Skip to content

Canonical Ubuntu 18.04 LTS Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-OS-000479-GPOS-00224

    Group
  • The Ubuntu operating system must have a crontab script running weekly to off-load audit events of standalone systems.

    Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Off-loading is a common process in information systems with limited audit storage capacity.
    Rule Low Severity
  • SRG-OS-000366-GPOS-00153

    Group
  • SRG-OS-000437-GPOS-00194

    Group
  • The Ubuntu operating system must be configured so that Advance package Tool (APT) removes all software components after updated versions have been installed.

    Previous versions of software components that are not removed from the information system after updates have been installed may be exploited by adversaries. Some information technology products may...
    Rule Medium Severity
  • SRG-OS-000095-GPOS-00049

    Group
  • The Ubuntu operating system must not have the Network Information Service (NIS) package installed.

    Removing the Network Information Service (NIS) package decreases the risk of the accidental (or intentional) activation of NIS or NIS+ services.
    Rule High Severity
  • SRG-OS-000095-GPOS-00049

    Group
  • SRG-OS-000191-GPOS-00080

    Group
  • The Ubuntu operating system must deploy Endpoint Security for Linux Threat Prevention (ENSLTP).

    Without the use of automated mechanisms to scan for security flaws on a continuous and/or periodic basis, the operating system or other system components may remain vulnerable to the exploits prese...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules