- Rule ID: xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode
- Full FIPS mode is not available in the AWS us-east cloud as the hardware is not guaranteed to be certified. However, this site makes use of FIPS compliant openssl software and SSL certificates.
- Rule ID: xccdf_org.ssgproject.content_rule_install_antivirus
- This site employs ClamAV for anti-virus scanning and updates the database daily.
- Rule ID: xccdf_org.ssgproject.content_rule_security_patches_up_to_date
- Software patches are installed twice monthly.
- Rule ID: xccdf_org.ssgproject.content_rule_install_smartcard_packages
- Console and smart card logins are disallowed.
- Rule ID: xccdf_org.ssgproject.content_rule_smartcard_auth
- Console and smart card logins are disallowed.
- Rule ID: xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_unlock_time-storage_disabled
- Passwords are only used after SSH key login by administrators to achieve root access. Only administrators have accounts; two-factor authentication is used and the accounts are audited monthly.
- Rule ID: xccdf_org.ssgproject.content_rule_accounts_password_pam_maxrepeat
- Passwords are only used after SSH key login by administrators to achieve root access. Only administrators have accounts; two-factor authentication is used and the accounts are audited monthly.