Item Search

NameAudit NamePluginCategory
AIX7-00-001108 - AIX must implement NIST FIPS-validated cryptography for the following: to provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

AIX7-00-001130 - AIX must enforce password complexity by requiring that at least one special character be used.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001137 - AIX must be able to control the ability of remote login for users.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-001138 - NFS file systems on AIX must be mounted with the nosuid option unless the NFS file systems contain approved setuid or setgid programs.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-002003 - AIX must produce audit records containing information to establish where the events occurred.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002011 - AIX must provide the function to filter audit records for events of interest based upon all audit fields within audit records, support on-demand reporting requirements, and an audit reduction function that supports on-demand audit review and analysis and after-the-fact investigations of security incidents.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002060 - AIX ftpd daemon must not be running.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-002066 - AIX must not have IP forwarding for IPv6 enabled unless the system is an IPv6 router.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002079 - AIX audio devices must be group-owned by root, sys, bin, or system.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002088 - AIX library files must have mode 0755 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002090 - AIX time synchronization configuration file must have mode 0640 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002092 - The inetd.conf file on AIX must be group owned by the "system" group.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002093 - The AIX /etc/inetd.conf file must have a mode of 0640 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002097 - AIX must protect the confidentiality and integrity of transmitted information during preparation for transmission and maintain the confidentiality and integrity of information during reception and disable all non-encryption network access methods.DISA IBM AIX 7.x STIG v3r3Unix

MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

AIX7-00-002100 - AIX must monitor and record successful remote logins.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-002102 - On AIX, the SSH server must not permit root logins using remote access programs.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002103 - All AIX shells referenced in passwd file must be listed in /etc/shells file, except any shells specified for the purpose of preventing logins.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002105 - AIX must config the SSH idle timeout interval.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

AIX7-00-002111 - AIX SSH daemon must be configured to only use Message Authentication Codes (MACs) employing FIPS 140-2 approved cryptographic hash algorithms.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002112 - The AIX SSH daemon must be configured for IP filtering.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002113 - The AIX SSH daemon must not allow compression.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002115 - AIX must turn on SSH daemon reverse name checking.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002116 - AIX SSH daemon must perform strict mode checking of home directory configuration files.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002118 - AIX must turn off TCP forwarding for the SSH daemon.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002120 - The AIX SSH daemon must be configured to disable empty passwords.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002121 - The AIX SSH daemon must be configured to disable user .rhosts files.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002122 - The AIX SSH daemon must be configured to not use host-based authentication.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002123 - The AIX SSH daemon must not allow RhostsRSAAuthentication.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002141 - The AIX /etc/hosts file must be group-owned by system.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002148 - The AIX /var/spool/cron/atjobs directory must be group-owned by cron.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002200 - The AIX audit configuration files must be owned by root.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-003007 - AIX log files must not have extended ACLs, except as needed to support authorized software.DISA IBM AIX 7.x STIG v3r3Unix

SYSTEM AND INFORMATION INTEGRITY

AIX7-00-003010 - All library files must not have extended ACLs.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003038 - AIX sendmail logging must not be set to less than nine in the sendmail.cf file.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003039 - AIX run control scripts executable search paths must contain only absolute paths.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003050 - If DHCP is not enabled in the network on AIX, the dhcprd daemon must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003067 - The uucp (UNIX to UNIX Copy Program) daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003072 - The discard daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003073 - The dtspc daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003075 - The rstatd daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003088 - If Stream Control Transmission Protocol (SCTP) must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003101 - The AIX system must have no .netrc files on the system.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-003105 - The rwalld daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003111 - AIX public directories must be the only world-writable directories and world-writable files must be located only in public directories.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003120 - All global initialization file executable search paths must contain only absolute paths.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003122 - The SMTP service HELP command must not be enabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003126 - AIX control scripts library search paths must contain only absolute paths.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003143 - AIX must employ a deny-all, allow-by-exception firewall policy for allowing connections to other systems.DISA IBM AIX 7.x STIG v3r3Unix

SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT

AIX7-00-003200 - The AIX operating system must use Multi Factor Authentication.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-003205 - The AIX operating system must accept and verify Personal Identity Verification (PIV) credentials.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION