Item Search

NameAudit NamePluginCategory
2.1.2 Disable Local CDE Calendar Manager - Make sure that /network/rpc/cde-calendar-manager is disabledCIS Solaris 10 L1 v5.2Unix
2.1.4 Disable Local Web Console - Make sure that /system/webconsole:console is disabledCIS Solaris 10 L1 v5.2Unix
2.2.1 Disable RPC Encryption Key - Make sure that /network/rpc/keyserv is disabledCIS Solaris 10 L1 v5.2Unix
2.2.2 Disable NIS Server Daemons - Make sure that /network/nis/server is disabledCIS Solaris 10 L1 v5.2Unix
2.2.12 Disable Solaris Volume Manager Services - Make sure that system/mdmonitor is disabled - Solaris 10 <= 11/06CIS Solaris 10 L1 v5.2Unix
2.3 Disable RPC Encryption KeyCIS Solaris 11.1 L1 v1.0.0Unix
2.3 Establish a Secure Baseline - Make sure that application/graphical-login/cde-login is only limited to local connectionsCIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that application/print/rfc1179:default is only limited to local connectionsCIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/login:rlogin is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/nfs/rquota:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/rpc/meta is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/rpc/metamed:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/rpc/metamh:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.4 Disable NIS Server Services - domainCIS Solaris 11.1 L1 v1.0.0Unix
2.11 Configure TCP Wrappers - inetadm tcp_wrapers = trueCIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1.3 Disable Broadcast Packet Forwarding - Check ip_forward_directed_broadcasts value. Expected value: 0.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1.5 Disable Response to ICMP Broadcast Timestamp Requests - Check ip_respond_to_timestamp_broadcast value. Expected value: 0.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1.10 Set Interval for Scanning IRE_CACHE - Check ip_ire_arp_interval value. Expected value: 60000.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1.11 Ignore ICMP Redirect Messages - Check ip6_ignore_redirect value. Expected value: 1.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1.14 Set ARP Cleanup Interval - Check arp_cleanup_interval value. Expected value: 60000.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2 Restrict Core Dumps to Protected Directory - Check if COREADM_GLOB_CONTENT is set to defaultCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

3.2 Restrict Core Dumps to Protected Directory - Check if COREADM_GLOB_SETID_ENABLED is set to yesCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

3.2 Restrict Core Dumps to Protected Directory - Check if COREADM_PROC_ENABLED is set to noCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

4.2 Enable FTP daemon Logging - Make sure that exec is set to /usr/sbin/in.ftpd -a -l -dCIS Solaris 10 L1 v5.2Unix

AUDIT AND ACCOUNTABILITY

4.7 Enable cron Logging - Check if CRONLOG is set to yes in /etc/default/cron.CIS Solaris 10 L1 v5.2Unix

AUDIT AND ACCOUNTABILITY

5.3 Set Sticky Bit on World Writable DirectoriesCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

6.1.2 Set SSH Protocol to 2 - Check if Protocol is set to 2 and not commented for client.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

6.1.4 Set SSH MaxAuth Tries to 3 - Check if MaxAuthTries is set to 3 or lower and not commented for the server.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

6.1.7 Set SSH RhostsAuthentication to no - Check if RhostsAuthentication is set to no and not commented for the server.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

6.4 Disable .rhosts Support in /etc/pam.confCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

6.11 Set Retry Limit for Account Lockout, Check if 'LOCK_AFTER_RETRIES' in /etc/default/login is set to YESCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

7.1 Disable System Accounts - Ensure account 'gdm' is locked.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

7.1 Disable System Accounts - Ensure account 'listen' is locked.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

7.1 Disable System Accounts - Ensure account 'noaccess' is locked.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

7.1 Disable System Accounts - should pass if the default shell for 'noaccess' is set to /usr/bin/false.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

7.1 Disable System Accounts - should pass if the default shell for 'smmsp' is set to /usr/bin/false.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

7.1 Disable System Accounts - should pass if the default shell for 'uucp' is set to /usr/bin/false.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

9.2 Verify System File Permissions - /etc/passwd File Permissions.CIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

9.4 Verify No Legacy '+' Entries Exist in passwd, shadow, and group Files - Check for groupCIS Solaris 10 L1 v5.2Unix

CONFIGURATION MANAGEMENT

9.4 Verify No Legacy '+' Entries Exist in passwd, shadow, and group Files - Check for passwdCIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

9.11 Check Groups in /etc/passwdCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

9.14 Check User Home Directory OwnershipCIS Solaris 10 L1 v5.2Unix

CONFIGURATION MANAGEMENT

9.17 Check That Reserved UIDs Are Assigned to System AccountsCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

9.22 Find World Writable FilesCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

9.24 Find Un-owned Files and DirectoriesCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

10.4 Restrict access to sys-suspend featureCIS Solaris 10 L2 v5.2Unix

ACCESS CONTROL

10.5 Create symlinks for dangerous files - /etc/hosts.equivCIS Solaris 10 L2 v5.2Unix
11.1 Samba: Enable SSH Port Forwarding in Web Admin ToolCIS Solaris 10 L2 v5.2Unix

CONFIGURATION MANAGEMENT

11.7 sendmail: Set Secure Logfile Ownership to the root UserCIS Solaris 10 L2 v5.2Unix
11.8 sendmail: Set Secure Permissions on Log FileCIS Solaris 10 L2 v5.2Unix