Item Search

NameAudit NamePluginCategory
AIX7-00-001018 - All system files, programs, and directories must be owned by a system account.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001032 - AIX administrative accounts must not run a web browser, except as needed for local service administration.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001039 - The AIX root accounts home directory (other than /) must have mode 0700.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001041 - AIX must display the Standard Mandatory DoD Notice and Consent Banner before granting local or remote login access to the system.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-001046 - If LDAP authentication is required, AIX must setup LDAP client to refresh user and group caches less than a day.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001053 - AIX must provide time synchronization applications that can synchronize the system clock to external time sources at least every 24 hours.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-001055 - All AIX NFS anonymous UIDs and GIDs must be configured to values without permissions.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001100 - AIX must be configured to allow users to directly initiate a session lock for all connection types.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-001101 - AIX CDE must conceal, via the session lock, information previously visible on the display with a publicly viewable image.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-001105 - AIX must only allow the use of DoD PKI-established certificate authorities for verification of the establishment of protected sessions.DISA IBM AIX 7.x STIG v3r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

AIX7-00-001122 - AIX must enforce password complexity by requiring that at least one numeric character be used.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001134 - The password hashes stored on AIX system must have been generated using a FIPS 140-2 approved cryptographic hashing algorithm.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002005 - AIX must produce audit records containing information to establish the outcome of the events.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002006 - AIX must produce audit records containing the full-text recording of privileged commands.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002015 - Audit logs on the AIX system must be set to 660 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002016 - AIX must provide audit record generation functionality for DoD-defined auditable events.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, MAINTENANCE

AIX7-00-002025 - AIX audit tools must be owned by root.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002036 - AIX must provide a report generation function that supports on-demand audit review and analysis, on-demand reporting requirements, and after-the-fact investigations of security incidents.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002058 - The AIX rexec daemon must not be running.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-002077 - The inetd.conf file on AIX must be owned by root.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002085 - All AIX interactive users home directories must be owned by their respective users.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002088 - AIX library files must have mode 0755 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002090 - AIX time synchronization configuration file must have mode 0640 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002092 - The inetd.conf file on AIX must be group owned by the "system" group.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002100 - AIX must monitor and record successful remote logins.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-002103 - All AIX shells referenced in passwd file must be listed in /etc/shells file, except any shells specified for the purpose of preventing logins.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002105 - AIX must config the SSH idle timeout interval.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

AIX7-00-002111 - AIX SSH daemon must be configured to only use Message Authentication Codes (MACs) employing FIPS 140-2 approved cryptographic hash algorithms.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002113 - The AIX SSH daemon must not allow compression.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002115 - AIX must turn on SSH daemon reverse name checking.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002116 - AIX SSH daemon must perform strict mode checking of home directory configuration files.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002120 - The AIX SSH daemon must be configured to disable empty passwords.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002121 - The AIX SSH daemon must be configured to disable user .rhosts files.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002131 - AIX must implement a remote syslog server that is documented using site-defined procedures.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

AIX7-00-002132 - The AIX syslog daemon must not accept remote messages unless it is a syslog server documented using site-defined procedures.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002133 - AIX must be configured to use syslogd to log events by TCPD.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002147 - The AIX /var/spool/cron/atjobs directory must be owned by root or bin.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002150 - The AIX cron and crontab directories must be group-owned by cron.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003016 - The AIX ldd command must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003018 - All AIX users home directories must have mode 0750 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003025 - AIX must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003028 - AIX must remove all software components after updated versions have been installed.DISA IBM AIX 7.x STIG v3r3Unix

SYSTEM AND INFORMATION INTEGRITY

AIX7-00-003030 - AIX system must restrict the ability to switch to the root user to members of a defined group.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003036 - The AIX global initialization files must contain the mesg -n or mesg n commands.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003041 - The AIX rlogind service must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-003042 - The AIX qdaemon must be disabled if local or remote printing is not required.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003043 - If AIX system does not act as a remote print server for other servers, the lpd daemon must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003046 - If NFS is not required on AIX, the NFS daemon must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003054 - If AIX server is not functioning as a DNS server, the named daemon must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003060 - If SNMP is not required on AIX, the snmpmibd daemon must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT