| AIX7-00-001000 - AIX /etc/security/mkuser.sys.custom file must not exist unless it is needed for customizing a new user account. | DISA IBM AIX 7.x STIG v3r3 | Unix | ACCESS CONTROL |
| AIX7-00-001007 - If AIX is using LDAP for authentication or account information, the /etc/ldap.conf file (or equivalent) must not contain passwords. | DISA IBM AIX 7.x STIG v3r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| AIX7-00-001014 - The AIX system must automatically remove or disable emergency accounts after the crisis is resolved or 72 hours. | DISA IBM AIX 7.x STIG v3r3 | Unix | ACCESS CONTROL |
| AIX7-00-001019 - AIX device files and directories must only be writable by users with a system account or as configured by the vendor. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-001028 - AIX must provide the lock command to let users retain their session lock until users are reauthenticated. | DISA IBM AIX 7.x STIG v3r3 | Unix | ACCESS CONTROL |
| AIX7-00-001031 - All AIX public directories must be owned by root or an application account. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-001033 - AIX default system accounts (with the exception of root) must not be listed in the cron.allow file or must be included in the cron.deny file, if cron.allow does not exist. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-001035 - The Group Identifiers (GIDs) reserved for AIX system accounts must not be assigned to non-system accounts as their primary group GID. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-001036 - UIDs reserved for system accounts must not be assigned to non-system accounts on AIX systems. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-001037 - The AIX root accounts list of preloaded libraries must be empty. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-001047 - The AIX /etc/passwd, /etc/security/passwd, and/or /etc/group files must not contain a plus (+) without defining entries for NIS+ netgroups or LDAP netgroups. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-001122 - AIX must enforce password complexity by requiring that at least one numeric character be used. | DISA IBM AIX 7.x STIG v3r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| AIX7-00-001129 - AIX must enforce a minimum 15-character password length. | DISA IBM AIX 7.x STIG v3r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| AIX7-00-001134 - The password hashes stored on AIX system must have been generated using a FIPS 140-2 approved cryptographic hashing algorithm. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-001139 - AIX removable media, remote file systems, and any file system not containing approved device files must be mounted with the nodev option. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-002005 - AIX must produce audit records containing information to establish the outcome of the events. | DISA IBM AIX 7.x STIG v3r3 | Unix | AUDIT AND ACCOUNTABILITY |
| AIX7-00-002006 - AIX must produce audit records containing the full-text recording of privileged commands. | DISA IBM AIX 7.x STIG v3r3 | Unix | AUDIT AND ACCOUNTABILITY |
| AIX7-00-002008 - AIX must be configured to generate an audit record when 75% of the audit file system is full. | DISA IBM AIX 7.x STIG v3r3 | Unix | AUDIT AND ACCOUNTABILITY |
| AIX7-00-002015 - Audit logs on the AIX system must be set to 660 or less permissive. | DISA IBM AIX 7.x STIG v3r3 | Unix | AUDIT AND ACCOUNTABILITY |
| AIX7-00-002016 - AIX must provide audit record generation functionality for DoD-defined auditable events. | DISA IBM AIX 7.x STIG v3r3 | Unix | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, MAINTENANCE |
| AIX7-00-002017 - AIX must be configured so that the audit system takes appropriate action when the audit storage volume is full. | DISA IBM AIX 7.x STIG v3r3 | Unix | AUDIT AND ACCOUNTABILITY |
| AIX7-00-002023 - AIX must start audit at boot. | DISA IBM AIX 7.x STIG v3r3 | Unix | AUDIT AND ACCOUNTABILITY |
| AIX7-00-002025 - AIX audit tools must be owned by root. | DISA IBM AIX 7.x STIG v3r3 | Unix | AUDIT AND ACCOUNTABILITY |
| AIX7-00-002028 - AIX must verify the hash of audit tools. | DISA IBM AIX 7.x STIG v3r3 | Unix | AUDIT AND ACCOUNTABILITY |
| AIX7-00-002032 - AIX must provide the function for assigned ISSOs or designated SAs to change the auditing to be performed on all operating system components, based on all selectable event criteria in near real time. | DISA IBM AIX 7.x STIG v3r3 | Unix | AUDIT AND ACCOUNTABILITY |
| AIX7-00-002036 - AIX must provide a report generation function that supports on-demand audit review and analysis, on-demand reporting requirements, and after-the-fact investigations of security incidents. | DISA IBM AIX 7.x STIG v3r3 | Unix | AUDIT AND ACCOUNTABILITY |
| AIX7-00-002058 - The AIX rexec daemon must not be running. | DISA IBM AIX 7.x STIG v3r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| AIX7-00-002063 - AIX must be configured with a default gateway for IPv4 if the system uses IPv4, unless the system is a router. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-002070 - AIX log files must be owned by a system account. | DISA IBM AIX 7.x STIG v3r3 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| AIX7-00-002077 - The inetd.conf file on AIX must be owned by root. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-002084 - The AIX /etc/group file must be group-owned by security. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-002085 - All AIX interactive users home directories must be owned by their respective users. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-002086 - All AIX interactive users home directories must be group-owned by the home directory owner primary group. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-002089 - Samba packages must be removed from AIX. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-002096 - AIX must encrypt user data at rest using AIX Encrypted File System (EFS) if it is required. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| AIX7-00-002107 - AIX must disable Kerberos Authentication in ssh config file to enforce access restrictions. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-002108 - If GSSAPI authentication is not required on AIX, the SSH daemon must disable GSSAPI authentication. | DISA IBM AIX 7.x STIG v3r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| AIX7-00-002130 - If csh/tcsh shell is used, AIX must display logout messages. | DISA IBM AIX 7.x STIG v3r3 | Unix | ACCESS CONTROL |
| AIX7-00-002144 - The AIX /etc/syslog.conf file must be owned by root. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-002149 - The AIX /var/spool/cron/atjobs directory must have a mode of 0640 or less permissive. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-003005 - AIX must disable /usr/bin/rcp,/usr/bin/rlogin,/usr/bin/rsh, /usr/bin/rexec and /usr/bin/telnet commands. | DISA IBM AIX 7.x STIG v3r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| AIX7-00-003006 - AIX log files must have mode 0640 or less permissive. | DISA IBM AIX 7.x STIG v3r3 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| AIX7-00-003015 - The AIX /etc/group file must not have an extended ACL. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-003020 - AIX must use Trusted Execution (TE) Check policy. | DISA IBM AIX 7.x STIG v3r3 | Unix | ACCESS CONTROL |
| AIX7-00-003034 - All AIX files and directories must have a valid owner. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-003037 - The AIX hosts.lpd file must not contain a + character. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-003040 - The AIX rsh daemon must be disabled. | DISA IBM AIX 7.x STIG v3r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| AIX7-00-003044 - If AIX system does not support either local or remote printing, the piobe service must be disabled. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-003045 - If there are no X11 clients that require CDE on AIX, the dt service must be disabled. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |
| AIX7-00-003047 - If sendmail is not required on AIX, the sendmail service must be disabled. | DISA IBM AIX 7.x STIG v3r3 | Unix | CONFIGURATION MANAGEMENT |