BigFix Compliance: Updated CIS Red Hat Enterprise Linux 9 with bugfixes, published 2026-04-22

Product:
BigFix Compliance

Title:
Updated CIS Red Hat Enterprise Linux 9 with bugfixes.

Security Benchmark:
CIS Red Hat Enterprise Linux 9 Benchmark, v2.0.0

Published Sites:
CIS Checklist for RHEL 9, site version 13
(The site version is provided for air-gap customers.)

Details:

Updated Fixlets:

· Updated the Deploy and Run Task.

· Fixed the Measured Value and the Metadata.

· Ensure system accounts do not have a valid login shell

· Ensure accounts without a valid login shell are locked

· Ensure GDM login banner is configured

· Ensure events that modify user/group information are collected

· Ensure nftables is installed

· Ensure SELinux is not disabled in bootloader configuration

· Ensure the SELinux mode is not disabled

· Ensure active authselect profile includes pam modules

· Ensure password history is enforced for the root user

· Ensure cryptographic mechanisms are used to protect the integrity of audit tools

· Ensure unsuccessful file access attempts are collected

Additional details:

· Both analysis and remediation checks are included

· Some of the checks allow you to use the parameterized setting to enable customization for compliance evaluation. Note that parameterization and remediation actions require the creation of a custom site.

· Improved few checks by adding the pending restart feature to them. The pending restart feature works in the following ways:

· The action results will show “Pending Restart” instead of “Fixed” for those checks which requires OS reboot.

· The check will show relevant for those endpoints until they are rebooted.

· Post reboot of the endpoint the action results will show as “Fixed”, and the check will be compliant.

Actions to take:

More information:
To know more about the BigFix Compliance SCM checklists, please see the following resources:

We hope you find this latest release of SCM content useful and effective. Thank you!

– The BigFix Compliance team