Ship hardened Linux images without writing a single hardening script
Pick your distro, choose the CIS Benchmark controls you need, and we build, validate, and package a bootable image with an attached compliance report — ready for your servers, VMs, or airgapped environments.
1. Pick a base image
Ubuntu, Rocky Linux, Debian, or Fedora — server or workstation profile, any supported version.
2. Select your controls
Apply full CIS Level 1 or Level 2 profiles, or hand-pick individual controls to match your compliance scope.
3. Get a verified image
We remediate with Ansible, scan the result with OpenSCAP, and hand you an ISO or cloud image plus the compliance report.
Configure your image
Select your distribution, profile and CIS benchmark level to generate a custom hardened Linux image for your organization.
CIS Controls
Pick your benchmarks individually before submitting this order. The generated image will allow you to enable/disable most of the controls after the boot on its custom terminal control panel.
| Select | ID | Title | Type |
|---|---|---|---|
| 1.1.1.1 | Ensure cramfs kernel module is not available | Automated | |
| 1.1.1.2 | Ensure freevxfs kernel module is not available | Automated | |
| 1.1.1.3 | Ensure hfs kernel module is not available | Automated | |
| 1.1.1.4 | Ensure hfsplus kernel module is not available | Automated | |
| 1.1.1.5 | Ensure jffs2 kernel module is not available | Automated | |
| 1.1.1.6 | Ensure squashfs kernel module is not available | Automated | |
| 1.1.1.7 | Ensure udf kernel module is not available | Automated | |
| 1.1.1.8 | Ensure usb-storage kernel module is not available | Automated | |
| 1.1.2.1.1 | Ensure /tmp is a separate partition | Automated | |
| 1.1.2.1.2 | Ensure nodev option set on /tmp partition | Automated | |
| 1.1.2.1.3 | Ensure nosuid option set on /tmp partition | Automated | |
| 1.1.2.1.4 | Ensure noexec option set on /tmp partition | Automated | |
| 1.1.2.2.1 | Ensure /dev/shm is a separate partition | Automated | |
| 1.1.2.2.2 | Ensure nodev option set on /dev/shm partition | Automated | |
| 1.1.2.2.3 | Ensure nosuid option set on /dev/shm partition | Automated | |
| 1.1.2.2.4 | Ensure noexec option set on /dev/shm partition | Automated | |
| 1.1.2.3.1 | Ensure separate partition exists for /var | Automated | |
| 1.1.2.4.1 | Ensure separate partition exists for /var/tmp | Automated | |
| 1.1.2.4.2 | Ensure nodev option set on /var/tmp partition | Automated | |
| 1.1.2.4.3 | Ensure nosuid option set on /var/tmp partition | Automated | |
| 1.1.2.4.4 | Ensure noexec option set on /var/tmp partition | Automated | |
| 1.1.2.5.1 | Ensure separate partition exists for /var/log | Automated | |
| 1.1.2.6.1 | Ensure separate partition exists for /var/log/audit | Automated | |
| 1.1.2.7.1 | Ensure separate partition exists for /home | Automated | |
| 1.1.2.7.2 | Ensure nodev option set on /home partition | Automated | |
| 1.2.1.1 | Ensure GPG keys are configured | Automated | |
| 1.2.1.2 | Ensure package manager repositories are configured | Automated | |
| 1.2.2.1 | Ensure updates, patches, and additional security software are installed | Automated | |
| 1.3.1.1 | Ensure AppArmor is installed | Automated | |
| 1.3.1.2 | Ensure AppArmor is enabled in the bootloader configuration | Automated | |
| 1.3.1.3 | Ensure all AppArmor Profiles are in enforce or complain mode | Automated | |
| 1.3.1.4 | Ensure all AppArmor Profiles are enforcing | Automated | |
| 1.4.1 | Ensure address space layout randomization (ASLR) is enabled | Automated | |
| 1.4.2 | Ensure ptrace_scope is restricted | Automated | |
| 1.4.3 | Ensure core dump backtraces are disabled | Automated | |
| 1.4.4 | Ensure core dump storage is disabled | Automated | |
| 1.5.1 | Ensure XD/NX support is enabled | Manual | |
| 1.5.2 | Ensure prelink is not installed | Automated | |
| 1.5.3 | Ensure Automatic Error Reporting is not enabled | Automated | |
| 1.6.1 | Ensure message of the day is configured properly | Automated | |
| 1.6.2 | Ensure local login warning banner is configured properly | Automated | |
| 1.6.3 | Ensure remote login warning banner is configured properly | Automated | |
| 1.6.4 | Ensure access to /etc/motd is configured | Automated | |
| 1.6.5 | Ensure access to /etc/issue is configured | Automated | |
| 1.6.6 | Ensure access to /etc/issue.net is configured | Automated | |
| 1.7.1 | Ensure GNOME Display Manager is removed | Automated | |
| 1.7.2 | Ensure GDM login banner is configured | Automated | |
| 1.7.10 | Ensure XDMCP is not enabled | Automated | |
| 2.1.1.1 | Ensure a single time synchronization daemon is in use | Automated | |
| 2.1.2.1 | Ensure systemd-timesyncd is configured with authorized timeserver | Automated | |
| 2.1.3.1 | Ensure chrony is configured with authorized timeserver | Automated | |
| 2.1.4.1 | Ensure ntp is configured with authorized timeserver | Automated | |
| 2.2.1 | Ensure autofs services are not in use | Automated | |
| 2.2.2 | Ensure avahi daemon services are not in use | Automated | |
| 2.2.3 | Ensure dhcp server services are not in use | Automated | |
| 2.2.4 | Ensure dns server services are not in use | Automated | |
| 2.2.5 | Ensure dnsmasq services are not in use | Automated | |
| 2.2.6 | Ensure samba file server services are not in use | Automated | |
| 2.2.7 | Ensure ftp server services are not in use | Automated | |
| 2.2.8 | Ensure message access server services are not in use | Automated | |
| 2.2.9 | Ensure network file system services are not in use | Automated | |
| 2.2.10 | Ensure nis server services are not in use | Automated | |
| 2.2.11 | Ensure print server services are not in use | Automated | |
| 2.2.12 | Ensure rpcbind services are not in use | Automated | |
| 2.2.13 | Ensure rsync services are not in use | Automated | |
| 2.2.14 | Ensure snmp services are not in use | Automated | |
| 2.2.15 | Ensure tftp server services are not in use | Automated | |
| 2.2.16 | Ensure web proxy server services are not in use | Automated | |
| 2.2.17 | Ensure web server services are not in use | Automated | |
| 2.2.18 | Ensure xinetd services are not in use | Automated | |
| 2.2.19 | Ensure X window server services are not in use | Automated | |
| 2.2.20 | Ensure mail transfer agent is configured for local-only mode | Automated | |
| 2.3.1 | Ensure NIS client is not installed | Automated | |
| 2.3.2 | Ensure rsh client is not installed | Automated | |
| 2.3.3 | Ensure talk client is not installed | Automated | |
| 2.3.4 | Ensure telnet client is not installed | Automated | |
| 2.3.5 | Ensure ldap client is not installed | Automated | |
| 2.3.6 | Ensure ftp client is not installed | Automated | |
| 3.1.1 | Ensure IPv6 status is identified | Manual | |
| 3.1.2 | Ensure wireless interfaces are disabled | Automated | |
| 3.1.3 | Ensure bluetooth services are not in use | Automated | |
| 3.2.1 | Ensure dccp kernel module is not available | Automated | |
| 3.2.2 | Ensure tipc kernel module is not available | Automated | |
| 3.2.3 | Ensure rds kernel module is not available | Automated | |
| 3.2.4 | Ensure sctp kernel module is not available | Automated | |
| 3.3.1 | Ensure ip forwarding is disabled | Automated | |
| 3.3.2 | Ensure packet redirect sending is disabled | Automated | |
| 3.3.3 | Ensure bogus icmp responses are ignored | Automated | |
| 3.3.4 | Ensure broadcast icmp requests are ignored | Automated | |
| 3.3.5 | Ensure icmp redirects are not accepted | Automated | |
| 3.3.6 | Ensure secure icmp redirects are not accepted | Automated | |
| 3.3.7 | Ensure reverse path filtering is enabled | Automated | |
| 3.3.8 | Ensure source routed packets are not accepted | Automated | |
| 3.3.9 | Ensure suspicious packets are logged | Automated | |
| 3.3.10 | Ensure tcp syn cookies is enabled | Automated | |
| 3.3.11 | Ensure ipv6 router advertisements are not accepted | Automated | |
| 3.4.1.1 | Ensure ufw is installed | Automated | |
| 3.4.1.2 | Ensure iptables-persistent is not installed with ufw | Automated | |
| 3.4.1.3 | Ensure ufw service is enabled | Automated | |
| 3.4.1.4 | Ensure ufw loopback traffic is configured | Automated | |
| 3.4.1.5 | Ensure ufw outbound connections are configured | Manual | |
| 3.4.1.6 | Ensure ufw firewall rules exist for all open ports | Manual | |
| 3.4.1.7 | Ensure ufw default deny firewall policy | Automated | |
| 4.1.1.1 | Ensure systemd-journal-remote is installed | Automated | |
| 4.1.1.2 | Ensure systemd-journal-remote is configured | Automated | |
| 4.1.1.3 | Ensure systemd-journal-upload authentication is configured | Automated | |
| 4.1.1.4 | Ensure systemd-journal-remote service is enabled | Automated | |
| 4.1.1.5 | Ensure journald is not configured to receive logs from a remote client | Automated | |
| 4.1.2.1 | Ensure journald service is enabled and active | Automated | |
| 4.1.2.2 | Ensure journald log file access is configured | Automated | |
| 4.1.2.3 | Ensure journald log file rotation is configured | Automated | |
| 4.1.2.4 | Ensure only one logging system is in use | Automated | |
| 4.1.3.1 | Ensure rsyslog is installed | Automated | |
| 4.1.3.2 | Ensure rsyslog service is enabled | Automated | |
| 4.1.3.3 | Ensure journald is configured to send logs to rsyslog | Automated | |
| 4.1.3.4 | Ensure rsyslog log file creation mode is configured | Automated | |
| 4.1.3.5 | Ensure rsyslog logging is configured | Automated | |
| 4.1.3.6 | Ensure rsyslog is configured to send logs to a remote log host | Automated | |
| 4.1.3.7 | Ensure logrotate is configured | Automated | |
| 4.1.3.8 | Ensure all logfiles have appropriate access configured | Automated | |
| 4.2.1.1 | Ensure auditd is installed | Automated | |
| 4.2.1.2 | Ensure auditd service is enabled | Automated | |
| 4.2.1.3 | Ensure auditing for processes that start prior to auditd is enabled | Automated | |
| 4.2.1.4 | Ensure audit_backlog_limit is sufficient | Automated | |
| 4.2.2.1 | Ensure audit log storage size is configured | Automated | |
| 4.2.2.2 | Ensure audit logs are not automatically deleted | Automated | |
| 4.2.2.3 | Ensure system is disabled when audit logs are full | Automated | |
| 4.2.2.4 | Ensure system warns when audit logs are low on space | Automated | |
| 4.2.3.1 | Ensure changes to system administration scope is collected | Automated | |
| 4.2.3.2 | Ensure actions as another user are always logged | Automated | |
| 4.2.3.3 | Ensure events that modify date and time information are collected | Automated | |
| 4.2.3.4 | Ensure events that modify user/group information are collected | Automated | |
| 4.2.3.5 | Ensure discretionary access control permission modification events are collected | Automated | |
| 4.2.3.6 | Ensure unsuccessful unauthorized file access attempts are collected | Automated | |
| 4.2.3.7 | Ensure events that modify the system's Mandatory Access Controls are collected | Automated | |
| 4.2.3.8 | Ensure successful file system mounts are collected | Automated | |
| 4.2.3.9 | Ensure session initiation information is collected | Automated | |
| 4.2.3.10 | Ensure login and logout events are collected | Automated | |
| 4.2.3.11 | Ensure file deletion events by users are collected | Automated | |
| 4.2.3.12 | Ensure events that modify the sudo log file are collected | Automated | |
| 4.2.3.13 | Ensure sudoers file changes are collected | Automated | |
| 4.2.3.14 | Ensure system administrator command executions (sudo) are collected | Automated | |
| 4.2.3.15 | Ensure kernel module loading unloading and modification is collected | Automated | |
| 4.2.3.16 | Ensure the audit configuration is immutable | Automated | |
| 4.2.3.17 | Ensure the running and on disk configuration is the same | Manual | |
| 4.2.4.1 | Ensure audit log files are mode 0640 or less permissive | Automated | |
| 4.2.4.2 | Ensure only authorized users own audit log files | Automated | |
| 4.2.4.3 | Ensure only authorized groups are assigned ownership of audit log files | Automated | |
| 4.2.4.4 | Ensure the audit log directory is 0750 or more restrictive | Automated | |
| 4.2.4.5 | Ensure audit configuration files are 640 or more restrictive | Automated | |
| 4.2.4.6 | Ensure audit configuration files are owned by root | Automated | |
| 4.2.4.7 | Ensure audit tools are 755 or more restrictive | Automated | |
| 4.2.4.8 | Ensure audit tools are owned by root | Automated | |
| 4.2.4.9 | Ensure cryptographic mechanisms are used to protect audit tools | Automated | |
| 5.1.1 | Ensure cron daemon is enabled and active | Automated | |
| 5.1.2 | Ensure permissions on /etc/crontab are configured | Automated | |
| 5.1.3 | Ensure permissions on /etc/cron.hourly are configured | Automated | |
| 5.1.4 | Ensure permissions on /etc/cron.daily are configured | Automated | |
| 5.1.5 | Ensure permissions on /etc/cron.weekly are configured | Automated | |
| 5.1.6 | Ensure permissions on /etc/cron.monthly are configured | Automated | |
| 5.1.7 | Ensure permissions on /etc/cron.d are configured | Automated | |
| 5.1.8 | Ensure cron is restricted to authorized users | Automated | |
| 5.1.9 | Ensure at is restricted to authorized users | Automated | |
| 5.2.1 | Ensure permissions on /etc/ssh/sshd_config are configured | Automated | |
| 5.2.2 | Ensure permissions on SSH private host key files are configured | Automated | |
| 5.2.3 | Ensure permissions on SSH public host key files are configured | Automated | |
| 5.2.4 | Ensure sshd access is configured | Automated | |
| 5.2.5 | Ensure sshd Banner is configured | Automated | |
| 5.2.6 | Ensure sshd Ciphers are configured | Automated | |
| 5.2.7 | Ensure sshd ClientAliveInterval and ClientAliveCountMax are configured | Automated | |
| 5.2.8 | Ensure sshd DisableForwarding is enabled | Automated | |
| 5.2.9 | Ensure sshd GSSAPIAuthentication is disabled | Automated | |
| 5.2.10 | Ensure sshd HostbasedAuthentication is disabled | Automated | |
| 5.2.11 | Ensure sshd IgnoreRhosts is enabled | Automated | |
| 5.2.12 | Ensure sshd KexAlgorithms is configured | Automated | |
| 5.2.13 | Ensure sshd LoginGraceTime is configured | Automated | |
| 5.2.14 | Ensure sshd LogLevel is configured | Automated | |
| 5.2.15 | Ensure sshd MACs are configured | Automated | |
| 5.2.16 | Ensure sshd MaxAuthTries is configured | Automated | |
| 5.2.17 | Ensure sshd MaxSessions is configured | Automated | |
| 5.2.18 | Ensure sshd MaxStartups is configured | Automated | |
| 5.2.19 | Ensure sshd PermitEmptyPasswords is disabled | Automated | |
| 5.2.20 | Ensure sshd PermitRootLogin is disabled | Automated | |
| 5.2.21 | Ensure sshd PermitUserEnvironment is disabled | Automated | |
| 5.2.22 | Ensure sshd UsePAM is enabled | Automated | |
| 5.3.1 | Ensure PAM software packages are up to date | Automated | |
| 5.3.2 | Ensure pam_faillock module is enabled | Automated | |
| 5.3.3 | Ensure pam_pwquality module is enabled | Automated | |
| 5.3.4 | Ensure pam_pwhistory module is enabled | Automated | |
| 5.3.5 | Ensure password failed attempts lockout is configured | Automated | |
| 5.3.6 | Ensure password unlock time is configured | Automated | |
| 5.3.7 | Ensure password number of changed characters is configured | Automated | |
| 5.3.8 | Ensure minimum password length is configured | Automated | |
| 5.3.9 | Ensure password complexity is configured | Automated | |
| 5.3.10 | Ensure password same consecutive characters is limited | Automated | |
| 5.3.11 | Ensure password maximum sequential characters is configured | Automated | |
| 5.3.12 | Ensure password dictionary check is enabled | Automated | |
| 5.3.13 | Ensure password quality checking is enforced for the root user | Automated | |
| 5.3.14 | Ensure password history remember is configured | Automated | |
| 5.3.15 | Ensure password history is enforced for the root user | Automated | |
| 5.3.16 | Ensure pam_pwhistory includes use_authtok | Automated | |
| 5.3.17 | Ensure strong password hashing algorithm is configured | Automated | |
| 5.4.1.1 | Ensure password expiration is configured | Automated | |
| 5.4.1.2 | Ensure minimum password days is configured | Automated | |
| 5.4.1.3 | Ensure password expiration warning days is configured | Automated | |
| 5.4.1.4 | Ensure strong password hashing algorithm is configured | Automated | |
| 5.4.1.5 | Ensure inactive password lock is configured | Automated | |
| 5.4.1.6 | Ensure all users last password change date is in the past | Manual | |
| 5.4.2.1 | Ensure root is the only UID 0 account | Automated | |
| 5.4.2.2 | Ensure root is the only GID 0 account | Automated | |
| 5.4.2.3 | Ensure group root is the only GID 0 group | Automated | |
| 5.4.2.4 | Ensure root account access is controlled | Manual | |
| 5.4.2.5 | Ensure root path integrity | Automated | |
| 5.4.2.6 | Ensure root user umask is configured | Automated | |
| 5.4.2.7 | Ensure system accounts do not have a valid login shell | Automated | |
| 5.4.2.8 | Ensure accounts without a valid login shell are locked | Automated | |
| 5.4.3.1 | Ensure default group for the root account is GID 0 | Automated | |
| 5.4.3.2 | Ensure default user umask is configured | Automated | |
| 5.4.3.3 | Ensure default user shell timeout is configured | Automated | |
| 5.4.3.4 | Ensure nologin is not listed in /etc/shells | Automated | |
| 6.1.1 | Ensure permissions on /etc/passwd are configured | Automated | |
| 6.1.2 | Ensure permissions on /etc/passwd- are configured | Automated | |
| 6.1.3 | Ensure permissions on /etc/group are configured | Automated | |
| 6.1.4 | Ensure permissions on /etc/group- are configured | Automated | |
| 6.1.5 | Ensure permissions on /etc/shadow are configured | Automated | |
| 6.1.6 | Ensure permissions on /etc/shadow- are configured | Automated | |
| 6.1.7 | Ensure permissions on /etc/gshadow are configured | Automated | |
| 6.1.8 | Ensure permissions on /etc/gshadow- are configured | Automated | |
| 6.1.9 | Ensure no world writable files exist | Automated | |
| 6.1.10 | Ensure no unowned files or directories exist | Automated | |
| 6.1.11 | Ensure no ungrouped files or directories exist | Automated | |
| 6.1.12 | Ensure sticky bit is set on all world-writable directories | Automated | |
| 6.1.13 | Ensure suid and sgid files are reviewed | Manual | |
| 6.2.1 | Ensure accounts in /etc/passwd use shadowed passwords | Automated | |
| 6.2.2 | Ensure /etc/shadow password fields are not empty | Automated | |
| 6.2.3 | Ensure all groups in /etc/passwd exist in /etc/group | Automated | |
| 6.2.4 | Ensure no duplicate UIDs exist | Automated | |
| 6.2.5 | Ensure no duplicate GIDs exist | Automated | |
| 6.2.6 | Ensure no duplicate user names exist | Automated | |
| 6.2.7 | Ensure no duplicate group names exist | Automated | |
| 6.2.8 | Ensure local interactive user home directories are configured | Automated | |
| 6.2.9 | Ensure local interactive users own their home directories | Automated | |
| 6.2.10 | Ensure local interactive user home directories are mode 750 or more restrictive | Automated | |
| 6.2.11 | Ensure no local interactive user has a .netrc, .forward or .rhosts file | Automated | |
| 6.2.12 | Ensure local interactive user dot files access is configured | Automated |
Complete Order
Our sales team will contact you after your order is placed.