diff --git a/reports/sample-output.json b/reports/sample-output.json new file mode 100644 index 0000000..6ed587a --- /dev/null +++ b/reports/sample-output.json @@ -0,0 +1,228 @@ +{ + "meta": { + "standard": "IEC 62443-3-3", + "security_level": "SL2", + "target": "ics-gateway-01", + "timestamp": "2026-07-07T16:42:00+02:00", + "executed_by": "auditor" + }, + "summary": { + "total": 15, + "passed": 10, + "failed": 4, + "skipped": 1 + }, + "results": [ + { + "test_id": "IAC-01", + "category": "FR1 - Identification and Authentication Control", + "requirement": "SR 1.1 — Unique User Identification", + "description": "Every user account shall have a unique UID", + "passed": true, + "expected": "No duplicate UIDs in /etc/passwd", + "actual": "None found", + "severity": "high", + "remediation": "Change duplicate UIDs with: usermod -u " + }, + { + "test_id": "IAC-02", + "category": "FR1 - Identification and Authentication Control", + "requirement": "SR 1.3 — Account Management", + "description": "Default/unnecessary system accounts shall be removed or disabled", + "passed": false, + "expected": "No default accounts present", + "actual": "games\nftp", + "severity": "medium", + "remediation": "Delete default accounts: userdel " + }, + { + "test_id": "IAC-03", + "category": "FR1 - Identification and Authentication Control", + "requirement": "SR 1.3 — Account Management", + "description": "Human user accounts that have never logged in shall be reviewed", + "passed": false, + "expected": "No unused human accounts with valid shells", + "actual": "operator (shell: /bin/bash)", + "severity": "low", + "remediation": "Lock stale accounts: usermod -L " + }, + { + "test_id": "IAC-04", + "category": "FR1 - Identification and Authentication Control", + "requirement": "SR 1.4 — Identifier Strength", + "description": "No account shall have an empty or trivially-weak password hash", + "passed": true, + "expected": "All accounts have proper password hashes", + "actual": "All accounts OK", + "severity": "critical", + "remediation": "Set a password or lock the account: passwd -l " + }, + { + "test_id": "IAC-05", + "category": "FR1 - Identification and Authentication Control", + "requirement": "SR 1.5 — Authenticator Strength", + "description": "Password minimum length shall be ≥ 14 characters", + "passed": false, + "expected": "minlen >= 14 in /etc/security/pwquality.conf", + "actual": "minlen = 8", + "severity": "high", + "remediation": "Set minlen=14 in /etc/security/pwquality.conf" + }, + { + "test_id": "IAC-06", + "category": "FR1 - Identification and Authentication Control", + "requirement": "SR 1.5 — Authenticator Strength", + "description": "Password shall require at least 1 of each character class", + "passed": true, + "expected": "At least 3 character classes required", + "actual": "dcredit=-1\nucredit=-1\nlcredit=-1\nocredit=-1\nminclass=NOT SET", + "severity": "medium", + "remediation": "Set dcredit=-1, ucredit=-1, lcredit=-1, ocredit=-1 in pwquality.conf" + }, + { + "test_id": "IAC-07", + "category": "FR1 - Identification and Authentication Control", + "requirement": "SR 1.7 — Password Lifetime", + "description": "Password maximum age shall be ≤ 90 days", + "passed": true, + "expected": "PASS_MAX_DAYS ≤ 90", + "actual": "PASS_MAX_DAYS=90", + "severity": "medium", + "remediation": "Set PASS_MAX_DAYS 90 in /etc/login.defs" + }, + { + "test_id": "IAC-08", + "category": "FR1 - Identification and Authentication Control", + "requirement": "SR 1.7 — Password Lifetime", + "description": "Password minimum change interval shall be ≥ 1 day", + "passed": true, + "expected": "PASS_MIN_DAYS ≥ 1", + "actual": "PASS_MIN_DAYS=1", + "severity": "low", + "remediation": "Set PASS_MIN_DAYS 1 in /etc/login.defs" + }, + { + "test_id": "IAC-09", + "category": "FR1 - Identification and Authentication Control", + "requirement": "SR 1.11 — Unsuccessful Login Attempts", + "description": "Account lockout shall trigger after ≤ 5 failed attempts", + "passed": true, + "expected": "Account lockout configured with deny ≤ 5", + "actual": "3", + "severity": "high", + "remediation": "Configure pam_faillock in /etc/pam.d/common-auth: deny=5" + }, + { + "test_id": "IAC-10", + "category": "FR1 - Identification and Authentication Control", + "requirement": "SR 1.6 — Password History", + "description": "Password history shall prevent reuse of last 5+ passwords", + "passed": true, + "expected": "pam_pwhistory remember ≥ 5", + "actual": "remember=5", + "severity": "medium", + "remediation": "Add \"remember=5\" to pam_pwhistory.so in /etc/pam.d/common-password" + }, + { + "test_id": "UC-01", + "category": "FR2 — Use Control", + "requirement": "SR 2.1 — Authorization Enforcement", + "description": "No user shall have unrestricted NOPASSWD sudo access to all commands", + "passed": true, + "expected": "No NOPASSWD ALL entries in sudoers", + "actual": "None found", + "severity": "high", + "remediation": "Restrict sudo rules to specific commands and require authentication" + }, + { + "test_id": "UC-02", + "category": "FR2 — Use Control", + "requirement": "SR 2.1 — Authorization Enforcement", + "description": "/etc/sudoers shall be owned by root:root with mode 0440", + "passed": true, + "expected": "root:root 0440", + "actual": "root:root 0440", + "severity": "critical", + "remediation": "chown root:root /etc/sudoers && chmod 0440 /etc/sudoers" + }, + { + "test_id": "UC-03", + "category": "FR2 — Use Control", + "requirement": "SR 2.5 — Session Lock", + "description": "Interactive shell sessions shall timeout after ≤ 900 seconds", + "passed": true, + "expected": "TMOUT set between 1-900 seconds", + "actual": "TMOUT=900", + "severity": "medium", + "remediation": "Add \"readonly TMOUT=900\" to /etc/profile" + }, + { + "test_id": "UC-04", + "category": "FR2 — Use Control", + "requirement": "SR 2.4 — Audit Log Integrity", + "description": "Audit configuration shall be immutable (-e 2)", + "passed": false, + "expected": "audit.rules contains -e 2", + "actual": "Immutable flag NOT set", + "severity": "high", + "remediation": "Add \"-e 2\" to /etc/audit/audit.rules (requires reboot)" + }, + { + "test_id": "UC-05", + "category": "FR2 — Use Control", + "requirement": "SR 2.8 — Auditable Events", + "description": "The audit daemon (auditd) shall be running and enabled", + "passed": true, + "expected": "auditd service is active", + "actual": "auditd is active", + "severity": "high", + "remediation": "systemctl enable --now auditd" + } + ], + "failures": [ + { + "test_id": "IAC-02", + "category": "FR1 - Identification and Authentication Control", + "requirement": "SR 1.3 — Account Management", + "description": "Default/unnecessary system accounts shall be removed or disabled", + "passed": false, + "expected": "No default accounts present", + "actual": "games\nftp", + "severity": "medium", + "remediation": "Delete default accounts: userdel " + }, + { + "test_id": "IAC-03", + "category": "FR1 - Identification and Authentication Control", + "requirement": "SR 1.3 — Account Management", + "description": "Human user accounts that have never logged in shall be reviewed", + "passed": false, + "expected": "No unused human accounts with valid shells", + "actual": "operator (shell: /bin/bash)", + "severity": "low", + "remediation": "Lock stale accounts: usermod -L " + }, + { + "test_id": "IAC-05", + "category": "FR1 - Identification and Authentication Control", + "requirement": "SR 1.5 — Authenticator Strength", + "description": "Password minimum length shall be ≥ 14 characters", + "passed": false, + "expected": "minlen >= 14 in /etc/security/pwquality.conf", + "actual": "minlen = 8", + "severity": "high", + "remediation": "Set minlen=14 in /etc/security/pwquality.conf" + }, + { + "test_id": "UC-04", + "category": "FR2 — Use Control", + "requirement": "SR 2.4 — Audit Log Integrity", + "description": "Audit configuration shall be immutable (-e 2)", + "passed": false, + "expected": "audit.rules contains -e 2", + "actual": "Immutable flag NOT set", + "severity": "high", + "remediation": "Add \"-e 2\" to /etc/audit/audit.rules (requires reboot)" + } + ] +}