Item Search

NameAudit NamePluginCategory
GEN002752 - The audit system must be configured to audit account disabling - '/etc/security/audit/config USER_Locked exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002760 - System must be configured to audit all admin/privileged/security actions - '/etc/security/audit/config ACCT_Disable exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002760 - System must be configured to audit all admin/privileged/security actions - '/etc/security/audit/config PROC_Setpgid exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002760 - System must be configured to audit all admin/privileged/security actions - '/etc/security/audit/config RESTORE_Import exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002760 - System must be configured to audit all admin/privileged/security actions - '/etc/security/audit/config TCBCK_Delete exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002760 - System must be configured to audit all admin/privileged/security actions - '/etc/security/audit/events AUD_it exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002760 - System must be configured to audit all admin/privileged/security actions - '/etc/security/audit/events DEV_Change exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002760 - System must be configured to audit all admin/privileged/security actions - '/etc/security/audit/events PASSWORD_Check exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002760 - System must be configured to audit all admin/privileged/security actions - '/etc/security/audit/events PROC_SetUserIDs exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002760 - System must be configured to audit all admin/privileged/security actions - '/etc/security/audit/events TCBCK_Delete exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002760 - System must be configured to audit all admin/privileged/security actions - '/etc/security/audit/events USER_Reboot exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002760 - System must be configured to audit all admin/privileged/security actions - 'User audit class assignments should be reviewed'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN002800 - System must be configured to audit login, logout, and session initiation - '/etc/security/audit/config USER_SU exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002825 - System must be configured to audit load/unload dynamic kernel modules - '/etc/security/audit/config DEV_Remove exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002825 - System must be configured to audit load/unload dynamic kernel modules - '/etc/security/audit/config DEV_Stop exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002825 - System must be configured to audit load/unload dynamic kernel modules - '/etc/security/audit/config DEV_Unconfigure exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002825 - System must be configured to audit load/unload dynamic kernel modules - '/etc/security/audit/events DEV_Unconfigure exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002960 - Access to the cron utility must be controlled using the cron.allow and/or cron.deny file(s) - '/var/adm/cron/cron.allow'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003060 - Default system accounts must be included in the cron.allow file - 'snapp'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003060 - Default system accounts must be included in the cron.allow file - 'sshd'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003060 - Default system accounts must be included in the cron.allow file - 'sys'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003060 - Default system accounts must be included in the cron.deny file - 'adm'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003060 - Default system accounts must be included in the cron.deny file - 'invscout'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003060 - Default system accounts must be included in the cron.deny file - 'pconsole'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003090 - Crontab files must not have extended ACLs.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003110 - Cron and crontab directories must not have extended ACLs - '/var/spool/cron' - acls disabledDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003255 - The at.deny file must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003280 - Access to the at utility must be controlled via the at.allow and/or at.deny file(s) - '/var/adm/cron/at.deny exists'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'guest' - at.allowDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'ipsec' - at.allowDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'ipsec' - at.denyDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'lpd' - at.allowDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'sshd' - at.allowDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003410 - The at directory must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003460 - The at.allow file must be owned by root, bin, or sys.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003510 - Kernel core dumps must be disabled unless needed - 'secondary dump device'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003522 - The kernel core dump data directory must have mode 0700 or less permissive.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003623 - The system must use a separate file system for the system audit data path.DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN003650 - All local file systems must employ journaling or another mechanism ensuring file system consistency.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003760 - The services file must be owned by root or bin.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN003800 - Inetd or xinetd logging/tracing must be enabled.DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN003815 - The portmap or rpcbind service must not be installed unless needed.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN003850 - The telnet daemon must not be running.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN003865 - Network analysis tools must not be installed - 'netcat'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN003865 - Network analysis tools must not be installed - 'tshark'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN003960 - The traceroute command owner must be root.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN004380 - The alias file must have mode 0644 or less permissive.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN004430 - Files executed through a mail aliases file must not have extended ACLs.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN004580 - The system must not use .forward files.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN004640 - The SMTP service must not have a uudecode alias active - '/etc/aliases uudecode alias does not exist'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT