[BESAdmin-Announcements] BigFix Compliance: Updated CIS Checklist for Oracle Linux 8, published 2026-09-29

Announcements for BES Administrators besadmin-announcements at bigmail.bigfix.com
Tue Sep 29 11:58:32 PDT 2026


*Product:*
BigFix Compliance

*Title:*
Updated CIS Checklist for Oracle Linux 8

*Security Benchmark:*
CIS Oracle Linux 8 Benchmark, V4.0.0

*Published Sites:*
CIS Checklist for Oracle Linux 8, site version 12
(The site version is provided for air-gap customers.)

*Details: *

●       Total New Fixlets: 59

●       Total Updated Fixlets: 65

●       Total Deleted Fixlets: 25

●       Total Fixlets in Site: 318

*New Fixlets:*

●      Ensure access to /etc/cron.yearly is configured

●      Ensure access to /etc/security/opasswd is configured

●      Ensure access to /etc/sysconfig/sshd is configured

●      Ensure accounts without a valid login shell are locked

●      Ensure atm kernel module is not available

●      Ensure audit tools group owner is configured

●      Ensure auditd packages are installed

●      Ensure can kernel module is not available

●      Ensure cockpit web services are not in use

●      Ensure core file size is configured

●      Ensure firewalld backend is configured

●      Ensure firewalld is installed

●      Ensure firewalld loopback source address traffic is configured

●      Ensure firewalld loopback traffic is configured

●      Ensure firewalld.service is configured

●      Ensure firewire-core kernel module is not available

●      Ensure fs.protected_hardlinks is configured

●      Ensure fs.protected_symlinks is configured

●      Ensure fs.suid_dumpable is configured

●      Ensure GDM disable-user-list is configured

●      Ensure group root is the only GID 0 group

●      Ensure journald log file access is configured

●      Ensure journald service is active

●      Ensure kernel.dmesg_restrict is configured

●      Ensure kernel.kptr_restrict is configured

●      Ensure minimum password days is configured

●      Ensure net.ipv4.conf.all.accept_redirects is configured

●      Ensure net.ipv4.conf.all.accept_source_route is configured

●      Ensure net.ipv4.conf.all.forwarding is configured

●      Ensure net.ipv4.conf.all.log_martians is configured

●      Ensure net.ipv4.conf.all.rp_filter is configured

●      Ensure net.ipv4.conf.all.secure_redirects is configured

●      Ensure net.ipv4.conf.all.send_redirects is configured

●      Ensure net.ipv4.conf.default.accept_redirects is configured

●      Ensure net.ipv4.conf.default.accept_source_route is configured

●      Ensure net.ipv4.conf.default.forwarding is configured

●      Ensure net.ipv4.conf.default.log_martians is configured

●      Ensure net.ipv4.conf.default.rp_filter is configured

●      Ensure net.ipv4.conf.default.secure_redirects is configured

●      Ensure net.ipv4.conf.default.send_redirects is configured

●      Ensure net.ipv4.ip_forward is configured

●      Ensure net.ipv6.conf.all.accept_ra is configured

●      Ensure net.ipv6.conf.all.accept_redirects is configured

●      Ensure net.ipv6.conf.all.accept_source_route is configured

●      Ensure net.ipv6.conf.all.forwarding is configured

●      Ensure net.ipv6.conf.default.accept_ra is configured

●      Ensure net.ipv6.conf.default.accept_redirects is configured

●      Ensure net.ipv6.conf.default.accept_source_route is configured

●      Ensure net.ipv6.conf.default.forwarding is configured

●      Ensure overlay kernel module is not available

●      Ensure rsyslog service is enabled and active

●      Ensure sshd GSSAPIAuthentication is disabled

●      Ensure system accounts do not have a valid login shell

●      Ensure system wide crypto policy disables chacha20-poly1305 for ssh

●      Ensure system wide crypto policy disables EtM for ssh

●      Ensure systemd-coredump Storage is configured

●      Ensure the audit configuration is loaded regardless of errors

●      Ensure weak dependencies are configured

●      Ensure Xwayland is configured

*Updated Fixlets:*

●      Ensure cramfs kernel module is not available

●      Ensure freevxfs kernel module is not available

●      Ensure hfs kernel module is not available

●      Ensure hfsplus kernel module is not available

●      Ensure jffs2 kernel module is not available

●      Ensure udf kernel module is not available

●      Ensure GPG keys are configured

●      Ensure package manager repositories are configured

●      Ensure SELinux is not disabled in bootloader configuration

●      Ensure SELinux policy is configured

●      Ensure system wide crypto policy disables sha1 hash and signature
support

●      Ensure system wide crypto policy disables cbc for ssh

●      Ensure XDMCP is not enabled

●      Ensure GNOME Display Manager is removed

●      Ensure X window server services are not in use

●      Ensure mail transfer agents are configured for local-only mode

●      Ensure cron daemon is enabled and active

●      Ensure sshd crypto_policy is not set

●      Ensure sshd access is configured

●      Ensure sshd Banner is configured

●      Ensure sshd Ignore Rhosts is enabled

●      Ensure sshd Login Grace Time is configured

●      Ensure sshd MaxAuthTries is configured

●      Ensure sshd MaxSessions is configured

●      Ensure sshd MaxStartups is configured

●      Ensure sshd PermitEmptyPasswords is disabled

●      Ensure sshd PermitRootLogin is disabled

●      Ensure sshd PermitUserEnvironment is disabled

●      Ensure sshd UsePAM is enabled

●      Ensure sudo commands use pty

●      Ensure sudo log file exists

●      Ensure re-authentication for privilege escalation is not disabled
globally

●      Ensure access to the su command is restricted

●      Ensure password failed attempts lockout includes root account

●      Ensure password number of changed characters is configured

●      Ensure password length is configured

●      Ensure password complexity is configured

●      Ensure password same consecutive characters is configured

●      Ensure password maximum sequential characters is configured

●      Ensure password dictionary check is enabled

●      Ensure password quality is enforced for the root user

●      Ensure password history is enforced for the root user

●      Ensure pam_pwhistory includes use_authtok

●      Ensure pam_unix does not include nullok

●      Ensure pam_unix includes a strong password hashing algorithm

●      Ensure pam_unix includes use_authtok

●      Ensure all users last password change date is in the past

●      Ensure root is the only UID 0 account

●      Ensure root user umask is configured

●      Ensure nologin is not listed in /etc/shells

●      Ensure cryptographic mechanisms are used to protect the integrity of
audit tools

●      Ensure rsyslog is installed

●      Ensure auditing for processes that start prior to auditd is enabled

●      Ensure audit log storage size is configured

●      Ensure events that modify the sudo log file are collected

●      Ensure events that modify date and time information are collected

●      Ensure use of privileged commands are collected

●      Ensure session initiation information is collected

●      Ensure events that modify the system's Mandatory Access Controls are
collected

●      Ensure the audit configuration is immutable

●      Ensure the running and on disk configuration is the same

●      Ensure world writable files and directories are secured

●      Ensure SUID and SGID files are reviewed

●      Ensure all groups in /etc/passwd exist in /etc/group

●      Ensure local interactive user home directories are configured

*Deleted Fixlets:*

●      Ensure a single firewall configuration utility is in use

●      Ensure audit is installed

●      Ensure audit tools are 755 or more restrictive

●      Ensure core dump storage is disabled

●      Ensure GDM automatic mounting of removable media is disabled

●      Ensure GDM autorun-never is enabled

●      Ensure GDM disable-user-list option is enabled

●      Ensure GDM screen locks when the user is idle

●      Ensure host based firewall loopback traffic is configured

●      Ensure icmp redirects are not accepted

●      Ensure ip forwarding is disabled

●      Ensure ipv6 router advertisements are not accepted

●      Ensure journald service is enabled

●      Ensure nftables base chains exist

●      Ensure nftables default deny firewall policy

●      Ensure nftables established connections are configured

●      Ensure nftables is installed

●      Ensure packet redirect sending is disabled

●      Ensure permissions on /etc/opasswd are configured

●      Ensure reverse path filtering is enabled

●      Ensure rsyslog service is enabled

●      Ensure secure icmp redirects are not accepted

●      Ensure source routed packets are not accepted

●      Ensure suspicious packets are logged

●      Ensure system accounts are secured

*Additional details:*

●      Both analysis and remediation checks are included.

●      Some of the checks allow you to use the parameterized setting to
enable customization for compliance evaluation. Note that parameterization
and remediation actions require the creation of a custom site.

●      Improved a few checks by adding the pending restart feature to them.
The pending restart feature works in the following ways:

●       The action results will show “Pending Restart” instead of “Fixed”
for those checks which require OS reboot.

●      The check will show relevant for those endpoints until they are
rebooted.

●      Post reboot of the endpoint the action results will show as “Fixed”
and the check will be compliant.



*Action to take:*

●      To subscribe to the above site, you can use the License Overview
Dashboard to enable and gather the site. Note that you must be entitled to
the BigFix Compliance product and you must be using BigFix version 10.0.0
and later.

●      If you use custom sites, update your custom sites accordingly to use
the latest content. You can synchronize your content by using the
Synchronize Custom Checks wizard. For more information, see Using the
Synchronize Custom Checks wizard
<https://help.hcltechsw.com/bigfix/11.0/compliance/Compliance/SCM_Users_Guide/c_using_synchronize_custom_checks_wiz.html>


*More information: *To know more about the BigFix Compliance SCM
checklists, please see the following resources:

●      BigFix Forum:

*Compliance (Release Announcements)*
<https://forum.bigfix.com/c/release-announcements/compliance/63>
This category is used by HCL to announce new releases for BigFix Compliance.

●      BigFix Compliance SCM Checklists:
*SCM Checklists*
<https://forum.bigfix.com/c/release-announcements/scm-checklists/86>

This category is the central reference for all SCM Checklists supported by
BigFix Compliance. It covers the complete list of active checklists across
all supported frameworks and platforms, including CIS, DISA STIG, PCI DSS,
NIST, and more, along with site name, version details, and supported OS
versions.

We hope you find this latest release of SCM content useful and effective.
Thank you!
*– The BigFix Compliance team*
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://bigmail.bigfix.com/pipermail/besadmin-announcements/attachments/20260929/d38c2257/attachment.html>


More information about the Besadmin-announcements mailing list