| 2.5 Ensure all files and directories are owned by a user (uid) and assigned to a group (gid) - gid | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 3.1.2.1 Disable ntalk/talk/write - writesrv | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | CONFIGURATION MANAGEMENT |
| 3.1.2.18 timed | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | CONFIGURATION MANAGEMENT |
| 3.1.4.5 NFS - no root access via NFS exports | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | CONFIGURATION MANAGEMENT |
| 3.1.5.5 discard | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | CONFIGURATION MANAGEMENT |
| 3.1.5.6 echo | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | CONFIGURATION MANAGEMENT |
| 3.1.5.8 finger | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | CONFIGURATION MANAGEMENT |
| 3.1.5.11 instsrv | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | CONFIGURATION MANAGEMENT |
| 3.1.5.14 login | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | CONFIGURATION MANAGEMENT |
| 3.1.5.21 rstatd | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | CONFIGURATION MANAGEMENT |
| 3.1.5.23 rwalld | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | CONFIGURATION MANAGEMENT |
| 3.1.5.27 talk | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | CONFIGURATION MANAGEMENT |
| 3.1.5.30 time | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | CONFIGURATION MANAGEMENT |
| 3.3.1 bcastping | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | CONFIGURATION MANAGEMENT |
| 3.3.3 directed_broadcast | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 3.3.4 icmpaddressmask | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 3.3.5 ipforwarding | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 3.3.6 ipignoreredirects | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 3.3.12 nfs_use_reserved_ports - portcheck | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | CONFIGURATION MANAGEMENT |
| 3.3.13 nonlocsrcroute | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 3.3.14 sockthresh | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 3.3.15 tcp_pmtu_discover | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 3.4.1 /etc/security/login.cfg - logintimeout - logintimeout | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | ACCESS CONTROL |
| 3.4.2 /etc/security/login.cfg - logindelay - logindelay | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | ACCESS CONTROL |
| 3.4.5 /etc/security/login.cfg - pwd_algorithm | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 3.4.6 Unattended terminal session timeout is 900 seconds (or less) - readonly | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | ACCESS CONTROL |
| 3.6.1.3 OpenSSH - Banner - banner text | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | ACCESS CONTROL |
| 3.6.1.4 Ensure SSH IgnoreRhosts is enabled | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | CONFIGURATION MANAGEMENT |
| 3.6.1.6 Configuring SSH - disallow host based authentication | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 3.6.1.7 Configuring SSH - removal of .shosts files | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | CONFIGURATION MANAGEMENT |
| 3.6.1.13 Ignore user-provided environment variables | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | CONFIGURATION MANAGEMENT |
| 3.6.2.2 /etc/mail/sendmail.cf - permissions and ownership | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 3.6.3.1 FTPD: Prevent world access and group write to files | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 3.6.3.3 FTPD: Disable root access to ftp | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | ACCESS CONTROL |
| 3.7.1.1 Ensure all directories in root PATH deny write access to all | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 3.7.2.1 crontab entries - owned by userid - owned by userid | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 3.7.2.8 /etc/ssh/ssh_config | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 3.7.2.10 /var/adm/cron/at.allow | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 3.7.2.15 /var/tmp/hostmibd.log | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 3.9 Ensure root access is controlled - sugroups | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 3.14 Configuration: /etc/motd | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | CONFIGURATION MANAGEMENT |
| 4.1.1 All accounts must have a hashed password | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 4.2.4 maxexpired | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | ACCESS CONTROL |
| 4.2.14 minupperalpha | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 4.3.1 adm | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 4.3.3 daemon | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE |
| 4.3.4 guest | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 4.3.7 nuucp | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.6 Adding authorised users in cron.allow | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | ACCESS CONTROL |
| 6.1.1 Configuring syslog - local logging - auth.info in /etc/syslog.conf | CIS IBM AIX 7.1 L1 v2.1.0 | Unix | AUDIT AND ACCOUNTABILITY |