CIS Ubuntu 22.04 hardening guide: benchmark to config file mapping
Where each family of CIS Ubuntu Linux 22.04 LTS Benchmark recommendations is configured on disk, which directive controls it, and which items are not a config file change at all.
What this guide is
The CIS Ubuntu Linux Benchmark numbers every recommendation, but a failing finding such as 3.3.x does not tell you which file to open. This page maps recommendation families to the configuration file and directive an administrator edits, from sysctl.d to audit.rules.
Sections follow the CIS Ubuntu Linux 22.04 LTS Benchmark structure. Sub-numbering shifts between benchmark versions, so rows use family numbers (for example 5.2.x); confirm the exact number against the benchmark PDF you are assessing. This page never states a prescribed value; it maps location only. Drop-in file names are conventions, not requirements.
How to apply a recommendation on Ubuntu
- 01Read the recommendation number
The leading number tells you which subsystem to open. 1.x covers filesystems, boot and kernel hardening, 3.x network sysctl parameters, 4.x logging and auditd, 5.x SSH, sudo and PAM, and 6.x file permissions and account audits.
- 02Edit a drop-in, not the vendor file
Ubuntu reads /etc/sysctl.d/, /etc/modprobe.d/, /etc/audit/rules.d/ and /etc/ssh/sshd_config.d/. Drop-ins survive package upgrades and are easier to manage with Ansible, Puppet or cloud-init.
- 03Set the value from the benchmark, not from this page
This guide maps where a setting lives. The prescribed value belongs to the CIS Ubuntu Linux Benchmark PDF for your exact release and version. Server and Workstation profiles, and Level 1 and Level 2, differ.
- 04Reload the right service
sysctl --system for kernel parameters, augenrules --load for audit rules, systemctl reload ssh for SSH, update-grub for bootloader changes. Some items, such as audit=1 and module blacklists, only take full effect after a reboot.
- 05Verify with a scan, not with the file
A file can say one thing while the running kernel says another. Run CIS-CAT or your scanner after the change, then import the result here to see which recommendations remain open and why.
1.x - Initial Setup: filesystem and kernel modules
Unused filesystem modules are disabled through modprobe drop-ins; mount options are set in fstab. Mount option changes need a remount or reboot to take effect.
| Rec # | Recommendation | Level | File and directive |
|---|---|---|---|
| 1.1.1.x | Ensure cramfs / freevxfs / hfs / squashfs / udf modules are not available | Level 1 | /etc/modprobe.d/<module>.conf install <module> /bin/false and blacklist <module> |
| 1.1.2.x | Ensure nodev, nosuid, noexec on /tmp | Level 1 | /etc/fstab (or the tmp.mount systemd unit) Mount options on the /tmp entry |
| 1.1.x | Ensure nodev, nosuid, noexec on /dev/shm | Level 1 | /etc/fstab Mount options on the /dev/shm entry |
| 1.4.x | Ensure bootloader password is set | Level 1 | /etc/grub.d/40_custom, then update-grub set superusers and password_pbkdf2 |
| 1.5.x | Ensure address space layout randomization is enabled | Level 1 | /etc/sysctl.d/60-kernel_sysctl.conf kernel.randomize_va_space |
| 1.5.x | Ensure core dumps are restricted | Level 1 | /etc/security/limits.conf and /etc/sysctl.d/*.conf hard core and fs.suid_dumpable |
| 1.6.x | Ensure AppArmor is enabled and profiles are enforcing | Level 1 | /etc/default/grub GRUB_CMDLINE_LINUX apparmor=1 security=apparmor |
3.x - Network: kernel parameters
Network hardening is almost entirely sysctl. Put values in a drop-in under /etc/sysctl.d/ rather than editing /etc/sysctl.conf directly, and apply both the 'all' and 'default' interface keys.
| Rec # | Recommendation | Level | File and directive |
|---|---|---|---|
| 3.3.x | Ensure IP forwarding is disabled | Level 1 | /etc/sysctl.d/60-netipv4_sysctl.conf net.ipv4.ip_forward, net.ipv6.conf.all.forwarding |
| 3.3.x | Ensure packet redirect sending is disabled | Level 1 | /etc/sysctl.d/60-netipv4_sysctl.conf net.ipv4.conf.all.send_redirects, net.ipv4.conf.default.send_redirects |
| 3.3.x | Ensure ICMP redirects are not accepted | Level 1 | /etc/sysctl.d/60-netipv4_sysctl.conf net.ipv4.conf.all.accept_redirects, net.ipv6.conf.all.accept_redirects |
| 3.3.x | Ensure source routed packets are not accepted | Level 1 | /etc/sysctl.d/60-netipv4_sysctl.conf net.ipv4.conf.all.accept_source_route |
| 3.3.x | Ensure reverse path filtering is enabled | Level 1 | /etc/sysctl.d/60-netipv4_sysctl.conf net.ipv4.conf.all.rp_filter |
| 3.3.x | Ensure TCP SYN cookies are enabled | Level 1 | /etc/sysctl.d/60-netipv4_sysctl.conf net.ipv4.tcp_syncookies |
4.x - Logging and auditing: auditd
Audit rules live in drop-in files under /etc/audit/rules.d/ and are compiled by augenrules. Make the rule set immutable last, because '-e 2' blocks further changes until reboot.
| Rec # | Recommendation | Level | File and directive |
|---|---|---|---|
| 4.1.1.x | Ensure auditing for processes that start prior to auditd | Level 2 | /etc/default/grub GRUB_CMDLINE_LINUX audit=1 audit_backlog_limit= |
| 4.1.2.x | Ensure audit log storage size and retention | Level 2 | /etc/audit/auditd.conf max_log_file, max_log_file_action |
| 4.1.3.x | Ensure changes to sudoers are collected | Level 2 | /etc/audit/rules.d/50-scope.rules -w /etc/sudoers -p wa -k scope |
| 4.1.3.x | Ensure events that modify identity files are collected | Level 2 | /etc/audit/rules.d/50-identity.rules -w /etc/passwd, /etc/group, /etc/shadow -p wa -k identity |
| 4.1.3.x | Ensure session and login events are collected | Level 2 | /etc/audit/rules.d/50-login.rules -w /var/log/lastlog, /var/run/faillock -p wa |
| 4.1.3.x | Ensure the audit configuration is immutable | Level 2 | /etc/audit/rules.d/99-finalize.rules -e 2 |
5.x - Access, authentication and authorization
SSH, sudo, PAM and password aging. On Ubuntu, prefer drop-ins under /etc/ssh/sshd_config.d/ and use pam-auth-update profiles instead of hand-editing common-* files.
| Rec # | Recommendation | Level | File and directive |
|---|---|---|---|
| 5.2.x | Ensure SSH root login is disabled | Level 1 | /etc/ssh/sshd_config.d/*.conf PermitRootLogin |
| 5.2.x | Ensure SSH MaxAuthTries is configured | Level 1 | /etc/ssh/sshd_config.d/*.conf MaxAuthTries |
| 5.2.x | Ensure only strong ciphers, MACs and KEX algorithms are used | Level 1 | /etc/ssh/sshd_config.d/*.conf Ciphers, MACs, KexAlgorithms |
| 5.2.x | Ensure SSH idle timeout is configured | Level 1 | /etc/ssh/sshd_config.d/*.conf ClientAliveInterval, ClientAliveCountMax |
| 5.3.x | Ensure sudo commands use pty and a sudo log file exists | Level 1 | /etc/sudoers.d/<file> (edit with visudo) Defaults use_pty, Defaults logfile= |
| 5.4.x | Ensure password creation requirements are configured | Level 1 | /etc/security/pwquality.conf minlen, minclass |
| 5.4.x | Ensure lockout for failed password attempts | Level 1 | /etc/security/faillock.conf deny, unlock_time |
| 5.5.x | Ensure password expiration and minimum days are configured | Level 1 | /etc/login.defs PASS_MAX_DAYS, PASS_MIN_DAYS, PASS_WARN_AGE |
Recommendations that are not config file edits
Some benchmark items are install-time decisions, package state or inspections. Track them separately so a configuration management run does not report a false clean result.
- Separate partitions for /var, /var/log, /var/log/audit and /home, which must be planned at install time rather than edited later.
- Package removal items such as ensuring telnet, rsh or X Window System are not installed, which are handled with apt rather than a config file.
- Account and file audits in section 6, such as world-writable files, duplicate UIDs and orphaned files, which are assessed by inspection.
- Firewall rules, where the benchmark lets you choose ufw, nftables or iptables but expects only one to be active.
Next step
After applying changes, re-scan and work the remaining failures. The sample scan shows the register and remediation views without an account. Managing Windows too? See the Group Policy mapping guide.