CIS Level 2 Guidelines

Support Ubuntu Pro 22.04

For more details about Center for Internet Security (CIS) please refer to this document.

Instruction steps

Install the UA client

sudo apt update sudo apt install ubuntu-advantage-tools

Set up the Ubuntu Security Guide

sudo ua enable usg sudo apt install usg

Check SCAP Content Overview (Security Content Automation Protocol)

sudo oscap info /usr/share/ubuntu-scap-security-guides/1/benchmarks/ssg-ubuntu2204-ds.xml

Auditing an Ubuntu System for DISA-STIG compliance

sudo usg audit cis_level2_server

The report is generated in /var/lib/usg/

Applying the CIS rules to a set of systems

There are 2 ways that apply CIS rules

Method 1: directly using usg command - recommend

sudo usg fix cis_level2_server

Method 2: using usg to generate script and then run the script

sudo usg generate-fix cis_level2_server --output fix.sh #And the run ./fix.sh

Notes

  • CIS Level 2 requires /tmp folder to be mounted in a separate partition. Please ensure that that new partition have enough disk space for MetaDefender Core to run.