Item Search

NameAudit NamePluginCategory
1.3 Install Solaris Encryption Kit - Check if Package SUNWcrman is installedCIS Solaris 10 L1 v5.2Unix

CONFIGURATION MANAGEMENT

2.1.3 Disable Local Graphical Login Environment - Make sure that /application/graphical-login/cde-login is disabledCIS Solaris 10 L1 v5.2Unix
2.1.3 Disable Local Graphical Login Environment - Make sure that /application/graphical-login/gdm2-login is disabledCIS Solaris 10 L1 v5.2Unix
2.1.5 Disable Local WBEM - Make sure that application/management/wbem is disabledCIS Solaris 10 L1 v5.2Unix
2.1.6 Disable Local BSD Print Protocol Adapter - Make sure that /application/print/rfc1179 is disabledCIS Solaris 10 L1 v5.2Unix
2.2.4 Disable NIS+ daemons - Make sure that /network/rpc/nisplus is disabledCIS Solaris 10 L1 v5.2Unix
2.2.6 Disable Kerberos TGT Expiration Warning - Make sure that /network/security/ktkt_warn is disabledCIS Solaris 10 L1 v5.2Unix
2.2.7 Disable Generic Security Services (GSS) daemons - Make sure that /network/rpc/gss is disabledCIS Solaris 10 L1 v5.2Unix
2.2.13 Disable Solaris Volume Manager GUI - Make sure that network/rpc/meta is disabled.CIS Solaris 10 L1 v5.2Unix
2.2.13 Disable Solaris Volume Manager GUI - Make sure that network/rpc/metamed is disabled.CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that /network/rpc/bind only allows local connections (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that application/management/sma:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that application/x11/xfs:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/nfs/client:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/rpc/rstat:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/shell:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/telnet:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that system/webconsole:console only allows local connections (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.7 Disable Generic Security Services (GSS)CIS Solaris 11.1 L1 v1.0.0Unix
2.11 Configure TCP Wrappers - svcprop tcp_wrappers falseCIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1 Restrict Core Dumps to Protected Directory - global setid core dumps = enabledCIS Solaris 11.1 L1 v1.0.0Unix

ACCESS CONTROL

3.1.2 Disable Source Packet Forwarding - Check ip6_forward_src_routed value. Expected value: 0.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1.9 Disable Response to Multicast Echo Request - Check ip_respond_to_echo_multicast value. Expected value: 0.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1.9 Disable Response to Multicast Echo Request - Check ip6_respond_to_echo_multicast value. Expected value: 0.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1.11 Ignore ICMP Redirect Messages - Check ip_ignore_redirect value. Expected value: 1.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1.13 Disable ICMPv4 Redirect Messages - Check ip_send_redirects value. Expected value: 0.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.5 Disable Network Routing - Make sure that ipv6-forwarding is disabledCIS Solaris 10 L1 v5.2Unix
4.1 Enable inetd Connection Logging - Make sure that tcp_trace is set to trueCIS Solaris 10 L1 v5.2Unix

AUDIT AND ACCOUNTABILITY

4.6 Capture All Failed Login Attempts - Check if SYSLOG_FAILED_LOGINS is set to 0 in /etc/default/login.CIS Solaris 10 L1 v5.2Unix

AUDIT AND ACCOUNTABILITY

4.8 Enable System Accounting - Check if contents of /var/spool/cron/crontabs/sys (/usr/lib/sa/sa1)are OK.CIS Solaris 10 L1 v5.2Unix

AUDIT AND ACCOUNTABILITY

4.8 Enable System Accounting - Check if contents of /var/spool/cron/crontabs/sys (/usr/lib/sa/sa2) are OK.CIS Solaris 10 L1 v5.2Unix

AUDIT AND ACCOUNTABILITY

5.1 Set daemon umask - Check if CMASK is set to 022 in /etc/default/init.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

6.8 Set Default Screen Lock for GNOME Users - Check if timeout is set to 0:10:00 in /usr/openwin/lib/app-defaults/XScreenSaver.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

6.8 Set Default Screen Lock for GNOME Users - GNOME package was not foundCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

6.9 Restrict at/cron To Authorized Users - should pass if /etc/cron.d/cron.deny does not exist.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

6.11 Set Retry Limit for Account Lockout - Check if 'RETRIES' in /etc/default/login is set to 3.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

6.13 Secure the GRUB Menu - should pass if /boot/grub/menu.lst permissions are OK.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND INFORMATION INTEGRITY

7.1 Disable System Accounts - Ensure account 'daemon' is locked.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

7.1 Disable System Accounts - Ensure account 'lp' disallows password login.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

7.1 Disable System Accounts - should pass if the default shell for 'postgres' is set to /usr/bin/false.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

7.10 Ensure Password Encryption Uses SHA algorithms 'CRYPT_ALGORITHMS_ALLOW'CIS Solaris 10 L2 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

8.1 Create warnings for Standard Login Services - Check if /etc/issue is set appropriately.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

8.4 Create warnings for FTP daemon - Check if /etc/ftpd/banner.msg is set appropriately. Applicable only for Solaris 2.6 or laterCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

8.5 Check Banner Setting for telnet is NullCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

9.25 Find Files and Directories with Extended AttributesCIS Solaris 10 L1 v5.2Unix
10.1 Enable process accounting at boot timeCIS Solaris 10 L2 v5.2Unix
10.3 Restrict access to power management functions - CPRCHANGEPERMCIS Solaris 10 L2 v5.2Unix

ACCESS CONTROL

10.3 Restrict access to power management functions - PMCHANGEPERMCIS Solaris 10 L2 v5.2Unix

ACCESS CONTROL

11.5 Samba: Set Group Ownership of smbpasswd FileCIS Solaris 10 L2 v5.2Unix
11.6 Samba: Set Secure smb.conf File Options - permissionsCIS Solaris 10 L2 v5.2Unix