Item Search

NameAudit NamePluginCategory
SOL-11.1-010100 - The audit records must provide data for all auditable events defined at the organizational level for the organization-defined information system components.DISA Solaris 11 SPARC STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-010260 - The operating system must automatically audit account disabling actions.DISA Solaris 11 SPARC STIG v3r6Unix

ACCESS CONTROL

SOL-11.1-010300 - The audit system must be configured to audit all administrative, privileged, and security actions.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-010330 - The audit system must be configured to audit the loading and unloading of dynamic kernel modules.DISA Solaris 11 SPARC STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-010390 - The operating system must alert designated organizational officials in the event of an audit processing failure.DISA Solaris 11 SPARC STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-010440 - The operating system must protect audit information from unauthorized access.DISA Solaris 11 SPARC STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-020020 - The system must verify that package updates are digitally signed.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020030 - The operating system must protect audit tools from unauthorized access.DISA Solaris 11 SPARC STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-020090 - The finger daemon package must not be installed.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020100 - The legacy remote network access utilities daemons must not be installed.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020110 - The NIS package must not be installed.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020130 - The FTP daemon must not be installed unless required.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020140 - The TFTP service daemon must not be installed unless required.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020150 - The telnet service daemon must not be installed unless required.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020160 - The UUCP service daemon must not be installed unless required.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020180 - The VNC server package must not be installed unless required.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020220 - The operating system must be configured to provide essential capabilities.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020330 - Run control scripts library search paths must contain only authorized paths.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020340 - Run control scripts lists of preloaded libraries must contain only authorized paths.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020350 - Run control scripts must not execute world writable programs or scripts.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020380 - System start-up files must only execute programs owned by a privileged UID or an application.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020500 - Any X Windows host must write .Xauthority files.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020520 - The .Xauthority files must not have extended ACLs.DISA Solaris 11 SPARC STIG v3r6Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

SOL-11.1-040020 - The operating system must automatically terminate temporary accounts within 72 hours.DISA Solaris 11 SPARC STIG v3r6Unix

ACCESS CONTROL

SOL-11.1-040120 - The system must not have accounts configured with blank or null passwords.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-040130 - Systems must employ cryptographic hashes for passwords using the SHA-2 family of algorithms or FIPS 140-2 approved successors.DISA Solaris 11 SPARC STIG v3r6Unix

IDENTIFICATION AND AUTHENTICATION

SOL-11.1-040330 - X11 forwarding for SSH must be disabled.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-040350 - The rhost-based authentication for SSH must be disabled.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-040430 - Logins to the root account must be restricted to the system console only.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-050020 - The system must not respond to ICMP timestamp requests.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-050120 - The system must set maximum number of incoming connections to 1024.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-060070 - The operating system must protect the integrity of transmitted information.DISA Solaris 11 SPARC STIG v3r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SOL-11.1-060110 - The operating system must employ cryptographic mechanisms to prevent unauthorized disclosure of information during transmission unless otherwise protected by alternative physical measures.DISA Solaris 11 SPARC STIG v3r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SOL-11.1-060120 - The operating system must maintain the confidentiality of information during aggregation, packaging, and transformation in preparation for transmission.DISA Solaris 11 SPARC STIG v3r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SOL-11.1-060150 - The operating system must employ cryptographic mechanisms to protect information in storage.DISA Solaris 11 SPARC STIG v3r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SOL-11.1-060160 - The operating system must protect the confidentiality and integrity of information at rest.DISA Solaris 11 SPARC STIG v3r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SOL-11.1-070040 - Permissions on user .netrc files must be 750 or less permissive.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-070060 - Groups assigned to users must exist in the /etc/group file.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-070100 - Duplicate User IDs (UIDs) must not exist for users within the organization.DISA Solaris 11 SPARC STIG v3r6Unix

IDENTIFICATION AND AUTHENTICATION

SOL-11.1-070150 - Duplicate group names must not exist.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-070190 - All valid SUID/SGID files must be documented.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-080010 - The operating system must be a supported release.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-080045 - The system must be configured to store any process core dumps in a specific, centralized directory.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-080060 - The centralized process core dump data directory must be group-owned by root, bin, or sys.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-080080 - Kernel core dumps must be disabled unless needed.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-090010 - A file integrity baseline must be created, maintained, and reviewed at least weekly to determine if unauthorized changes have been made to important system files located in the root file system.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-090030 - Direct logins must not be permitted to shared, default, application, or utility accounts.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-090040 - The system must not have any unnecessary accounts.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-090240 - All manual editing of system-relevant files shall be done using the pfedit command, which logs changes made to the files.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-090280 - The operating system must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial of service attacks.DISA Solaris 11 SPARC STIG v3r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION