Item Search

NameAudit NamePluginCategory
SOL-11.1-010120 - The operating system must generate audit records for the selected list of auditable events as defined in DoD list of events.DISA Solaris 11 SPARC STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-010140 - Audit records must include what type of events occurred.DISA Solaris 11 SPARC STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-010380 - The audit system must alert the System Administrator (SA) if there is any type of audit failure.DISA Solaris 11 SPARC STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-010410 - The operating system must configure auditing to reduce the likelihood of storage capacity being exceeded.DISA Solaris 11 SPARC STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-010420 - The operating system must shut down by default upon audit failure (unless availability is an overriding concern).DISA Solaris 11 SPARC STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-020010 - The System packages must be up to date with the most recent vendor updates and security fixes.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020040 - The operating system must protect audit tools from unauthorized modification.DISA Solaris 11 SPARC STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-020120 - The pidgin IM client package must not be installed.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020230 - The operating system must employ automated mechanisms to prevent program execution in accordance with the organization-defined specifications.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020310 - All run control scripts must have no extended ACLs.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020320 - Run control scripts executable search paths must contain only authorized paths.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020540 - .Xauthority or X*.hosts (or equivalent) file(s) must be used to restrict access to the X server.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020560 - X Window System connections that are not required must be disabled.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-030010 - The graphical login service provides the capability of logging into the system using an X-Windows type interface from the console. If graphical login access for the console is required, the service must be in local-only mode.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-030040 - Systems services that are not required must be disabled.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-030050 - TCP Wrappers must be enabled and configured per site policy to only allow access by approved hosts and services.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-030060 - The operating system must disable information system functionality that provides the capability for automatic execution of code on mobile devices without user direction.DISA Solaris 11 SPARC STIG v3r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SOL-11.1-040010 - User passwords must be changed at least every 60 days.DISA Solaris 11 SPARC STIG v3r6Unix

IDENTIFICATION AND AUTHENTICATION

SOL-11.1-040030 - The operating system must enforce minimum password lifetime restrictions.DISA Solaris 11 SPARC STIG v3r6Unix

IDENTIFICATION AND AUTHENTICATION

SOL-11.1-040060 - The system must require at least eight characters be changed between the old and new passwords during a password change.DISA Solaris 11 SPARC STIG v3r6Unix

IDENTIFICATION AND AUTHENTICATION

SOL-11.1-040080 - The operating system must enforce password complexity requiring that at least one lowercase character is used.DISA Solaris 11 SPARC STIG v3r6Unix

IDENTIFICATION AND AUTHENTICATION

SOL-11.1-040110 - The system must require passwords to contain no more than three consecutive repeating characters.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-040170 - The system must require users to re-authenticate to unlock a graphical desktop environment.DISA Solaris 11 SPARC STIG v3r6Unix

ACCESS CONTROL

SOL-11.1-040190 - The system must prevent the use of dictionary words for passwords.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-040200 - The system must restrict the ability of users to assume excessive privileges to members of a defined group and prevent unauthorized users from accessing administrative tools.DISA Solaris 11 SPARC STIG v3r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SOL-11.1-040230 - The operating system must require individuals to be authenticated with an individual authenticator prior to using a group authenticator.DISA Solaris 11 SPARC STIG v3r6Unix

IDENTIFICATION AND AUTHENTICATION

SOL-11.1-040280 - User accounts must be locked after 35 days of inactivity.DISA Solaris 11 SPARC STIG v3r6Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

SOL-11.1-040320 - The nobody access for RPC encryption key storage service must be disabled.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-040331 - The sshd server must bind the X11 forwarding server to the loopback address.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-040410 - The system must not allow autologin capabilities from the GNOME desktop.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-040450 - The operating system, upon successful logon, must display to the user the date and time of the last logon (access).DISA Solaris 11 SPARC STIG v3r6Unix

ACCESS CONTROL

SOL-11.1-040460 - The operating system must provide the capability for users to directly initiate session lock mechanisms.DISA Solaris 11 SPARC STIG v3r6Unix

ACCESS CONTROL

SOL-11.1-040470 - The operating system session lock mechanism, when activated on a device with a display screen, must place a publicly viewable pattern onto the associated display, hiding what was previously visible on the screen.DISA Solaris 11 SPARC STIG v3r6Unix

ACCESS CONTROL

SOL-11.1-040490 - The operating system must prevent remote devices that have established a non-remote connection with the system from communicating outside of the communication path with resources in external networks.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-050030 - The system must not respond to ICMP broadcast timestamp requests.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-050040 - The system must not respond to ICMP broadcast netmask requests.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-050080 - The system must set strict multihoming.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-050100 - The system must disable TCP reverse IP source routing.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-050240 - The boundary protection system (firewall) must be configured to deny network traffic by default and must allow network traffic by exception (i.e., deny all, permit by exception).DISA Solaris 11 SPARC STIG v3r6Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

SOL-11.1-050460 - The operating system must terminate all sessions and network connections when nonlocal maintenance is completed.DISA Solaris 11 SPARC STIG v3r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SOL-11.1-050470 - The operating system must prevent internal users from sending out packets which attempt to manipulate or spoof invalid IP addresses.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-060100 - The operating system must protect the confidentiality of transmitted information.DISA Solaris 11 SPARC STIG v3r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SOL-11.1-060190 - The operating system must protect the integrity of transmitted information.DISA Solaris 11 SPARC STIG v3r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SOL-11.1-070110 - Duplicate UIDs must not exist for multiple non-organizational users.DISA Solaris 11 SPARC STIG v3r6Unix

IDENTIFICATION AND AUTHENTICATION

SOL-11.1-070130 - Reserved UIDs 0-99 must only be used by system accounts.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-070140 - Duplicate user names must not exist.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-070160 - User .netrc files must not exist.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-080030 - Address Space Layout Randomization (ASLR) must be enabled.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-080160 - SNMP default community strings and passphrases must be changed from vendor defaults.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-090250 - The operating system must verify the correct operation of security functions in accordance with organization-defined conditions and in accordance with organization-defined frequency (if periodic verification).DISA Solaris 11 SPARC STIG v3r6Unix

SYSTEM AND INFORMATION INTEGRITY