Item Search

NameAudit NamePluginCategory
OL6-00-000036 - The /etc/gshadow file must be owned by root.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000045 - Library files must have mode 0755 or less permissive - '/usr/lib'DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000045 - Library files must have mode 0755 or less permissive - '/usr/lib64'DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000054 - Users must be warned 7 days in advance of password expiration.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000056 - The system must require passwords to contain at least one numeric character - system-authDISA STIG Oracle Linux 6 v2r7Unix

IDENTIFICATION AND AUTHENTICATION

OL6-00-000057 - The system must require passwords to contain at least one uppercase alphabetic character - password-authDISA STIG Oracle Linux 6 v2r7Unix

IDENTIFICATION AND AUTHENTICATION

OL6-00-000057 - The system must require passwords to contain at least one uppercase alphabetic character - system-authDISA STIG Oracle Linux 6 v2r7Unix

IDENTIFICATION AND AUTHENTICATION

OL6-00-000060 - The system must require at least eight characters be changed between the old and new passwords during a password change - system-authDISA STIG Oracle Linux 6 v2r7Unix

IDENTIFICATION AND AUTHENTICATION

OL6-00-000061 - The system must disable accounts after three consecutive unsuccessful logon attempts - password-authDISA STIG Oracle Linux 6 v2r7Unix

ACCESS CONTROL

OL6-00-000067 - The system boot loader configuration file(s) must have mode 0600 or less permissive.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000068 - The system boot loader must require authentication.DISA STIG Oracle Linux 6 v2r7Unix

ACCESS CONTROL

OL6-00-000081 - The system must not send ICMPv4 redirects from any interface.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000090 - The system must not accept ICMPv4 secure redirect packets by default.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000091 - The system must ignore ICMPv4 redirect messages by default.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000093 - The system must ignore ICMPv4 bogus error responses.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000096 - The system must use a reverse-path filter for IPv4 network traffic when possible on all interfaces.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000103 - The system must employ a local IPv6 firewall.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000116 - The operating system must connect to external networks or information systems only through managed IPv4 interfaces consisting of boundary protection devices arranged in accordance with an organizational security architecture.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000120 - The systems local IPv4 firewall must implement a deny-all, allow-by-exception policy for inbound packets.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000126 - The Reliable Datagram Sockets (RDS) protocol must be disabled unless required.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000137 - The operating system must support the requirement to centrally manage the content of audit records generated by organization defined information system components.DISA STIG Oracle Linux 6 v2r7Unix

AUDIT AND ACCOUNTABILITY

OL6-00-000148 - The operating system must employ automated mechanisms to facilitate the monitoring and control of remote access methods - PROCESS_CHECKDISA STIG Oracle Linux 6 v2r7Unix

ACCESS CONTROL

OL6-00-000160 - The system must set a maximum audit log file size.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000171 - The audit system must be configured to audit all attempts to alter system time through clock_settime - b32DISA STIG Oracle Linux 6 v2r7Unix

AUDIT AND ACCOUNTABILITY

OL6-00-000174 - The operating system must automatically audit account creation - '/etc/gshadow'DISA STIG Oracle Linux 6 v2r7Unix

ACCESS CONTROL

OL6-00-000176 - The operating system must automatically audit account disabling actions - '/etc/security/opasswd'DISA STIG Oracle Linux 6 v2r7Unix

ACCESS CONTROL

OL6-00-000177 - The operating system must automatically audit account termination - '/etc/group'DISA STIG Oracle Linux 6 v2r7Unix

ACCESS CONTROL

OL6-00-000177 - The operating system must automatically audit account termination - '/etc/gshadow'DISA STIG Oracle Linux 6 v2r7Unix

ACCESS CONTROL

OL6-00-000182 - The audit system must be configured to audit modifications to the systems network configuration - '/etc/issue'DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000182 - The audit system must be configured to audit modifications to the systems network configuration - b64 audit_network_modificationsDISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000184 - The audit system must be configured to audit all discretionary access control permission modifications using chmod, fchmod, and fchmodat - b32 auid>=500DISA STIG Oracle Linux 6 v2r7Unix

AUDIT AND ACCOUNTABILITY

OL6-00-000190 - The audit system must be configured to audit all discretionary access control permission modifications using setxattr, lsetxattr, fsetxattr, removexattr, lremovexattr, and fremovexattr - b64 auid=0DISA STIG Oracle Linux 6 v2r7Unix

AUDIT AND ACCOUNTABILITY

OL6-00-000197 - The audit system must be configured to audit failed attempts to access files and programs - b64 EACCES auid=0DISA STIG Oracle Linux 6 v2r7Unix

AUDIT AND ACCOUNTABILITY

OL6-00-000203 - The xinetd service must be disabled if no network services utilizing it are enabled - PROCESS_CHECKDISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000216 - The rexecd service must not be running - CHKCONFIGDISA STIG Oracle Linux 6 v2r7Unix

ACCESS CONTROL

OL6-00-000218 - The rlogind service must not be running - CHKCONFIGDISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000221 - The ypbind service must not be running - CHKCONFIGDISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000227 - The SSH daemon must be configured to use only the SSHv2 protocol.DISA STIG Oracle Linux 6 v2r7Unix

IDENTIFICATION AND AUTHENTICATION

OL6-00-000239 - The SSH daemon must not allow authentication using an empty password.DISA STIG Oracle Linux 6 v2r7Unix

IDENTIFICATION AND AUTHENTICATION

OL6-00-000241 - The SSH daemon must not permit user environment settings.DISA STIG Oracle Linux 6 v2r7Unix

ACCESS CONTROL

OL6-00-000243 - The Oracle Linux 6 operating system must implement DoD-approved encryption to protect the confidentiality of SSH connections.DISA STIG Oracle Linux 6 v2r7Unix

ACCESS CONTROL

OL6-00-000246 - The avahi service must be disabled.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000249 - Mail relaying must be restricted.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000253 - The LDAP client must use a TLS connection using trust certificates signed by the site CA.DISA STIG Oracle Linux 6 v2r7Unix

ACCESS CONTROL

OL6-00-000256 - The openldap-servers package must not be installed unless required.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000257 - The graphical desktop environment must set the idle timeout to no more than 15 minutes.DISA STIG Oracle Linux 6 v2r7Unix

ACCESS CONTROL

OL6-00-000260 - The system must display a publicly-viewable pattern during a graphical desktop environment session lock.DISA STIG Oracle Linux 6 v2r7Unix

ACCESS CONTROL

OL6-00-000261 - The Automatic Bug Reporting Tool (abrtd) service must not be running - CHKCONFIGDISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000261 - The Automatic Bug Reporting Tool (abrtd) service must not be running - PROCESS_CHECKDISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000262 - The atd service must be disabled - PROCESS_CHECKDISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT