1.1.8_Ensure_nodev_option_set_on_devshm_partition:def:1
    
      - Title: Ensure nodev option set on /dev/shm partition
 
- oval:simp.cis.3.1.1.CentOS7.1.1.9_Ensure_nosuid_option_set_on_devshm_partition:def:1
    
      - Title: Ensure nosuid option set on /dev/shm partition
 
- oval:simp.cis.3.1.1.CentOS7.1.2.1_Ensure_GPG_keys_are_configured:def:1
    
      - Title: Ensure GPG keys are configured
 
- oval:simp.cis.3.1.1.CentOS7.1.2.3_Ensure_gpgcheck_is_globally_activated:def:1
    
      - Title: Ensure gpgcheck is globally activated
 
- oval:simp.cis.3.1.1.CentOS7.1.3.1_Ensure_AIDE_is_installed:def:1
    
      - Title: Ensure AIDE is installed
 
- oval:simp.cis.3.1.1.CentOS7.1.3.2_Ensure_filesystem_integrity_is_regularly_checked:def:1
    
      - Title: Ensure filesystem integrity is regularly checked
 
- oval:simp.cis.3.1.1.CentOS7.1.4.1_Ensure_bootloader_password_is_set:def:1
    
      - Title: Ensure bootloader password is set
 
- oval:simp.cis.3.1.1.CentOS7.1.4.2_Ensure_permissions_on_bootloader_config_are_configured:def:1
    
      - Title: Ensure permissions on bootloader config are configured
 
- oval:simp.cis.3.1.1.CentOS7.1.4.3_Ensure_authentication_required_for_single_user_mode:def:1
    
      - Title: Ensure authentication required for single user mode
 
- oval:simp.cis.3.1.1.CentOS7.1.5.1_Ensure_core_dumps_are_restricted:def:1
    
      - Title: Ensure core dumps are restricted
 
- oval:simp.cis.3.1.1.CentOS7.1.5.3_Ensure_address_space_layout_randomization_ASLR_is_enabled:def:1
    
      - Title: Ensure address space layout randomization (ASLR) is enabled
 
- oval:simp.cis.3.1.1.CentOS7.1.5.4_Ensure_prelink_is_not_installed:def:1
    
      - Title: Ensure prelink is not installed
 
- oval:simp.cis.3.1.1.CentOS7.1.6.1.1_Ensure_SELinux_is_installed:def:1
    
      - Title: Ensure SELinux is installed
 
- oval:simp.cis.3.1.1.CentOS7.1.6.1.2_Ensure_SELinux_is_not_disabled_in_bootloader_configuration:def:1
    
      - Title: Ensure SELinux is not disabled in bootloader configuration
 
- oval:simp.cis.3.1.1.CentOS7.1.6.1.3_Ensure_SELinux_policy_is_configured:def:1
    
      - Title: Ensure SELinux policy is configured
 
- oval:simp.cis.3.1.1.CentOS7.1.6.1.4_Ensure_the_SELinux_mode_is_enforcing_or_permissive:def:1
    
      - Title: Ensure the SELinux mode is enforcing or permissive
 
- oval:simp.cis.3.1.1.CentOS7.1.6.1.5_Ensure_the_SELinux_mode_is_enforcing:def:1
    
      - Title: Ensure the SELinux mode is enforcing
 
- oval:simp.cis.3.1.1.CentOS7.1.6.1.7_Ensure_SETroubleshoot_is_not_installed:def:1
    
      - Title: Ensure SETroubleshoot is not installed
 
- oval:simp.cis.3.1.1.CentOS7.1.6.1.8_Ensure_the_MCS_Translation_Service_mcstrans_is_not_installed:def:1
    
      - Title: Ensure the MCS Translation Service (mcstrans) is not installed
 
- oval:simp.cis.3.1.1.CentOS7.1.7.1_Ensure_message_of_the_day_is_configured_properly:def:1
    
      - Title: Ensure message of the day is configured properly
 
- oval:simp.cis.3.1.1.CentOS7.1.7.2_Ensure_local_login_warning_banner_is_configured_properly:def:1
    
      - Title: Ensure local login warning banner is configured properly
 
- oval:simp.cis.3.1.1.CentOS7.1.7.3_Ensure_remote_login_warning_banner_is_configured_properly:def:1
    
      - Title: Ensure remote login warning banner is configured properly
 
- oval:simp.cis.3.1.1.CentOS7.1.7.4_Ensure_permissions_on_etcmotd_are_configured:def:1
    
      - Title: Ensure permissions on /etc/motd are configured
 
- oval:simp.cis.3.1.1.CentOS7.1.7.5_Ensure_permissions_on_etcissue_are_configured:def:1
    
      - Title: Ensure permissions on /etc/issue are configured
 
- oval:simp.cis.3.1.1.CentOS7.1.7.6_Ensure_permissions_on_etcissue.net_are_configured:def:1
    
      - Title: Ensure permissions on /etc/issue.net are configured
 
- oval:simp.cis.3.1.1.CentOS7.1.8.1_Ensure_GNOME_Display_Manager_is_removed:def:1
    
      - Title: Ensure GNOME Display Manager is removed
 
- oval:simp.cis.3.1.1.CentOS7.1.8.2_Ensure_GDM_login_banner_is_configured:def:1
    
      - Title: Ensure GDM login banner is configured
 
- oval:simp.cis.3.1.1.CentOS7.1.8.3_Ensure_last_logged_in_user_display_is_disabled:def:1
    
      - Title: Ensure last logged in user display is disabled
 
- oval:simp.cis.3.1.1.CentOS7.1.8.4_Ensure_XDCMP_is_not_enabled:def:1
    
      - Title: Ensure XDCMP is not enabled
 
- oval:simp.cis.3.1.1.CentOS7.1.9_Ensure_updates_patches_and_additional_security_software_are_installed:def:1
    
      - Title: Ensure updates, patches, and additional security software are installed
 
- oval:simp.cis.3.1.1.CentOS7.2.1.1_Ensure_xinetd_is_not_installed:def:1
    
      - Title: Ensure xinetd is not installed
 
- oval:simp.cis.3.1.1.CentOS7.2.2.1.1_Ensure_time_synchronization_is_in_use:def:1
    
      - Title: Ensure time synchronization is in use
 
- oval:simp.cis.3.1.1.CentOS7.2.2.1.2_Ensure_chrony_is_configured:def:1
    
      - Title: Ensure chrony is configured
- NOTE: We are configuring the system to use ntpd instead of chrony.
 
- oval:simp.cis.3.1.1.CentOS7.2.2.1.3_Ensure_ntp_is_configured:def:1
    
      - Title: Ensure ntp is configured
 
- oval:simp.cis.3.1.1.CentOS7.2.2.10_Ensure_IMAP_and_POP3_server_is_not_installed:def:1
    
      - Title: Ensure IMAP and POP3 server is not installed
 
- oval:simp.cis.3.1.1.CentOS7.2.2.11_Ensure_Samba_is_not_installed:def:1
    
      - Title: Ensure Samba is not installed
 
- oval:simp.cis.3.1.1.CentOS7.2.2.12_Ensure_HTTP_Proxy_Server_is_not_installed:def:1
    
      - Title: Ensure HTTP Proxy Server is not installed
 
- oval:simp.cis.3.1.1.CentOS7.2.2.13_Ensure_net-snmp_is_not_installed:def:1
    
      - Title: Ensure net-snmp is not installed
 
- oval:simp.cis.3.1.1.CentOS7.2.2.14_Ensure_NIS_server_is_not_installed:def:1
    
      - Title: Ensure NIS server is not installed
 
- oval:simp.cis.3.1.1.CentOS7.2.2.15_Ensure_telnet-server_is_not_installed:def:1
    
      - Title: Ensure telnet-server is not installed
 
- oval:simp.cis.3.1.1.CentOS7.2.2.16_Ensure_mail_transfer_agent_is_configured_for_local-only_mode:def:1
    
      - Title: Ensure mail transfer agent is configured for local-only mode
 
- oval:simp.cis.3.1.1.CentOS7.2.2.17_Ensure_nfs-utils_is_not_installed_or_the__nfs-server_service_is_masked:def:1
    
      - Title: Ensure nfs-utils is not installed or the nfs-server service is masked
 
- oval:simp.cis.3.1.1.CentOS7.2.2.18_Ensure_rpcbind_is_not_installed_or_the__rpcbind_services_are_masked:def:1
    
      - Title: Ensure rpcbind is not installed or the rpcbind services are masked
 
- oval:simp.cis.3.1.1.CentOS7.2.2.19_Ensure_rsync_is_not_installed_or_the_rsyncd_service_is_masked:def:1
    
      - Title: Ensure rsync is not installed or the rsyncd service is masked
 
- oval:simp.cis.3.1.1.CentOS7.2.2.2_Ensure_X11_Server_components_are_not_installed:def:1
    
      - Title: Ensure X11 Server components are not installed
 
- oval:simp.cis.3.1.1.CentOS7.2.2.3_Ensure_Avahi_Server_is_not_installed:def:1
    
      - Title: Ensure Avahi Server is not installed
 
- oval:simp.cis.3.1.1.CentOS7.2.2.4_Ensure_CUPS_is_not_installed:def:1
    
      - Title: Ensure CUPS is not installed
 
- oval:simp.cis.3.1.1.CentOS7.2.2.5_Ensure_DHCP_Server_is_not_installed:def:1
    
      - Title: Ensure DHCP Server is not installed
 
- oval:simp.cis.3.1.1.CentOS7.2.2.6_Ensure_LDAP_server_is_not_installed:def:1
    
      - Title: Ensure LDAP server is not installed
 
- oval:simp.cis.3.1.1.CentOS7.2.2.7_Ensure_DNS_Server_is_not_installed:def:1
    
      - Title: Ensure DNS Server is not installed
 
- oval:simp.cis.3.1.1.CentOS7.2.2.8_Ensure_FTP_Server_is_not_installed:def:1
    
      - Title: Ensure FTP Server is not installed
 
- oval:simp.cis.3.1.1.CentOS7.2.2.9_Ensure_HTTP_server_is_not_installed:def:1
    
      - Title: Ensure HTTP server is not installed
 
- oval:simp.cis.3.1.1.CentOS7.2.3.1_Ensure_NIS_Client_is_not_installed:def:1
    
      - Title: Ensure NIS Client is not installed
 
- oval:simp.cis.3.1.1.CentOS7.2.3.2_Ensure_rsh_client_is_not_installed:def:1
    
      - Title: Ensure rsh client is not installed
 
- oval:simp.cis.3.1.1.CentOS7.2.3.3_Ensure_talk_client_is_not_installed:def:1
    
      - Title: Ensure talk client is not installed
 
- oval:simp.cis.3.1.1.CentOS7.2.3.4_Ensure_telnet_client_is_not_installed:def:1
    
      - Title: Ensure telnet client is not installed
 
- oval:simp.cis.3.1.1.CentOS7.2.3.5_Ensure_LDAP_client_is_not_installed:def:1
    
      - Title: Ensure LDAP client is not installed
 
- oval:simp.cis.3.1.1.CentOS7.2.4_Ensure_nonessential_services_are_removed_or_masked:def:1
    
      - Title: Ensure nonessential services are removed or masked
 
- oval:simp.cis.3.1.1.CentOS7.3.1.1_Disable_IPv6:def:1
    
      - Title: Disable IPv6
- NOTE: Disabled via sysctl instead of kernel command line
 
- oval:simp.cis.3.1.1.CentOS7.3.1.2_Ensure_wireless_interfaces_are_disabled:def:1
    
      - Title: Ensure wireless interfaces are disabled
 
- oval:simp.cis.3.1.1.CentOS7.3.2.1_Ensure_IP_forwarding_is_disabled:def:1
    
      - Title: Ensure IP forwarding is disabled
 
- oval:simp.cis.3.1.1.CentOS7.3.2.2_Ensure_packet_redirect_sending_is_disabled:def:1
    
      - Title: Ensure packet redirect sending is disabled
 
- oval:simp.cis.3.1.1.CentOS7.3.3.1_Ensure_source_routed_packets_are_not_accepted:def:1
    
      - Title: Ensure source routed packets are not accepted
 
- oval:simp.cis.3.1.1.CentOS7.3.3.2_Ensure_ICMP_redirects_are_not_accepted:def:1
    
      - Title: Ensure ICMP redirects are not accepted
 
- oval:simp.cis.3.1.1.CentOS7.3.3.3_Ensure_secure_ICMP_redirects_are_not_accepted:def:1
    
      - Title: Ensure secure ICMP redirects are not accepted
 
- oval:simp.cis.3.1.1.CentOS7.3.3.4_Ensure_suspicious_packets_are_logged:def:1
    
      - Title: Ensure suspicious packets are logged
 
- oval:simp.cis.3.1.1.CentOS7.3.3.5_Ensure_broadcast_ICMP_requests_are_ignored:def:1
    
      - Title: Ensure broadcast ICMP requests are ignored
 
- oval:simp.cis.3.1.1.CentOS7.3.3.6_Ensure_bogus_ICMP_responses_are_ignored:def:1
    
      - Title: Ensure bogus ICMP responses are ignored
 
- oval:simp.cis.3.1.1.CentOS7.3.3.7_Ensure_Reverse_Path_Filtering_is_enabled:def:1
    
      - Title: Ensure Reverse Path Filtering is enabled
 
- oval:simp.cis.3.1.1.CentOS7.3.3.8_Ensure_TCP_SYN_Cookies_is_enabled:def:1
    
      - Title: Ensure TCP SYN Cookies is enabled
 
- oval:simp.cis.3.1.1.CentOS7.3.3.9_Ensure_IPv6_router_advertisements_are_not_accepted:def:1
    
      - Title: Ensure IPv6 router advertisements are not accepted
 
- oval:simp.cis.3.1.1.CentOS7.3.4.1_Ensure_DCCP_is_disabled:def:1
    
      - Title: Ensure DCCP is disabled
 
- oval:simp.cis.3.1.1.CentOS7.3.4.2_Ensure_SCTP_is_disabled:def:1
    
      - Title: Ensure SCTP is disabled
 
- oval:simp.cis.3.1.1.CentOS7.3.5.1.1_Ensure_firewalld_is_installed:def:1
    
      - Title: Ensure firewalld is installed
 
- oval:simp.cis.3.1.1.CentOS7.3.5.1.2_Ensure_iptables-services_not_installed_with_firewalld:def:1
    
      - Title: Ensure iptables-services not installed with firewalld
 
- oval:simp.cis.3.1.1.CentOS7.3.5.1.3_Ensure_nftables_either_not_installed_or_masked_with_firewalld:def:1
    
      - Title: Ensure nftables either not installed or masked with firewalld
 
- oval:simp.cis.3.1.1.CentOS7.3.5.1.4_Ensure_firewalld_service_enabled_and_running:def:1
    
      - Title: Ensure firewalld service enabled and running
 
- oval:simp.cis.3.1.1.CentOS7.3.5.1.5_Ensure_firewalld_default_zone_is_set:def:1
    
      - Title: Ensure firewalld default zone is set
 
- oval:simp.cis.3.1.1.CentOS7.3.5.1.6_Ensure_network_interfaces_are_assigned_to_appropriate_zone:def:1
    
      - Title: Ensure network interfaces are assigned to appropriate zone
 
- oval:simp.cis.3.1.1.CentOS7.3.5.1.7_Ensure_firewalld_drops_unnecessary_services_and_ports:def:1
    
      - Title: Ensure firewalld drops unnecessary services and ports
 
- oval:simp.cis.3.1.1.CentOS7.3.5.2.10_Ensure_nftables_service_is_enabled:def:1
    
      - Title: Ensure nftables service is enabled
 
- oval:simp.cis.3.1.1.CentOS7.3.5.2.11_Ensure_nftables_rules_are_permanent:def:1
    
      - Title: Ensure nftables rules are permanent
- NOTE: Only applies when nftables is used for firewall provider
 
- oval:simp.cis.3.1.1.CentOS7.3.5.2.1_Ensure_nftables_is_installed:def:1
    
      - Title: Ensure nftables is installed
- NOTE: Only applies when nftables is used for firewall provider
 
- oval:simp.cis.3.1.1.CentOS7.3.5.2.2_Ensure_firewalld_is_either_not_installed_or_masked_with_nftables:def:1
    
      - Title: Ensure firewalld is either not installed or masked with nftables
- NOTE: Only applies when nftables is used for firewall provider
 
- oval:simp.cis.3.1.1.CentOS7.3.5.2.3_Ensure_iptables-services_not_installed_with_nftables:def:1
    
      - Title: Ensure iptables-services not installed with nftables
- NOTE: Only applies when nftables is used for firewall provider
 
- oval:simp.cis.3.1.1.CentOS7.3.5.2.4_Ensure_iptables_are_flushed_with_nftables:def:1
    
      - Title: Ensure iptables are flushed with nftables
- NOTE: Only applies when nftables is used for firewall provider
 
- oval:simp.cis.3.1.1.CentOS7.3.5.2.5_Ensure_an_nftables_table_exists:def:1
    
      - Title: Ensure an nftables table exists
- NOTE: Only applies when nftables is used for firewall provider
 
- oval:simp.cis.3.1.1.CentOS7.3.5.2.6_Ensure_nftables_base_chains_exist:def:1
    
      - Title: Ensure nftables base chains exist
- NOTE: Only applies when nftables is used for firewall provider
 
- oval:simp.cis.3.1.1.CentOS7.3.5.2.7_Ensure_nftables_loopback_traffic_is_configured:def:1
    
      - Title: Ensure nftables loopback traffic is configured
- NOTE: Only applies when nftables is used for firewall provider
 
- oval:simp.cis.3.1.1.CentOS7.3.5.2.8_Ensure_nftables_outbound_and_established_connections_are_configured:def:1
    
      - Title: Ensure nftables outbound and established connections are configured
- NOTE: Only applies when nftables is used for firewall provider
 
- oval:simp.cis.3.1.1.CentOS7.3.5.2.9_Ensure_nftables_default_deny_firewall_policy:def:1
    
      - Title: Ensure nftables default deny firewall policy
- NOTE: Only applies when nftables is used for firewall provider
 
- oval:simp.cis.3.1.1.CentOS7.3.5.3.1.1_Ensure_iptables_packages_are_installed:def:1
    
      - Title: Ensure iptables packages are installed
 
- oval:simp.cis.3.1.1.CentOS7.3.5.3.1.2_Ensure_nftables_is_not_installed_with_iptables:def:1
    
      - Title: Ensure nftables is not installed with iptables
- NOTE: Only applies when iptables is used for firewall provider
 
- oval:simp.cis.3.1.1.CentOS7.3.5.3.1.3_Ensure_firewalld_is_either_not_installed_or_masked_with_iptables:def:1
    
      - Title: Ensure firewalld is either not installed or masked with iptables
- NOTE: Only applies when nftables is used for firewall provider
 
- oval:simp.cis.3.1.1.CentOS7.3.5.3.2.1_Ensure_iptables_loopback_traffic_is_configured:def:1
    
      - Title: Ensure iptables loopback traffic is configured
- NOTE: Only applies when iptables is used for firewall provider
 
- oval:simp.cis.3.1.1.CentOS7.3.5.3.2.2_Ensure_iptables_outbound_and_established_connections_are_configured:def:1
    
      - Title: Ensure iptables outbound and established connections are configured
- NOTE: Only applies when iptables is used for firewall provider
 
- oval:simp.cis.3.1.1.CentOS7.3.5.3.2.3_Ensure_iptables_rules_exist_for_all_open_ports:def:1
    
      - Title: Ensure iptables rules exist for all open ports
- NOTE: Only applies when iptables is used for firewall provider
 
- oval:simp.cis.3.1.1.CentOS7.3.5.3.2.4_Ensure_iptables_default_deny_firewall_policy:def:1
    
      - Title: Ensure iptables default deny firewall policy
- NOTE: Only applies when iptables is used for firewall provider
 
- oval:simp.cis.3.1.1.CentOS7.3.5.3.2.5_Ensure_iptables_rules_are_saved:def:1
    
      - Title: Ensure iptables rules are saved
 
- oval:simp.cis.3.1.1.CentOS7.3.5.3.2.6_Ensure_iptables_is_enabled_and_running:def:1
    
      - Title: Ensure iptables is enabled and running
 
- oval:simp.cis.3.1.1.CentOS7.3.5.3.3.1_Ensure_ip6tables_loopback_traffic_is_configured:def:1
    
      - Title: Ensure ip6tables loopback traffic is configured
 
- oval:simp.cis.3.1.1.CentOS7.3.5.3.3.2_Ensure_ip6tables_outbound_and_established_connections_are_configured:def:1
    
      - Title: Ensure ip6tables outbound and established connections are configured
- NOTE: Only applies when iptables is used for firewall provider
 
- oval:simp.cis.3.1.1.CentOS7.3.5.3.3.3_Ensure_ip6tables_firewall_rules_exist_for_all_open_ports:def:1
    
      - Title: Ensure ip6tables firewall rules exist for all open ports
- NOTE: Only applies when iptables is used for firewall provider
 
- oval:simp.cis.3.1.1.CentOS7.3.5.3.3.4_Ensure_ip6tables_default_deny_firewall_policy:def:1
    
      - Title: Ensure ip6tables default deny firewall policy
- NOTE: Only applies when iptables is used for firewall provider
 
- oval:simp.cis.3.1.1.CentOS7.3.5.3.3.5_Ensure_ip6tables_rules_are_saved:def:1
    
      - Title: Ensure ip6tables rules are saved
 
- oval:simp.cis.3.1.1.CentOS7.3.5.3.3.6_Ensure_ip6tables_is_enabled_and_running:def:1
    
      - Title: Ensure ip6tables is enabled and running
 
- oval:simp.cis.3.1.1.CentOS7.4.1.1.1_Ensure_auditd_is_installed:def:1
    
      - Title: Ensure auditd is installed
 
- oval:simp.cis.3.1.1.CentOS7.4.1.1.2_Ensure_auditd_service_is_enabled_and_running:def:1
    
      - Title: Ensure auditd service is enabled and running
 
- oval:simp.cis.3.1.1.CentOS7.4.1.1.3_Ensure_auditing_for_processes_that_start_prior_to_auditd_is_enabled:def:1
    
      - Title: Ensure auditing for processes that start prior to auditd is enabled
 
- oval:simp.cis.3.1.1.CentOS7.4.1.10_Ensure_unsuccessful_unauthorized_file_access_attempts_are_collected:def:1
    
      - Title: Ensure unsuccessful unauthorized file access attempts are collected
 
- oval:simp.cis.3.1.1.CentOS7.4.1.11_Ensure_use_of_privileged_commands_is_collected:def:1
    
      - Title: Ensure use of privileged commands is collected
 
- oval:simp.cis.3.1.1.CentOS7.4.1.12_Ensure_successful_file_system_mounts_are_collected:def:1
    
      - Title: Ensure successful file system mounts are collected
 
- oval:simp.cis.3.1.1.CentOS7.4.1.13_Ensure_file_deletion_events_by_users_are_collected:def:1
    
      - Title: Ensure file deletion events by users are collected
 
- oval:simp.cis.3.1.1.CentOS7.4.1.14_Ensure_changes_to_system_administration_scope_sudoers_is_collected:def:1
    
      - Title: Ensure changes to system administration scope (sudoers) is collected
 
- oval:simp.cis.3.1.1.CentOS7.4.1.15_Ensure_system_administrator_command_executions_sudo_are_collected:def:1
    
      - Title: Ensure system administrator command executions (sudo) are collected
 
- oval:simp.cis.3.1.1.CentOS7.4.1.16_Ensure_kernel_module_loading_and_unloading_is_collected:def:1
    
      - Title: Ensure kernel module loading and unloading is collected
 
- oval:simp.cis.3.1.1.CentOS7.4.1.17_Ensure_the_audit_configuration_is_immutable:def:1
    
      - Title: Ensure the audit configuration is immutable
 
- oval:simp.cis.3.1.1.CentOS7.4.1.2.1_Ensure_audit_log_storage_size_is_configured:def:1
    
      - Title: Ensure audit log storage size is configured
 
- oval:simp.cis.3.1.1.CentOS7.4.1.2.2_Ensure_audit_logs_are_not_automatically_deleted:def:1
    
      - Title: Ensure audit logs are not automatically deleted
 
- oval:simp.cis.3.1.1.CentOS7.4.1.2.3_Ensure_system_is_disabled_when_audit_logs_are_full:def:1
    
      - Title: Ensure system is disabled when audit logs are full
 
- oval:simp.cis.3.1.1.CentOS7.4.1.2.4_Ensure_audit_backlog_limit_is_sufficient:def:1
    
      - Title: Ensure audit_backlog_limit is sufficient
 
- oval:simp.cis.3.1.1.CentOS7.4.1.3_Ensure_events_that_modify_date_and_time_information_are_collected:def:1
    
      - Title: Ensure events that modify date and time information are collected
 
- oval:simp.cis.3.1.1.CentOS7.4.1.4_Ensure_events_that_modify_usergroup_information_are_collected:def:1
    
      - Title: Ensure events that modify user/group information are collected
 
- oval:simp.cis.3.1.1.CentOS7.4.1.5_Ensure_events_that_modify_the_systems_network_environment_are_collected:def:1
    
      - Title: Ensure events that modify the system’s network environment are collected
 
- oval:simp.cis.3.1.1.CentOS7.4.1.6_Ensure_events_that_modify_the_systems_Mandatory_Access_Controls_are_collected:def:1
    
      - Title: Ensure events that modify the system’s Mandatory Access Controls are collected
 
- oval:simp.cis.3.1.1.CentOS7.4.1.7_Ensure_login_and_logout_events_are_collected:def:1
    
      - Title: Ensure login and logout events are collected
 
- oval:simp.cis.3.1.1.CentOS7.4.1.8_Ensure_session_initiation_information_is_collected:def:1
    
      - Title: Ensure session initiation information is collected
 
- oval:simp.cis.3.1.1.CentOS7.4.1.9_Ensure_discretionary_access_control_permission_modification_events_are_collected:def:1
    
      - Title: Ensure discretionary access control permission modification events are collected
 
- oval:simp.cis.3.1.1.CentOS7.4.2.1.1_Ensure_rsyslog_is_installed:def:1
    
      - Title: Ensure rsyslog is installed
 
- oval:simp.cis.3.1.1.CentOS7.4.2.1.2_Ensure_rsyslog_Service_is_enabled_and_running:def:1
    
      - Title: Ensure rsyslog Service is enabled and running
 
- oval:simp.cis.3.1.1.CentOS7.4.2.1.3_Ensure_rsyslog_default_file_permissions_configured:def:1
    
      - Title: Ensure rsyslog default file permissions configured
 
- oval:simp.cis.3.1.1.CentOS7.4.2.1.4_Ensure_logging_is_configured:def:1
    
      - Title: Ensure logging is configured
 
- oval:simp.cis.3.1.1.CentOS7.4.2.1.5_Ensure_rsyslog_is_configured_to_send_logs_to_a_remote_log_host:def:1
    
      - Title: Ensure rsyslog is configured to send logs to a remote log host
 
- oval:simp.cis.3.1.1.CentOS7.4.2.1.6_Ensure_remote_rsyslog_messages_are_only_accepted_on_designated_log_hosts.:def:1
    
      - Title: Ensure remote rsyslog messages are only accepted on designated log hosts.
 
- oval:simp.cis.3.1.1.CentOS7.4.2.2.1_Ensure_journald_is_configured_to_send_logs_to_rsyslog:def:1
    
      - Title: Ensure journald is configured to send logs to rsyslog
 
- oval:simp.cis.3.1.1.CentOS7.4.2.2.2_Ensure_journald_is_configured_to_compress_large_log_files:def:1
    
      - Title: Ensure journald is configured to compress large log files
 
- oval:simp.cis.3.1.1.CentOS7.4.2.2.3_Ensure_journald_is_configured_to_write_logfiles_to_persistent_disk:def:1
    
      - Title: Ensure journald is configured to write logfiles to persistent disk
 
- oval:simp.cis.3.1.1.CentOS7.4.2.3_Ensure_permissions_on_all_logfiles_are_configured:def:1
    
      - Title: Ensure permissions on all logfiles are configured
 
- oval:simp.cis.3.1.1.CentOS7.4.2.4_Ensure_logrotate_is_configured:def:1
    
      - Title: Ensure logrotate is configured
 
- oval:simp.cis.3.1.1.CentOS7.5.1.1_Ensure_cron_daemon_is_enabled_and_running:def:1
    
      - Title: Ensure cron daemon is enabled and running
 
- oval:simp.cis.3.1.1.CentOS7.5.1.2_Ensure_permissions_on_etccrontab_are_configured:def:1
    
      - Title: Ensure permissions on /etc/crontab are configured
 
- oval:simp.cis.3.1.1.CentOS7.5.1.3_Ensure_permissions_on_etccron.hourly_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.hourly are configured
 
- oval:simp.cis.3.1.1.CentOS7.5.1.4_Ensure_permissions_on_etccron.daily_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.daily are configured
 
- oval:simp.cis.3.1.1.CentOS7.5.1.5_Ensure_permissions_on_etccron.weekly_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.weekly are configured
 
- oval:simp.cis.3.1.1.CentOS7.5.1.6_Ensure_permissions_on_etccron.monthly_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.monthly are configured
 
- oval:simp.cis.3.1.1.CentOS7.5.1.7_Ensure_permissions_on_etccron.d_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.d are configured
 
- oval:simp.cis.3.1.1.CentOS7.5.1.8_Ensure_cron_is_restricted_to_authorized_users:def:1
    
      - Title: Ensure cron is restricted to authorized users
 
- oval:simp.cis.3.1.1.CentOS7.5.1.9_Ensure_at_is_restricted_to_authorized_users:def:1
    
      - Title: Ensure at is restricted to authorized users
 
- oval:simp.cis.3.1.1.CentOS7.5.2.1_Ensure_sudo_is_installed:def:1
    
      - Title: Ensure sudo is installed
 
- oval:simp.cis.3.1.1.CentOS7.5.2.2_Ensure_sudo_commands_use_pty:def:1
    
      - Title: Ensure sudo commands use pty
 
- oval:simp.cis.3.1.1.CentOS7.5.2.3_Ensure_sudo_log_file_exists:def:1
    
      - Title: Ensure sudo log file exists
 
- oval:simp.cis.3.1.1.CentOS7.5.3.10_Ensure_SSH_root_login_is_disabled:def:1
    
      - Title: Ensure SSH root login is disabled
 
- oval:simp.cis.3.1.1.CentOS7.5.3.11_Ensure_SSH_PermitEmptyPasswords_is_disabled:def:1
    
      - Title: Ensure SSH PermitEmptyPasswords is disabled
 
- oval:simp.cis.3.1.1.CentOS7.5.3.12_Ensure_SSH_PermitUserEnvironment_is_disabled:def:1
    
      - Title: Ensure SSH PermitUserEnvironment is disabled
 
- oval:simp.cis.3.1.1.CentOS7.5.3.13_Ensure_only_strong_Ciphers_are_used:def:1
    
      - Title: Ensure only strong Ciphers are used
 
- oval:simp.cis.3.1.1.CentOS7.5.3.14_Ensure_only_strong_MAC_algorithms_are_used:def:1
    
      - Title: Ensure only strong MAC algorithms are used
 
- oval:simp.cis.3.1.1.CentOS7.5.3.15_Ensure_only_strong_Key_Exchange_algorithms_are_used:def:1
    
      - Title: Ensure only strong Key Exchange algorithms are used
 
- oval:simp.cis.3.1.1.CentOS7.5.3.16_Ensure_SSH_Idle_Timeout_Interval_is_configured:def:1
    
      - Title: Ensure SSH Idle Timeout Interval is configured
 
- oval:simp.cis.3.1.1.CentOS7.5.3.17_Ensure_SSH_LoginGraceTime_is_set_to_one_minute_or_less:def:1
    
      - Title: Ensure SSH LoginGraceTime is set to one minute or less
 
- oval:simp.cis.3.1.1.CentOS7.5.3.18_Ensure_SSH_warning_banner_is_configured:def:1
    
      - Title: Ensure SSH warning banner is configured
 
- oval:simp.cis.3.1.1.CentOS7.5.3.19_Ensure_SSH_PAM_is_enabled:def:1
    
      - Title: Ensure SSH PAM is enabled
 
- oval:simp.cis.3.1.1.CentOS7.5.3.1_Ensure_permissions_on_etcsshsshd_config_are_configured:def:1
    
      - Title: Ensure permissions on /etc/ssh/sshd_config are configured
 
- oval:simp.cis.3.1.1.CentOS7.5.3.20_Ensure_SSH_AllowTcpForwarding_is_disabled:def:1
    
      - Title: Ensure SSH AllowTcpForwarding is disabled
 
- oval:simp.cis.3.1.1.CentOS7.5.3.21_Ensure_SSH_MaxStartups_is_configured:def:1
    
      - Title: Ensure SSH MaxStartups is configured
 
- oval:simp.cis.3.1.1.CentOS7.5.3.22_Ensure_SSH_MaxSessions_is_limited:def:1
    
      - Title: Ensure SSH MaxSessions is limited
 
- oval:simp.cis.3.1.1.CentOS7.5.3.2_Ensure_permissions_on_SSH_private_host_key_files_are_configured:def:1
    
      - Title: Ensure permissions on SSH private host key files are configured
 
- oval:simp.cis.3.1.1.CentOS7.5.3.3_Ensure_permissions_on_SSH_public_host_key_files_are_configured:def:1
    
      - Title: Ensure permissions on SSH public host key files are configured
 
- oval:simp.cis.3.1.1.CentOS7.5.3.4_Ensure_SSH_access_is_limited:def:1
    
      - Title: Ensure SSH access is limited
 
- oval:simp.cis.3.1.1.CentOS7.5.3.5_Ensure_SSH_LogLevel_is_appropriate:def:1
    
      - Title: Ensure SSH LogLevel is appropriate
 
- oval:simp.cis.3.1.1.CentOS7.5.3.6_Ensure_SSH_X11_forwarding_is_disabled:def:1
    
      - Title: Ensure SSH X11 forwarding is disabled
 
- oval:simp.cis.3.1.1.CentOS7.5.3.7_Ensure_SSH_MaxAuthTries_is_set_to_4_or_less:def:1
    
      - Title: Ensure SSH MaxAuthTries is set to 4 or less
 
- oval:simp.cis.3.1.1.CentOS7.5.3.8_Ensure_SSH_IgnoreRhosts_is_enabled:def:1
    
      - Title: Ensure SSH IgnoreRhosts is enabled
 
- oval:simp.cis.3.1.1.CentOS7.5.3.9_Ensure_SSH_HostbasedAuthentication_is_disabled:def:1
    
      - Title: Ensure SSH HostbasedAuthentication is disabled
 
- oval:simp.cis.3.1.1.CentOS7.5.4.1_Ensure_password_creation_requirements_are_configured:def:1
    
      - Title: Ensure password creation requirements are configured
 
- oval:simp.cis.3.1.1.CentOS7.5.4.2_Ensure_lockout_for_failed_password_attempts_is_configured:def:1
    
      - Title: Ensure lockout for failed password attempts is configured
 
- oval:simp.cis.3.1.1.CentOS7.5.4.3_Ensure_password_hashing_algorithm_is_SHA-512:def:1
    
      - Title: Ensure password hashing algorithm is SHA-512
 
- oval:simp.cis.3.1.1.CentOS7.5.4.4_Ensure_password_reuse_is_limited:def:1
    
      - Title: Ensure password reuse is limited
 
- oval:simp.cis.3.1.1.CentOS7.5.5.1.1_Ensure_password_expiration_is_365_days_or_less:def:1
    
      - Title: Ensure password expiration is 365 days or less
 
- oval:simp.cis.3.1.1.CentOS7.5.5.1.2_Ensure_minimum_days_between_password_changes_is_configured:def:1
    
      - Title: Ensure minimum days between password changes is configured
 
- oval:simp.cis.3.1.1.CentOS7.5.5.1.3_Ensure_password_expiration_warning_days_is_7_or_more:def:1
    
      - Title: Ensure password expiration warning days is 7 or more
 
- oval:simp.cis.3.1.1.CentOS7.5.5.1.4_Ensure_inactive_password_lock_is_30_days_or_less:def:1
    
      - Title: Ensure inactive password lock is 30 days or less
 
- oval:simp.cis.3.1.1.CentOS7.5.5.1.5_Ensure_all_users_last_password_change_date_is_in_the_past:def:1
    
      - Title: Ensure all users last password change date is in the past
 
- oval:simp.cis.3.1.1.CentOS7.5.5.2_Ensure_system_accounts_are_secured:def:1
    
      - Title: Ensure system accounts are secured
 
- oval:simp.cis.3.1.1.CentOS7.5.5.3_Ensure_default_group_for_the_root_account_is_GID_0:def:1
    
      - Title: Ensure default group for the root account is GID 0
 
- oval:simp.cis.3.1.1.CentOS7.5.5.4_Ensure_default_user_shell_timeout_is_configured:def:1
    
      - Title: Ensure default user shell timeout is configured
 
- oval:simp.cis.3.1.1.CentOS7.5.5.5_Ensure_default_user_umask_is_configured:def:1
    
      - Title: Ensure default user umask is configured
 
- oval:simp.cis.3.1.1.CentOS7.5.6_Ensure_root_login_is_restricted_to_system_console:def:1
    
      - Title: Ensure root login is restricted to system console
 
- oval:simp.cis.3.1.1.CentOS7.5.7_Ensure_access_to_the_su_command_is_restricted:def:1
    
      - Title: Ensure access to the su command is restricted
 
- oval:simp.cis.3.1.1.CentOS7.6.1.2_Ensure_permissions_on_etcpasswd_are_configured:def:1
    
      - Title: Ensure permissions on /etc/passwd are configured
 
- oval:simp.cis.3.1.1.CentOS7.6.1.3_Ensure_permissions_on_etcpasswd-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/passwd- are configured
 
- oval:simp.cis.3.1.1.CentOS7.6.1.4_Ensure_permissions_on_etcshadow_are_configured:def:1
    
      - Title: Ensure permissions on /etc/shadow are configured
 
- oval:simp.cis.3.1.1.CentOS7.6.1.5_Ensure_permissions_on_etcshadow-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/shadow- are configured
 
- oval:simp.cis.3.1.1.CentOS7.6.1.6_Ensure_permissions_on_etcgshadow-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/gshadow- are configured
 
- oval:simp.cis.3.1.1.CentOS7.6.1.7_Ensure_permissions_on_etcgshadow_are_configured:def:1
    
      - Title: Ensure permissions on /etc/gshadow are configured
 
- oval:simp.cis.3.1.1.CentOS7.6.1.8_Ensure_permissions_on_etcgroup_are_configured:def:1
    
      - Title: Ensure permissions on /etc/group are configured
 
- oval:simp.cis.3.1.1.CentOS7.6.1.9_Ensure_permissions_on_etcgroup-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/group- are configured
 
- oval:simp.cis.3.1.1.CentOS7.6.2.10_Ensure_root_PATH_Integrity:def:1
    
      - Title: Ensure root PATH Integrity
 
- oval:simp.cis.3.1.1.CentOS7.6.2.11_Ensure_all_users_home_directories_exist:def:1
    
      - Title: Ensure all users’ home directories exist
 
- oval:simp.cis.3.1.1.CentOS7.6.2.12_Ensure_users_own_their_home_directories:def:1
    
      - Title: Ensure users own their home directories
 
- oval:simp.cis.3.1.1.CentOS7.6.2.13_Ensure_users_home_directories_permissions_are_750_or_more_restrictive:def:1
    
      - Title: Ensure users’ home directories permissions are 750 or more restrictive
 
- oval:simp.cis.3.1.1.CentOS7.6.2.14_Ensure_users_dot_files_are_not_group_or_world_writable:def:1
    
      - Title: Ensure users’ dot files are not group or world writable
 
- oval:simp.cis.3.1.1.CentOS7.6.2.15Ensure_no_users_have.forward_files:def:1
    
      - Title: Ensure no users have .forward files
 
- oval:simp.cis.3.1.1.CentOS7.6.2.16Ensure_no_users_have.netrc_files:def:1
    
      - Title: Ensure no users have .netrc files
 
- oval:simp.cis.3.1.1.CentOS7.6.2.17Ensure_no_users_have.rhosts_files:def:1
    
      - Title: Ensure no users have .rhosts files
 
- oval:simp.cis.3.1.1.CentOS7.6.2.1_Ensure_accounts_in_etcpasswd_use_shadowed_passwords:def:1
    
      - Title: Ensure accounts in /etc/passwd use shadowed passwords
 
- oval:simp.cis.3.1.1.CentOS7.6.2.2_Ensure_etcshadow_password_fields_are_not_empty:def:1
    
      - Title: Ensure /etc/shadow password fields are not empty
 
- oval:simp.cis.3.1.1.CentOS7.6.2.3_Ensure_all_groups_in_etcpasswd_exist_in_etcgroup:def:1
    
      - Title: Ensure all groups in /etc/passwd exist in /etc/group
 
- oval:simp.cis.3.1.1.CentOS7.6.2.4_Ensure_shadow_group_is_empty:def:1
    
      - Title: Ensure shadow group is empty
 
- oval:simp.cis.3.1.1.CentOS7.6.2.5_Ensure_no_duplicate_user_names_exist:def:1
    
      - Title: Ensure no duplicate user names exist
 
- oval:simp.cis.3.1.1.CentOS7.6.2.6_Ensure_no_duplicate_group_names_exist:def:1
    
      - Title: Ensure no duplicate group names exist
 
- oval:simp.cis.3.1.1.CentOS7.6.2.7_Ensure_no_duplicate_UIDs_exist:def:1
    
      - Title: Ensure no duplicate UIDs exist
 
- oval:simp.cis.3.1.1.CentOS7.6.2.8_Ensure_no_duplicate_GIDs_exist:def:1
    
      - Title: Ensure no duplicate GIDs exist
 
- oval:simp.cis.3.1.1.CentOS7.6.2.9_Ensure_root_is_the_only_UID_0_account:def:1
    
      - Title: Ensure root is the only UID 0 account
        OracleLinux 7 (232/246 [94%])
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.1.1_Ensure_mounting_of_cramfs_filesystems_is_disabled:def:1
    
      - Title: Ensure mounting of cramfs filesystems is disabled
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.1.2_Ensure_mounting_of_squashfs_filesystems_is_disabled:def:1
    
      - Title: Ensure mounting of squashfs filesystems is disabled
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.1.3_Ensure_mounting_of_udf_filesystems_is_disabled:def:1
    
      - Title: Ensure mounting of udf filesystems is disabled
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.12_Ensure_vartmp_partition_includes_the_noexec_option:def:1
    
      - Title: Ensure /var/tmp partition includes the noexec option
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.13_Ensure_vartmp_partition_includes_the_nodev_option:def:1
    
      - Title: Ensure /var/tmp partition includes the nodev option
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.14_Ensure_vartmp_partition_includes_the_nosuid_option:def:1
    
      - Title: Ensure /var/tmp partition includes the nosuid option
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.18_Ensure_home_partition_includes_the_nodev_option:def:1
    
      - Title: Ensure /home partition includes the nodev option
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.19_Ensure_removable_media_partitions_include_noexec_option:def:1
    
      - Title: Ensure removable media partitions include noexec option
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.20_Ensure_nodev_option_set_on_removable_media_partitions:def:1
    
      - Title: Ensure nodev option set on removable media partitions
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.21_Ensure_nosuid_option_set_on_removable_media_partitions:def:1
    
      - Title: Ensure nosuid option set on removable media partitions
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.22_Ensure_sticky_bit_is_set_on_all_world-writable_directories:def:1
    
      - Title: Ensure sticky bit is set on all world-writable directories
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.23_Disable_Automounting:def:1
    
      - Title: Disable Automounting
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.24_Disable_USB_Storage:def:1
    
      - Title: Disable USB Storage
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.2_Ensure_tmp_is_configured:def:1
    
      - Title: Ensure /tmp is configured
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.3_Ensure_noexec_option_set_on_tmp_partition:def:1
    
      - Title: Ensure noexec option set on /tmp partition
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.4_Ensure_nodev_option_set_on_tmp_partition:def:1
    
      - Title: Ensure nodev option set on /tmp partition
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.5_Ensure_nosuid_option_set_on_tmp_partition:def:1
    
      - Title: Ensure nosuid option set on /tmp partition
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.6_Ensure_devshm_is_configured:def:1
    
      - Title: Ensure /dev/shm is configured
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.7_Ensure_noexec_option_set_on_devshm_partition:def:1
    
      - Title: Ensure noexec option set on /dev/shm partition
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.8_Ensure_nodev_option_set_on_devshm_partition:def:1
    
      - Title: Ensure nodev option set on /dev/shm partition
 
- oval:simp.cis.3.1.1.OracleLinux7.1.1.9_Ensure_nosuid_option_set_on_devshm_partition:def:1
    
      - Title: Ensure nosuid option set on /dev/shm partition
 
- oval:simp.cis.3.1.1.OracleLinux7.1.2.1_Ensure_GPG_keys_are_configured:def:1
    
      - Title: Ensure GPG keys are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.1.2.3_Ensure_gpgcheck_is_globally_activated:def:1
    
      - Title: Ensure gpgcheck is globally activated
 
- oval:simp.cis.3.1.1.OracleLinux7.1.3.1_Ensure_AIDE_is_installed:def:1
    
      - Title: Ensure AIDE is installed
 
- oval:simp.cis.3.1.1.OracleLinux7.1.3.2_Ensure_filesystem_integrity_is_regularly_checked:def:1
    
      - Title: Ensure filesystem integrity is regularly checked
 
- oval:simp.cis.3.1.1.OracleLinux7.1.4.1_Ensure_bootloader_password_is_set:def:1
    
      - Title: Ensure bootloader password is set
 
- oval:simp.cis.3.1.1.OracleLinux7.1.4.2_Ensure_permissions_on_bootloader_config_are_configured:def:1
    
      - Title: Ensure permissions on bootloader config are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.1.4.3_Ensure_authentication_required_for_single_user_mode:def:1
    
      - Title: Ensure authentication required for single user mode
 
- oval:simp.cis.3.1.1.OracleLinux7.1.5.1_Ensure_core_dumps_are_restricted:def:1
    
      - Title: Ensure core dumps are restricted
 
- oval:simp.cis.3.1.1.OracleLinux7.1.5.3_Ensure_address_space_layout_randomization_ASLR_is_enabled:def:1
    
      - Title: Ensure address space layout randomization (ASLR) is enabled
 
- oval:simp.cis.3.1.1.OracleLinux7.1.5.4_Ensure_prelink_is_not_installed:def:1
    
      - Title: Ensure prelink is not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.1.6.1.1_Ensure_SELinux_is_installed:def:1
    
      - Title: Ensure SELinux is installed
 
- oval:simp.cis.3.1.1.OracleLinux7.1.6.1.2_Ensure_SELinux_is_not_disabled_in_bootloader_configuration:def:1
    
      - Title: Ensure SELinux is not disabled in bootloader configuration
 
- oval:simp.cis.3.1.1.OracleLinux7.1.6.1.3_Ensure_SELinux_policy_is_configured:def:1
    
      - Title: Ensure SELinux policy is configured
 
- oval:simp.cis.3.1.1.OracleLinux7.1.6.1.4_Ensure_the_SELinux_mode_is_enforcing_or_permissive:def:1
    
      - Title: Ensure the SELinux mode is enforcing or permissive
 
- oval:simp.cis.3.1.1.OracleLinux7.1.6.1.5_Ensure_the_SELinux_mode_is_enforcing:def:1
    
      - Title: Ensure the SELinux mode is enforcing
 
- oval:simp.cis.3.1.1.OracleLinux7.1.6.1.7_Ensure_SETroubleshoot_is_not_installed:def:1
    
      - Title: Ensure SETroubleshoot is not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.1.6.1.8_Ensure_the_MCS_Translation_Service_mcstrans_is_not_installed:def:1
    
      - Title: Ensure the MCS Translation Service (mcstrans) is not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.1.7.1_Ensure_message_of_the_day_is_configured_properly:def:1
    
      - Title: Ensure message of the day is configured properly
 
- oval:simp.cis.3.1.1.OracleLinux7.1.7.2_Ensure_local_login_warning_banner_is_configured_properly:def:1
    
      - Title: Ensure local login warning banner is configured properly
 
- oval:simp.cis.3.1.1.OracleLinux7.1.7.3_Ensure_remote_login_warning_banner_is_configured_properly:def:1
    
      - Title: Ensure remote login warning banner is configured properly
 
- oval:simp.cis.3.1.1.OracleLinux7.1.7.4_Ensure_permissions_on_etcmotd_are_configured:def:1
    
      - Title: Ensure permissions on /etc/motd are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.1.7.5_Ensure_permissions_on_etcissue_are_configured:def:1
    
      - Title: Ensure permissions on /etc/issue are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.1.7.6_Ensure_permissions_on_etcissue.net_are_configured:def:1
    
      - Title: Ensure permissions on /etc/issue.net are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.1.8.1_Ensure_GNOME_Display_Manager_is_removed:def:1
    
      - Title: Ensure GNOME Display Manager is removed
 
- oval:simp.cis.3.1.1.OracleLinux7.1.8.2_Ensure_GDM_login_banner_is_configured:def:1
    
      - Title: Ensure GDM login banner is configured
 
- oval:simp.cis.3.1.1.OracleLinux7.1.8.3_Ensure_last_logged_in_user_display_is_disabled:def:1
    
      - Title: Ensure last logged in user display is disabled
 
- oval:simp.cis.3.1.1.OracleLinux7.1.8.4_Ensure_XDCMP_is_not_enabled:def:1
    
      - Title: Ensure XDCMP is not enabled
 
- oval:simp.cis.3.1.1.OracleLinux7.1.9_Ensure_updates_patches_and_additional_security_software_are_installed:def:1
    
      - Title: Ensure updates, patches, and additional security software are installed
 
- oval:simp.cis.3.1.1.OracleLinux7.2.1.1_Ensure_xinetd_is_not_installed:def:1
    
      - Title: Ensure xinetd is not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.2.2.1.1_Ensure_time_synchronization_is_in_use:def:1
    
      - Title: Ensure time synchronization is in use
 
- oval:simp.cis.3.1.1.OracleLinux7.2.2.1.2_Ensure_chrony_is_configured:def:1
    
      - Title: Ensure chrony is configured
- NOTE: We are configuring the system to use ntpd instead of chrony.
 
- oval:simp.cis.3.1.1.OracleLinux7.2.2.1.3_Ensure_ntp_is_configured:def:1
    
      - Title: Ensure ntp is configured
 
- oval:simp.cis.3.1.1.OracleLinux7.2.2.10_Ensure_IMAP_and_POP3_server_is_not_installed:def:1
    
      - Title: Ensure IMAP and POP3 server is not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.2.2.11_Ensure_Samba_is_not_installed:def:1
    
      - Title: Ensure Samba is not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.2.2.12_Ensure_HTTP_Proxy_Server_is_not_installed:def:1
    
      - Title: Ensure HTTP Proxy Server is not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.2.2.13_Ensure_net-snmp_is_not_installed:def:1
    
      - Title: Ensure net-snmp is not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.2.2.14_Ensure_NIS_server_is_not_installed:def:1
    
      - Title: Ensure NIS server is not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.2.2.15_Ensure_telnet-server_is_not_installed:def:1
    
      - Title: Ensure telnet-server is not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.2.2.16_Ensure_mail_transfer_agent_is_configured_for_local-only_mode:def:1
    
      - Title: Ensure mail transfer agent is configured for local-only mode
 
- oval:simp.cis.3.1.1.OracleLinux7.2.2.17_Ensure_nfs-utils_is_not_installed_or_the__nfs-server_service_is_masked:def:1
    
      - Title: Ensure nfs-utils is not installed or the nfs-server service is masked
 
- oval:simp.cis.3.1.1.OracleLinux7.2.2.18_Ensure_rpcbind_is_not_installed_or_the__rpcbind_services_are_masked:def:1
    
      - Title: Ensure rpcbind is not installed or the rpcbind services are masked
 
- oval:simp.cis.3.1.1.OracleLinux7.2.2.19_Ensure_rsync_is_not_installed_or_the_rsyncd_service_is_masked:def:1
    
      - Title: Ensure rsync is not installed or the rsyncd service is masked
 
- oval:simp.cis.3.1.1.OracleLinux7.2.2.2_Ensure_X11_Server_components_are_not_installed:def:1
    
      - Title: Ensure X11 Server components are not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.2.2.3_Ensure_Avahi_Server_is_not_installed:def:1
    
      - Title: Ensure Avahi Server is not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.2.2.4_Ensure_CUPS_is_not_installed:def:1
    
      - Title: Ensure CUPS is not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.2.2.5_Ensure_DHCP_Server_is_not_installed:def:1
    
      - Title: Ensure DHCP Server is not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.2.2.6_Ensure_LDAP_server_is_not_installed:def:1
    
      - Title: Ensure LDAP server is not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.2.2.7_Ensure_DNS_Server_is_not_installed:def:1
    
      - Title: Ensure DNS Server is not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.2.2.8_Ensure_FTP_Server_is_not_installed:def:1
    
      - Title: Ensure FTP Server is not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.2.2.9_Ensure_HTTP_server_is_not_installed:def:1
    
      - Title: Ensure HTTP server is not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.2.3.1_Ensure_NIS_Client_is_not_installed:def:1
    
      - Title: Ensure NIS Client is not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.2.3.2_Ensure_rsh_client_is_not_installed:def:1
    
      - Title: Ensure rsh client is not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.2.3.3_Ensure_talk_client_is_not_installed:def:1
    
      - Title: Ensure talk client is not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.2.3.4_Ensure_telnet_client_is_not_installed:def:1
    
      - Title: Ensure telnet client is not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.2.3.5_Ensure_LDAP_client_is_not_installed:def:1
    
      - Title: Ensure LDAP client is not installed
 
- oval:simp.cis.3.1.1.OracleLinux7.2.4_Ensure_nonessential_services_are_removed_or_masked:def:1
    
      - Title: Ensure nonessential services are removed or masked
 
- oval:simp.cis.3.1.1.OracleLinux7.3.1.1_Disable_IPv6:def:1
    
  
- oval:simp.cis.3.1.1.OracleLinux7.3.1.2_Ensure_wireless_interfaces_are_disabled:def:1
    
      - Title: Ensure wireless interfaces are disabled
 
- oval:simp.cis.3.1.1.OracleLinux7.3.2.1_Ensure_IP_forwarding_is_disabled:def:1
    
      - Title: Ensure IP forwarding is disabled
 
- oval:simp.cis.3.1.1.OracleLinux7.3.2.2_Ensure_packet_redirect_sending_is_disabled:def:1
    
      - Title: Ensure packet redirect sending is disabled
 
- oval:simp.cis.3.1.1.OracleLinux7.3.3.1_Ensure_source_routed_packets_are_not_accepted:def:1
    
      - Title: Ensure source routed packets are not accepted
 
- oval:simp.cis.3.1.1.OracleLinux7.3.3.2_Ensure_ICMP_redirects_are_not_accepted:def:1
    
      - Title: Ensure ICMP redirects are not accepted
 
- oval:simp.cis.3.1.1.OracleLinux7.3.3.3_Ensure_secure_ICMP_redirects_are_not_accepted:def:1
    
      - Title: Ensure secure ICMP redirects are not accepted
 
- oval:simp.cis.3.1.1.OracleLinux7.3.3.4_Ensure_suspicious_packets_are_logged:def:1
    
      - Title: Ensure suspicious packets are logged
 
- oval:simp.cis.3.1.1.OracleLinux7.3.3.5_Ensure_broadcast_ICMP_requests_are_ignored:def:1
    
      - Title: Ensure broadcast ICMP requests are ignored
 
- oval:simp.cis.3.1.1.OracleLinux7.3.3.6_Ensure_bogus_ICMP_responses_are_ignored:def:1
    
      - Title: Ensure bogus ICMP responses are ignored
 
- oval:simp.cis.3.1.1.OracleLinux7.3.3.7_Ensure_Reverse_Path_Filtering_is_enabled:def:1
    
      - Title: Ensure Reverse Path Filtering is enabled
 
- oval:simp.cis.3.1.1.OracleLinux7.3.3.8_Ensure_TCP_SYN_Cookies_is_enabled:def:1
    
      - Title: Ensure TCP SYN Cookies is enabled
 
- oval:simp.cis.3.1.1.OracleLinux7.3.3.9_Ensure_IPv6_router_advertisements_are_not_accepted:def:1
    
      - Title: Ensure IPv6 router advertisements are not accepted
 
- oval:simp.cis.3.1.1.OracleLinux7.3.4.1_Ensure_DCCP_is_disabled:def:1
    
      - Title: Ensure DCCP is disabled
 
- oval:simp.cis.3.1.1.OracleLinux7.3.4.2_Ensure_SCTP_is_disabled:def:1
    
      - Title: Ensure SCTP is disabled
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.1.1_Ensure_firewalld_is_installed:def:1
    
      - Title: Ensure firewalld is installed
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.1.2_Ensure_iptables-services_not_installed_with_firewalld:def:1
    
      - Title: Ensure iptables-services not installed with firewalld
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.1.3_Ensure_nftables_either_not_installed_or_masked_with_firewalld:def:1
    
      - Title: Ensure nftables either not installed or masked with firewalld
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.1.4_Ensure_firewalld_service_enabled_and_running:def:1
    
      - Title: Ensure firewalld service enabled and running
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.1.5_Ensure_firewalld_default_zone_is_set:def:1
    
      - Title: Ensure firewalld default zone is set
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.1.6_Ensure_network_interfaces_are_assigned_to_appropriate_zone:def:1
    
      - Title: Ensure network interfaces are assigned to appropriate zone
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.1.7_Ensure_firewalld_drops_unnecessary_services_and_ports:def:1
    
      - Title: Ensure firewalld drops unnecessary services and ports
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.2.10_Ensure_nftables_service_is_enabled:def:1
    
      - Title: Ensure nftables service is enabled
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.2.11_Ensure_nftables_rules_are_permanent:def:1
    
      - Title: Ensure nftables rules are permanent
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.2.1_Ensure_nftables_is_installed:def:1
    
      - Title: Ensure nftables is installed
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.2.2_Ensure_firewalld_is_either_not_installed_or_masked_with_nftables:def:1
    
      - Title: Ensure firewalld is either not installed or masked with nftables
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.2.3_Ensure_iptables-services_not_installed_with_nftables:def:1
    
      - Title: Ensure iptables-services not installed with nftables
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.2.4_Ensure_iptables_are_flushed_with_nftables:def:1
    
      - Title: Ensure iptables are flushed with nftables
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.2.5_Ensure_an_nftables_table_exists:def:1
    
      - Title: Ensure an nftables table exists
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.2.6_Ensure_nftables_base_chains_exist:def:1
    
      - Title: Ensure nftables base chains exist
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.2.7_Ensure_nftables_loopback_traffic_is_configured:def:1
    
      - Title: Ensure nftables loopback traffic is configured
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.2.8_Ensure_nftables_outbound_and_established_connections_are_configured:def:1
    
      - Title: Ensure nftables outbound and established connections are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.2.9_Ensure_nftables_default_deny_firewall_policy:def:1
    
      - Title: Ensure nftables default deny firewall policy
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.1.1_Ensure_iptables_packages_are_installed:def:1
    
      - Title: Ensure iptables packages are installed
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.1.2_Ensure_nftables_is_not_installed_with_iptables:def:1
    
      - Title: Ensure nftables is not installed with iptables
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.1.3_Ensure_firewalld_is_either_not_installed_or_masked_with_iptables:def:1
    
      - Title: Ensure firewalld is either not installed or masked with iptables
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.2.1_Ensure_iptables_loopback_traffic_is_configured:def:1
    
      - Title: Ensure iptables loopback traffic is configured
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.2.2_Ensure_iptables_outbound_and_established_connections_are_configured:def:1
    
      - Title: Ensure iptables outbound and established connections are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.2.3_Ensure_iptables_rules_exist_for_all_open_ports:def:1
    
      - Title: Ensure iptables rules exist for all open ports
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.2.4_Ensure_iptables_default_deny_firewall_policy:def:1
    
      - Title: Ensure iptables default deny firewall policy
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.2.5_Ensure_iptables_rules_are_saved:def:1
    
      - Title: Ensure iptables rules are saved
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.2.6_Ensure_iptables_is_enabled_and_running:def:1
    
      - Title: Ensure iptables is enabled and running
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.3.1_Ensure_ip6tables_loopback_traffic_is_configured:def:1
    
      - Title: Ensure ip6tables loopback traffic is configured
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.3.2_Ensure_ip6tables_outbound_and_established_connections_are_configured:def:1
    
      - Title: Ensure ip6tables outbound and established connections are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.3.3_Ensure_ip6tables_firewall_rules_exist_for_all_open_ports:def:1
    
      - Title: Ensure ip6tables firewall rules exist for all open ports
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.3.4_Ensure_ip6tables_default_deny_firewall_policy:def:1
    
      - Title: Ensure ip6tables default deny firewall policy
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.3.5_Ensure_ip6tables_rules_are_saved:def:1
    
      - Title: Ensure ip6tables rules are saved
 
- oval:simp.cis.3.1.1.OracleLinux7.3.5.3.3.6_Ensure_ip6tables_is_enabled_and_running:def:1
    
      - Title: Ensure ip6tables is enabled and running
 
- oval:simp.cis.3.1.1.OracleLinux7.4.1.1.1_Ensure_auditd_is_installed:def:1
    
      - Title: Ensure auditd is installed
 
- oval:simp.cis.3.1.1.OracleLinux7.4.1.1.2_Ensure_auditd_service_is_enabled_and_running:def:1
    
      - Title: Ensure auditd service is enabled and running
 
- oval:simp.cis.3.1.1.OracleLinux7.4.1.1.3_Ensure_auditing_for_processes_that_start_prior_to_auditd_is_enabled:def:1
    
      - Title: Ensure auditing for processes that start prior to auditd is enabled
 
- oval:simp.cis.3.1.1.OracleLinux7.4.1.10_Ensure_unsuccessful_unauthorized_file_access_attempts_are_collected:def:1
    
      - Title: Ensure unsuccessful unauthorized file access attempts are collected
 
- oval:simp.cis.3.1.1.OracleLinux7.4.1.11_Ensure_use_of_privileged_commands_is_collected:def:1
    
      - Title: Ensure use of privileged commands is collected
 
- oval:simp.cis.3.1.1.OracleLinux7.4.1.12_Ensure_successful_file_system_mounts_are_collected:def:1
    
      - Title: Ensure successful file system mounts are collected
 
- oval:simp.cis.3.1.1.OracleLinux7.4.1.13_Ensure_file_deletion_events_by_users_are_collected:def:1
    
      - Title: Ensure file deletion events by users are collected
 
- oval:simp.cis.3.1.1.OracleLinux7.4.1.14_Ensure_changes_to_system_administration_scope_sudoers_is_collected:def:1
    
      - Title: Ensure changes to system administration scope (sudoers) is collected
 
- oval:simp.cis.3.1.1.OracleLinux7.4.1.15_Ensure_system_administrator_command_executions_sudo_are_collected:def:1
    
      - Title: Ensure system administrator command executions (sudo) are collected
 
- oval:simp.cis.3.1.1.OracleLinux7.4.1.16_Ensure_kernel_module_loading_and_unloading_is_collected:def:1
    
      - Title: Ensure kernel module loading and unloading is collected
 
- oval:simp.cis.3.1.1.OracleLinux7.4.1.17_Ensure_the_audit_configuration_is_immutable:def:1
    
      - Title: Ensure the audit configuration is immutable
 
- oval:simp.cis.3.1.1.OracleLinux7.4.1.2.1_Ensure_audit_log_storage_size_is_configured:def:1
    
      - Title: Ensure audit log storage size is configured
 
- oval:simp.cis.3.1.1.OracleLinux7.4.1.2.2_Ensure_audit_logs_are_not_automatically_deleted:def:1
    
      - Title: Ensure audit logs are not automatically deleted
 
- oval:simp.cis.3.1.1.OracleLinux7.4.1.2.3_Ensure_system_is_disabled_when_audit_logs_are_full:def:1
    
      - Title: Ensure system is disabled when audit logs are full
 
- oval:simp.cis.3.1.1.OracleLinux7.4.1.2.4_Ensure_audit_backlog_limit_is_sufficient:def:1
    
      - Title: Ensure audit_backlog_limit is sufficient
 
- oval:simp.cis.3.1.1.OracleLinux7.4.1.3_Ensure_events_that_modify_date_and_time_information_are_collected:def:1
    
      - Title: Ensure events that modify date and time information are collected
 
- oval:simp.cis.3.1.1.OracleLinux7.4.1.4_Ensure_events_that_modify_usergroup_information_are_collected:def:1
    
      - Title: Ensure events that modify user/group information are collected
 
- oval:simp.cis.3.1.1.OracleLinux7.4.1.5_Ensure_events_that_modify_the_systems_network_environment_are_collected:def:1
    
      - Title: Ensure events that modify the system’s network environment are collected
 
- oval:simp.cis.3.1.1.OracleLinux7.4.1.6_Ensure_events_that_modify_the_systems_Mandatory_Access_Controls_are_collected:def:1
    
      - Title: Ensure events that modify the system’s Mandatory Access Controls are collected
 
- oval:simp.cis.3.1.1.OracleLinux7.4.1.7_Ensure_login_and_logout_events_are_collected:def:1
    
      - Title: Ensure login and logout events are collected
 
- oval:simp.cis.3.1.1.OracleLinux7.4.1.8_Ensure_session_initiation_information_is_collected:def:1
    
      - Title: Ensure session initiation information is collected
 
- oval:simp.cis.3.1.1.OracleLinux7.4.1.9_Ensure_discretionary_access_control_permission_modification_events_are_collected:def:1
    
      - Title: Ensure discretionary access control permission modification events are collected
 
- oval:simp.cis.3.1.1.OracleLinux7.4.2.1.1_Ensure_rsyslog_is_installed:def:1
    
      - Title: Ensure rsyslog is installed
 
- oval:simp.cis.3.1.1.OracleLinux7.4.2.1.2_Ensure_rsyslog_Service_is_enabled_and_running:def:1
    
      - Title: Ensure rsyslog Service is enabled and running
 
- oval:simp.cis.3.1.1.OracleLinux7.4.2.1.3_Ensure_rsyslog_default_file_permissions_configured:def:1
    
      - Title: Ensure rsyslog default file permissions configured
 
- oval:simp.cis.3.1.1.OracleLinux7.4.2.1.4_Ensure_logging_is_configured:def:1
    
      - Title: Ensure logging is configured
 
- oval:simp.cis.3.1.1.OracleLinux7.4.2.1.5_Ensure_rsyslog_is_configured_to_send_logs_to_a_remote_log_host:def:1
    
      - Title: Ensure rsyslog is configured to send logs to a remote log host
 
- oval:simp.cis.3.1.1.OracleLinux7.4.2.1.6_Ensure_remote_rsyslog_messages_are_only_accepted_on_designated_log_hosts.:def:1
    
      - Title: Ensure remote rsyslog messages are only accepted on designated log hosts.
 
- oval:simp.cis.3.1.1.OracleLinux7.4.2.2.1_Ensure_journald_is_configured_to_send_logs_to_rsyslog:def:1
    
      - Title: Ensure journald is configured to send logs to rsyslog
 
- oval:simp.cis.3.1.1.OracleLinux7.4.2.2.2_Ensure_journald_is_configured_to_compress_large_log_files:def:1
    
      - Title: Ensure journald is configured to compress large log files
 
- oval:simp.cis.3.1.1.OracleLinux7.4.2.2.3_Ensure_journald_is_configured_to_write_logfiles_to_persistent_disk:def:1
    
      - Title: Ensure journald is configured to write logfiles to persistent disk
 
- oval:simp.cis.3.1.1.OracleLinux7.4.2.3_Ensure_permissions_on_all_logfiles_are_configured:def:1
    
      - Title: Ensure permissions on all logfiles are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.4.2.4_Ensure_logrotate_is_configured:def:1
    
      - Title: Ensure logrotate is configured
 
- oval:simp.cis.3.1.1.OracleLinux7.5.1.1_Ensure_cron_daemon_is_enabled_and_running:def:1
    
      - Title: Ensure cron daemon is enabled and running
 
- oval:simp.cis.3.1.1.OracleLinux7.5.1.2_Ensure_permissions_on_etccrontab_are_configured:def:1
    
      - Title: Ensure permissions on /etc/crontab are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.5.1.3_Ensure_permissions_on_etccron.hourly_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.hourly are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.5.1.4_Ensure_permissions_on_etccron.daily_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.daily are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.5.1.5_Ensure_permissions_on_etccron.weekly_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.weekly are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.5.1.6_Ensure_permissions_on_etccron.monthly_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.monthly are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.5.1.7_Ensure_permissions_on_etccron.d_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.d are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.5.1.8_Ensure_cron_is_restricted_to_authorized_users:def:1
    
      - Title: Ensure cron is restricted to authorized users
 
- oval:simp.cis.3.1.1.OracleLinux7.5.1.9_Ensure_at_is_restricted_to_authorized_users:def:1
    
      - Title: Ensure at is restricted to authorized users
 
- oval:simp.cis.3.1.1.OracleLinux7.5.2.1_Ensure_sudo_is_installed:def:1
    
      - Title: Ensure sudo is installed
 
- oval:simp.cis.3.1.1.OracleLinux7.5.2.2_Ensure_sudo_commands_use_pty:def:1
    
      - Title: Ensure sudo commands use pty
 
- oval:simp.cis.3.1.1.OracleLinux7.5.2.3_Ensure_sudo_log_file_exists:def:1
    
      - Title: Ensure sudo log file exists
 
- oval:simp.cis.3.1.1.OracleLinux7.5.3.10_Ensure_SSH_root_login_is_disabled:def:1
    
      - Title: Ensure SSH root login is disabled
 
- oval:simp.cis.3.1.1.OracleLinux7.5.3.11_Ensure_SSH_PermitEmptyPasswords_is_disabled:def:1
    
      - Title: Ensure SSH PermitEmptyPasswords is disabled
 
- oval:simp.cis.3.1.1.OracleLinux7.5.3.12_Ensure_SSH_PermitUserEnvironment_is_disabled:def:1
    
      - Title: Ensure SSH PermitUserEnvironment is disabled
 
- oval:simp.cis.3.1.1.OracleLinux7.5.3.13_Ensure_only_strong_Ciphers_are_used:def:1
    
      - Title: Ensure only strong Ciphers are used
 
- oval:simp.cis.3.1.1.OracleLinux7.5.3.14_Ensure_only_strong_MAC_algorithms_are_used:def:1
    
      - Title: Ensure only strong MAC algorithms are used
 
- oval:simp.cis.3.1.1.OracleLinux7.5.3.15_Ensure_only_strong_Key_Exchange_algorithms_are_used:def:1
    
      - Title: Ensure only strong Key Exchange algorithms are used
 
- oval:simp.cis.3.1.1.OracleLinux7.5.3.16_Ensure_SSH_Idle_Timeout_Interval_is_configured:def:1
    
      - Title: Ensure SSH Idle Timeout Interval is configured
 
- oval:simp.cis.3.1.1.OracleLinux7.5.3.17_Ensure_SSH_LoginGraceTime_is_set_to_one_minute_or_less:def:1
    
      - Title: Ensure SSH LoginGraceTime is set to one minute or less
 
- oval:simp.cis.3.1.1.OracleLinux7.5.3.18_Ensure_SSH_warning_banner_is_configured:def:1
    
      - Title: Ensure SSH warning banner is configured
 
- oval:simp.cis.3.1.1.OracleLinux7.5.3.19_Ensure_SSH_PAM_is_enabled:def:1
    
      - Title: Ensure SSH PAM is enabled
 
- oval:simp.cis.3.1.1.OracleLinux7.5.3.1_Ensure_permissions_on_etcsshsshd_config_are_configured:def:1
    
      - Title: Ensure permissions on /etc/ssh/sshd_config are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.5.3.20_Ensure_SSH_AllowTcpForwarding_is_disabled:def:1
    
      - Title: Ensure SSH AllowTcpForwarding is disabled
 
- oval:simp.cis.3.1.1.OracleLinux7.5.3.21_Ensure_SSH_MaxStartups_is_configured:def:1
    
      - Title: Ensure SSH MaxStartups is configured
 
- oval:simp.cis.3.1.1.OracleLinux7.5.3.22_Ensure_SSH_MaxSessions_is_limited:def:1
    
      - Title: Ensure SSH MaxSessions is limited
 
- oval:simp.cis.3.1.1.OracleLinux7.5.3.2_Ensure_permissions_on_SSH_private_host_key_files_are_configured:def:1
    
      - Title: Ensure permissions on SSH private host key files are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.5.3.3_Ensure_permissions_on_SSH_public_host_key_files_are_configured:def:1
    
      - Title: Ensure permissions on SSH public host key files are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.5.3.4_Ensure_SSH_access_is_limited:def:1
    
      - Title: Ensure SSH access is limited
 
- oval:simp.cis.3.1.1.OracleLinux7.5.3.5_Ensure_SSH_LogLevel_is_appropriate:def:1
    
      - Title: Ensure SSH LogLevel is appropriate
 
- oval:simp.cis.3.1.1.OracleLinux7.5.3.6_Ensure_SSH_X11_forwarding_is_disabled:def:1
    
      - Title: Ensure SSH X11 forwarding is disabled
 
- oval:simp.cis.3.1.1.OracleLinux7.5.3.7_Ensure_SSH_MaxAuthTries_is_set_to_4_or_less:def:1
    
      - Title: Ensure SSH MaxAuthTries is set to 4 or less
 
- oval:simp.cis.3.1.1.OracleLinux7.5.3.8_Ensure_SSH_IgnoreRhosts_is_enabled:def:1
    
      - Title: Ensure SSH IgnoreRhosts is enabled
 
- oval:simp.cis.3.1.1.OracleLinux7.5.3.9_Ensure_SSH_HostbasedAuthentication_is_disabled:def:1
    
      - Title: Ensure SSH HostbasedAuthentication is disabled
 
- oval:simp.cis.3.1.1.OracleLinux7.5.4.1_Ensure_password_creation_requirements_are_configured:def:1
    
      - Title: Ensure password creation requirements are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.5.4.2_Ensure_lockout_for_failed_password_attempts_is_configured:def:1
    
      - Title: Ensure lockout for failed password attempts is configured
 
- oval:simp.cis.3.1.1.OracleLinux7.5.4.3_Ensure_password_hashing_algorithm_is_SHA-512:def:1
    
      - Title: Ensure password hashing algorithm is SHA-512
 
- oval:simp.cis.3.1.1.OracleLinux7.5.4.4_Ensure_password_reuse_is_limited:def:1
    
      - Title: Ensure password reuse is limited
 
- oval:simp.cis.3.1.1.OracleLinux7.5.5.1.1_Ensure_password_expiration_is_365_days_or_less:def:1
    
      - Title: Ensure password expiration is 365 days or less
 
- oval:simp.cis.3.1.1.OracleLinux7.5.5.1.2_Ensure_minimum_days_between_password_changes_is_configured:def:1
    
      - Title: Ensure minimum days between password changes is configured
 
- oval:simp.cis.3.1.1.OracleLinux7.5.5.1.3_Ensure_password_expiration_warning_days_is_7_or_more:def:1
    
      - Title: Ensure password expiration warning days is 7 or more
 
- oval:simp.cis.3.1.1.OracleLinux7.5.5.1.4_Ensure_inactive_password_lock_is_30_days_or_less:def:1
    
      - Title: Ensure inactive password lock is 30 days or less
 
- oval:simp.cis.3.1.1.OracleLinux7.5.5.1.5_Ensure_all_users_last_password_change_date_is_in_the_past:def:1
    
      - Title: Ensure all users last password change date is in the past
 
- oval:simp.cis.3.1.1.OracleLinux7.5.5.2_Ensure_system_accounts_are_secured:def:1
    
      - Title: Ensure system accounts are secured
 
- oval:simp.cis.3.1.1.OracleLinux7.5.5.3_Ensure_default_group_for_the_root_account_is_GID_0:def:1
    
      - Title: Ensure default group for the root account is GID 0
 
- oval:simp.cis.3.1.1.OracleLinux7.5.5.4_Ensure_default_user_shell_timeout_is_configured:def:1
    
      - Title: Ensure default user shell timeout is configured
 
- oval:simp.cis.3.1.1.OracleLinux7.5.5.5_Ensure_default_user_umask_is_configured:def:1
    
      - Title: Ensure default user umask is configured
 
- oval:simp.cis.3.1.1.OracleLinux7.5.6_Ensure_root_login_is_restricted_to_system_console:def:1
    
      - Title: Ensure root login is restricted to system console
 
- oval:simp.cis.3.1.1.OracleLinux7.5.7_Ensure_access_to_the_su_command_is_restricted:def:1
    
      - Title: Ensure access to the su command is restricted
 
- oval:simp.cis.3.1.1.OracleLinux7.6.1.2_Ensure_permissions_on_etcpasswd_are_configured:def:1
    
      - Title: Ensure permissions on /etc/passwd are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.6.1.3_Ensure_permissions_on_etcpasswd-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/passwd- are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.6.1.4_Ensure_permissions_on_etcshadow_are_configured:def:1
    
      - Title: Ensure permissions on /etc/shadow are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.6.1.5_Ensure_permissions_on_etcshadow-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/shadow- are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.6.1.6_Ensure_permissions_on_etcgshadow-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/gshadow- are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.6.1.7_Ensure_permissions_on_etcgshadow_are_configured:def:1
    
      - Title: Ensure permissions on /etc/gshadow are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.6.1.8_Ensure_permissions_on_etcgroup_are_configured:def:1
    
      - Title: Ensure permissions on /etc/group are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.6.1.9_Ensure_permissions_on_etcgroup-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/group- are configured
 
- oval:simp.cis.3.1.1.OracleLinux7.6.2.10_Ensure_root_PATH_Integrity:def:1
    
      - Title: Ensure root PATH Integrity
 
- oval:simp.cis.3.1.1.OracleLinux7.6.2.11_Ensure_all_users_home_directories_exist:def:1
    
      - Title: Ensure all users’ home directories exist
 
- oval:simp.cis.3.1.1.OracleLinux7.6.2.12_Ensure_users_own_their_home_directories:def:1
    
      - Title: Ensure users own their home directories
 
- oval:simp.cis.3.1.1.OracleLinux7.6.2.13_Ensure_users_home_directories_permissions_are_750_or_more_restrictive:def:1
    
      - Title: Ensure users’ home directories permissions are 750 or more restrictive
 
- oval:simp.cis.3.1.1.OracleLinux7.6.2.14_Ensure_users_dot_files_are_not_group_or_world_writable:def:1
    
      - Title: Ensure users’ dot files are not group or world writable
 
- oval:simp.cis.3.1.1.OracleLinux7.6.2.15Ensure_no_users_have.forward_files:def:1
    
      - Title: Ensure no users have .forward files
 
- oval:simp.cis.3.1.1.OracleLinux7.6.2.16Ensure_no_users_have.netrc_files:def:1
    
      - Title: Ensure no users have .netrc files
 
- oval:simp.cis.3.1.1.OracleLinux7.6.2.17Ensure_no_users_have.rhosts_files:def:1
    
      - Title: Ensure no users have .rhosts files
 
- oval:simp.cis.3.1.1.OracleLinux7.6.2.1_Ensure_accounts_in_etcpasswd_use_shadowed_passwords:def:1
    
      - Title: Ensure accounts in /etc/passwd use shadowed passwords
 
- oval:simp.cis.3.1.1.OracleLinux7.6.2.2_Ensure_etcshadow_password_fields_are_not_empty:def:1
    
      - Title: Ensure /etc/shadow password fields are not empty
 
- oval:simp.cis.3.1.1.OracleLinux7.6.2.3_Ensure_all_groups_in_etcpasswd_exist_in_etcgroup:def:1
    
      - Title: Ensure all groups in /etc/passwd exist in /etc/group
 
- oval:simp.cis.3.1.1.OracleLinux7.6.2.4_Ensure_shadow_group_is_empty:def:1
    
      - Title: Ensure shadow group is empty
 
- oval:simp.cis.3.1.1.OracleLinux7.6.2.5_Ensure_no_duplicate_user_names_exist:def:1
    
      - Title: Ensure no duplicate user names exist
 
- oval:simp.cis.3.1.1.OracleLinux7.6.2.6_Ensure_no_duplicate_group_names_exist:def:1
    
      - Title: Ensure no duplicate group names exist
 
- oval:simp.cis.3.1.1.OracleLinux7.6.2.7_Ensure_no_duplicate_UIDs_exist:def:1
    
      - Title: Ensure no duplicate UIDs exist
 
- oval:simp.cis.3.1.1.OracleLinux7.6.2.8_Ensure_no_duplicate_GIDs_exist:def:1
    
      - Title: Ensure no duplicate GIDs exist
 
- oval:simp.cis.3.1.1.OracleLinux7.6.2.9_Ensure_root_is_the_only_UID_0_account:def:1
    
      - Title: Ensure root is the only UID 0 account
        RedHat 7 (233/248 [93%])
 
- oval:simp.cis.3.1.1.RedHat7.1.1.1.1_Ensure_mounting_of_cramfs_filesystems_is_disabled:def:1
    
      - Title: Ensure mounting of cramfs filesystems is disabled
 
- oval:simp.cis.3.1.1.RedHat7.1.1.1.2_Ensure_mounting_of_squashfs_filesystems_is_disabled:def:1
    
      - Title: Ensure mounting of squashfs filesystems is disabled
 
- oval:simp.cis.3.1.1.RedHat7.1.1.1.3_Ensure_mounting_of_udf_filesystems_is_disabled:def:1
    
      - Title: Ensure mounting of udf filesystems is disabled
 
- oval:simp.cis.3.1.1.RedHat7.1.1.12_Ensure_vartmp_partition_includes_the_noexec_option:def:1
    
      - Title: Ensure /var/tmp partition includes the noexec option
 
- oval:simp.cis.3.1.1.RedHat7.1.1.13_Ensure_vartmp_partition_includes_the_nodev_option:def:1
    
      - Title: Ensure /var/tmp partition includes the nodev option
 
- oval:simp.cis.3.1.1.RedHat7.1.1.14_Ensure_vartmp_partition_includes_the_nosuid_option:def:1
    
      - Title: Ensure /var/tmp partition includes the nosuid option
 
- oval:simp.cis.3.1.1.RedHat7.1.1.18_Ensure_home_partition_includes_the_nodev_option:def:1
    
      - Title: Ensure /home partition includes the nodev option
 
- oval:simp.cis.3.1.1.RedHat7.1.1.19_Ensure_removable_media_partitions_include_noexec_option:def:1
    
      - Title: Ensure removable media partitions include noexec option
 
- oval:simp.cis.3.1.1.RedHat7.1.1.20_Ensure_nodev_option_set_on_removable_media_partitions:def:1
    
      - Title: Ensure nodev option set on removable media partitions
 
- oval:simp.cis.3.1.1.RedHat7.1.1.21_Ensure_nosuid_option_set_on_removable_media_partitions:def:1
    
      - Title: Ensure nosuid option set on removable media partitions
 
- oval:simp.cis.3.1.1.RedHat7.1.1.22_Ensure_sticky_bit_is_set_on_all_world-writable_directories:def:1
    
      - Title: Ensure sticky bit is set on all world-writable directories
 
- oval:simp.cis.3.1.1.RedHat7.1.1.23_Disable_Automounting:def:1
    
      - Title: Disable Automounting
 
- oval:simp.cis.3.1.1.RedHat7.1.1.24_Disable_USB_Storage:def:1
    
      - Title: Disable USB Storage
 
- oval:simp.cis.3.1.1.RedHat7.1.1.2_Ensure_tmp_is_configured:def:1
    
      - Title: Ensure /tmp is configured
 
- oval:simp.cis.3.1.1.RedHat7.1.1.3_Ensure_noexec_option_set_on_tmp_partition:def:1
    
      - Title: Ensure noexec option set on /tmp partition
 
- oval:simp.cis.3.1.1.RedHat7.1.1.4_Ensure_nodev_option_set_on_tmp_partition:def:1
    
      - Title: Ensure nodev option set on /tmp partition
 
- oval:simp.cis.3.1.1.RedHat7.1.1.5_Ensure_nosuid_option_set_on_tmp_partition:def:1
    
      - Title: Ensure nosuid option set on /tmp partition
 
- oval:simp.cis.3.1.1.RedHat7.1.1.6_Ensure_devshm_is_configured:def:1
    
      - Title: Ensure /dev/shm is configured
 
- oval:simp.cis.3.1.1.RedHat7.1.1.7_Ensure_noexec_option_set_on_devshm_partition:def:1
    
      - Title: Ensure noexec option set on /dev/shm partition
 
- oval:simp.cis.3.1.1.RedHat7.1.1.8_Ensure_nodev_option_set_on_devshm_partition:def:1
    
      - Title: Ensure nodev option set on /dev/shm partition
 
- oval:simp.cis.3.1.1.RedHat7.1.1.9_Ensure_nosuid_option_set_on_devshm_partition:def:1
    
      - Title: Ensure nosuid option set on /dev/shm partition
 
- oval:simp.cis.3.1.1.RedHat7.1.2.1_Ensure_GPG_keys_are_configured:def:1
    
      - Title: Ensure GPG keys are configured
 
- oval:simp.cis.3.1.1.RedHat7.1.2.3_Ensure_gpgcheck_is_globally_activated:def:1
    
      - Title: Ensure gpgcheck is globally activated
 
- oval:simp.cis.3.1.1.RedHat7.1.2.5_Disable_the_rhnsd_Daemon:def:1
    
      - Title: Disable the rhnsd Daemon
- NOTE: rhnsd should only be disabled if it is not in use.
 
- oval:simp.cis.3.1.1.RedHat7.1.3.1_Ensure_AIDE_is_installed:def:1
    
      - Title: Ensure AIDE is installed
 
- oval:simp.cis.3.1.1.RedHat7.1.3.2_Ensure_filesystem_integrity_is_regularly_checked:def:1
    
      - Title: Ensure filesystem integrity is regularly checked
 
- oval:simp.cis.3.1.1.RedHat7.1.4.1_Ensure_bootloader_password_is_set:def:1
    
      - Title: Ensure bootloader password is set
 
- oval:simp.cis.3.1.1.RedHat7.1.4.2_Ensure_permissions_on_bootloader_config_are_configured:def:1
    
      - Title: Ensure permissions on bootloader config are configured
 
- oval:simp.cis.3.1.1.RedHat7.1.4.3_Ensure_authentication_required_for_single_user_mode:def:1
    
      - Title: Ensure authentication required for single user mode
 
- oval:simp.cis.3.1.1.RedHat7.1.5.1_Ensure_core_dumps_are_restricted:def:1
    
      - Title: Ensure core dumps are restricted
 
- oval:simp.cis.3.1.1.RedHat7.1.5.3_Ensure_address_space_layout_randomization_ASLR_is_enabled:def:1
    
      - Title: Ensure address space layout randomization (ASLR) is enabled
 
- oval:simp.cis.3.1.1.RedHat7.1.5.4_Ensure_prelink_is_not_installed:def:1
    
      - Title: Ensure prelink is not installed
 
- oval:simp.cis.3.1.1.RedHat7.1.6.1.1_Ensure_SELinux_is_installed:def:1
    
      - Title: Ensure SELinux is installed
 
- oval:simp.cis.3.1.1.RedHat7.1.6.1.2_Ensure_SELinux_is_not_disabled_in_bootloader_configuration:def:1
    
      - Title: Ensure SELinux is not disabled in bootloader configuration
 
- oval:simp.cis.3.1.1.RedHat7.1.6.1.3_Ensure_SELinux_policy_is_configured:def:1
    
      - Title: Ensure SELinux policy is configured
 
- oval:simp.cis.3.1.1.RedHat7.1.6.1.4_Ensure_the_SELinux_mode_is_enforcing_or_permissive:def:1
    
      - Title: Ensure the SELinux mode is enforcing or permissive
 
- oval:simp.cis.3.1.1.RedHat7.1.6.1.5_Ensure_the_SELinux_mode_is_enforcing:def:1
    
      - Title: Ensure the SELinux mode is enforcing
 
- oval:simp.cis.3.1.1.RedHat7.1.6.1.7_Ensure_SETroubleshoot_is_not_installed:def:1
    
      - Title: Ensure SETroubleshoot is not installed
 
- oval:simp.cis.3.1.1.RedHat7.1.6.1.8_Ensure_the_MCS_Translation_Service_mcstrans_is_not_installed:def:1
    
      - Title: Ensure the MCS Translation Service (mcstrans) is not installed
 
- oval:simp.cis.3.1.1.RedHat7.1.7.1_Ensure_message_of_the_day_is_configured_properly:def:1
    
      - Title: Ensure message of the day is configured properly
 
- oval:simp.cis.3.1.1.RedHat7.1.7.2_Ensure_local_login_warning_banner_is_configured_properly:def:1
    
      - Title: Ensure local login warning banner is configured properly
 
- oval:simp.cis.3.1.1.RedHat7.1.7.3_Ensure_remote_login_warning_banner_is_configured_properly:def:1
    
      - Title: Ensure remote login warning banner is configured properly
 
- oval:simp.cis.3.1.1.RedHat7.1.7.4_Ensure_permissions_on_etcmotd_are_configured:def:1
    
      - Title: Ensure permissions on /etc/motd are configured
 
- oval:simp.cis.3.1.1.RedHat7.1.7.5_Ensure_permissions_on_etcissue_are_configured:def:1
    
      - Title: Ensure permissions on /etc/issue are configured
 
- oval:simp.cis.3.1.1.RedHat7.1.7.6_Ensure_permissions_on_etcissue.net_are_configured:def:1
    
      - Title: Ensure permissions on /etc/issue.net are configured
 
- oval:simp.cis.3.1.1.RedHat7.1.8.1_Ensure_GNOME_Display_Manager_is_removed:def:1
    
      - Title: Ensure GNOME Display Manager is removed
 
- oval:simp.cis.3.1.1.RedHat7.1.8.2_Ensure_GDM_login_banner_is_configured:def:1
    
      - Title: Ensure GDM login banner is configured
 
- oval:simp.cis.3.1.1.RedHat7.1.8.3_Ensure_last_logged_in_user_display_is_disabled:def:1
    
      - Title: Ensure last logged in user display is disabled
 
- oval:simp.cis.3.1.1.RedHat7.1.8.4_Ensure_XDCMP_is_not_enabled:def:1
    
      - Title: Ensure XDCMP is not enabled
 
- oval:simp.cis.3.1.1.RedHat7.1.9_Ensure_updates_patches_and_additional_security_software_are_installed:def:1
    
      - Title: Ensure updates, patches, and additional security software are installed
 
- oval:simp.cis.3.1.1.RedHat7.2.1.1_Ensure_xinetd_is_not_installed:def:1
    
      - Title: Ensure xinetd is not installed
 
- oval:simp.cis.3.1.1.RedHat7.2.2.1.1_Ensure_time_synchronization_is_in_use:def:1
    
      - Title: Ensure time synchronization is in use
 
- oval:simp.cis.3.1.1.RedHat7.2.2.1.2_Ensure_chrony_is_configured:def:1
    
      - Title: Ensure chrony is configured
- NOTE: We are configuring the system to use ntpd instead of chrony.
 
- oval:simp.cis.3.1.1.RedHat7.2.2.1.3_Ensure_ntp_is_configured:def:1
    
      - Title: Ensure ntp is configured
 
- oval:simp.cis.3.1.1.RedHat7.2.2.10_Ensure_IMAP_and_POP3_server_is_not_installed:def:1
    
      - Title: Ensure IMAP and POP3 server is not installed
 
- oval:simp.cis.3.1.1.RedHat7.2.2.11_Ensure_Samba_is_not_installed:def:1
    
      - Title: Ensure Samba is not installed
 
- oval:simp.cis.3.1.1.RedHat7.2.2.12_Ensure_HTTP_Proxy_Server_is_not_installed:def:1
    
      - Title: Ensure HTTP Proxy Server is not installed
 
- oval:simp.cis.3.1.1.RedHat7.2.2.13_Ensure_net-snmp_is_not_installed:def:1
    
      - Title: Ensure net-snmp is not installed
 
- oval:simp.cis.3.1.1.RedHat7.2.2.14_Ensure_NIS_server_is_not_installed:def:1
    
      - Title: Ensure NIS server is not installed
 
- oval:simp.cis.3.1.1.RedHat7.2.2.15_Ensure_telnet-server_is_not_installed:def:1
    
      - Title: Ensure telnet-server is not installed
 
- oval:simp.cis.3.1.1.RedHat7.2.2.16_Ensure_mail_transfer_agent_is_configured_for_local-only_mode:def:1
    
      - Title: Ensure mail transfer agent is configured for local-only mode
 
- oval:simp.cis.3.1.1.RedHat7.2.2.17_Ensure_nfs-utils_is_not_installed_or_the__nfs-server_service_is_masked:def:1
    
      - Title: Ensure nfs-utils is not installed or the nfs-server service is masked
 
- oval:simp.cis.3.1.1.RedHat7.2.2.18_Ensure_rpcbind_is_not_installed_or_the__rpcbind_services_are_masked:def:1
    
      - Title: Ensure rpcbind is not installed or the rpcbind services are masked
 
- oval:simp.cis.3.1.1.RedHat7.2.2.19_Ensure_rsync_is_not_installed_or_the_rsyncd_service_is_masked:def:1
    
      - Title: Ensure rsync is not installed or the rsyncd service is masked
 
- oval:simp.cis.3.1.1.RedHat7.2.2.2_Ensure_X11_Server_components_are_not_installed:def:1
    
      - Title: Ensure X11 Server components are not installed
 
- oval:simp.cis.3.1.1.RedHat7.2.2.3_Ensure_Avahi_Server_is_not_installed:def:1
    
      - Title: Ensure Avahi Server is not installed
 
- oval:simp.cis.3.1.1.RedHat7.2.2.4_Ensure_CUPS_is_not_installed:def:1
    
      - Title: Ensure CUPS is not installed
 
- oval:simp.cis.3.1.1.RedHat7.2.2.5_Ensure_DHCP_Server_is_not_installed:def:1
    
      - Title: Ensure DHCP Server is not installed
 
- oval:simp.cis.3.1.1.RedHat7.2.2.6_Ensure_LDAP_server_is_not_installed:def:1
    
      - Title: Ensure LDAP server is not installed
 
- oval:simp.cis.3.1.1.RedHat7.2.2.7_Ensure_DNS_Server_is_not_installed:def:1
    
      - Title: Ensure DNS Server is not installed
 
- oval:simp.cis.3.1.1.RedHat7.2.2.8_Ensure_FTP_Server_is_not_installed:def:1
    
      - Title: Ensure FTP Server is not installed
 
- oval:simp.cis.3.1.1.RedHat7.2.2.9_Ensure_HTTP_server_is_not_installed:def:1
    
      - Title: Ensure HTTP server is not installed
 
- oval:simp.cis.3.1.1.RedHat7.2.3.1_Ensure_NIS_Client_is_not_installed:def:1
    
      - Title: Ensure NIS Client is not installed
 
- oval:simp.cis.3.1.1.RedHat7.2.3.2_Ensure_rsh_client_is_not_installed:def:1
    
      - Title: Ensure rsh client is not installed
 
- oval:simp.cis.3.1.1.RedHat7.2.3.3_Ensure_talk_client_is_not_installed:def:1
    
      - Title: Ensure talk client is not installed
 
- oval:simp.cis.3.1.1.RedHat7.2.3.4_Ensure_telnet_client_is_not_installed:def:1
    
      - Title: Ensure telnet client is not installed
 
- oval:simp.cis.3.1.1.RedHat7.2.3.5_Ensure_LDAP_client_is_not_installed:def:1
    
      - Title: Ensure LDAP client is not installed
 
- oval:simp.cis.3.1.1.RedHat7.2.4_Ensure_nonessential_services_are_removed_or_masked:def:1
    
      - Title: Ensure nonessential services are removed or masked
 
- oval:simp.cis.3.1.1.RedHat7.3.1.1_Disable_IPv6:def:1
    
  
- oval:simp.cis.3.1.1.RedHat7.3.1.2_Ensure_wireless_interfaces_are_disabled:def:1
    
      - Title: Ensure wireless interfaces are disabled
 
- oval:simp.cis.3.1.1.RedHat7.3.2.1_Ensure_IP_forwarding_is_disabled:def:1
    
      - Title: Ensure IP forwarding is disabled
 
- oval:simp.cis.3.1.1.RedHat7.3.2.2_Ensure_packet_redirect_sending_is_disabled:def:1
    
      - Title: Ensure packet redirect sending is disabled
 
- oval:simp.cis.3.1.1.RedHat7.3.3.1_Ensure_source_routed_packets_are_not_accepted:def:1
    
      - Title: Ensure source routed packets are not accepted
 
- oval:simp.cis.3.1.1.RedHat7.3.3.2_Ensure_ICMP_redirects_are_not_accepted:def:1
    
      - Title: Ensure ICMP redirects are not accepted
 
- oval:simp.cis.3.1.1.RedHat7.3.3.3_Ensure_secure_ICMP_redirects_are_not_accepted:def:1
    
      - Title: Ensure secure ICMP redirects are not accepted
 
- oval:simp.cis.3.1.1.RedHat7.3.3.4_Ensure_suspicious_packets_are_logged:def:1
    
      - Title: Ensure suspicious packets are logged
 
- oval:simp.cis.3.1.1.RedHat7.3.3.5_Ensure_broadcast_ICMP_requests_are_ignored:def:1
    
      - Title: Ensure broadcast ICMP requests are ignored
 
- oval:simp.cis.3.1.1.RedHat7.3.3.6_Ensure_bogus_ICMP_responses_are_ignored:def:1
    
      - Title: Ensure bogus ICMP responses are ignored
 
- oval:simp.cis.3.1.1.RedHat7.3.3.7_Ensure_Reverse_Path_Filtering_is_enabled:def:1
    
      - Title: Ensure Reverse Path Filtering is enabled
 
- oval:simp.cis.3.1.1.RedHat7.3.3.8_Ensure_TCP_SYN_Cookies_is_enabled:def:1
    
      - Title: Ensure TCP SYN Cookies is enabled
 
- oval:simp.cis.3.1.1.RedHat7.3.3.9_Ensure_IPv6_router_advertisements_are_not_accepted:def:1
    
      - Title: Ensure IPv6 router advertisements are not accepted
 
- oval:simp.cis.3.1.1.RedHat7.3.4.1_Ensure_DCCP_is_disabled:def:1
    
      - Title: Ensure DCCP is disabled
 
- oval:simp.cis.3.1.1.RedHat7.3.4.2_Ensure_SCTP_is_disabled:def:1
    
      - Title: Ensure SCTP is disabled
 
- oval:simp.cis.3.1.1.RedHat7.3.5.1.1_Ensure_firewalld_is_installed:def:1
    
      - Title: Ensure firewalld is installed
 
- oval:simp.cis.3.1.1.RedHat7.3.5.1.2_Ensure_iptables-services_not_installed_with_firewalld:def:1
    
      - Title: Ensure iptables-services not installed with firewalld
 
- oval:simp.cis.3.1.1.RedHat7.3.5.1.3_Ensure_nftables_either_not_installed_or_masked_with_firewalld:def:1
    
      - Title: Ensure nftables either not installed or masked with firewalld
 
- oval:simp.cis.3.1.1.RedHat7.3.5.1.4_Ensure_firewalld_service_enabled_and_running:def:1
    
      - Title: Ensure firewalld service enabled and running
 
- oval:simp.cis.3.1.1.RedHat7.3.5.1.5_Ensure_firewalld_default_zone_is_set:def:1
    
      - Title: Ensure firewalld default zone is set
 
- oval:simp.cis.3.1.1.RedHat7.3.5.1.6_Ensure_network_interfaces_are_assigned_to_appropriate_zone:def:1
    
      - Title: Ensure network interfaces are assigned to appropriate zone
 
- oval:simp.cis.3.1.1.RedHat7.3.5.1.7_Ensure_firewalld_drops_unnecessary_services_and_ports:def:1
    
      - Title: Ensure firewalld drops unnecessary services and ports
 
- oval:simp.cis.3.1.1.RedHat7.3.5.2.10_Ensure_nftables_service_is_enabled:def:1
    
      - Title: Ensure nftables service is enabled
 
- oval:simp.cis.3.1.1.RedHat7.3.5.2.11_Ensure_nftables_rules_are_permanent:def:1
    
      - Title: Ensure nftables rules are permanent
 
- oval:simp.cis.3.1.1.RedHat7.3.5.2.1_Ensure_nftables_is_installed:def:1
    
      - Title: Ensure nftables is installed
 
- oval:simp.cis.3.1.1.RedHat7.3.5.2.2_Ensure_firewalld_is_either_not_installed_or_masked_with_nftables:def:1
    
      - Title: Ensure firewalld is either not installed or masked with nftables
 
- oval:simp.cis.3.1.1.RedHat7.3.5.2.3_Ensure_iptables-services_not_installed_with_nftables:def:1
    
      - Title: Ensure iptables-services not installed with nftables
 
- oval:simp.cis.3.1.1.RedHat7.3.5.2.4_Ensure_iptables_are_flushed_with_nftables:def:1
    
      - Title: Ensure iptables are flushed with nftables
 
- oval:simp.cis.3.1.1.RedHat7.3.5.2.5_Ensure_an_nftables_table_exists:def:1
    
      - Title: Ensure an nftables table exists
 
- oval:simp.cis.3.1.1.RedHat7.3.5.2.6_Ensure_nftables_base_chains_exist:def:1
    
      - Title: Ensure nftables base chains exist
 
- oval:simp.cis.3.1.1.RedHat7.3.5.2.7_Ensure_nftables_loopback_traffic_is_configured:def:1
    
      - Title: Ensure nftables loopback traffic is configured
 
- oval:simp.cis.3.1.1.RedHat7.3.5.2.8_Ensure_nftables_outbound_and_established_connections_are_configured:def:1
    
      - Title: Ensure nftables outbound and established connections are configured
 
- oval:simp.cis.3.1.1.RedHat7.3.5.2.9_Ensure_nftables_default_deny_firewall_policy:def:1
    
      - Title: Ensure nftables default deny firewall policy
 
- oval:simp.cis.3.1.1.RedHat7.3.5.3.1.1_Ensure_iptables_packages_are_installed:def:1
    
      - Title: Ensure iptables packages are installed
 
- oval:simp.cis.3.1.1.RedHat7.3.5.3.1.2_Ensure_nftables_is_not_installed_with_iptables:def:1
    
      - Title: Ensure nftables is not installed with iptables
 
- oval:simp.cis.3.1.1.RedHat7.3.5.3.1.3_Ensure_firewalld_is_either_not_installed_or_masked_with_iptables:def:1
    
      - Title: Ensure firewalld is either not installed or masked with iptables
 
- oval:simp.cis.3.1.1.RedHat7.3.5.3.2.1_Ensure_iptables_loopback_traffic_is_configured:def:1
    
      - Title: Ensure iptables loopback traffic is configured
 
- oval:simp.cis.3.1.1.RedHat7.3.5.3.2.2_Ensure_iptables_outbound_and_established_connections_are_configured:def:1
    
      - Title: Ensure iptables outbound and established connections are configured
 
- oval:simp.cis.3.1.1.RedHat7.3.5.3.2.3_Ensure_iptables_rules_exist_for_all_open_ports:def:1
    
      - Title: Ensure iptables rules exist for all open ports
 
- oval:simp.cis.3.1.1.RedHat7.3.5.3.2.4_Ensure_iptables_default_deny_firewall_policy:def:1
    
      - Title: Ensure iptables default deny firewall policy
 
- oval:simp.cis.3.1.1.RedHat7.3.5.3.2.5_Ensure_iptables_rules_are_saved:def:1
    
      - Title: Ensure iptables rules are saved
 
- oval:simp.cis.3.1.1.RedHat7.3.5.3.2.6_Ensure_iptables_is_enabled_and_running:def:1
    
      - Title: Ensure iptables is enabled and running
 
- oval:simp.cis.3.1.1.RedHat7.3.5.3.3.1_Ensure_ip6tables_loopback_traffic_is_configured:def:1
    
      - Title: Ensure ip6tables loopback traffic is configured
 
- oval:simp.cis.3.1.1.RedHat7.3.5.3.3.2_Ensure_ip6tables_outbound_and_established_connections_are_configured:def:1
    
      - Title: Ensure ip6tables outbound and established connections are configured
 
- oval:simp.cis.3.1.1.RedHat7.3.5.3.3.3_Ensure_ip6tables_firewall_rules_exist_for_all_open_ports:def:1
    
      - Title: Ensure ip6tables firewall rules exist for all open ports
 
- oval:simp.cis.3.1.1.RedHat7.3.5.3.3.4_Ensure_ip6tables_default_deny_firewall_policy:def:1
    
      - Title: Ensure ip6tables default deny firewall policy
 
- oval:simp.cis.3.1.1.RedHat7.3.5.3.3.5_Ensure_ip6tables_rules_are_saved:def:1
    
      - Title: Ensure ip6tables rules are saved
 
- oval:simp.cis.3.1.1.RedHat7.3.5.3.3.6_Ensure_ip6tables_is_enabled_and_running:def:1
    
      - Title: Ensure ip6tables is enabled and running
 
- oval:simp.cis.3.1.1.RedHat7.4.1.1.1_Ensure_auditd_is_installed:def:1
    
      - Title: Ensure auditd is installed
 
- oval:simp.cis.3.1.1.RedHat7.4.1.1.2_Ensure_auditd_service_is_enabled_and_running:def:1
    
      - Title: Ensure auditd service is enabled and running
 
- oval:simp.cis.3.1.1.RedHat7.4.1.1.3_Ensure_auditing_for_processes_that_start_prior_to_auditd_is_enabled:def:1
    
      - Title: Ensure auditing for processes that start prior to auditd is enabled
 
- oval:simp.cis.3.1.1.RedHat7.4.1.10_Ensure_unsuccessful_unauthorized_file_access_attempts_are_collected:def:1
    
      - Title: Ensure unsuccessful unauthorized file access attempts are collected
 
- oval:simp.cis.3.1.1.RedHat7.4.1.11_Ensure_use_of_privileged_commands_is_collected:def:1
    
      - Title: Ensure use of privileged commands is collected
 
- oval:simp.cis.3.1.1.RedHat7.4.1.12_Ensure_successful_file_system_mounts_are_collected:def:1
    
      - Title: Ensure successful file system mounts are collected
 
- oval:simp.cis.3.1.1.RedHat7.4.1.13_Ensure_file_deletion_events_by_users_are_collected:def:1
    
      - Title: Ensure file deletion events by users are collected
 
- oval:simp.cis.3.1.1.RedHat7.4.1.14_Ensure_changes_to_system_administration_scope_sudoers_is_collected:def:1
    
      - Title: Ensure changes to system administration scope (sudoers) is collected
 
- oval:simp.cis.3.1.1.RedHat7.4.1.15_Ensure_system_administrator_command_executions_sudo_are_collected:def:1
    
      - Title: Ensure system administrator command executions (sudo) are collected
 
- oval:simp.cis.3.1.1.RedHat7.4.1.16_Ensure_kernel_module_loading_and_unloading_is_collected:def:1
    
      - Title: Ensure kernel module loading and unloading is collected
 
- oval:simp.cis.3.1.1.RedHat7.4.1.17_Ensure_the_audit_configuration_is_immutable:def:1
    
      - Title: Ensure the audit configuration is immutable
 
- oval:simp.cis.3.1.1.RedHat7.4.1.2.1_Ensure_audit_log_storage_size_is_configured:def:1
    
      - Title: Ensure audit log storage size is configured
 
- oval:simp.cis.3.1.1.RedHat7.4.1.2.2_Ensure_audit_logs_are_not_automatically_deleted:def:1
    
      - Title: Ensure audit logs are not automatically deleted
 
- oval:simp.cis.3.1.1.RedHat7.4.1.2.3_Ensure_system_is_disabled_when_audit_logs_are_full:def:1
    
      - Title: Ensure system is disabled when audit logs are full
 
- oval:simp.cis.3.1.1.RedHat7.4.1.2.4_Ensure_audit_backlog_limit_is_sufficient:def:1
    
      - Title: Ensure audit_backlog_limit is sufficient
 
- oval:simp.cis.3.1.1.RedHat7.4.1.3_Ensure_events_that_modify_date_and_time_information_are_collected:def:1
    
      - Title: Ensure events that modify date and time information are collected
 
- oval:simp.cis.3.1.1.RedHat7.4.1.4_Ensure_events_that_modify_usergroup_information_are_collected:def:1
    
      - Title: Ensure events that modify user/group information are collected
 
- oval:simp.cis.3.1.1.RedHat7.4.1.5_Ensure_events_that_modify_the_systems_network_environment_are_collected:def:1
    
      - Title: Ensure events that modify the system’s network environment are collected
 
- oval:simp.cis.3.1.1.RedHat7.4.1.6_Ensure_events_that_modify_the_systems_Mandatory_Access_Controls_are_collected:def:1
    
      - Title: Ensure events that modify the system’s Mandatory Access Controls are collected
 
- oval:simp.cis.3.1.1.RedHat7.4.1.7_Ensure_login_and_logout_events_are_collected:def:1
    
      - Title: Ensure login and logout events are collected
 
- oval:simp.cis.3.1.1.RedHat7.4.1.8_Ensure_session_initiation_information_is_collected:def:1
    
      - Title: Ensure session initiation information is collected
 
- oval:simp.cis.3.1.1.RedHat7.4.1.9_Ensure_discretionary_access_control_permission_modification_events_are_collected:def:1
    
      - Title: Ensure discretionary access control permission modification events are collected
 
- oval:simp.cis.3.1.1.RedHat7.4.2.1.1_Ensure_rsyslog_is_installed:def:1
    
      - Title: Ensure rsyslog is installed
 
- oval:simp.cis.3.1.1.RedHat7.4.2.1.2_Ensure_rsyslog_Service_is_enabled_and_running:def:1
    
      - Title: Ensure rsyslog Service is enabled and running
 
- oval:simp.cis.3.1.1.RedHat7.4.2.1.3_Ensure_rsyslog_default_file_permissions_configured:def:1
    
      - Title: Ensure rsyslog default file permissions configured
 
- oval:simp.cis.3.1.1.RedHat7.4.2.1.4_Ensure_logging_is_configured:def:1
    
      - Title: Ensure logging is configured
 
- oval:simp.cis.3.1.1.RedHat7.4.2.1.5_Ensure_rsyslog_is_configured_to_send_logs_to_a_remote_log_host:def:1
    
      - Title: Ensure rsyslog is configured to send logs to a remote log host
 
- oval:simp.cis.3.1.1.RedHat7.4.2.1.6_Ensure_remote_rsyslog_messages_are_only_accepted_on_designated_log_hosts.:def:1
    
      - Title: Ensure remote rsyslog messages are only accepted on designated log hosts.
 
- oval:simp.cis.3.1.1.RedHat7.4.2.2.1_Ensure_journald_is_configured_to_send_logs_to_rsyslog:def:1
    
      - Title: Ensure journald is configured to send logs to rsyslog
 
- oval:simp.cis.3.1.1.RedHat7.4.2.2.2_Ensure_journald_is_configured_to_compress_large_log_files:def:1
    
      - Title: Ensure journald is configured to compress large log files
 
- oval:simp.cis.3.1.1.RedHat7.4.2.2.3_Ensure_journald_is_configured_to_write_logfiles_to_persistent_disk:def:1
    
      - Title: Ensure journald is configured to write logfiles to persistent disk
 
- oval:simp.cis.3.1.1.RedHat7.4.2.3_Ensure_permissions_on_all_logfiles_are_configured:def:1
    
      - Title: Ensure permissions on all logfiles are configured
 
- oval:simp.cis.3.1.1.RedHat7.4.2.4_Ensure_logrotate_is_configured:def:1
    
      - Title: Ensure logrotate is configured
 
- oval:simp.cis.3.1.1.RedHat7.5.1.1_Ensure_cron_daemon_is_enabled_and_running:def:1
    
      - Title: Ensure cron daemon is enabled and running
 
- oval:simp.cis.3.1.1.RedHat7.5.1.2_Ensure_permissions_on_etccrontab_are_configured:def:1
    
      - Title: Ensure permissions on /etc/crontab are configured
 
- oval:simp.cis.3.1.1.RedHat7.5.1.3_Ensure_permissions_on_etccron.hourly_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.hourly are configured
 
- oval:simp.cis.3.1.1.RedHat7.5.1.4_Ensure_permissions_on_etccron.daily_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.daily are configured
 
- oval:simp.cis.3.1.1.RedHat7.5.1.5_Ensure_permissions_on_etccron.weekly_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.weekly are configured
 
- oval:simp.cis.3.1.1.RedHat7.5.1.6_Ensure_permissions_on_etccron.monthly_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.monthly are configured
 
- oval:simp.cis.3.1.1.RedHat7.5.1.7_Ensure_permissions_on_etccron.d_are_configured:def:1
    
      - Title: Ensure permissions on /etc/cron.d are configured
 
- oval:simp.cis.3.1.1.RedHat7.5.1.8_Ensure_cron_is_restricted_to_authorized_users:def:1
    
      - Title: Ensure cron is restricted to authorized users
 
- oval:simp.cis.3.1.1.RedHat7.5.1.9_Ensure_at_is_restricted_to_authorized_users:def:1
    
      - Title: Ensure at is restricted to authorized users
 
- oval:simp.cis.3.1.1.RedHat7.5.2.1_Ensure_sudo_is_installed:def:1
    
      - Title: Ensure sudo is installed
 
- oval:simp.cis.3.1.1.RedHat7.5.2.2_Ensure_sudo_commands_use_pty:def:1
    
      - Title: Ensure sudo commands use pty
 
- oval:simp.cis.3.1.1.RedHat7.5.2.3_Ensure_sudo_log_file_exists:def:1
    
      - Title: Ensure sudo log file exists
 
- oval:simp.cis.3.1.1.RedHat7.5.3.10_Ensure_SSH_root_login_is_disabled:def:1
    
      - Title: Ensure SSH root login is disabled
 
- oval:simp.cis.3.1.1.RedHat7.5.3.11_Ensure_SSH_PermitEmptyPasswords_is_disabled:def:1
    
      - Title: Ensure SSH PermitEmptyPasswords is disabled
 
- oval:simp.cis.3.1.1.RedHat7.5.3.12_Ensure_SSH_PermitUserEnvironment_is_disabled:def:1
    
      - Title: Ensure SSH PermitUserEnvironment is disabled
 
- oval:simp.cis.3.1.1.RedHat7.5.3.13_Ensure_only_strong_Ciphers_are_used:def:1
    
      - Title: Ensure only strong Ciphers are used
 
- oval:simp.cis.3.1.1.RedHat7.5.3.14_Ensure_only_strong_MAC_algorithms_are_used:def:1
    
      - Title: Ensure only strong MAC algorithms are used
 
- oval:simp.cis.3.1.1.RedHat7.5.3.15_Ensure_only_strong_Key_Exchange_algorithms_are_used:def:1
    
      - Title: Ensure only strong Key Exchange algorithms are used
 
- oval:simp.cis.3.1.1.RedHat7.5.3.16_Ensure_SSH_Idle_Timeout_Interval_is_configured:def:1
    
      - Title: Ensure SSH Idle Timeout Interval is configured
 
- oval:simp.cis.3.1.1.RedHat7.5.3.17_Ensure_SSH_LoginGraceTime_is_set_to_one_minute_or_less:def:1
    
      - Title: Ensure SSH LoginGraceTime is set to one minute or less
 
- oval:simp.cis.3.1.1.RedHat7.5.3.18_Ensure_SSH_warning_banner_is_configured:def:1
    
      - Title: Ensure SSH warning banner is configured
 
- oval:simp.cis.3.1.1.RedHat7.5.3.19_Ensure_SSH_PAM_is_enabled:def:1
    
      - Title: Ensure SSH PAM is enabled
 
- oval:simp.cis.3.1.1.RedHat7.5.3.1_Ensure_permissions_on_etcsshsshd_config_are_configured:def:1
    
      - Title: Ensure permissions on /etc/ssh/sshd_config are configured
 
- oval:simp.cis.3.1.1.RedHat7.5.3.20_Ensure_SSH_AllowTcpForwarding_is_disabled:def:1
    
      - Title: Ensure SSH AllowTcpForwarding is disabled
 
- oval:simp.cis.3.1.1.RedHat7.5.3.21_Ensure_SSH_MaxStartups_is_configured:def:1
    
      - Title: Ensure SSH MaxStartups is configured
 
- oval:simp.cis.3.1.1.RedHat7.5.3.22_Ensure_SSH_MaxSessions_is_limited:def:1
    
      - Title: Ensure SSH MaxSessions is limited
 
- oval:simp.cis.3.1.1.RedHat7.5.3.2_Ensure_permissions_on_SSH_private_host_key_files_are_configured:def:1
    
      - Title: Ensure permissions on SSH private host key files are configured
 
- oval:simp.cis.3.1.1.RedHat7.5.3.3_Ensure_permissions_on_SSH_public_host_key_files_are_configured:def:1
    
      - Title: Ensure permissions on SSH public host key files are configured
 
- oval:simp.cis.3.1.1.RedHat7.5.3.4_Ensure_SSH_access_is_limited:def:1
    
      - Title: Ensure SSH access is limited
 
- oval:simp.cis.3.1.1.RedHat7.5.3.5_Ensure_SSH_LogLevel_is_appropriate:def:1
    
      - Title: Ensure SSH LogLevel is appropriate
 
- oval:simp.cis.3.1.1.RedHat7.5.3.6_Ensure_SSH_X11_forwarding_is_disabled:def:1
    
      - Title: Ensure SSH X11 forwarding is disabled
 
- oval:simp.cis.3.1.1.RedHat7.5.3.7_Ensure_SSH_MaxAuthTries_is_set_to_4_or_less:def:1
    
      - Title: Ensure SSH MaxAuthTries is set to 4 or less
 
- oval:simp.cis.3.1.1.RedHat7.5.3.8_Ensure_SSH_IgnoreRhosts_is_enabled:def:1
    
      - Title: Ensure SSH IgnoreRhosts is enabled
 
- oval:simp.cis.3.1.1.RedHat7.5.3.9_Ensure_SSH_HostbasedAuthentication_is_disabled:def:1
    
      - Title: Ensure SSH HostbasedAuthentication is disabled
 
- oval:simp.cis.3.1.1.RedHat7.5.4.1_Ensure_password_creation_requirements_are_configured:def:1
    
      - Title: Ensure password creation requirements are configured
 
- oval:simp.cis.3.1.1.RedHat7.5.4.2_Ensure_lockout_for_failed_password_attempts_is_configured:def:1
    
      - Title: Ensure lockout for failed password attempts is configured
 
- oval:simp.cis.3.1.1.RedHat7.5.4.3_Ensure_password_hashing_algorithm_is_SHA-512:def:1
    
      - Title: Ensure password hashing algorithm is SHA-512
 
- oval:simp.cis.3.1.1.RedHat7.5.4.4_Ensure_password_reuse_is_limited:def:1
    
      - Title: Ensure password reuse is limited
 
- oval:simp.cis.3.1.1.RedHat7.5.5.1.1_Ensure_password_expiration_is_365_days_or_less:def:1
    
      - Title: Ensure password expiration is 365 days or less
 
- oval:simp.cis.3.1.1.RedHat7.5.5.1.2_Ensure_minimum_days_between_password_changes_is_configured:def:1
    
      - Title: Ensure minimum days between password changes is configured
 
- oval:simp.cis.3.1.1.RedHat7.5.5.1.3_Ensure_password_expiration_warning_days_is_7_or_more:def:1
    
      - Title: Ensure password expiration warning days is 7 or more
 
- oval:simp.cis.3.1.1.RedHat7.5.5.1.4_Ensure_inactive_password_lock_is_30_days_or_less:def:1
    
      - Title: Ensure inactive password lock is 30 days or less
 
- oval:simp.cis.3.1.1.RedHat7.5.5.1.5_Ensure_all_users_last_password_change_date_is_in_the_past:def:1
    
      - Title: Ensure all users last password change date is in the past
 
- oval:simp.cis.3.1.1.RedHat7.5.5.2_Ensure_system_accounts_are_secured:def:1
    
      - Title: Ensure system accounts are secured
 
- oval:simp.cis.3.1.1.RedHat7.5.5.3_Ensure_default_group_for_the_root_account_is_GID_0:def:1
    
      - Title: Ensure default group for the root account is GID 0
 
- oval:simp.cis.3.1.1.RedHat7.5.5.4_Ensure_default_user_shell_timeout_is_configured:def:1
    
      - Title: Ensure default user shell timeout is configured
 
- oval:simp.cis.3.1.1.RedHat7.5.5.5_Ensure_default_user_umask_is_configured:def:1
    
      - Title: Ensure default user umask is configured
 
- oval:simp.cis.3.1.1.RedHat7.5.6_Ensure_root_login_is_restricted_to_system_console:def:1
    
      - Title: Ensure root login is restricted to system console
 
- oval:simp.cis.3.1.1.RedHat7.5.7_Ensure_access_to_the_su_command_is_restricted:def:1
    
      - Title: Ensure access to the su command is restricted
 
- oval:simp.cis.3.1.1.RedHat7.6.1.2_Ensure_permissions_on_etcpasswd_are_configured:def:1
    
      - Title: Ensure permissions on /etc/passwd are configured
 
- oval:simp.cis.3.1.1.RedHat7.6.1.3_Ensure_permissions_on_etcpasswd-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/passwd- are configured
 
- oval:simp.cis.3.1.1.RedHat7.6.1.4_Ensure_permissions_on_etcshadow_are_configured:def:1
    
      - Title: Ensure permissions on /etc/shadow are configured
 
- oval:simp.cis.3.1.1.RedHat7.6.1.5_Ensure_permissions_on_etcshadow-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/shadow- are configured
 
- oval:simp.cis.3.1.1.RedHat7.6.1.6_Ensure_permissions_on_etcgshadow-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/gshadow- are configured
 
- oval:simp.cis.3.1.1.RedHat7.6.1.7_Ensure_permissions_on_etcgshadow_are_configured:def:1
    
      - Title: Ensure permissions on /etc/gshadow are configured
 
- oval:simp.cis.3.1.1.RedHat7.6.1.8_Ensure_permissions_on_etcgroup_are_configured:def:1
    
      - Title: Ensure permissions on /etc/group are configured
 
- oval:simp.cis.3.1.1.RedHat7.6.1.9_Ensure_permissions_on_etcgroup-_are_configured:def:1
    
      - Title: Ensure permissions on /etc/group- are configured
 
- oval:simp.cis.3.1.1.RedHat7.6.2.10_Ensure_root_PATH_Integrity:def:1
    
      - Title: Ensure root PATH Integrity
 
- oval:simp.cis.3.1.1.RedHat7.6.2.11_Ensure_all_users_home_directories_exist:def:1
    
      - Title: Ensure all users’ home directories exist
 
- oval:simp.cis.3.1.1.RedHat7.6.2.12_Ensure_users_own_their_home_directories:def:1
    
      - Title: Ensure users own their home directories
 
- oval:simp.cis.3.1.1.RedHat7.6.2.13_Ensure_users_home_directories_permissions_are_750_or_more_restrictive:def:1
    
      - Title: Ensure users’ home directories permissions are 750 or more restrictive
 
- oval:simp.cis.3.1.1.RedHat7.6.2.14_Ensure_users_dot_files_are_not_group_or_world_writable:def:1
    
      - Title: Ensure users’ dot files are not group or world writable
 
- oval:simp.cis.3.1.1.RedHat7.6.2.15Ensure_no_users_have.forward_files:def:1
    
      - Title: Ensure no users have .forward files
 
- oval:simp.cis.3.1.1.RedHat7.6.2.16Ensure_no_users_have.netrc_files:def:1
    
      - Title: Ensure no users have .netrc files
 
- oval:simp.cis.3.1.1.RedHat7.6.2.17Ensure_no_users_have.rhosts_files:def:1
    
      - Title: Ensure no users have .rhosts files
 
- oval:simp.cis.3.1.1.RedHat7.6.2.1_Ensure_accounts_in_etcpasswd_use_shadowed_passwords:def:1
    
      - Title: Ensure accounts in /etc/passwd use shadowed passwords
 
- oval:simp.cis.3.1.1.RedHat7.6.2.2_Ensure_etcshadow_password_fields_are_not_empty:def:1
    
      - Title: Ensure /etc/shadow password fields are not empty
 
- oval:simp.cis.3.1.1.RedHat7.6.2.3_Ensure_all_groups_in_etcpasswd_exist_in_etcgroup:def:1
    
      - Title: Ensure all groups in /etc/passwd exist in /etc/group
 
- oval:simp.cis.3.1.1.RedHat7.6.2.4_Ensure_shadow_group_is_empty:def:1
    
      - Title: Ensure shadow group is empty
 
- oval:simp.cis.3.1.1.RedHat7.6.2.5_Ensure_no_duplicate_user_names_exist:def:1
    
      - Title: Ensure no duplicate user names exist
 
- oval:simp.cis.3.1.1.RedHat7.6.2.6_Ensure_no_duplicate_group_names_exist:def:1
    
      - Title: Ensure no duplicate group names exist
 
- oval:simp.cis.3.1.1.RedHat7.6.2.7_Ensure_no_duplicate_UIDs_exist:def:1
    
      - Title: Ensure no duplicate UIDs exist
 
- oval:simp.cis.3.1.1.RedHat7.6.2.8_Ensure_no_duplicate_GIDs_exist:def:1
    
      - Title: Ensure no duplicate GIDs exist
 
- oval:simp.cis.3.1.1.RedHat7.6.2.9_Ensure_root_is_the_only_UID_0_account:def:1
    
      - Title: Ensure root is the only UID 0 account