Item Search

NameAudit NamePluginCategory
AIX7-00-001008 - All accounts on AIX system must have unique account names.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001009 - All accounts on AIX must be assigned unique User Identification Numbers (UIDs) and must authenticate organizational and non-organizational users (or processes acting on behalf of these users).DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001029 - AIX must provide xlock command in the CDE environment to let users retain their sessions lock until users are reauthenticated.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-001044 - Any publically accessible connection to AIX operating system must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the system.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-001123 - AIX must require the change of at least 50% of the total number of characters when passwords are changed.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001126 - AIX Operating systems must enforce a 60-day maximum password lifetime restriction.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001136 - AIX must require passwords to contain no more than three consecutive repeating characters.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002001 - AIX must produce audit records containing information to establish what the date, time, and type of events that occurred.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002004 - AIX must produce audit records containing information to establish the source and the identity of any individual or process associated with an event.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002013 - Audit logs on the AIX system must be owned by root.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002062 - AIX must remove !authenticate option from sudo config files.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-002064 - IP forwarding for IPv4 must not be enabled on AIX unless the system is a router.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002065 - AIX must be configured with a default gateway for IPv6 if the system uses IPv6 unless the system is a router.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002072 - AIX system files, programs, and directories must be group-owned by a system group.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002082 - AIX time synchronization configuration file must be group-owned by bin, or system.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002087 - All files and directories contained in users home directories on AIX must be group-owned by a group in which the home directory owner is a member.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002101 - AIX must monitor and record unsuccessful remote logins.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-002110 - AIX must setup SSH daemon to disable revoked public keys.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-002117 - AIX must turn off X11 forwarding for the SSH daemon.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002124 - If AIX SSH daemon is required, the SSH daemon must only listen on the approved listening IP addresses.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002127 - AIX system must require authentication upon booting into single-user and maintenance modes.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002128 - If bash is used, AIX must display logout messages.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-002129 - If Bourne / ksh shell is used, AIX must display logout messages.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-002140 - The AIX /etc/hosts file must be owned by root.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003052 - If AIX server is not functioning as a network router, the gated daemon must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003053 - If AIX server is not functioning as a multicast router, the mrouted daemon must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003057 - The timed daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003058 - If AIX server does not host an SNMP agent, the dpid2 daemon must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003064 - The daytime daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003065 - The cmsd daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003069 - The talk daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003071 - The chargen daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003074 - The pcnfsd daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003077 - The sprayd daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003084 - The finger daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003085 - The instsrv daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003087 - The Internet Network News (INN) server must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003089 - The Reliable Datagram Sockets (RDS) protocol must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003109 - In the event of a system failure, AIX must preserve any information necessary to determine cause of failure and any information necessary to return to operations with least disruption to mission processes.DISA IBM AIX 7.x STIG v3r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

AIX7-00-003110 - The /etc/shells file must exist on AIX systems.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003114 - If the AIX host is running an SMTP service, the SMTP greeting must not provide version information.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003116 - The sendmail server must have the debug feature disabled on AIX systems.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003124 - The AIX systems access control program must be configured to grant or deny system access to specific hosts.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003127 - The control script lists of preloaded libraries must contain only absolute paths on AIX systems.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003128 - The global initialization file lists of preloaded libraries must contain only absolute paths on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003131 - AIX package management tool must be used daily to verify system software.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003132 - The AIX DHCP client must not send dynamic DNS updates.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003141 - All AIX interactive users must be assigned a home directory in the passwd file and the directory must exist.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003201 - The AIX operating system must be configured to authenticate using Multi Factor Authentication.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003202 - The AIX operating system must be configured to use Multi Factor Authentication for remote connections.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT