Item Search

NameAudit NamePluginCategory
3.3.6 Secure the JDK 64-bit runtime library - FILE_PERMISSIONSCIS IBM DB2 9 Benchmark v3.0.1 Level 2 OS WindowsWindows
5.4.2 Ensure system accounts are securedCIS Ubuntu Linux 18.04 LXD Container L1 v1.0.0Unix

ACCESS CONTROL

18.6.11.4 Ensure 'Require domain users to elevate when setting a network's location' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L1Windows

ACCESS CONTROL

18.6.11.4 Ensure 'Require domain users to elevate when setting a network's location' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L1Windows

ACCESS CONTROL

AIX7-00-001006 - If the AIX system is using LDAP for authentication or account information, the LDAP SSL, or TLS connection must require the server provide a certificate and this certificate must have a valid path to a trusted CA.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001012 - AIX must use the SSH server to implement replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001015 - The shipped /etc/security/mkuser.sys file on AIX must not be customized directly.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-001030 - AIX system must prevent the root account from directly logging in except from the system console.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001034 - The AIX root account must not have world-writable directories in its executable search path.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001038 - AIX must not have accounts configured with blank or null passwords.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001042 - The Department of Defense (DoD) login banner must be displayed immediately prior to, or as part of, graphical desktop environment login prompts on AIX.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-001043 - The Department of Defense (DoD) login banner must be displayed during SSH, sftp, and scp login sessions on AIX.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-001048 - AIX must protect the confidentiality and integrity of all information at rest.DISA IBM AIX 7.x STIG v3r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

AIX7-00-001056 - AIX nosuid option must be enabled on all NFS client mounts.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001104 - If LDAP authentication is required on AIX, SSL must be used between LDAP clients and the LDAP servers to protect the integrity of remote access sessions.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-001120 - AIX must enforce password complexity by requiring that at least one upper-case character be used.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001121 - AIX must enforce password complexity by requiring that at least one lower-case character be used.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001124 - AIX root passwords must never be passed over a network in clear text form.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001125 - AIX Operating systems must enforce 24 hours/1 day as the minimum password lifetime.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001128 - AIX must use Loadable Password Algorithm (LPA) password hashing algorithm.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001132 - AIX must prevent the use of dictionary words for passwords.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001135 - If SNMP service is enabled on AIX, the default SNMP password must not be used in the /etc/snmpd.conf config file.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002014 - Audit logs on the AIX system must be group-owned by system.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002026 - AIX audit tools must be group-owned by audit.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002027 - AIX audit tools must be set to 4550 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002033 - AIX must allocate audit record storage capacity to store at least one weeks worth of audit records, when audit records are not immediately sent to a central audit record storage facility.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002038 - AIX must record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002059 - AIX telnet daemon must not be running.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-002061 - AIX must remove NOPASSWD tag from sudo config files.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-003062 - The ndpd-host daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003063 - The ndpd-router must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003068 - The time daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003070 - The ntalk daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003076 - The rusersd daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003078 - The klogin daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003079 - The kshell daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003081 - The tftp daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003086 - The echo daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003093 - AIX process core dumps must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003094 - AIX kernel core dumps must be disabled unless needed.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003096 - AIX must set Stack Execution Disable (SED) system wide mode to all.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

AIX7-00-003098 - AIX must allow admins to send a message to all the users who logged in currently.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-003104 - If DHCP server is not required on AIX, the DHCP server must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003112 - AIX must be configured to only boot from the system boot device.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003113 - AIX must not use removable media as the boot loader.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003115 - AIX must contain no .forward files.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003130 - The local initialization file lists of preloaded libraries must contain only absolute paths on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003133 - AIX must not run any routing protocol daemons unless the system is a router.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003138 - There must be no .rhosts, .shosts, hosts.equiv, or shosts.equiv files on the AIX system.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003203 - AIX must have the have the PowerSC Multi Factor Authentication Product configured.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT