{"repo":"ovh/debian-cis","free":true,"listed":false,"github":"https://github.com/ovh/debian-cis","clone":"git clone https://github.com/ovh/debian-cis.git","description":"PCI-DSS compliant Debian 11/12/13 hardening","language":"Shell","stars":1050,"topics":["debian","audit","cis","pci-dss","security","shell"],"license":null,"category":"security-tools","readme_excerpt":":lock: CIS Debian 11/12/13 Hardening --- Modular Debian 11/12/13 security hardening scripts based on cisecurity.org recommendations. We use it at OVHcloud to harden our PCI-DSS infrastructure. NB : Although Debian 13 CIS Hardening guide is still in development, we do use this set of scripts in production at OVHcloud on Debian 13 Operating Systems. :dizzy: Quickstart :hammer: Usage Configuration Hardening scripts are in bin/hardening . Each script has a corresponding configuration file in etc/conf.d/[script name].cfg . Each hardening script can be individually enabled from its configuration file. For example, this is the default configuration file for disable system accounts : status parameter may take 3 values: - disabled (do nothing): The script will not run. - audit (RO): The script will check if any change should be applied. - enabled (RW): The script will check if any change should be done and automatically apply what it can. Global configuration is in etc/hardening.cfg . This file controls the log level as well as the backup directory. Whenever a script is instructed to edit a file, it will create a timestamped backup in this directory. Run aka \"Harden your distro\" To run the checks and apply the fixes, run bin/hardening.sh . This command has 2 main operation modes: - --audit : Audit your system with all enabled and audit mode scripts - --apply : Audit your system with all enabled and audit mode scripts and apply changes for enabled scripts Additionally, some options add","default_branch":null,"files":null,"tree":[],"storefront":"/r/ovh","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ovh/debian-cis/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}