Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Release 4 (Target Date November 30, 2020) Incubation Requirements:

Month6/20207/20208/20209/202010/202011/202012/20201/2021
Release




Rel. 4

Security Requirement

Update

v. 1.0






Minimum Security

Requirement






v. 1.0

Maximum Security

Requirement






v. 1.0




Release 4 Minimum Security Requirement

Lock Out Window





Maturity Review:  Security Requirements Criteria

...

Current Maturity Requirements:

Month6/20207/20208/20209/202010/202011/202012/20201/2021
Maturity Request







Security Requirement

Update

v. 1.0






Minimum Security

Requirement


v. 1.0v. 1.0v. 1.0v. 1.0v. 1.0v. 1.0

Maximum Security

Requirement


v. 1.0v. 1.0v. 1.0v. 1.0v. 1.0v. 1.0



Release 4 Minimum Security Requirement

Lock Out Window




Vuls

Vuls will be integrated with Blueprint Validation Framework (Bluval User Guide)

...


Anchor
Vuls Incubation and Maturity PASS FAIL
Vuls Incubation and Maturity PASS FAIL
Vuls Incubation and Maturity:

...

PASS/FAIL Criteria, v1.0

All Critical vulnerabilities detected by Vuls must be patched/fixed.  Critical vulnerabilities are defined as a CVSS score of 9.0-10.0.  After patches/fixes are applied, Vuls must be run again to verify that the vulnerability is no longer detected.

...

  • Remarks = #<remark>
  • Section = [<section name>]
  • Option/value = <option name>=<value of option>

Lynis Incubation

...

:  PASS/FAIL Criteria, v1.0

  1. The Lynis Program Update test MUST pass with no errors.
  2. The following list of tests MUST complete as passing as described below.

    In the lynis.log outputfile each test suite has one or more individual tests.  The beginning and ending of a test suite is marked with "====".  For example, the 'ID BOOT-5122' test suite should display:

    020-04-08 15:36:28 ====
    2020-04-08 15:36:28 Performing test ID BOOT-5122 (Check for GRUB boot password)
    ...
    2020-04-08 15:36:29 Hardening: assigned maximum number of hardening points for this item (3). 
    2020-04-08 15:36:29 ===

    If any tests in the test suit failed, there would be the following:

    2020-04-08 15:36:29 Suggestion: <Description of failed test>

    Also, the 'Hardening' line show above would not say 'assigned maximum number of hardening points', instead it would say 'assigned partial number of hardening points'.

1Test: Checking PASS_MAX_DAYS option in /etc/login.defs
2Performing test ID BOOTAUTH-5122 (Check for GRUB boot password9328 (Default umask values)
23Performing test ID BOOTSSH-7440 (Check OpenSSH option: AllowUsers and AllowGroups)
4Test: checking for file /etc/network/if-up.d/ntpdate
5Performing test ID KRNL-6000 (Check sysctl key pairs in scan profile) :  Following sub-tests required
5asysctl key fs.suid_dumpable contains equal expected and current value (0)
5bsysctl key kernel.dmesg_restrict contains equal expected and current value (1)
5csysctl key net.ipv4.conf.default.accept_source_route contains equal expected and current value (0)
6Test: Check if one or more compilers can be found on the system


The lynis.log output file and exception requests for any of the items listed above that cannot be fixed must be sent to the security sub-committee.

Anchor
Lynis Incubation and Maturity PASS FAIL
Lynis Incubation and Maturity PASS FAIL
Lynis Maturity:  PASS/FAIL Criteria, v1.0

  1. The Lynis Program Update test MUST pass with no errors.
  2. The following list of tests MUST complete as passing as described below.

    In the lynis.log outputfile each test suite has one or more individual tests.  The beginning and ending of a test suite is marked with "====".  For example, the 'ID BOOT-5122' test suite should display:

    020-04-08 15:36:28 ====
    2020-04-08 15:36:28 Performing test ID BOOT-5122 (Check for GRUB boot password)
    ...
    2020-04-08 15:36:29 Hardening: assigned maximum number of hardening points for this item (3). 
    2020-04-08 15:36:29 ===

    If any tests in the test suit failed, there would be the following:

    2020-04-08 15:36:29 Suggestion: <Description of failed test>

    Also, the 'Hardening' line show above would not say 'assigned maximum number of hardening points', instead it would say 'assigned partial number of hardening points'.

1Performing test ID BOOT-5122 (Check for GRUB boot password)
2Performing test ID BOOT-5184 (Check permissions for boot files/5184 (Check permissions for boot files/scripts)
3Test: Checking presence /var/run/reboot-required.pkgs
4Performing test ID AUTH-9228 (Check password file consistency with pwck)
5Performing test ID AUTH-9229 (Check password hashing methods)
6Test: Checking SHA_CRYPT_MIN_ROUNDS option in /etc/login.defs
7Test: Checking PASS_MAX_DAYS option in /etc/login.defs
8Test: collecting accounts which have an expired password (last day changed + maximum change time)
9Performing test ID AUTH-9328 (Default umask values)
10Performing test ID FILE-6368 (Checking ACL support on root file system)
11Performing test ID USB-2000 (Check USB authorizations)
12Performing test ID USB-3000 (Check for presence of USBGuard)
13Performing test ID PKGS-7370 (Checking for debsums utility)
14Performing test ID PKGS-7388 (Check security repository in apt sources.list file)
15Performing test ID SSH-7408 (Check SSH specific defined options)
16Test: Checking AllowTcpForwarding in /tmp/lynis.ZotHQ7RQAj
17Test: Checking ClientAliveCountMax in /tmp/lynis.ZotHQ7RQAj
18Test: Checking ClientAliveInterval in /tmp/lynis.ZotHQ7RQAj
19Test: Checking FingerprintHash in /tmp/lynis.ZotHQ7RQAj
20Test: Checking IgnoreRhosts in /tmp/lynis.ZotHQ7RQAj
21Test: Checking MaxAuthTries in /tmp/lynis.ZotHQ7RQAj
22Test: Checking MaxSessions in /tmp/lynis.ZotHQ7RQAj
23Test: Checking Port in /tmp/lynis.ZotHQ7RQAj
24Test: Checking StrictModes in /tmp/lynis.ZotHQ7RQAj
25Test: Checking TCPKeepAlive in /tmp/lynis.ZotHQ7RQAj
26Performing test ID SSH-7440 (Check OpenSSH option: AllowUsers and AllowGroups)
27Test: checking for file /etc/network/if-up.d/ntpdate
28Performing test ID KRNL-6000 (Check sysctl key pairs in scan profile)
29Test: Check if one or more compilers can be found on the system

...

The lynis.log output file and exception requests for any of the items listed above that cannot be fixed must be sent to the security sub-committee.

Kuber-Hunter

Anchor
Kube Hunter Incubation and Maturity PASS FAIL
Kube Hunter Incubation and Maturity PASS FAIL
Kube-Hunter Incubation and Maturity:  PASS/FAIL Criteria, v1.0

The kube-hunter vulnerabilities listed as 'Yes' in the 'Critical' column MUST be resolved.

...