Measure hardening against a published baseline and raise the score

applied · 60 min · Objective 3.5

Task

Audit lin-b against a published hardening baseline with Lynis, record its hardening index and top warnings, fix a set of findings -- defaults, weak settings, unneeded components -- and audit again. Document every finding you chose not to fix, with the reason, because a baseline deviation without a reason is indistinguishable from an oversight.

Steps

  1. Run lynis audit system and save the report to lab/harden/audit-before.txt. Record the hardening index in lab/harden/scores.txt as before: <n>.
  2. Pick at least eight warnings or suggestions to fix: for example SSH settings, password ageing, unneeded packages, file permissions on key files, and a login banner. Record each in lab/harden/findings.csv with header id,finding,action,reason, where action is fixed or accepted.
  3. Make the fixes, testing after each that you can still log in over SSH from lin-srv.
  4. Run the audit again, save it to lab/harden/audit-after.txt, and add after: <n> to the scores file.
  5. For every finding marked accepted, make sure the reason says why the risk is acceptable, and who would sign that off in production.

Verify

These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.

grep -Ei 'Hardening index' lab/harden/audit-before.txt lab/harden/audit-after.txt
awk -F': ' '/^before/ {b=$2} /^after/ {a=$2} END {print "index "b" -> "a; exit !(a>b)}' lab/harden/scores.txt
awk -F, 'NR>1 && $3=="fixed" {n++} END {print n" finding(s) fixed"}' lab/harden/findings.csv
awk -F, 'NR>1 && $3=="accepted" && $4=="" {bad++} END {print bad+0" accepted finding(s) with no reason"}' lab/harden/findings.csv

The hardening index rose, so the second command exits zero; at least eight findings were fixed; and no accepted finding lacks a reason. The index is a proxy, not the goal. What makes this a baseline is the findings file: the next audit compares against it, and anything new is drift.

Notes

On Windows, the equivalent is Microsoft's security baseline applied through Group Policy and checked with the Policy Analyzer, or a CIS-CAT scan against the CIS Benchmark for Windows Server.

This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.