Item Search

NameAudit NamePluginCategory
GEN000000-AIX00080 - The SYSTEM attribute must not be set to NONE for any account.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN000252 - The time synchronization configuration file (such as /etc/ntp.conf) must have mode 0640 or less permissive.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN001180 - All network services daemon files must have mode 0755 or less permissive - '/usr/sbin/*'DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN001190 - All network services daemon files must not have extended ACLs - /usr/bin/*DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN001290 - All manual page files must not have extended ACLs - '/usr/share/infopage/*'DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN001340 - NIS/NIS+/yp files must be group-owned by sys, bin, other, or system - '/var/yp/*'DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN001364 - The /etc/resolv.conf file must have mode 0644 or less permissive.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN001366 - The /etc/hosts file must be owned by root.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN001380 - The /etc/passwd file must have mode 0644 or less permissive.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN001500 - All interactive users' home directories must be owned by their respective users.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN001550 - All files and directories in user's home directories must be group-owned by a group the home directory's owner is a member.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN001660 - All system start-up files must be owned by root.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN001730 - All global initialization files must not have extended ACLs - '/etc/bashrc'DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN001760 - All global initialization files must be group-owned by sys, bin, system, or security - '/etc/csh.login'DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN001830 - All skeleton files (typically in /etc/skel) must be group-owned by security - '/etc/security/mkuser.sys'DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN001870 - Local initialization files must be group-owned by the user's primary group or root - '~/.bashrc'DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN001880 - All local initialization files must have mode 0740 or less permissive - '~/.env'DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN001880 - All local initialization files must have mode 0755 or less permissive - '~/.dtprofile'DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN001890 - Local initialization files must not have extended ACLs - '.exrc'DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN002220 - All shell files must have mode 0755 or less permissive.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN002300 - Device files used for backup must only be readable and/or writable by root or the backup user - '/dev/cd*'DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN002340 - Audio devices must be owned by root.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN002420 - Removable media, remote file systems and any file system not containing approved setuid files must be mounted with nosuid.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN002960 - Access to the cron utility must be controlled using the cron.allow and/or cron.deny file(s) - '/var/adm/cron/cron.deny'DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN003000 - Cron must not execute group-writable or world-writable programs.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN003060 - Default system accounts must not be in the cron.allow file or must be in cron.deny - 'nuucp'DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN003140 - Cron and crontab directories must be group-owned by system, sys, bin, or cron.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN003200 - The cron.deny file must have mode 0600 or less permissive.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN003280 - Access to the at utility must be controlled via the at.allow and/or at.deny file(s) - '/var/adm/cron/at.allow exists'DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'invscout'DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'nuucp'DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN003380 - The 'at' daemon must not execute programs in, or subordinate to, world-writable directories.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN003490 - The at.deny file must be group-owned by system, bin, sys, or cron.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN003523 - The kernel core dump data directory must not have an extended ACL.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN003720 - The inetd.conf file, xinetd.conf file, and the xinetd.d directory must be owned by root or bin - 'inetd.conf'DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN003770 - The services file must be group-owned by bin, sys, or system.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN004000 - The traceroute file must have mode 0700 or less permissive.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN004010 - The traceroute file must not have an extended ACL.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN004380 - The alias file must have mode 0644 or less permissive.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN004410 - Files executed through a mail aliases file must be group-owned by root, bin, sys, or other.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN005040 - All FTP users must have a default umask of 077.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN005100 - The TFTP daemon must have mode 0755 or less permissive.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN005120 - The TFTP daemon must be configured to vendor specs including a home directory owned by the TFTP user - 'tftp user exists'DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN005390 - The /etc/syslog.conf file must have mode 0640 or less permissive.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN005536 - The SSH daemon must perform strict mode checking of home directory configuration files.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN005760 - The NFS export configuration file must have mode 0644 or less permissive.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN005900 - The nosuid option must be enabled on all NFS client mounts.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN006100 - The /usr/lib/smb.conf file must be owned by root.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN006280 - The /etc/news/hosts.nntp.nolimit (or equivalent) must have mode 0600 or less permissive.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN006290 - The /etc/news/hosts.nntp.nolimit file must not have an extended ACL.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL