Item Search

NameAudit NamePluginCategory
2.3 Disable RPC Encryption KeyCIS Solaris 11.2 L1 v1.1.0Unix
2.5 Disable NIS Client Services - clientCIS Solaris 11.1 L1 v1.0.0Unix
2.5 Disable NIS Client Services - clientCIS Solaris 11.2 L1 v1.1.0Unix
2.5 Disable NIS Client Services - domainCIS Solaris 11.2 L1 v1.1.0Unix
2.7 Disable Generic Security Services (GSS)CIS Solaris 11.2 L1 v1.1.0Unix
2.8 Disable Removable Volume Manager - smserverCIS Solaris 11.1 L1 v1.0.0Unix
2.9 Disable automount ServiceCIS Solaris 11.1 L1 v1.0.0Unix
2.10 Disable Apache ServiceCIS Solaris 11.2 L1 v1.1.0Unix
2.11 Configure TCP Wrappers - svcprop tcp_wrappers trueCIS Solaris 11.2 L1 v1.1.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1 Restrict Core Dumps to Protected Directory - global core dumps = enabledCIS Solaris 11.2 L1 v1.1.0Unix

ACCESS CONTROL

3.1 Restrict Core Dumps to Protected Directory - global core file patternCIS Solaris 11.1 L1 v1.0.0Unix

ACCESS CONTROL

3.1 Restrict Core Dumps to Protected Directory - init core file patternCIS Solaris 11.2 L1 v1.1.0Unix

ACCESS CONTROL

3.1 Restrict Core Dumps to Protected Directory - per-process core dumps = disabledCIS Solaris 11.1 L1 v1.0.0Unix

ACCESS CONTROL

3.1 Restrict Core Dumps to Protected Directory - per-process setid core dumps = disabledCIS Solaris 11.2 L1 v1.1.0Unix

ACCESS CONTROL

3.3 Enable Strong TCP Sequence Number Generation - TCP_STRONG_ISS = 2CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.4 Disable Source Packet Forwarding - persistent ipv4 = 0CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.7 Disable Response to ICMP Broadcast Timestamp Requests - current ip = 0CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.7 Disable Response to ICMP Broadcast Timestamp Requests - persistent ip = 0CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.9 Disable Response to Broadcast ICMPv4 Echo Request - current ip = 0CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.10 Disable Response to Multicast Echo Request - current ipv6 = 0CIS Solaris 11.2 L1 v1.1.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.10 Disable Response to Multicast Echo Request - current ipv4 = 0CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.11 Ignore ICMP Redirect Messages - current ipv6 = 1CIS Solaris 11.2 L1 v1.1.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.11 Ignore ICMP Redirect Messages - current ipv4 = 1CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.11 Ignore ICMP Redirect Messages - persistent ipv6 = 1CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.12 Set Strict Multihoming - current ipv4 = 1CIS Solaris 11.2 L1 v1.1.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.12 Set Strict Multihoming - current ipv4 = 0CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.12 Set Strict Multihoming - current ipv6 = 0CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.13 Disable ICMP Redirect Messages - persistent ipv4 = 0CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.14 Disable TCP Reverse IP Source Routing - current tcp = 0CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.14 Disable TCP Reverse IP Source Routing - persistent tcp = 0CIS Solaris 11.2 L1 v1.1.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.17 Disable Network Routing - ipv6-forwarding persistent = disabledCIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.17 Disable Network Routing - ipv6-routing current = disabledCIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

6.1 Disable login: Services on Serial Ports 'termb'CIS Solaris 11.1 L1 v1.0.0Unix
6.7 Blocking Authentication Using Empty/Null Passwords for SSH - PermitEmptyPasswords = noCIS Solaris 11.1 L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

6.11 Remove Autologin Capabilities from the GNOME desktop - pam.d/gdm-autologinCIS Solaris 11.1 L1 v1.0.0Unix

ACCESS CONTROL

6.12 Set Default Screen Lock for GNOME Users - lock = trueCIS Solaris 11.1 L1 v1.0.0Unix

ACCESS CONTROL

6.13 Restrict at/cron to Authorized Users - /etc/cron.d/at.allow permsCIS Solaris 11.1 L1 v1.0.0Unix

ACCESS CONTROL

6.16 Set EEPROM Security Mode and Log Failed Access (SPARC) - eeprom security-mode = commandCIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

7.1 Set Password Expiration Parameters on Active Accounts - loginsCIS Solaris 11.1 L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

7.1 Set Password Expiration Parameters on Active Accounts - MAXWEEKS = 13CIS Solaris 11.1 L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

7.2 Set Strong Password Creation Policies - MINUPPER = 1CIS Solaris 11.1 L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

7.4 Set Default File Creation Mask for FTP UsersCIS Solaris 11.1 L1 v1.0.0Unix

ACCESS CONTROL

8.4 Enable a Warning Banner for the FTP service - DisplayConnect /etc/issueCIS Solaris 11.1 L1 v1.0.0Unix

ACCESS CONTROL

9.2 Verify System File PermissionsCIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

9.7 Check Permissions on User Home DirectoriesCIS Solaris 11.1 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

9.9 Check Permissions on User .netrc FilesCIS Solaris 11.1 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

9.10 Check for Presence of User .rhosts FilesCIS Solaris 11.1 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

9.11 Check Groups in passwd(4)CIS Solaris 11.1 L1 v1.0.0Unix

ACCESS CONTROL

9.13 Check That Defined Home Directories ExistCIS Solaris 11.1 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

9.25 Find Files and Directories with Extended AttributesCIS Solaris 11.1 L1 v1.0.0Unix