Skip to content

Commit

Permalink
products/alinux2 && controls: Add CIS Alibaba Cloud Linux (Aliyun Lin…
Browse files Browse the repository at this point in the history
…ux) 2 profiles

CIS Aliyun Linux 2 Benchmark v1.0.0
(https://workbench.cisecurity.org/benchmarks/2228) was published
on Aug 16th 2019. Aliyun Linux 2 is compatible with CentOS 7 and it's
further renamed as Alibaba Cloud Linux 2.

I add the CIS Alibaba Cloud Linux (Aliyun Linux) 2 controls in the OpenSCAP
according to CIS Aliyun Linux 2 Benchmark v1.0.0
(https://workbench.cisecurity.org/benchmarks/2228)

Signed-off-by: YiLin.Li <[email protected]>
Signed-off-by: YuQing.Yang <[email protected]>
  • Loading branch information
hustliyilin committed Jun 8, 2022
1 parent 5a7b95a commit 7a25ff4
Show file tree
Hide file tree
Showing 286 changed files with 2,258 additions and 166 deletions.
1,763 changes: 1,763 additions & 0 deletions controls/cis_alinux2.yml

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: ol7,ol8,rhel7,rhel8,rhel9,sle12,sle15,ubuntu2004
prodtype: alinux2,ol7,ol8,rhel7,rhel8,rhel9,sle12,sle15,ubuntu2004

title: 'Disable Avahi Server Software'

Expand All @@ -22,6 +22,7 @@ identifiers:

references:
cis-csc: 11,14,3,9
cis@alinux2: 2.1.3
cis@rhel7: 2.2.3
cis@rhel8: 2.2.4
cis@sle12: 2.2.3
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004
prodtype: alinux2,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004

title: 'Verify Group Who Owns cron.d'

Expand All @@ -21,6 +21,7 @@ identifiers:

references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.7
cis@rhel7: 5.1.7
cis@rhel8: 5.1.7
cis@sle12: 5.2.7
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004
prodtype: alinux2,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004

title: 'Verify Group Who Owns cron.daily'

Expand All @@ -21,6 +21,7 @@ identifiers:

references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.4
cis@rhel7: 5.1.4
cis@rhel8: 5.1.4
cis@sle12: 5.2.4
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004
prodtype: alinux2,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004

title: 'Verify Group Who Owns cron.hourly'

Expand All @@ -21,6 +21,7 @@ identifiers:

references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.3
cis@rhel7: 5.1.3
cis@rhel8: 5.1.3
cis@sle12: 5.2.3
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004
prodtype: alinux2,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004

title: 'Verify Group Who Owns cron.monthly'

Expand All @@ -21,6 +21,7 @@ identifiers:

references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.6
cis@rhel7: 5.1.6
cis@rhel8: 5.1.6
cis@sle12: 5.2.6
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004
prodtype: alinux2,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004

title: 'Verify Group Who Owns cron.weekly'

Expand All @@ -21,6 +21,7 @@ identifiers:

references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.5
cis@rhel7: 5.1.5
cis@rhel8: 5.1.5
cis@sle12: 5.2.5
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004
prodtype: alinux2,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004

title: 'Verify Group Who Owns Crontab'

Expand All @@ -21,6 +21,7 @@ identifiers:

references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.2
cis@rhel7: 5.1.2
cis@rhel8: 5.1.2
cis@sle12: 5.2.2
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004
prodtype: alinux2,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004

title: 'Verify Owner on cron.d'

Expand All @@ -21,6 +21,7 @@ identifiers:

references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.7
cis@rhel7: 5.1.7
cis@rhel8: 5.1.7
cis@sle12: 5.2.7
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004
prodtype: alinux2,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004

title: 'Verify Owner on cron.daily'

Expand All @@ -21,6 +21,7 @@ identifiers:

references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.4
cis@rhel7: 5.1.4
cis@rhel8: 5.1.4
cis@sle12: 5.2.4
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004
prodtype: alinux2,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004

title: 'Verify Owner on cron.hourly'

Expand All @@ -21,6 +21,7 @@ identifiers:

references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.3
cis@rhel7: 5.1.3
cis@rhel8: 5.1.3
cis@sle12: 5.2.3
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004
prodtype: alinux2,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004

title: 'Verify Owner on cron.monthly'

Expand All @@ -21,6 +21,7 @@ identifiers:

references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.6
cis@rhel7: 5.1.6
cis@rhel8: 5.1.6
cis@sle12: 5.2.6
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004
prodtype: alinux2,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004

title: 'Verify Owner on cron.weekly'

Expand All @@ -21,6 +21,7 @@ identifiers:

references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.5
cis@rhel7: 5.1.5
cis@rhel8: 5.1.5
cis@sle12: 5.2.5
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004
prodtype: alinux2,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004

title: 'Verify Owner on crontab'

Expand All @@ -21,6 +21,7 @@ identifiers:

references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.2
cis@rhel7: 5.1.2
cis@rhel8: 5.1.2
cis@sle12: 5.2.2
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004
prodtype: alinux2,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004

title: 'Verify Permissions on cron.d'

Expand All @@ -21,6 +21,7 @@ identifiers:

references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.7
cis@rhel7: 5.1.7
cis@rhel8: 5.1.7
cis@sle12: 5.2.7
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004
prodtype: alinux2,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004

title: 'Verify Permissions on cron.daily'

Expand All @@ -21,6 +21,7 @@ identifiers:

references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.4
cis@rhel7: 5.1.4
cis@rhel8: 5.1.4
cis@sle12: 5.2.4
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004
prodtype: alinux2,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004

title: 'Verify Permissions on cron.hourly'

Expand All @@ -21,6 +21,7 @@ identifiers:

references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.3
cis@rhel7: 5.1.3
cis@rhel8: 5.1.3
cis@sle12: 5.2.3
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004
prodtype: alinux2,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004

title: 'Verify Permissions on cron.monthly'

Expand All @@ -21,6 +21,7 @@ identifiers:

references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.6
cis@rhel7: 5.1.6
cis@rhel8: 5.1.6
cis@sle12: 5.2.6
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004
prodtype: alinux2,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004

title: 'Verify Permissions on cron.weekly'

Expand All @@ -21,6 +21,7 @@ identifiers:

references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.5
cis@rhel7: 5.1.5
cis@rhel8: 5.1.5
cis@sle12: 5.2.5
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004
prodtype: alinux2,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004

title: 'Verify Permissions on crontab'

Expand All @@ -21,6 +21,7 @@ identifiers:

references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.2
cis@rhel7: 5.1.2
cis@rhel8: 5.1.2
cis@sle12: 5.2.2
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,rhel7,rhel8,rhel9
prodtype: alinux2,fedora,rhel7,rhel8,rhel9

title: 'Ensure that /etc/at.deny does not exist'

Expand All @@ -21,6 +21,7 @@ identifiers:
cce@rhel9: CCE-86946-1

references:
cis@alinux2: 5.1.8
cis@rhel7: 5.1.9
cis@rhel8: 5.1.8

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,rhel7,rhel8,rhel9,sle15
prodtype: alinux2,fedora,rhel7,rhel8,rhel9,sle15

title: 'Ensure that /etc/cron.deny does not exist'

Expand All @@ -21,6 +21,7 @@ identifiers:
cce@rhel9: CCE-86850-5

references:
cis@alinxu2: 5.1.8
cis@rhel7: 5.1.8
cis@rhel8: 5.1.8
cis@sle15: 5.1.8
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel8,rhel9,sle12,sle15,ubuntu2004
prodtype: alinux2,rhel8,rhel9,sle12,sle15,ubuntu2004

title: 'Verify Group Who Owns /etc/at.allow file'

Expand All @@ -20,6 +20,7 @@ identifiers:
cce@rhel9: CCE-87103-8

references:
cis@alinux2: 5.1.8
cis@rhel7: 5.1.9
cis@rhel8: 5.1.8
cis@sle12: 5.2.9
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: ol7,ol8,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004,wrlinux1019
prodtype: alinux2,ol7,ol8,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004,wrlinux1019

title: 'Verify Group Who Owns /etc/cron.allow file'

Expand All @@ -21,6 +21,7 @@ identifiers:

references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.8
cis@rhel7: 5.1.8
cis@rhel8: 5.1.8
cis@sle12: 5.2.8
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: sle12,sle15,ubuntu2004
prodtype: alinux2,sle12,sle15,ubuntu2004

title: 'Verify User Who Owns /etc/at.allow file'

Expand All @@ -20,6 +20,7 @@ identifiers:
cce@rhel9: CCE-86346-4

references:
cis@alinux2: 5.1.8
cis@rhel7: 5.1.9
cis@rhel8: 5.1.8
cis@sle12: 5.2.9
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: ol7,ol8,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004,wrlinux1019
prodtype: alinux2,ol7,ol8,rhel7,rhel8,rhel9,rhv4,sle12,sle15,ubuntu2004,wrlinux1019

title: 'Verify User Who Owns /etc/cron.allow file'

Expand All @@ -21,6 +21,7 @@ identifiers:

references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.8
cis@rhel7: 5.1.8
cis@rhel8: 5.1.8
cis@sle12: 5.2.8
Expand Down
Loading

0 comments on commit 7a25ff4

Please sign in to comment.