Item Search

NameAudit NamePluginCategory
AIX7-00-001000 - AIX /etc/security/mkuser.sys.custom file must not exist unless it is needed for customizing a new user account.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-001007 - If AIX is using LDAP for authentication or account information, the /etc/ldap.conf file (or equivalent) must not contain passwords.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001014 - The AIX system must automatically remove or disable emergency accounts after the crisis is resolved or 72 hours.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-001019 - AIX device files and directories must only be writable by users with a system account or as configured by the vendor.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001028 - AIX must provide the lock command to let users retain their session lock until users are reauthenticated.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-001031 - All AIX public directories must be owned by root or an application account.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001033 - AIX default system accounts (with the exception of root) must not be listed in the cron.allow file or must be included in the cron.deny file, if cron.allow does not exist.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001035 - The Group Identifiers (GIDs) reserved for AIX system accounts must not be assigned to non-system accounts as their primary group GID.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001036 - UIDs reserved for system accounts must not be assigned to non-system accounts on AIX systems.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001037 - The AIX root accounts list of preloaded libraries must be empty.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001047 - The AIX /etc/passwd, /etc/security/passwd, and/or /etc/group files must not contain a plus (+) without defining entries for NIS+ netgroups or LDAP netgroups.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001122 - AIX must enforce password complexity by requiring that at least one numeric character be used.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001129 - AIX must enforce a minimum 15-character password length.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001134 - The password hashes stored on AIX system must have been generated using a FIPS 140-2 approved cryptographic hashing algorithm.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001139 - AIX removable media, remote file systems, and any file system not containing approved device files must be mounted with the nodev option.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002005 - AIX must produce audit records containing information to establish the outcome of the events.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002006 - AIX must produce audit records containing the full-text recording of privileged commands.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002008 - AIX must be configured to generate an audit record when 75% of the audit file system is full.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002015 - Audit logs on the AIX system must be set to 660 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002016 - AIX must provide audit record generation functionality for DoD-defined auditable events.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, MAINTENANCE

AIX7-00-002017 - AIX must be configured so that the audit system takes appropriate action when the audit storage volume is full.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002023 - AIX must start audit at boot.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002025 - AIX audit tools must be owned by root.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002028 - AIX must verify the hash of audit tools.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002032 - AIX must provide the function for assigned ISSOs or designated SAs to change the auditing to be performed on all operating system components, based on all selectable event criteria in near real time.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002036 - AIX must provide a report generation function that supports on-demand audit review and analysis, on-demand reporting requirements, and after-the-fact investigations of security incidents.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002058 - The AIX rexec daemon must not be running.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-002063 - AIX must be configured with a default gateway for IPv4 if the system uses IPv4, unless the system is a router.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002070 - AIX log files must be owned by a system account.DISA IBM AIX 7.x STIG v3r3Unix

SYSTEM AND INFORMATION INTEGRITY

AIX7-00-002077 - The inetd.conf file on AIX must be owned by root.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002084 - The AIX /etc/group file must be group-owned by security.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002085 - All AIX interactive users home directories must be owned by their respective users.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002086 - All AIX interactive users home directories must be group-owned by the home directory owner primary group.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002089 - Samba packages must be removed from AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002096 - AIX must encrypt user data at rest using AIX Encrypted File System (EFS) if it is required.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

AIX7-00-002107 - AIX must disable Kerberos Authentication in ssh config file to enforce access restrictions.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002108 - If GSSAPI authentication is not required on AIX, the SSH daemon must disable GSSAPI authentication.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-002130 - If csh/tcsh shell is used, AIX must display logout messages.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-002144 - The AIX /etc/syslog.conf file must be owned by root.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002149 - The AIX /var/spool/cron/atjobs directory must have a mode of 0640 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003005 - AIX must disable /usr/bin/rcp,/usr/bin/rlogin,/usr/bin/rsh, /usr/bin/rexec and /usr/bin/telnet commands.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-003006 - AIX log files must have mode 0640 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

SYSTEM AND INFORMATION INTEGRITY

AIX7-00-003015 - The AIX /etc/group file must not have an extended ACL.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003020 - AIX must use Trusted Execution (TE) Check policy.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-003034 - All AIX files and directories must have a valid owner.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003037 - The AIX hosts.lpd file must not contain a + character.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003040 - The AIX rsh daemon must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-003044 - If AIX system does not support either local or remote printing, the piobe service must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003045 - If there are no X11 clients that require CDE on AIX, the dt service must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003047 - If sendmail is not required on AIX, the sendmail service must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT