Item Search

NameAudit NamePluginCategory
AIX7-00-001035 - The Group Identifiers (GIDs) reserved for AIX system accounts must not be assigned to non-system accounts as their primary group GID.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001036 - UIDs reserved for system accounts must not be assigned to non-system accounts on AIX systems.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001037 - The AIX root accounts list of preloaded libraries must be empty.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001047 - The AIX /etc/passwd, /etc/security/passwd, and/or /etc/group files must not contain a plus (+) without defining entries for NIS+ netgroups or LDAP netgroups.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001129 - AIX must enforce a minimum 15-character password length.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001139 - AIX removable media, remote file systems, and any file system not containing approved device files must be mounted with the nodev option.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002008 - AIX must be configured to generate an audit record when 75% of the audit file system is full.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002017 - AIX must be configured so that the audit system takes appropriate action when the audit storage volume is full.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002023 - AIX must start audit at boot.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002028 - AIX must verify the hash of audit tools.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002032 - AIX must provide the function for assigned ISSOs or designated SAs to change the auditing to be performed on all operating system components, based on all selectable event criteria in near real time.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002063 - AIX must be configured with a default gateway for IPv4 if the system uses IPv4, unless the system is a router.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002070 - AIX log files must be owned by a system account.DISA IBM AIX 7.x STIG v3r3Unix

SYSTEM AND INFORMATION INTEGRITY

AIX7-00-002084 - The AIX /etc/group file must be group-owned by security.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002086 - All AIX interactive users home directories must be group-owned by the home directory owner primary group.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002089 - Samba packages must be removed from AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002096 - AIX must encrypt user data at rest using AIX Encrypted File System (EFS) if it is required.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

AIX7-00-002107 - AIX must disable Kerberos Authentication in ssh config file to enforce access restrictions.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002108 - If GSSAPI authentication is not required on AIX, the SSH daemon must disable GSSAPI authentication.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-002130 - If csh/tcsh shell is used, AIX must display logout messages.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-002144 - The AIX /etc/syslog.conf file must be owned by root.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002149 - The AIX /var/spool/cron/atjobs directory must have a mode of 0640 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003005 - AIX must disable /usr/bin/rcp,/usr/bin/rlogin,/usr/bin/rsh, /usr/bin/rexec and /usr/bin/telnet commands.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-003006 - AIX log files must have mode 0640 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

SYSTEM AND INFORMATION INTEGRITY

AIX7-00-003015 - The AIX /etc/group file must not have an extended ACL.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003020 - AIX must use Trusted Execution (TE) Check policy.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-003034 - All AIX files and directories must have a valid owner.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003037 - The AIX hosts.lpd file must not contain a + character.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003040 - The AIX rsh daemon must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-003044 - If AIX system does not support either local or remote printing, the piobe service must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003045 - If there are no X11 clients that require CDE on AIX, the dt service must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003047 - If sendmail is not required on AIX, the sendmail service must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003052 - If AIX server is not functioning as a network router, the gated daemon must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003053 - If AIX server is not functioning as a multicast router, the mrouted daemon must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003057 - The timed daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003058 - If AIX server does not host an SNMP agent, the dpid2 daemon must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003064 - The daytime daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003065 - The cmsd daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003069 - The talk daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003071 - The chargen daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003074 - The pcnfsd daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003077 - The sprayd daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003084 - The finger daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003085 - The instsrv daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003087 - The Internet Network News (INN) server must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003089 - The Reliable Datagram Sockets (RDS) protocol must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003109 - In the event of a system failure, AIX must preserve any information necessary to determine cause of failure and any information necessary to return to operations with least disruption to mission processes.DISA IBM AIX 7.x STIG v3r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

AIX7-00-003110 - The /etc/shells file must exist on AIX systems.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003114 - If the AIX host is running an SMTP service, the SMTP greeting must not provide version information.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003116 - The sendmail server must have the debug feature disabled on AIX systems.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT