STIGQter STIGQter: STIG Summary:

Amazon Linux 2023 Security Technical Implementation Guide

Version: 1

Release: 4 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-273994r1119970_ruleAmazon Linux 2023 local disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at rest protection.
SV-273995r1119973_ruleAmazon Linux 2023 must ensure cryptographic verification of vendor software packages.
SV-273996r1119976_ruleAmazon Linux 2023 must check the GPG signature of locally installed software packages before installation.
SV-273997r1119979_ruleAmazon Linux 2023 must check the GPG signature of software packages originating from external software repositories before installation.
SV-273998r1119982_ruleAmazon Linux 2023 must have GPG signature verification enabled for all software repositories.
SV-273999r1155171_ruleAmazon Linux 2023 must be a vendor-supported release.
SV-274000r1119988_ruleAmazon Linux 2023 systemd-journald service must be enabled.
SV-274001r1198253_ruleAmazon Linux 2023 must restrict access to the kernel message buffer.
SV-274002r1198253_ruleAmazon Linux 2023 must prevent kernel profiling by nonprivileged users.
SV-274003r1198253_ruleAmazon Linux 2023 must restrict exposed kernel pointer addresses access.
SV-274004r1198253_ruleAmazon Linux 2023 must disable access to network bpf system call from nonprivileged processes.
SV-274005r1198253_ruleAmazon Linux 2023 must restrict usage of ptrace to descendant processes.
SV-274006r1120006_ruleAmazon Linux 2023 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution.
SV-274007r1120009_ruleAmazon Linux 2023 must not have the vsftpd package installed.
SV-274008r1120012_ruleAmazon Linux 2023 must not have the sendmail package installed.
SV-274009r1120015_ruleAmazon Linux 2023 must not have the nfs-utils package installed.
SV-274010r1120018_ruleAmazon Linux 2023 must not have the telnet-server package installed.
SV-274011r1184000_ruleAmazon Linux 2023 must not have the gssproxy package installed.
SV-274012r1120710_ruleAmazon Linux 2023 must have the sudo package installed.
SV-274013r1120027_ruleAmazon Linux 2023 must not be configured to bypass password requirements for privilege escalation.
SV-274014r1120030_ruleAmazon Linux 2023 must require reauthentication when using the "sudo" command.
SV-274015r1120033_ruleAmazon Linux 2023 must require users to reauthenticate for privilege escalation.
SV-274016r1120036_ruleAmazon Linux 2023 must require users to provide a password for privilege escalation.
SV-274017r1120039_ruleAmazon Linux 2023 must have the audit package installed.
SV-274018r1120042_ruleAmazon Linux 2023 must produce audit records containing information to establish what type of events occurred.
SV-274019r1120045_ruleAmazon Linux 2023 audispd-plugins package must be installed.
SV-274020r1208263_ruleAmazon Linux 2023 must have the rsyslog package installed.
SV-274021r1120695_ruleAmazon Linux 2023 must monitor remote access methods.
SV-274022r1120054_ruleAmazon Linux 2023 must have the chrony package installed.
SV-274023r1120057_ruleAmazon Linux 2023 chronyd service must be enabled.
SV-274024r1190697_ruleAmazon Linux 2023 must have the Advanced Intrusion Detection Environment (AIDE) package installed.
SV-274025r1192649_ruleAmazon Linux 2023 must routinely check the baseline configuration for unauthorized changes and notify the system administrator (SA) when anomalies in the operation of any security functions are discovered.
SV-274026r1120066_ruleAmazon Linux 2023 must use cryptographic mechanisms to protect the integrity of audit tools.
SV-274027r1120069_ruleAmazon Linux 2023 must have the firewalld package installed.
SV-274028r1190806_ruleAmazon Linux 2023 must have the firewalld service active.
SV-274030r1120078_ruleAmazon Linux 2023 must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial-of-service (DoS) attacks.
SV-274031r1120081_ruleAmazon Linux 2023 must have the s-nail package installed.
SV-274032r1184010_ruleAmazon Linux 2023 must have the libreswan package installed.
SV-274033r1120087_ruleAmazon Linux 2023 must have the policycoreutils package installed.
SV-274034r1120090_ruleAmazon Linux 2023 must have the pcsc-lite package installed.
SV-274035r1120093_ruleAmazon Linux 2023 must have the packages required for encrypting off-loaded audit logs installed.
SV-274036r1120096_ruleAmazon Linux 2023 must have the opensc package installed.
SV-274037r1120099_ruleAmazon Linux 2023 must have the openssl-pkcs11 package installed.
SV-274038r1120102_ruleAmazon Linux 2023 must have SSH installed.
SV-274039r1120105_ruleAmazon Linux 2023 must implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
SV-274040r1184011_ruleAmazon Linux 2023 must have the crypto-policies package installed.
SV-274042r1184013_ruleAmazon Linux 2023 server must be configured to use only DOD-approved encryption ciphers employing FIPS 140-2/140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.
SV-274043r1184014_ruleAmazon Linux 2023 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-2/140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.
SV-274044r1120120_ruleAmazon Linux 2023 SSH daemon must not allow Generic Security Service Application Program Interface (GSSAPI) authentication.
SV-274045r1120123_ruleAmazon Linux 2023 SSH daemon must not allow Kerberos authentication.
SV-274046r1120126_ruleAmazon Linux 2023 must force a frequent session key renegotiation for SSH connections to the server.
SV-274047r1120129_ruleAmazon Linux 2023 SSHD must accept public key authentication.
SV-274048r1120132_ruleAmazon Linux 2023 SSHD must not allow blank passwords.
SV-274049r1120747_ruleAmazon Linux 2023 must not permit direct logons to the root account using remote access via SSH.
SV-274050r1120138_ruleAmazon Linux 2023 must be configured so that all network connections associated with SSH traffic are terminated after 10 minutes of becoming unresponsive.
SV-274051r1120141_ruleAmazon Linux 2023 must be configured so that all network connections associated with SSH traffic terminate after becoming unresponsive.
SV-274052r1120144_ruleAmazon Linux 2023 must enable the Pluggable Authentication Module (PAM) interface for SSHD.
SV-274058r1186176_ruleAmazon Linux 2023 crypto policy must not be overridden.
SV-274059r1120165_ruleAmazon Linux 2023 must enable certificate-based smart card authentication.
SV-274060r1120168_ruleAmazon Linux 2023 must map the authenticated identity to the user or group account for PKI-based authentication.
SV-274061r1120171_ruleAmazon Linux 2023 must implement certificate status checking for multifactor authentication.
SV-274062r1120174_ruleAmazon Linux 2023 must prohibit the use of cached authenticators after one day.
SV-274063r1120712_ruleAmazon Linux 2023, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
SV-274064r1120180_ruleAmazon Linux 2023, for PKI-based authentication, must enforce authorized access to the corresponding private key.
SV-274065r1184021_ruleAmazon Linux 2023 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system.
SV-274066r1120186_ruleAmazon Linux 2023 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a SSH logon.
SV-274067r1120653_ruleAmazon Linux 2023 must allocate audit record storage capacity to store at least one week's worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
SV-274068r1120192_ruleAmazon Linux 2023 must use a separate file system for the system audit data path.
SV-274069r1120195_ruleAmazon Linux 2023 must label all off-loaded audit logs before sending them to the central log server.
SV-274070r1120198_ruleAmazon Linux 2023 must take appropriate action when the internal event queue is full.
SV-274071r1184023_ruleAmazon Linux 2023 must take action when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity.
SV-274072r1120204_ruleAmazon Linux 2023 must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume 75 percent utilization.
SV-274073r1120207_ruleAmazon Linux 2023 must take action when allocated audit record storage volume reaches 95 percent of the audit record storage capacity.
SV-274074r1120210_ruleAmazon Linux 2023 must take action when allocated audit record storage volume reaches 95 percent of the repository maximum audit record storage capacity.
SV-274075r1120700_ruleAmazon Linux 2023 must immediately notify the system administrator (SA) and information system security officer (ISSO), at a minimum, of an audit processing failure event.
SV-274076r1120216_ruleAmazon Linux 2023 must be configured to off-load audit records onto a different system from the system being audited via syslog.
SV-274077r1120219_ruleAmazon Linux 2023 must authenticate the remote logging server for off-loading audit logs via rsyslog.
SV-274078r1120222_ruleAmazon Linux 2023 must encrypt the transfer of audit records off-loaded onto a different system or media from the system being audited via rsyslog.
SV-274079r1210985_ruleAmazon Linux 2023 must encrypt, via the OpenSSL TLS (ossl) driver, the transfer of audit records off-loaded onto a different system or media from the system being audited by rsyslog.
SV-274080r1120228_ruleAmazon Linux 2023 must be configured to off-load audit records onto a different system from the system being audited via syslog.
SV-274081r1120231_ruleAmazon Linux 2023 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.
SV-274082r1120234_ruleAmazon Linux 2023 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory.
SV-274083r1120237_ruleAmazon Linux 2023 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
SV-274084r1120240_ruleAmazon Linux 2023 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
SV-274085r1120243_ruleAmazon Linux 2023 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
SV-274086r1120246_ruleAmazon Linux 2023 must audit uses of the "execve" system call.
SV-274087r1120249_ruleAmazon Linux 2023 must audit all uses of the chmod, fchmod, and fchmodat system calls.
SV-274088r1120252_ruleAmazon Linux 2023 must audit all uses of the chown, fchown, fchownat, and lchown system calls.
SV-274089r1120255_ruleAmazon Linux 2023 must audit all uses of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls.
SV-274090r1120258_ruleAmazon Linux 2023 must audit all uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls.
SV-274091r1120261_ruleAmazon Linux 2023 must audit all uses of the init_module and finit_module system calls.
SV-274092r1120264_ruleAmazon Linux 2023 must audit all uses of the create_module system call.
SV-274093r1120267_ruleAmazon Linux 2023 must audit all uses of the kmod command.
SV-274094r1120270_ruleAmazon Linux 2023 must audit all uses of the rename, unlink, rmdir, renameat, and unlinkat system calls.
SV-274095r1120273_ruleAmazon Linux 2023 must audit all uses of the chcon command.
SV-274096r1120276_ruleAmazon Linux 2023 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/faillock.
SV-274097r1120279_ruleAmazon Linux 2023 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/lastlog.
SV-274098r1120282_ruleAmazon Linux 2023 must audit all uses of the init command.
SV-274099r1120285_ruleAmazon Linux 2023 must audit all uses of the reboot command.
SV-274100r1120288_ruleAmazon Linux 2023 must audit all uses of the shutdown command.
SV-274101r1120291_ruleAmazon Linux 2023 audit tools must have a mode of "0755" or less permissive.
SV-274102r1120294_ruleAmazon Linux 2023 audit tools must be owned by root.
SV-274103r1120297_ruleAmazon Linux 2023 audit tools must be group-owned by root.
SV-274104r1120300_ruleAmazon Linux 2023 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
SV-274105r1120661_ruleAmazon Linux 2023 must audit all successful/unsuccessful uses of the chage command.
SV-274107r1120309_ruleAmazon Linux 2023 must off-load audit records onto a different system in the event the audit storage volume is full.
SV-274108r1120312_ruleAmazon Linux 2023 audit logs must be group-owned by root or by a restricted logging group to prevent unauthorized read access.
SV-274109r1120315_ruleAmazon Linux 2023 audit log directory must be owned by root to prevent unauthorized read access.
SV-274110r1120318_ruleAmazon Linux 2023 audit logs file must have mode "0600" or less permissive to prevent unauthorized access to the audit log.
SV-274111r1210984_ruleAmazon Linux 2023 must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.
SV-274112r1120324_ruleAmazon Linux 2023 must audit all uses of the sudo command.
SV-274113r1120327_ruleAmazon Linux 2023 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
SV-274114r1120330_ruleAmazon Linux 2023 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
SV-274115r1120333_ruleAmazon Linux 2023 must produce audit records containing information to establish the identity of any individual or process associated with the event.
SV-274116r1120336_ruleAmazon Linux 2023 audit logs must be group-owned by root or by a restricted logging group to prevent unauthorized read access.
SV-274117r1120339_ruleAmazon Linux 2023 must ensure the audit log directory be owned by root to prevent unauthorized read access.
SV-274119r1120345_ruleAmazon Linux 2023 library directories must be group-owned by root or a system account.
SV-274120r1120348_ruleAmazon Linux 2023 library directories must have mode "755" or less permissive.
SV-274121r1155161_ruleAmazon Linux 2023 library files must have mode "755" or less permissive.
SV-274122r1155164_ruleAmazon Linux 2023 library files must be owned by root.
SV-274123r1155167_ruleAmazon Linux 2023 library files must be group-owned by root or a system account.
SV-274124r1120360_ruleAmazon Linux 2023 library directories must be owned by root.
SV-274125r1120363_ruleAmazon Linux 2023 must ensure the /var/log directory have mode "0755" or less permissive.
SV-274126r1120366_ruleAmazon Linux 2023 must ensure the /var/log directory be owned by root.
SV-274127r1120369_ruleAmazon Linux 2023 must ensure the /var/log directory be group-owned by root.
SV-274128r1120372_ruleAmazon Linux 2023 must ensure the /var/log/messages file have mode "0640" or less permissive.
SV-274129r1120375_ruleAmazon Linux 2023 must ensure the /var/log/messages file be group-owned by root.
SV-274130r1120378_ruleAmazon Linux 2023 must ensure the /var/log/messages file be owned by root.
SV-274131r1120381_ruleAmazon Linux 2023 system commands must be owned by root.
SV-274132r1208253_ruleAmazon Linux 2023 system commands must be group-owned by root or a system account.
SV-274133r1120387_ruleAmazon Linux 2023 must enforce password complexity by requiring that at least one uppercase character be used.
SV-274134r1120390_ruleAmazon Linux 2023 must enforce password complexity by requiring that at least one lowercase character be used.
SV-274135r1120393_ruleAmazon Linux 2023 must enforce password complexity by requiring that at least one numeric character be used.
SV-274136r1120697_ruleAmazon Linux 2023 must require the change of at least 50 percent of the total number of characters when passwords are changed.
SV-274137r1120725_ruleAmazon Linux 2023 must enforce a minimum 15-character password length.
SV-274138r1120402_ruleAmazon Linux 2023 must enforce password complexity by requiring that at least one special character be used.
SV-274139r1120405_ruleAmazon Linux 2023 must enforce password complexity rules for the root account.
SV-274140r1120408_ruleAmazon Linux 2023 must prevent the use of dictionary words for passwords.
SV-274141r1120411_ruleAmazon Linux 2023 must limit the number of concurrent sessions to ten for all accounts and/or account types.
SV-274142r1208254_ruleAmazon Linux 2023 must automatically exit interactive command shell user sessions after 10 minutes of inactivity.
SV-274143r1120417_ruleAmazon Linux 2023 must enforce 24 hours/1 day as the minimum password lifetime.
SV-274144r1120420_ruleAmazon Linux 2023 must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
SV-274145r1120423_ruleAmazon Linux 2023 must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.
SV-274146r1120426_ruleAmazon Linux 2023 must automatically remove or disable temporary user accounts after 72 hours.
SV-274147r1184027_ruleAmazon Linux 2023 must automatically lock an account when three unsuccessful logon attempts occur.
SV-274148r1120432_ruleAmazon Linux 2023 must be able to enforce a 60-day maximum password lifetime restriction.
SV-274149r1120435_ruleAmazon Linux 2023 must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.
SV-274150r1120438_ruleAmazon Linux 2023 must automatically expire temporary accounts within 72 hours.
SV-274151r1120441_ruleAmazon Linux 2023 must restrict the use of the "su" command.
SV-274152r1120738_ruleAmazon Linux 2023 must enable the SELinux targeted policy.
SV-274153r1120713_ruleAmazon Linux 2023 must use a Linux Security Module configured to enforce limits on system services.
SV-274154r1120450_ruleAmazon Linux 2023 must automatically lock an account when three unsuccessful logon attempts occur.
SV-274155r1120453_ruleAmazon Linux 2023 must automatically lock the root account until the root account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.
SV-274156r1184029_ruleAmazon Linux 2023 must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts in 15 minutes occur.
SV-274157r1120459_ruleAmazon Linux 2023 must maintain an account lock until the locked account is released by an administrator.
SV-274158r1184031_ruleAmazon Linux 2023 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL) and vulnerability assessments.
SV-274159r1120465_ruleAmazon Linux 2023 must insure all interactive users have a primary group that exists.
SV-274160r1120663_ruleAmazon Linux 2023 must ensure all interactive users have unique User IDs (UIDs).
SV-274161r1120471_ruleAmazon Linux 2023 must ensure the password complexity module is enabled in the password-auth file.
SV-274162r1120474_ruleAmazon Linux 2023 password-auth must be configured to use a sufficient number of hashing rounds.
SV-274163r1120477_ruleAmazon Linux 2023 system-auth must be configured to use a sufficient number of hashing rounds.
SV-274164r1137695_ruleAmazon Linux 2023 must ensure a sticky bit be set on all public directories.
SV-274165r1137695_ruleAmazon Linux 2023 must ensure all world-writable directories be owned by root, sys, bin, or an application user.
SV-274166r1155170_ruleAmazon Linux 2023 must terminate idle user sessions.
SV-274167r1120489_ruleAmazon Linux 2023 must enable auditing of processes that start prior to the audit daemon.
SV-274168r1120492_ruleAmazon Linux 2023 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.
SV-274169r1120495_ruleAmazon Linux 2023 must enable discretionary access control on hardlinks.
SV-274170r1120498_ruleAmazon Linux 2023 must enable kernel parameters to enforce discretionary access control on symlinks.
SV-274173r1120507_ruleAmazon Linux 2023 debug-shell systemd service must be disabled.
SV-274175r1190705_ruleAmazon Linux 2023 must synchronize internal information system clocks to the authoritative time source at least every 24 hours.
SV-274177r1120519_ruleAmazon Linux 2023 must prevent the loading of a new kernel for later execution.
SV-274178r1120522_ruleAmazon Linux 2023 must prevent files with the setuid and setgid bit set from being executed on the /boot/efi directory.
SV-274179r1120525_ruleAmazon Linux 2023 must mount /dev/shm with the nodev option.
SV-274180r1198347_ruleAmazon Linux 2023 must mount /dev/shm with the nosuid option.
SV-274181r1208251_ruleAmazon Linux 2023 must ensure the pcscd socket is active.
SV-274182r1120729_ruleAmazon Linux 2023 file system automount function must be disabled unless required.
SV-274183r1120714_ruleAmazon Linux 2023 must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring rate-limiting measures are configured on impacted network interfaces.
SV-274184r1120540_ruleAmazon Linux 2023 must implement nonexecutable data to protect its memory from unauthorized code execution.
SV-274185r1120543_ruleAmazon Linux 2023 must remove all software components after updated versions have been installed.
SV-274186r1120546_ruleAmazon Linux 2023 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file.
SV-274187r1120715_ruleAmazon Linux 2023 audit system must protect logon user identifiers (UIDs) from unauthorized change.
SV-283440r1192648_ruleAmazon Linux 2023 must implement DOD-approved encryption in the bind package.
SV-283441r1192638_ruleAmazon Linux 2023 must enable FIPS mode.
SV-283442r1192640_ruleThe Amazon Linux 2023 SSH client must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.
SV-283443r1192643_ruleThe Amazon Linux 2023 SSH client must be configured to use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.
SV-283452r1188500_ruleAmazon Linux 2023 must implement a FIPS 140-2/140-3 compliant systemwide cryptographic policy.
SV-284944r1208267_ruleAmazon Linux 2023 must ensure that the rsyslog service is running and persistent.