Newsletter MesServicesCyber. Restez informé des nouveaux guides de l’ANSSI et autres actualités MesServicesCyber. S’abonner
Publié le 22 février 2019
Présentation
A few configuration rules make it possible to obtain reasonably secure systems as long as some fundamental principles are respected. It should be checked methodologically that these are applied correctly, for example using a checklist.
This guide focuses primarily on generic system configuration guidelines and common sense principles that should be applied when deploying services on a GNU/Linux system.
In particular, the following points are discussed:
- General principles of security and hardening
- Hardware and firmware configuration
- Securing the boot chain
- Configuring system services
- Kernel configuration
- Privilege and access management
- Isolation
The original version of the document, in French, can be found here.
Some of the versions below are obsolete and offered for archival purposes only.
This guide is accompanied by the tool ‘Actionnable Linux’, available at the URL https://github.com/ANSSI-FR/actionnable-linux. It is an Ansible role that provides, for illustrative purposes only, one way of implementing certain recommendations from the guide. The publication of this tool is part of ANSSI’s open-source policy, which aims to share with the cybersecurity community the code it produces. It enables the ecosystem to reuse the tool and thus contributes to improving the security of its information systems.
