Consider using CIS hardened images #1246
Replies: 4 comments
-
CIS hardened images for Safe Haven VMs available on AzureSource: https://www.cisecurity.org/cis-hardened-image-list/ CIS BenchmarksSource: https://www.cisecurity.org/cis-benchmarks/ These are hardening recommendations, not pre-built images. |
Beta Was this translation helpful? Give feedback.
-
DoD STIGsUS Department of Defence Security Technical Implementation Guides: https://www.stigviewer.com/stigs These are hardening recommendations, not pre-built images, and include generic STIGs for e.g. Network Security and Remote Access in addition to STIGs for specific operating systems and software. |
Beta Was this translation helpful? Give feedback.
-
I've had a look at their Ubuntu 18.04 benchmark. Do we know what changes they have implemented in their image? I understand they might not want to protect their work, but it's harder to have confidence when we can't see what they have done. Some of the recommendations, like having certain 'system' directories on separate partitions, would be hard to replicate ourselves as the default Ubuntu images comes with a standard one-partition layout. |
Beta Was this translation helpful? Give feedback.
-
We should check whether the CIS hardened VM images work with our deployments and if they do, consider the costs/benefits.
Beta Was this translation helpful? Give feedback.
All reactions