Independent baseline-to-hardened verification report
Verification gate: passed
Both independent audits must contain exactly the expected reviewed control set.
| Control | Severity | Baseline | Hardened verification |
|---|---|---|---|
| Build and Test AIDE Database | medium | fail | pass |
| Configure Systemd Timer Execution of AIDE | medium | notapplicable | pass |
| All AppArmor Profiles are in enforce or complain mode | medium | fail | pass |
| Disable Core Dumps for All Users | medium | fail | pass |
| Ensure All Files Are Owned by a Group | medium | fail | pass |
| Ensure AppArmor is enabled in the bootloader configuration | medium | fail | pass |
| Ensure journald is configured to send logs to rsyslog | medium | fail | pass |
| Disable Mounting of cramfs | low | fail | pass |
| Disable Mounting of freevxfs | low | fail | pass |
| Disable Mounting of hfs | low | fail | pass |
| Disable Mounting of hfsplus | low | fail | pass |
| Disable Mounting of jffs2 | low | fail | pass |
| Disable Modprobe Loading of USB Storage Driver | medium | fail | pass |
| Add nodev Option to /dev/shm | medium | fail | pass |
| Add noexec Option to /dev/shm | medium | fail | pass |
| Add nosuid Option to /dev/shm | medium | fail | pass |
| Install AIDE | medium | fail | pass |
| Ensure AppArmor Utils is installed | medium | fail | pass |
| Verify permissions of log files | medium | fail | pass |
| Disable Apport Service | unknown | fail | pass |
| Disable Core Dumps for SUID programs | medium | fail | pass |
| Enable Randomized Layout of Virtual Address Space | medium | fail | pass |
Controls that still fail in the independent hardened verification, including unchanged failures.
| Control | Severity | Baseline | Hardened verification |
|---|---|---|---|
| No remaining failed controls. | |||