| 1.147 SOL-11.1-060130 | CIS Solaris 11 X86 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 10.1 SN.1 Restrict access to suspend feature | CIS Solaris 11.1 L2 v1.0.0 | Unix | ACCESS CONTROL |
| SOL-11.1-010070 - The audit system records must be able to be used by a report generation capability. | DISA Solaris 11 SPARC STIG v3r6 | Unix | AUDIT AND ACCOUNTABILITY |
| SOL-11.1-010130 - The operating system must support the capability to compile audit records from multiple components within the system into a system-wide (logical or physical) audit trail that is time-correlated to within organization-defined level of tolerance. | DISA Solaris 11 SPARC STIG v3r6 | Unix | AUDIT AND ACCOUNTABILITY |
| SOL-11.1-010150 - Audit records must include when (date and time) the events occurred. | DISA Solaris 11 SPARC STIG v3r6 | Unix | AUDIT AND ACCOUNTABILITY |
| SOL-11.1-010160 - Audit records must include where the events occurred. | DISA Solaris 11 SPARC STIG v3r6 | Unix | AUDIT AND ACCOUNTABILITY |
| SOL-11.1-010170 - Audit records must include the sources of the events that occurred. | DISA Solaris 11 SPARC STIG v3r6 | Unix | AUDIT AND ACCOUNTABILITY |
| SOL-11.1-010250 - The audit system must be configured to audit account modification. | DISA Solaris 11 SPARC STIG v3r6 | Unix | ACCESS CONTROL |
| SOL-11.1-010270 - The operating system must automatically audit account termination. | DISA Solaris 11 SPARC STIG v3r6 | Unix | ACCESS CONTROL |
| SOL-11.1-010290 - The operating system must ensure unauthorized, security-relevant configuration changes detected are tracked. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-010340 - The audit system must be configured to audit failed attempts to access files and programs. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-010350 - The operating system must protect against an individual falsely denying having performed a particular action. In order to do so the system must be configured to send audit records to a remote audit server. | DISA Solaris 11 SPARC STIG v3r6 | Unix | AUDIT AND ACCOUNTABILITY |
| SOL-11.1-010360 - The auditing system must not define a different auditing level for specific users. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-010400 - The operating system must allocate audit record storage capacity. | DISA Solaris 11 SPARC STIG v3r6 | Unix | AUDIT AND ACCOUNTABILITY |
| SOL-11.1-020530 - X displays must not be exported to the world. | DISA Solaris 11 SPARC STIG v3r6 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| SOL-11.1-040040 - User passwords must be at least 15 characters in length. | DISA Solaris 11 SPARC STIG v3r6 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SOL-11.1-040070 - The system must require passwords to contain at least one uppercase alphabetic character. | DISA Solaris 11 SPARC STIG v3r6 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SOL-11.1-040100 - The system must require passwords to contain at least one special character. | DISA Solaris 11 SPARC STIG v3r6 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SOL-11.1-040140 - The system must disable accounts after three consecutive unsuccessful login attempts. | DISA Solaris 11 SPARC STIG v3r6 | Unix | ACCESS CONTROL |
| SOL-11.1-040260 - The default umask for FTP users must be 077. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-040310 - Login services for serial ports must be disabled. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-040315 - Access to a domain console via telnet must be restricted to the local host. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-040316 - Access to a logical domain console must be restricted to authorized users. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-040480 - The operating system must not allow logins for users with blank passwords. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-040500 - The operating system must limit the number of concurrent sessions for each account to an organization-defined number of sessions. | DISA Solaris 11 SPARC STIG v3r6 | Unix | ACCESS CONTROL |
| SOL-11.1-050010 - The system must disable directed broadcast packet forwarding. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-050070 - The system must ignore ICMP redirect messages. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-050140 - The system must implement TCP Wrappers. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-050390 - The operating system must display the DoD approved system use notification message or banner for SSH connections. | DISA Solaris 11 SPARC STIG v3r6 | Unix | ACCESS CONTROL |
| SOL-11.1-060080 - The operating system must employ cryptographic mechanisms to recognize changes to information during transmission unless otherwise protected by alternative physical measures. | DISA Solaris 11 SPARC STIG v3r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| SOL-11.1-060090 - The operating system must maintain the integrity of information during aggregation, packaging, and transformation in preparation for transmission. | DISA Solaris 11 SPARC STIG v3r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| SOL-11.1-060140 - The operating system must use cryptographic mechanisms to protect and restrict access to information on portable digital media. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-060180 - The operating system must use cryptographic mechanisms to protect the integrity of audit information. | DISA Solaris 11 SPARC STIG v3r6 | Unix | AUDIT AND ACCOUNTABILITY |
| SOL-11.1-070030 - Permissions on user . (hidden) files must be 750 or less permissive. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-070070 - Users must have a valid home directory assignment. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-070080 - All user accounts must be configured to use a home directory that exists. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-070120 - Duplicate Group IDs (GIDs) must not exist for multiple groups. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-070240 - The operating system must reveal error messages only to authorized personnel. | DISA Solaris 11 SPARC STIG v3r6 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| SOL-11.1-080020 - The system must implement non-executable program stacks. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-080050 - The centralized process core dump data directory must be owned by root. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-080110 - The kernel core dump data directory must have mode 0700 or less permissive. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-080150 - The operating system must implement transaction recovery for transaction-based systems. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-090060 - The operating system must conduct backups of system-level information contained in the information system per organization-defined frequency to conduct backups that are consistent with recovery time and recovery point objectives. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-090070 - The operating system must conduct backups of operating system documentation including security-related documentation per organization-defined frequency to conduct backups that is consistent with recovery time and recovery point objectives. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-090100 - The operating system must prevent the execution of prohibited mobile code. | DISA Solaris 11 SPARC STIG v3r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| SOL-11.1-090115 - The operating system must employ PKI solutions at workstations, servers, or mobile computing devices on the network to create, manage, distribute, use, store, and revoke digital certificates. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-100020 - The limitpriv zone option must be set to the vendor default or less permissive. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-100030 - The systems physical devices must not be assigned to non-global zones. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-100040 - The audit system must identify in which zone an event occurred. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |
| SOL-11.1-100050 - The audit system must maintain a central audit trail for all zones. | DISA Solaris 11 SPARC STIG v3r6 | Unix | CONFIGURATION MANAGEMENT |