CIS Hardened Image Level 1
Jump to navigation
Jump to search
Gemini:
- Hardened SSH: Key-only authentication, restricted session counts, mandatory idle timeouts, disablement of root password logins, and restrictive ciphers/MACs.
- Restrictive Firewall: Stateful firewall enabled by default with a default-deny inbound policy (usually allowing only port 22/SSH).
- Package Pruning: Unneeded or insecure packages (e.g., telnet, ftp, apport crash reporting) are removed or disabled.
- Account & File Policies: Restrictive permissions on configuration files (/etc/shadow,
/etc/crontab), account lockout rules, and system login banners.
Related
See also
Advertising: