| 1.149 SOL-11.1-060130 | CIS Solaris 11 SPARC STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 8.4 Enable a Warning Banner for the GNOME Service | CIS Oracle Solaris 11.4 L1 v1.1.0 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| SOL-11.1-010040 - The audit system must produce records containing sufficient information to establish the identity of any user/subject associated with the event. | DISA Solaris 11 SPARC STIG v3r6 | Unix | AUDIT AND ACCOUNTABILITY |
| SOL-11.1-010060 - The audit system must support an audit reduction capability. | DISA Solaris 11 SPARC STIG v3r6 | Unix | AUDIT AND ACCOUNTABILITY |
| SOL-11.1-010080 - The operating system must provide the capability to automatically process audit records for events of interest based upon selectable, event criteria. | DISA Solaris 11 SPARC STIG v3r6 | Unix | AUDIT AND ACCOUNTABILITY |
| SOL-11.1-010180 - Audit records must include the outcome (success or failure) of the events that occurred. | DISA Solaris 11 SPARC STIG v3r6 | Unix | AUDIT AND ACCOUNTABILITY |
| SOL-11.1-010220 - The audit system must be configured to audit file deletions. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-010230 - The audit system must be configured to audit account creation. | DISA Solaris 11 SPARC STIG v3r6 | Unix | ACCESS CONTROL |
| SOL-11.1-010310 - The audit system must be configured to audit login, logout, and session initiation. | DISA Solaris 11 SPARC STIG v3r6 | Unix | ACCESS CONTROL |
| SOL-11.1-010320 - The audit system must be configured to audit all discretionary access control permission modifications. | DISA Solaris 11 SPARC STIG v3r6 | Unix | AUDIT AND ACCOUNTABILITY |
| SOL-11.1-010370 - The audit system must alert the SA when the audit storage volume approaches its capacity. | DISA Solaris 11 SPARC STIG v3r6 | Unix | AUDIT AND ACCOUNTABILITY |
| SOL-11.1-020050 - The operating system must protect audit tools from unauthorized deletion. | DISA Solaris 11 SPARC STIG v3r6 | Unix | AUDIT AND ACCOUNTABILITY |
| SOL-11.1-020080 - System packages must be configured with the vendor-provided files, permissions, and ownerships. | DISA Solaris 11 SPARC STIG v3r6 | Unix | AUDIT AND ACCOUNTABILITY |
| SOL-11.1-020170 - The rpcbind service must be configured for local only services unless organizationally defined. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-020190 - The operating system must employ automated mechanisms, per organization-defined frequency, to detect the addition of unauthorized components/devices into the operating system. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-020300 - All run control scripts must have mode 0755 or less permissive. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-020360 - All system start-up files must be owned by root. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-020370 - All system start-up files must be group-owned by root, sys, or bin. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-020510 - All .Xauthority files must have mode 0600 or less permissive. | DISA Solaris 11 SPARC STIG v3r6 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| SOL-11.1-020550 - The .Xauthority utility must only permit access to authorized hosts. | DISA Solaris 11 SPARC STIG v3r6 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| SOL-11.1-030030 - Generic Security Services (GSS) must be disabled. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-040090 - The system must require passwords to contain at least one numeric character. | DISA Solaris 11 SPARC STIG v3r6 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SOL-11.1-040160 - The delay between login prompts following a failed login attempt must be at least 4 seconds. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-040180 - Graphical desktop environments provided by the system must automatically lock after 15 minutes of inactivity. | DISA Solaris 11 SPARC STIG v3r6 | Unix | ACCESS CONTROL |
| SOL-11.1-040250 - The default umask for system and users must be 077. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-040270 - The value mesg n must be configured as the default setting for all users. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-040360 - Direct root account login must not be permitted for SSH access. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-040370 - Login must not be permitted with empty/null passwords for SSH. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-040380 - The operating system must terminate the network connection associated with a communications session at the end of the session or after 10 minutes of inactivity. | DISA Solaris 11 SPARC STIG v3r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| SOL-11.1-040390 - Host-based authentication for login-based services must be disabled. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-040400 - The use of FTP must be restricted. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-040420 - Unauthorized use of the at or cron capabilities must not be permitted. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-050110 - The system must set maximum number of half-open TCP connections to 4096. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-050130 - The system must disable network routing unless required. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-050370 - The system must prevent local applications from generating source-routed packets. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-050430 - The FTP service must display the DOD-approved system use notification message or banner before granting access to the system. | DISA Solaris 11 SPARC STIG v3r6 | Unix | ACCESS CONTROL |
| SOL-11.1-050480 - Wireless network adapters must be disabled. | DISA Solaris 11 SPARC STIG v3r6 | Unix | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION |
| SOL-11.1-060010 - The operating system must use mechanisms for authentication to a cryptographic module meeting the requirements of applicable federal laws, Executive orders, directives, policies, regulations, standards, and guidance for such authentication. | DISA Solaris 11 SPARC STIG v3r6 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SOL-11.1-060060 - The operating system must employ FIPS-validate or NSA-approved cryptography to implement digital signatures. | DISA Solaris 11 SPARC STIG v3r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| SOL-11.1-070010 - The sticky bit must be set on all world writable directories. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-070200 - The operating system must have no unowned files. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-070220 - The root account must be the only account with GID of 0. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-070250 - The operating system must protect the audit records resulting from non-local accesses to privileged accounts and the execution of privileged functions. | DISA Solaris 11 SPARC STIG v3r6 | Unix | ACCESS CONTROL |
| SOL-11.1-080070 - The centralized process core dump data directory must have mode 0700 or less permissive. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-080100 - The kernel core dump data directory must be group-owned by root. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-080130 - The system must require passwords to change the boot device settings. (SPARC) | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-090020 - The operating system must synchronize internal information system clocks with a server that is synchronized to one of the redundant United States Naval Observatory (USNO) time servers or a time server designated for the appropriate DOD network (NIPRNet/SIPRNet), and/or the Global Positioning System (GPS). | DISA Solaris 11 SPARC STIG v3r6 | Unix | AUDIT AND ACCOUNTABILITY |
| SOL-11.1-090120 - The operating system must prevent non-privileged users from circumventing malicious code protection capabilities. | DISA Solaris 11 SPARC STIG v3r6 | Unix | ACCESS CONTROL |
| SOL-11.1-090270 - The operating system must identify potentially security-relevant error conditions. | DISA Solaris 11 SPARC STIG v3r6 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| SOL-11.1-120410 - The operating system must monitor for unauthorized connections of mobile devices to organizational information systems. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |