Item Search

NameAudit NamePluginCategory
GEN002760 - System must be configured to audit all admin/privileged/security actions - '/etc/security/audit/events RESTORE_Import exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002760 - System must be configured to audit all admin/privileged/security actions - '/etc/security/audit/events USER_Remove exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002800 - System must be configured to audit login, logout, and session initiation - '/etc/security/audit/events INIT_Start exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002800 - System must be configured to audit login, logout, and session initiation - '/etc/security/audit/events USER_Login exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002800 - System must be configured to audit login, logout, and session initiation - 'User audit class assignments should be reviewed'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002870 - The system must be configured to send audit records to a remote audit server - '/etc/security/audit/streamcmds is configured'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002960 - Access to the cron utility must be controlled using the cron.allow and/or cron.deny file(s) - '/var/adm/cron/cron.deny'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN002980 - The cron.allow file must have mode 0640 or less permissive.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003060 - Default system accounts must be included in the cron.allow file - 'bin'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003060 - Default system accounts must be included in the cron.allow file - 'lp'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003060 - Default system accounts must be included in the cron.allow file - 'lpd'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003060 - Default system accounts must be included in the cron.deny file - 'bin'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003060 - Default system accounts must GEN003580be included in the cron.deny file - 'sshd'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003100 - Cron and crontab directories must have mode 0755 or less permissive.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN003110 - Cron and crontab directories must not have extended ACLs - '/var/spool/cron/crontabs/*'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003160 - Cron logging must be implemented.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN003210 - The cron.deny file must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003220 - Cron programs must not set the umask to a value less restrictive than 077.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003280 - Access to the at utility must be controlled via the at.allow and/or at.deny file(s) - '/var/adm/cron/at.allow exists'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'daemon' - at.denyDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'lp' - at.denyDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'nobody' - at.allowDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'sshd' - at.denyDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'sys' - at.allowDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'uucp' - at.allowDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'uucp' - at.denyDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003340 - The at.allow file must have mode 0640 or less permissive.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003400 - The at directory must have mode 0755 or less permissive.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN003420 - The at directory must be owned by root, bin, sys, daemon, or cron.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN003470 - The at.allow file must be group-owned by system, bin, sys, or cron.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003521 - The kernel core dump data directory must be group-owned by bin, sys, or system.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003580 - The system must use initial TCP sequence numbers most resistant to sequence number guessing attacks.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003601 - TCP backlog queue sizes must be set appropriately.DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

GEN003604 - The system must not respond to ICMP timestamp requests sent to a broadcast address.DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

GEN003608 - Proxy ARP must not be enabled on the system.DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

GEN003660 - The system must log authentication informational data - 'auth.*'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN003770 - The services file must be group-owned by bin, sys, or system.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN003780 - The services file must have mode 0444 or less permissive.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN003810 - The portmap or rpcbind service must not be running unless needed.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003900 - The hosts.lpd file (or equivalent) must not contain a '+' character.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN004010 - The traceroute file must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN004220 - Administrative accounts must not run a web browser, except as needed for local service administration.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN004560 - The SMTP service's SMTP greeting must not provide version information.DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

GEN004620 - The Sendmail server must have the debug feature disabled.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN004640 - The SMTP service must not have a uudecode alias active - '/usr/lib/aliases decode alias does not exist'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN004680 - The SMTP service must not have the VRFY feature active.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN004800 - Unencrypted FTP must not be used on the system - 'ftp is disabled'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN004800 - Unencrypted FTP must not be used on the system - 'telnet is disabled'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN004820 - Anonymous FTP must not be active on the system unless authorized.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN005000 - Anonymous FTP accounts must not have a functional shell.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL