<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CIS Benchmark on PlumePHP</title><link>https://plumephp.com/tags/cis-benchmark/</link><description>Recent content in CIS Benchmark on PlumePHP</description><generator>Hugo</generator><language>zh-CN</language><lastBuildDate>Sun, 27 Sep 2026 14:50:00 +0800</lastBuildDate><atom:link href="https://plumephp.com/tags/cis-benchmark/index.xml" rel="self" type="application/rss+xml"/><item><title>系统安全基线配置与加固实战</title><link>https://plumephp.com/security-hardening-baseline/</link><pubDate>Sun, 27 Sep 2026 14:50:00 +0800</pubDate><guid>https://plumephp.com/security-hardening-baseline/</guid><description>&lt;h2 id="导语安全基线的意义是默认配置不安全"&gt;导语：安全基线的意义是&amp;quot;默认配置不安全&amp;quot;&lt;/h2&gt;
&lt;p&gt;大多数被入侵的主机，问题都不在某个高级漏洞，而是&lt;strong&gt;基础配置不当&lt;/strong&gt;：root 可以直接 SSH 登录、22 端口对公网开放、用户口令永不失效、日志没开审计、任意用户都能 sudo。安全基线（Hardening Baseline）就是把&amp;quot;不安全的默认值&amp;quot;改成&amp;quot;经评估的安全值&amp;quot;，并&lt;strong&gt;用自动化工具持续校验，防止配置漂移&lt;/strong&gt;。&lt;/p&gt;</description></item><item><title>配置漂移与安全基线：IaC漂移检测、CIS合规、供应链安全与密钥轮换</title><link>https://plumephp.com/config-drift-security/</link><pubDate>Sun, 27 Sep 2026 12:00:00 +0800</pubDate><guid>https://plumephp.com/config-drift-security/</guid><description>&lt;h2 id="引言"&gt;引言&lt;/h2&gt;
&lt;p&gt;&amp;ldquo;基础设施即代码&amp;quot;承诺了一件事：&lt;strong&gt;集群里的现实 = 仓库里的声明&lt;/strong&gt;。但现实中，这条等式经常被打破——有人为了排查故障手工 SSH 改了配置、某个自动化脚本直接调云 API 改了安全组、某个 AWS 控制台操作让数据库变成了公网可访问。当声明（Desired State）与现实（Actual State）不一致时，系统进入了**配置漂移（Configuration Drift）**状态。漂移的危害不只是&amp;quot;配置不一致&amp;rdquo;，更严重的是：&lt;strong&gt;安全基线被悄悄腐蚀&lt;/strong&gt;——合规基线要求关掉的端口被重新打开、要加密的存储桶被改成了私有、要轮换的密钥过期了三年。&lt;/p&gt;</description></item></channel></rss>