CIS Benchmarks

Consensus-built, prescriptive configuration baselines for hardening operating systems and software. Each recommendation carries a number, a level (1 = base, 2 = defence-in-depth), an audit and a remediation. Pavois maps to the per-OS benchmark version it targets.

Authority Center for Internet SecurityVersion per OS, see the benchmark tablecoverage 473 controlsOfficial documentation →Evidence & exportsID modelOSCAL ↓
10 high409 medium43 low9 OS95% reboot-proof

The benchmark version targeted, per OS

A CIS number means nothing without its version: the benchmark renumbers between releases. Here is the version each Pavois profile targets, and its source. Three OSes have NO published CIS benchmark: their numbers are inherited from a sibling OS, and this page says so rather than hiding it.

OSCIS version targetedSource
Debian 121.1.0ansible-lockdown/DEBIAN12-CIS
Debian 131.0.0ansible-lockdown/DEBIAN13-CIS
Fedorainherited from RHEL 9no CIS benchmark exists for Fedora; the mappings are inherited from the RHEL family
RHEL 10inherited from RHEL 9no dedicated RHEL 10 CIS benchmark yet; the mappings are inherited from RHEL9-CIS
RHEL 84.0.0ansible-lockdown/RHEL8-CIS
RHEL 92.0.0ansible-lockdown/RHEL9-CIS
Ubuntu 22.043.0.0ansible-lockdown/UBUNTU22-CIS
Ubuntu 24.041.0.0ansible-lockdown/UBUNTU24-CIS
Ubuntu 26.04inherited from Ubuntu 24.04no CIS benchmark exists for Ubuntu 26.04 yet; the mappings are inherited from UBUNTU24-CIS

CIS Debian 12 v2.0.0 landed in June 2026 (large additions, removals and renumberings). The re-anchoring is in progress; the mappings published here still target 1.1.0, and will say so for as long as that is true. How a mapping is validated →

How to read the references

CIS Benchmark references are hierarchical section numbers that follow the benchmark's table of contents for that OS, 5.1.20 means section 5 › 1 › recommendation 20.

Each recommendation also carries a Level:

  • Level 1, baseline hardening, broadly safe with minimal operational impact.
  • Level 2, defence-in-depth for high-security environments; may reduce functionality or performance.

Numbering and sections differ from one OS to the next, because each operating system has its own independently-versioned benchmark, Pavois targets a specific version per OS (the per-OS table above). Three OSes (Fedora, Ubuntu 26.04, RHEL 10) have no published CIS benchmark yet; their numbers are inherited from a sibling OS, marked as such in that table.

473 / 473
RefRuleOSDomainSev.CIS ref
SOCLE-CLD-IAM-001Verify Only Root Has UID 09Accountscritical5.4.2.1 · 8.2.1
SOCLE-CLD-IAM-002Verify All Account Password Hashes are Shadowed9Accountscritical7.2.1 · 8.3.2
SOCLE-CLD-IAM-003Verify Root Has A Primary GID 09Accountshigh5.4.2.2 · 8.2.1
SOCLE-CLD-IAM-004Set Account Expiration Following Inactivity8Accounts (login.defs)medium5.4.1.5
SOCLE-CLD-IAM-005All GIDs referenced in /etc/passwd must be defined in /etc/group9Accountslow7.2.3 · 8.2.2
SOCLE-CLD-IAM-006Prevent Login to Accounts With Empty Password9Accountscritical8.3.1 · 5.3.3.4.1 · 7.2.2
SOCLE-CLD-IAM-007Ensure all users last password change date is in the past8Accountsmedium5.4.1.6
SOCLE-RUN-AUD-001Record Events that Modify the System's Discretionary Access Controls - chmod9Audit (auditd)medium10.3.4 · 6.2.3.9 · 6.3.3.18 · 6.3.3.9
SOCLE-RUN-AUD-004Record Any Attempts to Run chacl9Audit (auditd)medium6.2.3.17 · 6.3.3.17 · 6.3.3.15 · 6.3.3.16 · 6.3.3.18 · 6.3.3.26 · 6.3.3.24 · 6.3.3.25 · 6.3.3.10 · 6.3.3.28 · 6.3.3.27 · 6.3.3.6 · 6.3.3.19 · 6.6.3.18
SOCLE-RUN-AUD-005Ensure auditd Collects File Deletion Events by User - rename9Audit (auditd)medium10.2.1.7 · 6.2.3.13 · 6.3.3.22 · 6.3.3.13
SOCLE-RUN-AUD-006Make the auditd Configuration Immutable9Audit (auditd)medium10.3.2 · 6.2.3.20 · 6.3.3.33 · 6.3.3.20 · 6.3.3.21
SOCLE-RUN-AUD-007Ensure auditd Collects Information on Kernel Module Unloading - create_module4Audit (auditd)medium6.3.3.29 · 6.3.3.30 · 6.3.3.31 · 6.3.3.19
SOCLE-RUN-AUD-008Record Attempts to Alter Logon and Logout Events - faillock9Audit (auditd)medium10.2.1.3 · 6.2.3.12 · 6.3.3.21 · 6.3.3.12
SOCLE-RUN-AUD-009Record Events that Modify the System's Mandatory Access Controls9Audit (auditd)medium10.3.4 · 6.3.3.14 · 6.3.3.23 · 6.2.3.14
SOCLE-RUN-AUD-010Ensure auditd Collects Information on Exporting to Media (successful)9Audit (auditd)medium10.2.1.7 · 6.2.3.10 · 6.3.3.19 · 6.3.3.10
SOCLE-RUN-AUD-011Record Events that Modify the System's Network Environment9Audit (auditd)medium10.3.4 · 6.2.3.5 · 6.3.3.5 · 6.3.3.7 · 6.3.3.6 · 6.3.3.8 · 6.3.3.9
SOCLE-RUN-AUD-012Record Events that Modify the System's Network Environment - /etc/sysconfig/network-scripts4Audit (auditd)medium6.3.3.5
SOCLE-RUN-AUD-013Ensure auditd Collects Information on the Use of Privileged Commands - fdisk3Audit (auditd)medium6.3.3.19 · 6.2.3.19
SOCLE-RUN-AUD-015Record Attempts to Alter Process and Session Initiation Information9Audit (auditd)medium6.2.3.11 · 6.3.3.20 · 6.3.3.11
SOCLE-RUN-AUD-017Record Events When Executables Are Run As Another User9Audit (auditd)medium6.2.3.2 · 6.3.3.2
SOCLE-RUN-AUD-018Record Events When Privileged Executables Are Run7Audit (auditd)medium10.2.1.2
SOCLE-RUN-AUD-019Ensure auditd Collects System Administrator Actions8Audit (auditd)medium10.2.1.5 · 6.2.3.1 · 6.3.3.1
SOCLE-RUN-AUD-020Record attempts to alter time through adjtimex9Audit (auditd)medium10.6.3 · 6.2.3.4 · 6.3.3.4
SOCLE-RUN-AUD-021Record Attempts to Alter Time Through clock_settime9Audit (auditd)medium10.6.3 · 6.2.3.4 · 6.3.3.4
SOCLE-RUN-AUD-022Record Unsuccessful Access Attempts to Files - creat9Audit (auditd)medium6.2.3.7 · 6.3.3.11 · 6.3.3.7
SOCLE-RUN-AUD-023Record Events that Modify User/Group Information - /etc/group9Audit (auditd)medium10.2.1.5 · 6.2.3.8 · 6.3.3.8 · 6.3.3.12 · 6.3.3.14 · 6.3.3.16 · 6.3.3.15 · 6.3.3.17 · 6.3.3.13
SOCLE-RUN-AUD-025Configure auditd mail_acct Action on Low Disk Space9Audit (auditd daemon)medium6.2.2.4 · 6.3.2.4
SOCLE-RUN-AUD-026Configure auditd admin_space_left Action on Low Disk Space9Audit (auditd daemon)medium10.5.1 · 6.2.2.4 · 6.3.2.4
SOCLE-RUN-AUD-028Configure auditd Disk Error Action on Disk Error9Audit (auditd daemon)medium6.2.2.3 · 6.3.2.3
SOCLE-RUN-AUD-029Configure auditd Disk Full Action when Disk Space Is Full9Audit (auditd daemon)medium6.2.2.3 · 6.3.2.3
SOCLE-RUN-AUD-032Configure auditd Max Log File Size9Audit (auditd daemon)medium6.2.2.1 · 6.3.2.1
SOCLE-RUN-AUD-033Configure auditd max_log_file_action Upon Reaching Maximum Log Size9Audit (auditd daemon)medium6.2.2.2 · 6.3.2.2
SOCLE-RUN-AUD-036Configure auditd space_left Action on Low Disk Space9Audit (auditd daemon)medium10.5.1 · 6.2.2.4 · 6.3.2.4
SOCLE-CLD-GEN-001Ensure Local Login Warning Banner Is Configured Properly9Bannersmedium1.6.2 · 1.7.2
SOCLE-CLD-GEN-002Ensure Remote Login Warning Banner Is Configured Properly9Bannersmedium1.6.3 · 1.7.3
SOCLE-CLD-GEN-003Ensure Message Of The Day Is Configured Properly9Bannersmedium1.6.1 · 1.7.1
SOCLE-CLD-KRN-001Enable Auditing for Processes Which Start Prior to the Audit Daemon9Kernel command linelow10.7.2 · 6.2.1.3 · 6.3.1.2 · 6.3.1.3
SOCLE-CLD-KRN-002Extend Audit Backlog Limit for the Audit Daemon9Kernel command linelow10.7.2 · 6.2.1.4 · 6.3.1.3
SOCLE-CLD-KRN-013Ensure SELinux Not Disabled in /etc/default/grub4Kernel command linemedium1.3.1.2
SOCLE-CLD-GEN-004Enable GNOME3 Login Warning Banner9GNOME desktop (dconf)medium1.7.2 · 1.8.2 · 1.8.1
SOCLE-CLD-GEN-005Disable GNOME3 Automounting9GNOME desktop (dconf)medium1.7.6 · 1.7.7 · 3.4.2 · 1.8.6 · 1.8.4
SOCLE-CLD-GEN-006Disable GNOME3 Automount Opening9GNOME desktop (dconf)medium1.7.6 · 1.7.7 · 3.4.2 · 1.8.6 · 1.8.4
SOCLE-CLD-GEN-007Disable GNOME3 Automount running9GNOME desktop (dconf)low1.7.8 · 1.7.9 · 1.8.8 · 1.8.5
SOCLE-CLD-GEN-010Disable the GNOME3 Login User List9GNOME desktop (dconf)medium1.7.3 · 1.8.3 · 1.8.2
SOCLE-CLD-GEN-012Set the GNOME3 Login Warning Banner Text9GNOME desktop (dconf)medium1.7.2 · 1.8.2 · 1.8.1
SOCLE-CLD-GEN-016Set GNOME3 Screensaver Lock Delay After Activation Period3GNOME desktop (dconf)medium1.7.4 · 1.8.5 · 1.7.5 · 8.2.8
SOCLE-CLD-GEN-018Set GNOME3 Screensaver Inactivity Timeout3GNOME desktop (dconf)medium1.7.4 · 1.8.5 · 1.7.5 · 8.2.8
SOCLE-CLD-GEN-019Enable GNOME3 Screensaver Lock After Idle Period9GNOME desktop (dconf)medium1.7.4 · 1.7.5 · 8.2.8
SOCLE-CLD-GEN-021Implement Blank Screensaver5GNOME desktop (dconf)medium8.2.8
SOCLE-CLD-GEN-023Ensure Users Cannot Change GNOME3 Screensaver Settings8GNOME desktop (dconf)medium1.8.5 · 1.8.3
SOCLE-CLD-GEN-024Ensure Users Cannot Change GNOME3 Session Idle Settings8GNOME desktop (dconf)medium1.8.5 · 1.8.3
SOCLE-CLD-IAM-008Lock Accounts After Failed Password Attempts9Accounts (faillock)medium5.3.3.1.1 · 8.3.4
SOCLE-CLD-IAM-009Set Lockout Time for Failed Password Attempts9Accounts (faillock)medium5.3.3.1.2 · 8.3.4
SOCLE-CLD-GEN-025Ensure that /etc/at.allow exists9Cron/at access controlmedium2.4.2.1
SOCLE-CLD-GEN-026Ensure that /etc/at.deny does not exist9Cron/at access controlmedium2.4.2.1
SOCLE-CLD-GEN-027Ensure that /etc/cron.allow exists9Cron/at access controlmedium2.4.1.2 · 2.4.1.8 · 2.4.1.9
SOCLE-CLD-GEN-028Ensure that /etc/cron.deny does not exist9Cron/at access controlmedium2.2.6 · 2.4.1.8 · 2.4.1.9
SOCLE-CLD-FSP-001Verify Group Who Owns /etc/at.allow file9File ownershipmedium2.2.6 · 2.4.2.1
SOCLE-CLD-FSP-002Verify Group Who Owns /etc/at.deny file9File ownershipmedium2.4.2.1
SOCLE-CLD-FSP-003Verify Group Who Owns Backup group File9File ownershipmedium2.2.6 · 7.1.4