Item Search

NameAudit NamePluginCategory
AIX7-00-001004 - AIX must limit the number of concurrent sessions to 10 for all accounts and/or account types.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-001010 - The AIX SYSTEM attribute must not be set to NONE for any account.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001011 - Direct logins to the AIX system must not be permitted to shared accounts, default accounts, application accounts, and utility accounts.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001016 - The regular users default primary group must be staff (or equivalent) on AIX.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-001025 - AIX must configure the ttys value for all interactive users.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001040 - The AIX root accounts home directory must not have an extended ACL.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001045 - IF LDAP is used, AIX LDAP client must use SSL to authenticate with LDAP server.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001056 - AIX nosuid option must be enabled on all NFS client mounts.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001102 - AIX must employ strong authenticators in the establishment of nonlocal maintenance and diagnostic sessions.DISA IBM AIX 7.x STIG v3r3Unix

MAINTENANCE

AIX7-00-001104 - If LDAP authentication is required on AIX, SSL must be used between LDAP clients and the LDAP servers to protect the integrity of remote access sessions.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-001120 - AIX must enforce password complexity by requiring that at least one upper-case character be used.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001121 - AIX must enforce password complexity by requiring that at least one lower-case character be used.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001124 - AIX root passwords must never be passed over a network in clear text form.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001125 - AIX Operating systems must enforce 24 hours/1 day as the minimum password lifetime.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001128 - AIX must use Loadable Password Algorithm (LPA) password hashing algorithm.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001132 - AIX must prevent the use of dictionary words for passwords.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001135 - If SNMP service is enabled on AIX, the default SNMP password must not be used in the /etc/snmpd.conf config file.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002014 - Audit logs on the AIX system must be group-owned by system.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002026 - AIX audit tools must be group-owned by audit.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002027 - AIX audit tools must be set to 4550 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002033 - AIX must allocate audit record storage capacity to store at least one weeks worth of audit records, when audit records are not immediately sent to a central audit record storage facility.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002038 - AIX must record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002057 - AIX audit logs must be rotated daily.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002059 - AIX telnet daemon must not be running.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-002061 - AIX must remove NOPASSWD tag from sudo config files.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-002071 - AIX log files must be owned by a system group.DISA IBM AIX 7.x STIG v3r3Unix

SYSTEM AND INFORMATION INTEGRITY

AIX7-00-002078 - AIX cron and crontab directories must be owned by root or bin.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002081 - AIX time synchronization configuration file must be owned by root.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002083 - The AIX /etc/group file must be owned by root.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002091 - The AIX /etc/group file must have mode 0644 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002104 - The AIX SSH server must use SSH Protocol 2.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-002114 - AIX must turn on SSH daemon privilege separation.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002142 - The AIX /etc/hosts file must have a mode of 0640 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002145 - The AIX /etc/syslog.conf file must be group-owned by system.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002202 - The AIX audit configuration files must be set to 640 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-003000 - AIX must automatically lock after 15 minutes of inactivity in the CDE Graphical desktop environment.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-003004 - AIX SSH private host key files must have mode 0600 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-003013 - AIX passwd.nntp file must have mode 0600 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003055 - If AIX server is not functioning as a network router, the routed daemon must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003056 - If rwhod is not required on AIX, the rwhod daemon must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003061 - The aixmibd daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003082 - The imap2 service must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003090 - If automated file system mounting tool is not required on AIX, it must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-003097 - AIX must protect against or limit the effects of Denial of Service (DoS) attacks by ensuring AIX is implementing rate-limiting measures on impacted network interfaces.DISA IBM AIX 7.x STIG v3r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

AIX7-00-003099 - AIX must allow admins to send a message to a user who logged in currently.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-003100 - The AIX SSH daemon must be configured to only use FIPS 140-2 approved ciphers.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-003125 - All AIX files and directories must have a valid group owner.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003134 - AIX must not process ICMP timestamp requests.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003135 - AIX must not respond to ICMPv6 echo requests sent to a broadcast address.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003140 - The AIX root user home directory must not be the root directory (/).DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT