content icon indicating copy to clipboard operation
content copied to clipboard

Update Ubuntu 22.04 profiles to comply with CIS Benchmark 2.0.0

Open uesandiIk opened this issue 1 year ago • 5 comments

Share the context

CIS released the benchmark version 2.0.0 for Ubuntu 22.04 on March 2024, leaving the existing profiles in this project outdated.

Description of problem:

Currently the profiles for Ubuntu 22.04 follow the CIS Benchmark v1.0.0, however, the v2.0.0 has been out since March 2024. Thus, the current profiles for Ubuntu 22.04 do not ensure compliance with the latest CIS Benchmarks.

Proposed change:

Updating the profiles for Ubuntu 22.04 in the project to make them usable with the latest benchmark version.

References:

  1. https://www.cisecurity.org/benchmark/ubuntu_linux
  2. https://static.open-scap.org/ssg-guides/ssg-ubuntu2204-guide-index.html

uesandiIk avatar Jul 11 '24 10:07 uesandiIk

any contributions for it are welcome right now we have no ETA on updating any of Ubuntu CIS benchmarks

dodys avatar Jul 29 '24 09:07 dodys

Currently we are prioritizing the Ubuntu 24.04 v1.0.0 benchmark, but will update the 22.04 benchmark right after. Since the 22.04 v2.0.0 is fairly similar to 24.04 v1.0.0, it shouldn't take too long once the 24.04 is released.

mpurg avatar Jan 13 '25 08:01 mpurg

Awesome, thank you for letting me know! Will be looking forward to it!

uesandiIk avatar Jan 16 '25 15:01 uesandiIk

@dodys @Mab879 Hello,

Do you have any updates on this one?

Thank you!

vit-corp avatar Jul 30 '25 12:07 vit-corp

@vit-corp hi! this was a bit pushed away because of DISA STIG for 24.04, that was finished a couple of weeks ago. So the team will be getting back to this one soon. Our hope is to have this done still before end of October 2025.

dodys avatar Jul 31 '25 14:07 dodys