Item Search

NameAudit NamePluginCategory
1.1.5.3.10 Set 'Windows Firewall: Public: Firewall state' to 'On (recommended)'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

9.1.1 Enable cron Daemon - anacron run level 4CIS Debian Linux 7 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

9.1.1 Enable cron Daemon - cron run level 4CIS Debian Linux 7 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

GEN000000-AIX00040 - The securetcpip command must be usedDISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN000000-AIX00060 - A baseline of AIX files with the TCB bit set must be checked weekly.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000241 - The system clock must be synchronized continuously, or at least daily - 'NTP daemon is running'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN000242 - The system must use at least two time sources for clock synchronization - 'at least 2 servers are configured'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN000252 - The time synchronization configuration file (such as /etc/ntp.conf) must have mode 0640 or less permissive.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN000253 - The time synchronization configuration file (such as /etc/ntp.conf) must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000290 - The system must not have unnecessary accounts - 'ftp does not exsit'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000360 - Group Identifiers (GIDs) reserved for system accounts must not be assigned to non-system groups.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000380 - All Group Identifiers (GIDs) referenced in the /etc/passwd file must be defined in the /etc/group file.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000410 - The FTPS/FTP service on the system must be configured with the DoD login banner - '/etc/ftpaccess.ctl contains herald'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000452 - The system must display the date and time of the last successful account login upon login.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000500 - Graphical desktop environments provided by the system must automatically lock after 15 minutes of inactivity.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000510 - The system must display a publicly-viewable pattern during a graphical desktop environment session lock.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000595 - Password hashes must have been generated using a FIPS 140-2 hashing algorithm - 'Verify no password hashes in /etc/passwd'DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN000680 - The system must require passwords to contain no more than three consecutive repeating characters.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN000920 - The root account's home directory (other than /) must have mode 0700 - Not ApplicableDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001180 - All network services daemon files must have mode 0755 or less permissive - '/usr/sbin/*'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001210 - All system command files must not have extended ACLs - '/sbin/*'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001240 - System files, programs, and directories must be group-owned by a system group - '/sbin/*'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001240 - System files, programs, and directories must be group-owned by a system group - '/usr/sbin/*'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001260 - System log files must have mode 0640 or less permissive - '/var/log/*'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001270 - System log files must not have extended ACLs, except as needed to support authorized software.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001360 - The NIS/NIS+/yp files must have mode 0755 or less permissive - '/var/yp/*'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001364 - The /etc/resolv.conf file must have mode 0644 or less permissive.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001367 - The /etc/hosts file must be group-owned by bin, sys, or system.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001373 - The /etc/nsswitch.conf file must have mode 0644 or less permissive - Not ApplicableDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001378 - The /etc/passwd file must be owned by root.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN001379 - The /etc/passwd file must be group-owned by bin, security, sys, or system.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN001394 - The /etc/group file must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001420 - The /etc/security/passwd file must have mode 0400.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN001430 - The /etc/security/passwd file must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001490 - User home directories must not have extended ACLs.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001500 - All interactive users' home directories must be owned by their respective users.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001605 - Run control scripts' library search paths must contain only absolute paths.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001700 - System start-up files must only execute programs owned by a privileged UID or an application.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001720 - All global initialization files must have mode 0644 or less permissive - '/etc/.login'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001720 - All global initialization files must have mode 0644 or less permissive - '/etc/bashrc'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001720 - All global initialization files must have mode 0644 or less permissive - '/etc/environment'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001720 - All global initialization files must have mode 0644 or less permissive - '/etc/profile'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

WNFWA-000009 - Windows Defender Firewall with Advanced Security log size must be configured for domain connections.DISA Microsoft Windows Defender Firewall with Advanced Security STIG v2r2Windows

AUDIT AND ACCOUNTABILITY

WNFWA-000012 - Windows Defender Firewall with Advanced Security must block unsolicited inbound connections when connected to a private network.DISA Microsoft Windows Defender Firewall with Advanced Security STIG v2r2Windows

CONFIGURATION MANAGEMENT

WNFWA-000013 - Windows Defender Firewall with Advanced Security must allow outbound connections, unless a rule explicitly blocks the connection when connected to a private network.DISA Microsoft Windows Defender Firewall with Advanced Security STIG v2r2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNFWA-000017 - Windows Defender Firewall with Advanced Security log size must be configured for private network connections.DISA Microsoft Windows Defender Firewall with Advanced Security STIG v2r2Windows

AUDIT AND ACCOUNTABILITY

WNFWA-000018 - Windows Defender Firewall with Advanced Security must log dropped packets when connected to a private network.DISA Microsoft Windows Defender Firewall with Advanced Security STIG v2r2Windows

AUDIT AND ACCOUNTABILITY

WNFWA-000024 - Windows Defender Firewall with Advanced Security local firewall rules must not be merged with Group Policy settings when connected to a public network.DISA Microsoft Windows Defender Firewall with Advanced Security STIG v2r2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNFWA-000025 - Windows Defender Firewall with Advanced Security local connection rules must not be merged with Group Policy settings when connected to a public network.DISA Microsoft Windows Defender Firewall with Advanced Security STIG v2r2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNFWA-000027 - Windows Defender Firewall with Advanced Security log size must be configured for public network connections.DISA Microsoft Windows Defender Firewall with Advanced Security STIG v2r2Windows

AUDIT AND ACCOUNTABILITY