CIS Ubuntu 14.04 LTS - 5.4.1.3 Ensure password expiration warning days is 7 or more
Verify PASS_WARN_AGE is set to 7 or more in /etc/login.defs for password expiry warnings
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Verify PASS_WARN_AGE is set to 7 or more in /etc/login.defs for password expiry warnings
Verify inactive password lock is set to 30 days or less to disable dormant accounts
Verify no users have a password change date set in the future which could bypass expiration
Verify system accounts have non-login shells and are locked to prevent interactive access
Verify the root account default group is GID 0 to prevent root-owned files becoming accessible
Verify default umask is set to 027 or more restrictive in shell configuration files
Verify TMOUT is set to 900 seconds or less in shell configuration files for idle session timeout
Verify root login is restricted to physically secure system consoles via /etc/securetty
Verify access to the su command is restricted to the wheel group via PAM configuration
Find and remediate world writable files across all local filesystems