|
| 1 | +<?xml version="1.0" encoding="UTF-8"?> |
| 2 | +<xccdf:Tailoring xmlns:xccdf="http://checklists.nist.gov/xccdf/1.2" id="xccdf_scap-workbench_tailoring_default"> |
| 3 | + <xccdf:benchmark href="/usr/share/xml/scap/ssg/content/ssg-rhel7-ds.xml"/> |
| 4 | + <xccdf:version time="2018-04-18T09:09:42">1</xccdf:version> |
| 5 | + <xccdf:Profile id="xccdf_org.ssgproject.content_profile_standard_customized" extends="xccdf_org.ssgproject.content_profile_standard"> |
| 6 | + <xccdf:title xmlns:xhtml="http://www.w3.org/1999/xhtml" xml:lang="en-US" override="true">Standard System Security Profile [CUSTOMIZED]</xccdf:title> |
| 7 | + <xccdf:description xmlns:xhtml="http://www.w3.org/1999/xhtml" xml:lang="en-US" override="true">This profile contains rules to ensure standard security baseline |
| 8 | +of Red Hat Enterprise Linux 7 system. Regardless of your system's workload |
| 9 | +all of these checks should pass.</xccdf:description> |
| 10 | + <xccdf:select idref="xccdf_org.ssgproject.content_group_gnome" selected="true"/> |
| 11 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_enable_dconf_user_profile" selected="true"/> |
| 12 | + <xccdf:select idref="xccdf_org.ssgproject.content_group_gnome_login_screen" selected="true"/> |
| 13 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_gnome_gdm_disable_automatic_login" selected="true"/> |
| 14 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_gnome_gdm_disable_guest_login" selected="true"/> |
| 15 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_user_list" selected="true"/> |
| 16 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_restart_shutdown" selected="true"/> |
| 17 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_enable_smartcard_auth" selected="true"/> |
| 18 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_login_retries" selected="true"/> |
| 19 | + <xccdf:select idref="xccdf_org.ssgproject.content_group_gnome_screen_locking" selected="true"/> |
| 20 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_idle_delay" selected="true"/> |
| 21 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_idle_activation_enabled" selected="true"/> |
| 22 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_lock_enabled" selected="true"/> |
| 23 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_lock_delay" selected="true"/> |
| 24 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_mode_blank" selected="true"/> |
| 25 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_user_info" selected="true"/> |
| 26 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_session_user_locks" selected="true"/> |
| 27 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_noexec" selected="true"/> |
| 28 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_bind" selected="true"/> |
| 29 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_nosuid" selected="true"/> |
| 30 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nosuid" selected="true"/> |
| 31 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_noexec" selected="true"/> |
| 32 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nodev" selected="true"/> |
| 33 | + </xccdf:Profile> |
| 34 | + <xccdf:Profile id="xccdf_org.ssgproject.content_profile_common_customized" extends="xccdf_org.ssgproject.content_profile_common"> |
| 35 | + <xccdf:title xmlns:xhtml="http://www.w3.org/1999/xhtml" xml:lang="en-US" override="true">Common Profile for General-Purpose Systems [CUSTOMIZED]</xccdf:title> |
| 36 | + <xccdf:description xmlns:xhtml="http://www.w3.org/1999/xhtml" xml:lang="en-US" override="true">This profile contains items common to general-purpose desktop and server installations.</xccdf:description> |
| 37 | + <xccdf:select idref="xccdf_org.ssgproject.content_group_proxy" selected="true"/> |
| 38 | + <xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_squid" selected="true"/> |
| 39 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_service_squid_disabled" selected="true"/> |
| 40 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_package_squid_removed" selected="true"/> |
| 41 | + <xccdf:select idref="xccdf_org.ssgproject.content_group_snmp" selected="true"/> |
| 42 | + <xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_snmp_service" selected="true"/> |
| 43 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_service_snmpd_disabled" selected="true"/> |
| 44 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_package_net-snmp_removed" selected="true"/> |
| 45 | + <xccdf:select idref="xccdf_org.ssgproject.content_group_snmp_configure_server" selected="true"/> |
| 46 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_snmpd_use_newer_protocol" selected="true"/> |
| 47 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_snmpd_not_default_password" selected="true"/> |
| 48 | + <xccdf:select idref="xccdf_org.ssgproject.content_group_routing" selected="true"/> |
| 49 | + <xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_quagga" selected="true"/> |
| 50 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_service_zebra_disabled" selected="true"/> |
| 51 | + <xccdf:select idref="xccdf_org.ssgproject.content_rule_package_quagga_removed" selected="true"/> |
| 52 | + </xccdf:Profile> |
| 53 | +</xccdf:Tailoring> |
0 commit comments