Skip to content

Instantly share code, notes, and snippets.

@X3MBoy
Last active September 20, 2021 20:45
Show Gist options
  • Save X3MBoy/f8d473d63d929f9375bfe768524dcd18 to your computer and use it in GitHub Desktop.
Save X3MBoy/f8d473d63d929f9375bfe768524dcd18 to your computer and use it in GitHub Desktop.
tailoring file
<?xml version="1.0" encoding="UTF-8"?>
<xccdf:Tailoring xmlns:xccdf="http://checklists.nist.gov/xccdf/1.2" id="xccdf_scap-workbench_tailoring_default">
<xccdf:benchmark href="/tmp/scap-workbench-KGnokV/ssg-ubuntu2004-ds.xml"/>
<xccdf:version time="2021-09-07T13:58:30">1</xccdf:version>
<xccdf:Profile id="xccdf_cl.falabella_profile_SCeI_Profile">
<xccdf:title xmlns:xhtml="http://www.w3.org/1999/xhtml" xml:lang="en-US" override="true">Standard System Security Profile for Ubuntu 20.04 [CUSTOMIZED]</xccdf:title>
<xccdf:description xmlns:xhtml="http://www.w3.org/1999/xhtml" xml:lang="en-US" override="true">This profile contains rules to ensure standard security baseline of an Ubuntu 20.04 system. Regardless of your system's workload all of these checks should pass.</xccdf:description>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_group" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_gshadow" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_passwd" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_shadow" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_group" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_gshadow" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_passwd" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_shadow" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_group" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_gshadow" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_passwd" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_shadow" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_systemmap" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_audit_installed" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_inetutils-telnetd_removed" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_nis_removed" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_ntpdate_removed" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_telnetd-ssl_removed" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_telnetd_removed" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_apport_disabled" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_auditd_enabled" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_empty_passwords" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_root_login" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_set_keepalive_0" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_hardlinks" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_symlinks" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_randomize_va_space" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_snmp_configure_server" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ftp_configure_vsftpd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ftp_restrict_users" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ftp_use_vsftpd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_usbguard" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_sssd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_sssd-ldap" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dns_server_protection" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dns_server_partition_with_views" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dns_server_separate_internal_external" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dns_server_isolation" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dns_server_dedicated" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dns_server_chroot" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_configuring_samba" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_smb_disable_printing" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_smb_restrict_file_sharing" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_configure_dovecot" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dovecot_support_necessary_protocols" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dovecot_allow_imap_access" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dovecot_enabling_ssl" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dhcp_client_configuration" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dhcp_server_configuration" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_client" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_servers" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_configure_exports_restrictively" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_export_filesystems_read_only" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_use_acl_enforce_auth_restrictions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_kerberos" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_printing" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_configure_printing" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_rng" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ldap" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_openldap_server" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ldap_server_config_certificate_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_openldap_client" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_intro" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_how-to-use" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_intro-test-non-production" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_intro-formatting-conventions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_intro-read-sections-completely" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_intro-root-shell-assumed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_intro-reboot-required" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_general-principles" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_principle-encrypt-transmitted-data" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_principle-least-privilege" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_principle-minimize-software" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_principle-use-security-tools" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_principle-separate-servers" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_remediation_functions" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_system" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_permissions" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_partitions" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nosuid" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nodev" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_permissions_local" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_files" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_permissions_important_account_files" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_shadow" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_gshadow" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_group" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_passwd" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_group" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_passwd" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_shadow" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_shadow" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_gshadow" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_gshadow" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_passwd" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_group" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_permissions_within_important_dirs" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_library_dirs" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dir_permissions_library_dirs" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_binary_dirs" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_ownership_library_dirs" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_world_writable" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_restrictions" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_enable_execshield_settings" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_kptr_restrict" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network-ipv6" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_configuring_ipv6" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network_ipv6_limit_requests" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_ipv6" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_disable_ipv6" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_kernel_module_ipv6_option_disabled" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network_ssl" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network_disable_unused_interfaces" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network-uncommon" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_kernel_module_rds_disabled" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_kernel_module_tipc_disabled" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_bootloader-zipl" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_entropy" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_kernel_disable_entropy_contribution_for_solid_state_drives" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_auditing" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_policy_rules" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_auditd_configure_rules" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_audit_time_rules" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_watch_localtime" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_settimeofday" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_clock_settime" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_adjtimex" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_stime" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_audit_dac_actions" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_setxattr" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fremovexattr" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_umount2" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lchown" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchownat" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchmodat" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lremovexattr" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fsetxattr" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_removexattr" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchmod" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lsetxattr" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchown" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_audit_execution_acl_commands" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_networkconfig_modification" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_immutable" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_var_log_audit" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_ownership_var_log_audit" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_mac_modification" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_sysadmin_actions" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_configure_auditd_data_retention" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_freq" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_action_mail_acct" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_local_events" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_max_log_file_action" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_num_logs" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_write_logs" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_name_format" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_log_format" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_max_log_file" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_audispd_syslog_plugin_activated" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_accounts" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_accounts-session" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_root_paths" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_root_path_no_dot" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_root_path_dirs_no_write" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_logon_fail_delay" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_software" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_integrity" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_certified-vendor" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_installed_OS_is_FIPS_certified" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_aide" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disk_partitioning" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_partition_for_var" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_partition_for_tmp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_partition_for_home" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_log_audit" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_log" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_partition_for_srv" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_gnome" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_gnome_network_settings" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_gnome_system_settings" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_gnome_login_screen" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gnome_gdm_disable_xdmcp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_gnome_screen_locking" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_gnome_remote_access_settings" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_gnome_media_settings" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_sap_host" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_accounts-pam" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_set_password_hashing_algorithm" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_locking_out_password_attempts" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_password_quality" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_password_quality_pwquality" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_password_quality_pamcracklib" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_display_login_attempts" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_accounts-restrictions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_password_expiration" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_maximum_age_login_defs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_password_warn_age_login_defs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_minimum_age_login_defs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_password_minlen_login_defs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_account_expiration" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_account_unique_name" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_account_use_centralized_automated_auth" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_password_storage" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_no_netrc_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_no_empty_passwords" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gid_passwd_group_same" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_password_all_shadowed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_root_logins" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_no_direct_root_logins" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_no_password_auth_for_systemaccounts" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_securetty_root_login_console_only" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_restrict_serial_port_logins" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_no_uid_except_zero" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network-iptables" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_iptables_ruleset_modifications" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_iptables_log_and_drop_suspicious" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_iptables_icmp_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_set_iptables_default_rule_forward" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_set_iptables_default_rule" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_iptables_activation" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_set_ip6tables_default_rule" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_iptables_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_ip6tables_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_logging" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_log_rotation" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_ensure_logrotate_activated" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_rsyslog_accepting_remote_messages" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_rsyslog_accept_remote_messages_tcp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_rsyslog_accept_remote_messages_udp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_syslogng_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_syslogng_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_configure_logwatch_on_logserver" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ensure_rsyslog_log_file_configuration" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_groupownership" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_permissions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_ownership" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_rsyslog_sending_messages" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_rsyslog_remote_loghost" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_rsyslog_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_rsyslog_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_samba" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_smb" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_dovecot" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_imap" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_squid" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_proxy" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ssh" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ssh_server" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_sshd_strengthen_firewall" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_set_loglevel_verbose" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_set_max_sessions" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_kerb_auth" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_pubkey_auth" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_print_last_log" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_use_priv_separation" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_tcp_forwarding" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_allow_only_protocol2" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_warning_banner" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_user_known_hosts" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_rhosts" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_set_loglevel_info" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_rekey_limit" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_gssapi_auth" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_set_max_auth_tries" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_x11_forwarding" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_gssapi_auth" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_strictmodes" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_x11_forwarding" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_do_not_permit_user_env" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_compression" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_rhosts_rsa" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_disable_host_auth" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_root_password_login" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_limit_user_access" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ssh_client" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_iptables_sshd_disabled" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_pub_key" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_private_key" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_openssh-server_installed" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ntp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_ntpd_specify_multiple_servers" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_ntpd_specify_remote_server" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_chronyd_specify_remote_server" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_timesyncd_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_ntpd_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_ntp_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_chronyd_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_timesyncd_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_ntp_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_chrony_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_apt" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_obsolete" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_tftp" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_nis" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_inetd_and_xinetd" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_r_services" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_no_rsh_trust_files" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_telnet" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_talk" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_avahi_disable_publishing" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_avahi_configuration" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_avahi" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disable_avahi_group" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_installing_httpd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_minimal_modules_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_httpd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_securing_httpd" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_configure_php_securely" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_info_leakage" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_minimize_loadable_modules" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_core_modules" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_optional_components" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_minimize_config_files_included" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_basic_authentication" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_modules_improve_security" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_security" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_ssl" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_secure_content" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_use_dos_protection_modules" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_directory_restrictions" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_configure_perl_securely" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_configure_os_protect_web_server" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_chroot" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_file_dir_access" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_http" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_clients" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_mounting_remote_filesystems" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_nfs_and_rpc" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_nfs" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_netfs" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_netfs_disabled" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_server" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dhcp" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_radius" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_docker" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_mail" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_client" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_postfix_client_configure_relayhost" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_postfix_client_configure_mail_alias" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_harden_os" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_server_cfg" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_server_relay" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_server_mail_smtpd_relay_restrictions" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_server_relay_smtp_auth_for_untrusted" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_server_relay_set_trusted" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_server_relay_require_tls" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_server_mail_smtpd_recipient_restrictions" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_server_dos" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_configure_ssl_certs" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_install_ssl_cert" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_rpm_verification" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_software-integrity" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_system-tools" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_nss-tools_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_gnutls-utils_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_user_umask" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_profile" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_login_defs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_bootloader-grub2" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_uefi" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_non-uefi" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_grub2_enable_iommu_force" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network-susefirewall2" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_openssh-server_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_sshd_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_cron_and_at" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_restrict_at_cron_users" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_cron_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_cron_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_prefer_64bit_os" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_accounts-physical" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_screen_locking" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_smart_card_login" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_console_screen_locking" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_selinux" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_selinux-booleans" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_selinux_state" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network-firewalld" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ruleset_modifications" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_firewalld_activation" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network-wireless" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_wireless_software" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_routing" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_quagga" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_all_machines" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_nfs_client_or_server_not_both" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_nfs_configure_fixed_ports" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_harden_ssh_client_crypto_policy" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_crypto" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_endpoint_security_software" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_mcafee_security_software" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_mcafee_hbss_software" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_MFEhiplsm_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_configure_user_data_backups" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_polyinstantiated_var_tmp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_polyinstantiated_tmp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_home_dirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_permissions_var_log_dir" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_var_log_messages" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_var_log" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_owner_var_log_messages" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_owner_var_log" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_var_log_messages" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_var_log" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_coredumps" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_coredump_disable_storage" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_coredump_disable_backtraces" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_suid_dumpable" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_audit-audispd-plugins_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_set_idle_timeout" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_set_keepalive" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_max_concurrent_login_sessions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_ownership_binary_dirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_umount" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_space_left_action" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_admin_space_left_action" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_data_disk_full_action" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_data_disk_error_action" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_audit_privileged_commands" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_rmdir" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_unlink" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_unlinkat" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_rename" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_renameat" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_audit_file_deletion_events" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_media_export" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_directory_access_var_log_audit" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_fips" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_updating" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_gui_login_banner" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_accounts-banners" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_audit_file_modification" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_audit_login_events" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_audit_kernel_module_loading" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_audit_execution_selinux_commands" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_mounting" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_poisoning" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_enable_nx" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_daemon_umask" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network-ipsec" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network_host_parameters" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network_host_and_router_parameters" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network-kernel" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_snmp_service" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_snmp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_fapolicyd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_nfsd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_nfs_services" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_xwindows" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_xwindows" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_vsftpd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ftp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_dns_server" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dns" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_base" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_sudo" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sudoers_no_command_negation" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sudo_remove_nopasswd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sudo_add_requiretty" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sudo_require_authentication" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sudo_add_use_pty" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sudo_vdsm_nopasswd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sudoers_no_root_target" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sudoers_validate_passwd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sudo_add_noexec" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sudo_remove_no_authenticate" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sudoers_explicit_command_args" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_sudo_installed" selected="false"/>
<xccdf:refine-value idref="xccdf_org.ssgproject.content_value_sshd_idle_timeout_value" selector="5_minutes"/>
<xccdf:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_set_keepalive" selector="0"/>
<xccdf:refine-value idref="xccdf_org.ssgproject.content_value_file_owner_logfiles_value" selector="syslog"/>
<xccdf:refine-value idref="xccdf_org.ssgproject.content_value_file_groupowner_logfiles_value" selector="adm"/>
</xccdf:Profile>
</xccdf:Tailoring>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment