CIS hardening

Every StoreFrame environment is hardened against CIS Benchmark Level 1 controls at provision time and re-applied on every platform run.

Every Ubuntu VM that StoreFrame provisions, including customer Magento environments and trial VMs, is hardened against CIS Benchmark Level 1 controls. The hardening runs as part of the platform's hardening role and is applied at provision time and on every subsequent platform run. There is no manual hardening step: a freshly provisioned VM passes the controls listed below the first time you SSH into it.

What gets applied

Each control targets a specific CIS section:

ControlCIS sectionWhat it does
SSH hardening5.2Restricts SSH ciphers, MACs, KEX algorithms; disables root login; enforces protocol 2
Fail2Ban—Adds Fail2Ban as a second layer of SSH brute-force protection
Kernel network settings3.xKernel-level network hardening (rp_filter, syncookies, redirects, etc.)
Audit trail4.1Installs and configures audit trail for security-relevant events
PAM hardening5.3, 5.4Password quality rules and account lockout via PAM
File integrity monitoring1.3AIDE file integrity monitoring with a daily check
Cron hardening5.1Tightens permissions and access control on cron directories
Unused kernel modules3.1Disables unused network protocols (dccp, sctp, rds, tipc)
Additional controlsVariousGRUB permissions, AppArmor enforce, core dumps disabled, time sync, journald, rsyslog, sudo logging
Loopback firewall rules3.5.3.3.1Loopback traffic rules in UFW
Docker network hardening—Preserves client IPs through Docker so security tools see real source IPs

Additional controls

These smaller controls are applied alongside the ones above:

  • Apport removed (CIS 1.5.5)
  • GRUB and audit binary permissions (CIS 1.4, 4.1.4.11) — chmod 600 on /boot/grub/grub.cfg and chmod 700 on audit binaries
  • AppArmor in enforce mode (CIS 1.6) — installed, all profiles set to enforce, enabled at boot
  • Core dumps disabled (CIS 1.4.1)
  • Shell timeout (CIS 5.5.4)
  • Default umask (CIS 5.5.5) — umask 027
  • Chrony for time sync (CIS 2.1.1)
  • Insecure packages removed (CIS 2.3) — ftp, tnftp, telnet, inetutils-telnet; rsync service masked
  • Journald hardened (CIS 4.2.1.x) — persistent storage, compression, syslog forwarding, rotation caps
  • Rsyslog file mode (CIS 4.2.2.4) — $FileCreateMode 0640
  • Sudo logging and PTY enforcement (CIS 5.2.4, 5.2.5)
  • Login banner (CIS 1.5.2) — authorized-users-only notice in /etc/issue
  • Group integrity (CIS 6.2.3, 6.2.4) — every GID in /etc/passwd exists in /etc/group; no users have shadow as primary group

Verification with Wazuh SCA

Every customer VM also runs the Wazuh agent (see Wazuh). Wazuh's Security Configuration Assessment (SCA) module evaluates the host against CIS Ubuntu policies and produces a compliance score visible on the Wazuh dashboard. Because the hardening applies the controls that the SCA policy expects, most checks pass on a freshly provisioned VM without manual intervention.

A few checks that don't apply to cloud VMs, such as separate disk partitions for /tmp and /var, are excluded from the score.

Scope

Environments are hardened to CIS Benchmark Level 1. If your workload needs Level 2, contact support.

  • Wazuh — agent that audits these controls and reports compliance
  • CrowdSec — behavioral firewall layer on top of the hardened base
  • OpenResty + Lua security pipeline — application-layer security on top of the OS-level hardening

On this page