ANSSI-BP-028

Recommandations de configuration d'un système GNU/Linux

The French cybersecurity agency's guide for hardening a GNU/Linux system, organised as numbered recommendations (R1…R80) graded from minimal to high. The reference for French public-sector and OIV/OSE systems.

Authority ANSSIVersion 2.0coverage 319 controlsOfficial documentation →Evidence & exportsID modelOSCAL ↓
10 high272 medium28 low9 OS93% reboot-proof
How to read the references

ANSSI-BP-028 references are R-numbers, R33 is recommendation 33 in the French cybersecurity agency's GNU/Linux hardening guide (R1…R80). Each is a single, self-contained recommendation.

Every recommendation carries a hardening level, which is cumulative (a higher profile includes all the lower ones):

  • minimal, the essential baseline
  • intermediary (intermédiaire)
  • enhanced (renforcé)
  • high (élevé), the strictest, for the most exposed systems

Pavois maps each control to its R-number and to the level at which ANSSI requires it.

319 / 319
RefRuleOSDomainSev.ANSSI ref
SOCLE-RUN-AUD-001Record Events that Modify the System's Discretionary Access Controls - chmod9Audit (auditd)mediumR73
SOCLE-RUN-AUD-004Record Any Attempts to Run chacl9Audit (auditd)mediumR73 · R33
SOCLE-RUN-AUD-005Ensure auditd Collects File Deletion Events by User - rename9Audit (auditd)mediumR73
SOCLE-RUN-AUD-006Make the auditd Configuration Immutable9Audit (auditd)mediumR73
SOCLE-RUN-AUD-007Ensure auditd Collects Information on Kernel Module Unloading - create_module4Audit (auditd)mediumR73
SOCLE-RUN-AUD-008Record Attempts to Alter Logon and Logout Events - faillock9Audit (auditd)mediumR73
SOCLE-RUN-AUD-009Record Events that Modify the System's Mandatory Access Controls9Audit (auditd)mediumR73
SOCLE-RUN-AUD-010Ensure auditd Collects Information on Exporting to Media (successful)9Audit (auditd)mediumR73
SOCLE-RUN-AUD-011Record Events that Modify the System's Network Environment9Audit (auditd)mediumR73
SOCLE-RUN-AUD-013Ensure auditd Collects Information on the Use of Privileged Commands - fdisk3Audit (auditd)mediumR73
SOCLE-RUN-AUD-015Record Attempts to Alter Process and Session Initiation Information9Audit (auditd)mediumR73
SOCLE-RUN-AUD-019Ensure auditd Collects System Administrator Actions8Audit (auditd)mediumR73
SOCLE-RUN-AUD-020Record attempts to alter time through adjtimex9Audit (auditd)mediumR73
SOCLE-RUN-AUD-021Record Attempts to Alter Time Through clock_settime9Audit (auditd)mediumR73
SOCLE-RUN-AUD-022Record Unsuccessful Access Attempts to Files - creat9Audit (auditd)mediumR73
SOCLE-RUN-AUD-023Record Events that Modify User/Group Information - /etc/group9Audit (auditd)mediumR73
SOCLE-CLD-KRN-004IOMMU configuration directive9Kernel command linemediumR7
SOCLE-CLD-KRN-005Configure L1 Terminal Fault mitigations9Kernel command linehighR8
SOCLE-CLD-KRN-006Force kernel panic on uncorrected MCEs9Kernel command linemediumR8
SOCLE-CLD-KRN-007Configure Microarchitectural Data Sampling mitigation9Kernel command linemediumR8
SOCLE-CLD-KRN-009Enable randomization of the page allocator9Kernel command linemediumR8
SOCLE-CLD-KRN-010Enable page allocator poisoning9Kernel command linemediumR8
SOCLE-CLD-KRN-011Enable Kernel Page-Table Isolation (KPTI)9Kernel command linelowR8
SOCLE-CLD-KRN-012Configure the confidence in TPM for entropy9Kernel command linelowR8
SOCLE-CLD-KRN-014Disable merging of slabs with similar size9Kernel command linemediumR8
SOCLE-CLD-KRN-015Enable SLUB/SLAB allocator poisoning9Kernel command linemediumR8
SOCLE-CLD-KRN-016Configure Speculative Store Bypass Mitigation9Kernel command linemediumR8
SOCLE-CLD-KRN-017Enforce Spectre v2 mitigation9Kernel command linehighR8
SOCLE-CLD-IAM-008Lock Accounts After Failed Password Attempts9Accounts (faillock)mediumR31
SOCLE-CLD-IAM-009Set Lockout Time for Failed Password Attempts9Accounts (faillock)mediumR31
SOCLE-CLD-FSP-017Verify the UEFI Boot Loader grub.cfg Group Ownership4File ownershipmediumR29
SOCLE-CLD-FSP-018Verify /boot/efi/EFI/redhat/user.cfg Group Ownership4File ownershipmediumR29
SOCLE-CLD-FSP-019Verify Group Who Owns /etc/crypttab File9File ownershipmediumR50
SOCLE-CLD-FSP-020Verify Group Who Owns group File9File ownershipmediumR50
SOCLE-CLD-FSP-021Verify Group Who Owns gshadow File9File ownershipmediumR50
SOCLE-CLD-FSP-022Verify Group Who Owns /etc/ipsec.conf File9File ownershipmediumR50
SOCLE-CLD-FSP-023Verify Group Who Owns /etc/ipsec.secrets File9File ownershipmediumR50
SOCLE-CLD-FSP-027Verify Group Who Owns passwd File9File ownershipmediumR50
SOCLE-CLD-FSP-030Verify Group Who Owns /etc/sestatus.conf File4File ownershipmediumR50
SOCLE-CLD-FSP-031Verify Group Who Owns shadow File9File ownershipmediumR50
SOCLE-CLD-FSP-032Verify Group Who Owns /etc/shells File9File ownershipmediumR50
SOCLE-CLD-FSP-033Verify Group Who Owns /etc/sudoers File9File ownershipmediumR50
SOCLE-CLD-FSP-035Verify /boot/grub2/grub.cfg Group Ownership8File ownershipmediumR29
SOCLE-CLD-FSP-037Verify Group Who Owns SSH Server config file9File ownershipmediumR50
SOCLE-CLD-FSP-039Verify Group Who Owns System.map Files9File ownershiplowR29
SOCLE-CLD-FSP-040Verify /boot/grub2/user.cfg Group Ownership8File ownershipmediumR29
SOCLE-CLD-FSP-053Verify Group Ownership on SSH Server Private *_key Key Files7File ownershipmediumR50
SOCLE-CLD-FSP-054Verify Group Ownership on SSH Server Public *.pub Key Files9File ownershipmediumR50
SOCLE-CLD-FSP-073Verify the UEFI Boot Loader grub.cfg User Ownership4File ownershipmediumR29
SOCLE-CLD-FSP-074Verify /boot/efi/EFI/redhat/user.cfg User Ownership4File ownershipmediumR29
SOCLE-CLD-FSP-075Verify User Who Owns /etc/crypttab File9File ownershipmediumR50
SOCLE-CLD-FSP-076Verify User Who Owns group File9File ownershipmediumR50
SOCLE-CLD-FSP-077Verify User Who Owns gshadow File9File ownershipmediumR50
SOCLE-CLD-FSP-078Verify User Who Owns /etc/ipsec.conf File9File ownershipmediumR50
SOCLE-CLD-FSP-079Verify User Who Owns /etc/ipsec.secrets File9File ownershipmediumR50
SOCLE-CLD-FSP-083Verify User Who Owns passwd File9File ownershipmediumR50
SOCLE-CLD-FSP-086Verify User Who Owns /etc/sestatus.conf File4File ownershipmediumR50
SOCLE-CLD-FSP-087Verify User Who Owns shadow File9File ownershipmediumR50
SOCLE-CLD-FSP-088Verify Who Owns /etc/shells File9File ownershipmediumR50
SOCLE-CLD-FSP-089Verify User Who Owns /etc/sudoers File9File ownershipmediumR50