GEN000000-AIX00060 - A baseline of AIX files with the TCB bit set must be checked weekly.

Information

If a baseline of files with the TCB bit set is not kept and checked weekly, the system could be compromised without the knowledge of any authority.

Solution

Add tcbck command as a weekly cronjob with the output sent to the SA.

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip