Item Search

NameAudit NamePluginCategory
GEN000000-AIX0090 - The /etc/netsvc.conf file must be group-owned by bin, sys, or system.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN000000-AIX0100 - The /etc/netsvc.conf file must have mode 0644 or less permissive.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN000000-AIX0300 - The system must not have the bootp service active.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN000242 - The system must use at least two time sources for clock synchronization - 'NTP daemon is started at boot'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN000251 - The time synchronization configuration file (such as /etc/ntp.conf) must be group-owned by bin, sys, or system.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN000280 - Direct logins must not be permitted to shared, default, application, or utility accounts - 'results of last should be reviewed'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000290 - The system must not have unnecessary accounts - 'uucp does not exsit'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000300 - All accounts on the system must have unique user or account names.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN000320 - All accounts must be assigned unique User Identification Numbers (UIDs).DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN000410 - The FTPS/FTP service on the system must be configured with the DoD login banner - '/etc/ftpaccess.ctl permissions are 640'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN000410 - The FTPS/FTP service on the system must be configured with the DoD login banner - '/etc/herald permissions are 644'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN000540 - Users must not be able to change passwords more than once every 24 hours.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN000560 - The system must not have accounts configured with blank or null passwords.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN000595 - Password hashes must have been generated using a FIPS 140-2 hashing algorithm - 'no password hashes in /etc/security/passwd'DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN000640 - The system must require that passwords contain at least one special character.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN000760 - Accounts must be locked upon 35 days of inactivity.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000960 - The root account must not have world-writable directories in its executable search path.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001020 - The root account must not be used for direct logins.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001140 - System files and directories must not have uneven access permissions - '/bin'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001140 - System files and directories must not have uneven access permissions - '/sbin'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001140 - System files and directories must not have uneven access permissions - '/usr/lbin'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001200 - All system command files must have mode 0755 or less permissive - '/etc/*'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001200 - All system command files must have mode 0755 or less permissive - '/usr/sbin/*'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001210 - All system command files must not have extended ACLs - '/etc/*'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

SLES-12-010331 - The SUSE operating system must automatically expire temporary accounts within 72 hours.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL

SLES-12-010375 - The SUSE operating system must restrict access to the kernel message buffer.DISA SLES 12 STIG v3r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-12-010500 - Advanced Intrusion Detection Environment (AIDE) must verify the baseline SUSE operating system configuration at least weekly.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

SLES-12-010520 - The SUSE operating system file integrity tool must be configured to verify Access Control Lists (ACLs).DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010550 - The SUSE operating system tool zypper must have gpgcheck enabled.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010620 - The SUSE operating system default permissions must be defined in such a way that all authenticated users can only read and modify their own files.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010630 - The SUSE operating system must not have unnecessary accounts.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010650 - The SUSE operating system root account must be the only account having unrestricted access to the system.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010680 - The SUSE operating system must configure the Linux Pluggable Authentication Modules (PAM) to prohibit the use of cached offline authentications after one day.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010740 - All SUSE operating system local interactive user home directories must have mode 0750 or less permissive.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010770 - All SUSE operating system local interactive user initialization files executable search paths must contain only paths that resolve to the users home directory.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010790 - SUSE operating system file systems that contain user home directories must be mounted to prevent files with the setuid and setgid bit set from being executed.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010810 - SUSE operating system file systems that are being imported via Network File System (NFS) must be mounted to prevent files with the setuid and setgid bit set from being executed.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-020199 - The SUSE operating system must not disable syscall auditing.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-020200 - The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

SLES-12-020320 - The SUSE operating system must generate audit records for all uses of the ssh-keysign command.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-020370 - The SUSE operating system must generate audit records for all uses of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr syscalls.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-030170 - The SUSE operating system must implement DoD-approved encryption to protect the confidentiality of SSH remote connections.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

SLES-12-030210 - The SUSE operating system SSH daemon public host key files must have mode 0644 or less permissive.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030260 - The SUSE operating system SSH daemon must disable forwarded remote X connections for interactive users, unless to fulfill documented and validated mission requirements.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030363 - The SUSE operating system must prevent Internet Protocol version 6 (IPv6) Internet Control Message Protocol (ICMP) redirect messages from being accepted.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030380 - The SUSE operating system must not respond to Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030430 - The SUSE operating system must not be performing Internet Protocol version 4 (IPv4) packet forwarding unless the system is a router.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030440 - The SUSE operating system must not have network interfaces in promiscuous mode unless approved and documented.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030500 - The SUSE operating system must have the packages required for multifactor authentication to be installed.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-030510 - The SUSE operating system must implement certificate status checking for multifactor authentication.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION