Skip to content

Canonical Ubuntu 20.04 LTS Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • The Ubuntu operating system must generate audit records for any successful/unsuccessful use of unlink, unlinkat, rename, renameat, and rmdir system calls.

    <VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...
    Rule Medium Severity
  • SRG-OS-000472-GPOS-00217

    <GroupDescription></GroupDescription>
    Group
  • The Ubuntu operating system must generate audit records for the /var/log/wtmp file.

    &lt;VulnDiscussion&gt;Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...
    Rule Medium Severity
  • SRG-OS-000472-GPOS-00217

    <GroupDescription></GroupDescription>
    Group
  • The Ubuntu operating system must generate audit records for the /var/run/utmp file.

    &lt;VulnDiscussion&gt;Without generating audit records specific to the security and mission needs of the organization, it would be difficult to est...
    Rule Medium Severity
  • SRG-OS-000472-GPOS-00217

    <GroupDescription></GroupDescription>
    Group
  • The Ubuntu operating system must generate audit records for the /var/log/btmp file.

    &lt;VulnDiscussion&gt;Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...
    Rule Medium Severity
  • SRG-OS-000477-GPOS-00222

    <GroupDescription></GroupDescription>
    Group
  • SRG-OS-000074-GPOS-00042

    <GroupDescription></GroupDescription>
    Group
  • The Ubuntu operating system must generate audit records when successful/unsuccessful attempts to use the kmod command.

    &lt;VulnDiscussion&gt;Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...
    Rule Medium Severity
  • SRG-OS-000477-GPOS-00222

    <GroupDescription></GroupDescription>
    Group
  • The Ubuntu operating system must generate audit records when successful/unsuccessful attempts to use the fdisk command.

    &lt;VulnDiscussion&gt;Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...
    Rule Medium Severity
  • SRG-OS-000479-GPOS-00224

    <GroupDescription></GroupDescription>
    Group
  • The Ubuntu operating system must have a crontab script running weekly to offload audit events of standalone systems.

    &lt;VulnDiscussion&gt;Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Offloading is a commo...
    Rule Low Severity
  • SRG-OS-000027-GPOS-00008

    <GroupDescription></GroupDescription>
    Group
  • The Ubuntu operating system must limit the number of concurrent sessions to ten for all accounts and/or account types.

    &lt;VulnDiscussion&gt;The Ubuntu operating system management includes the ability to control the number of users and user sessions that utilize an ...
    Rule Low Severity
  • SRG-OS-000032-GPOS-00013

    <GroupDescription></GroupDescription>
    Group
  • The Ubuntu operating system must monitor remote access methods.

    &lt;VulnDiscussion&gt;Remote access services, such as those providing remote access to network devices and information systems, which lack automate...
    Rule Medium Severity
  • SRG-OS-000120-GPOS-00061

    <GroupDescription></GroupDescription>
    Group
  • The Ubuntu operating system must encrypt all stored passwords with a FIPS 140-2 approved cryptographic hashing algorithm.

    &lt;VulnDiscussion&gt;Passwords need to be protected at all times, and encryption is the standard method for protecting passwords. If passwords are...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules