Although Linux is considered by many to be secure by default, some settings or misconfiguration can weaken a Linux system. To protect your data it is recommended to harden the system. For this purpose, many hardening guides and benchmarks are written (you can find a quick overview here).
Linux comes in different flavours, but some security advices are independent of the distribution. With Greenbone it is possible to check compliance with a policy for Linux hosts (GSF content only).
To run a policy scan against a Linux target, import this scan configuration (685.8 KB). If any of the policy test do not match your site policy, you can disable (uncheck) the VT in family “Policy”. Also you can modify the default values of some tests to be more or less restrictive by clicking “Select and edit NVT details” of the VT you want to modify. The default value of a VT is taken to determine the compliance status.
You can suppress reporting for each policy test and instead show summary VTs only by disable “Verbose Policy Controls” in VT “Compliance Tests” (22.214.171.124.4.1.256126.96.36.199888, family: Compliance).
|Compliance Tests||Compliance||188.8.131.52.4.1.256184.108.40.206888||Check that
|Policy Controls Summary||Compliance||220.127.116.11.4.1.25618.104.22.168006|
|Policy Controls: Ok||Policy||22.214.171.124.4.1.256126.96.36.199804||Summary of all passed tests|
|Policy Controls: Fail||Policy||188.8.131.52.4.1.256184.108.40.206805||Summary of all failed tests|
|Linux tests (beginning with
||Policy||220.127.116.11.4.1.25618.104.22.168714 - 22.214.171.124.4.1.256126.96.36.199836||VTs performing the actual tests|