CIS Ubuntu 22.04 hardening guide: benchmark to config file mapping

Where each family of CIS Ubuntu Linux 22.04 LTS Benchmark recommendations is configured on disk, which directive controls it, and which items are not a config file change at all.

What this guide is

The CIS Ubuntu Linux Benchmark numbers every recommendation, but a failing finding such as 3.3.x does not tell you which file to open. This page maps recommendation families to the configuration file and directive an administrator edits, from sysctl.d to audit.rules.

Sections follow the CIS Ubuntu Linux 22.04 LTS Benchmark structure. Sub-numbering shifts between benchmark versions, so rows use family numbers (for example 5.2.x); confirm the exact number against the benchmark PDF you are assessing. This page never states a prescribed value; it maps location only. Drop-in file names are conventions, not requirements.

How to apply a recommendation on Ubuntu

  1. 01
    Read the recommendation number

    The leading number tells you which subsystem to open. 1.x covers filesystems, boot and kernel hardening, 3.x network sysctl parameters, 4.x logging and auditd, 5.x SSH, sudo and PAM, and 6.x file permissions and account audits.

  2. 02
    Edit a drop-in, not the vendor file

    Ubuntu reads /etc/sysctl.d/, /etc/modprobe.d/, /etc/audit/rules.d/ and /etc/ssh/sshd_config.d/. Drop-ins survive package upgrades and are easier to manage with Ansible, Puppet or cloud-init.

  3. 03
    Set the value from the benchmark, not from this page

    This guide maps where a setting lives. The prescribed value belongs to the CIS Ubuntu Linux Benchmark PDF for your exact release and version. Server and Workstation profiles, and Level 1 and Level 2, differ.

  4. 04
    Reload the right service

    sysctl --system for kernel parameters, augenrules --load for audit rules, systemctl reload ssh for SSH, update-grub for bootloader changes. Some items, such as audit=1 and module blacklists, only take full effect after a reboot.

  5. 05
    Verify with a scan, not with the file

    A file can say one thing while the running kernel says another. Run CIS-CAT or your scanner after the change, then import the result here to see which recommendations remain open and why.

1.x - Initial Setup: filesystem and kernel modules

Unused filesystem modules are disabled through modprobe drop-ins; mount options are set in fstab. Mount option changes need a remount or reboot to take effect.

Rec #RecommendationLevelFile and directive
1.1.1.xEnsure cramfs / freevxfs / hfs / squashfs / udf modules are not availableLevel 1
/etc/modprobe.d/<module>.conf
install <module> /bin/false and blacklist <module>
1.1.2.xEnsure nodev, nosuid, noexec on /tmpLevel 1
/etc/fstab (or the tmp.mount systemd unit)
Mount options on the /tmp entry
1.1.xEnsure nodev, nosuid, noexec on /dev/shmLevel 1
/etc/fstab
Mount options on the /dev/shm entry
1.4.xEnsure bootloader password is setLevel 1
/etc/grub.d/40_custom, then update-grub
set superusers and password_pbkdf2
1.5.xEnsure address space layout randomization is enabledLevel 1
/etc/sysctl.d/60-kernel_sysctl.conf
kernel.randomize_va_space
1.5.xEnsure core dumps are restrictedLevel 1
/etc/security/limits.conf and /etc/sysctl.d/*.conf
hard core and fs.suid_dumpable
1.6.xEnsure AppArmor is enabled and profiles are enforcingLevel 1
/etc/default/grub
GRUB_CMDLINE_LINUX apparmor=1 security=apparmor

3.x - Network: kernel parameters

Network hardening is almost entirely sysctl. Put values in a drop-in under /etc/sysctl.d/ rather than editing /etc/sysctl.conf directly, and apply both the 'all' and 'default' interface keys.

Rec #RecommendationLevelFile and directive
3.3.xEnsure IP forwarding is disabledLevel 1
/etc/sysctl.d/60-netipv4_sysctl.conf
net.ipv4.ip_forward, net.ipv6.conf.all.forwarding
3.3.xEnsure packet redirect sending is disabledLevel 1
/etc/sysctl.d/60-netipv4_sysctl.conf
net.ipv4.conf.all.send_redirects, net.ipv4.conf.default.send_redirects
3.3.xEnsure ICMP redirects are not acceptedLevel 1
/etc/sysctl.d/60-netipv4_sysctl.conf
net.ipv4.conf.all.accept_redirects, net.ipv6.conf.all.accept_redirects
3.3.xEnsure source routed packets are not acceptedLevel 1
/etc/sysctl.d/60-netipv4_sysctl.conf
net.ipv4.conf.all.accept_source_route
3.3.xEnsure reverse path filtering is enabledLevel 1
/etc/sysctl.d/60-netipv4_sysctl.conf
net.ipv4.conf.all.rp_filter
3.3.xEnsure TCP SYN cookies are enabledLevel 1
/etc/sysctl.d/60-netipv4_sysctl.conf
net.ipv4.tcp_syncookies

4.x - Logging and auditing: auditd

Audit rules live in drop-in files under /etc/audit/rules.d/ and are compiled by augenrules. Make the rule set immutable last, because '-e 2' blocks further changes until reboot.

Rec #RecommendationLevelFile and directive
4.1.1.xEnsure auditing for processes that start prior to auditdLevel 2
/etc/default/grub
GRUB_CMDLINE_LINUX audit=1 audit_backlog_limit=
4.1.2.xEnsure audit log storage size and retentionLevel 2
/etc/audit/auditd.conf
max_log_file, max_log_file_action
4.1.3.xEnsure changes to sudoers are collectedLevel 2
/etc/audit/rules.d/50-scope.rules
-w /etc/sudoers -p wa -k scope
4.1.3.xEnsure events that modify identity files are collectedLevel 2
/etc/audit/rules.d/50-identity.rules
-w /etc/passwd, /etc/group, /etc/shadow -p wa -k identity
4.1.3.xEnsure session and login events are collectedLevel 2
/etc/audit/rules.d/50-login.rules
-w /var/log/lastlog, /var/run/faillock -p wa
4.1.3.xEnsure the audit configuration is immutableLevel 2
/etc/audit/rules.d/99-finalize.rules
-e 2

5.x - Access, authentication and authorization

SSH, sudo, PAM and password aging. On Ubuntu, prefer drop-ins under /etc/ssh/sshd_config.d/ and use pam-auth-update profiles instead of hand-editing common-* files.

Rec #RecommendationLevelFile and directive
5.2.xEnsure SSH root login is disabledLevel 1
/etc/ssh/sshd_config.d/*.conf
PermitRootLogin
5.2.xEnsure SSH MaxAuthTries is configuredLevel 1
/etc/ssh/sshd_config.d/*.conf
MaxAuthTries
5.2.xEnsure only strong ciphers, MACs and KEX algorithms are usedLevel 1
/etc/ssh/sshd_config.d/*.conf
Ciphers, MACs, KexAlgorithms
5.2.xEnsure SSH idle timeout is configuredLevel 1
/etc/ssh/sshd_config.d/*.conf
ClientAliveInterval, ClientAliveCountMax
5.3.xEnsure sudo commands use pty and a sudo log file existsLevel 1
/etc/sudoers.d/<file> (edit with visudo)
Defaults use_pty, Defaults logfile=
5.4.xEnsure password creation requirements are configuredLevel 1
/etc/security/pwquality.conf
minlen, minclass
5.4.xEnsure lockout for failed password attemptsLevel 1
/etc/security/faillock.conf
deny, unlock_time
5.5.xEnsure password expiration and minimum days are configuredLevel 1
/etc/login.defs
PASS_MAX_DAYS, PASS_MIN_DAYS, PASS_WARN_AGE

Recommendations that are not config file edits

Some benchmark items are install-time decisions, package state or inspections. Track them separately so a configuration management run does not report a false clean result.

  • Separate partitions for /var, /var/log, /var/log/audit and /home, which must be planned at install time rather than edited later.
  • Package removal items such as ensuring telnet, rsh or X Window System are not installed, which are handled with apt rather than a config file.
  • Account and file audits in section 6, such as world-writable files, duplicate UIDs and orphaned files, which are assessed by inspection.
  • Firewall rules, where the benchmark lets you choose ufw, nftables or iptables but expects only one to be active.

Next step

After applying changes, re-scan and work the remaining failures. The sample scan shows the register and remediation views without an account. Managing Windows too? See the Group Policy mapping guide.