CCI|CCI-001551

Title

The organization defines approved authorizations for controlling the flow of information between interconnected systems.

Reference Item Details

Category: 2010

Audit Items

View all Reference Audit Items

NamePluginAudit Name
GEN003600 - The system must not forward IPv4 source-routed packets - 'net.ipv4.conf.all.accept_source_route'UnixDISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit
GEN003600 - The system must not forward IPv4 source-routed packets - 'net.ipv4.conf.all.accept_source_route'UnixDISA STIG for Oracle Linux 5 v2r1
GEN003600 - The system must not forward IPv4 source-routed packets - 'net.ipv4.conf.default.accept_source_route'UnixDISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit
GEN003600 - The system must not forward IPv4 source-routed packets - 'net.ipv4.conf.default.accept_source_route'UnixDISA STIG for Oracle Linux 5 v2r1
GEN003600 - The system must not forward IPv4 source-routed packets.UnixDISA STIG AIX 6.1 v1r14
GEN003600 - The system must not forward IPv4 source-routed packets.UnixDISA STIG AIX 5.3 v1r2
GEN003602 - The system must not process ICMP timestamp requests.UnixDISA STIG AIX 6.1 v1r14
GEN003602 - The system must not process ICMP timestamp requests.UnixDISA STIG AIX 5.3 v1r2
GEN003602 - The system must not process Internet Control Message Protocol (ICMP) timestamp requests - 'timestamp-reply -j DROP'UnixDISA STIG for Oracle Linux 5 v2r1
GEN003602 - The system must not process Internet Control Message Protocol (ICMP) timestamp requests - 'timestamp-request -j DROP'UnixDISA STIG for Oracle Linux 5 v2r1
GEN003602 - The system must not process Internet Control Message Protocol (ICMP) timestamp requests - 'timestamp-reply -j DROP'UnixDISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit
GEN003602 - The system must not process Internet Control Message Protocol (ICMP) timestamp requests - 'timestamp-request -j DROP'UnixDISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit
GEN003603 - The system must not respond to ICMPv4 echoes sent to a broadcast address.UnixDISA STIG AIX 5.3 v1r2
GEN003603 - The system must not respond to ICMPv4 echoes sent to a broadcast address.UnixDISA STIG AIX 6.1 v1r14
GEN003603 - The system must not respond to ICMPv4 echoes sent to a broadcast address.UnixDISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit
GEN003603 - The system must not respond to Internet Control Message Protocol v4 (ICMPv4) echoes sent to a broadcast address.UnixDISA STIG for Oracle Linux 5 v2r1
GEN003604 - The system must not respond to ICMP timestamp requests sent to a broadcast address.UnixDISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit
GEN003604 - The system must not respond to ICMP timestamp requests sent to a broadcast address.UnixDISA STIG AIX 5.3 v1r2
GEN003604 - The system must not respond to ICMP timestamp requests sent to a broadcast address.UnixDISA STIG AIX 6.1 v1r14
GEN003604 - The system must not respond to Internet Control Message Protocol (ICMP) timestamp requests sent to a broadcast address.UnixDISA STIG for Oracle Linux 5 v2r1
GEN003605 - The system must not apply reversed source routing to TCP responses.UnixDISA STIG AIX 6.1 v1r14
GEN003605 - The system must not apply reversed source routing to TCP responses.UnixDISA STIG AIX 5.3 v1r2
GEN003606 - The system must prevent local applications from generating source-routed packets.UnixDISA STIG AIX 5.3 v1r2
GEN003606 - The system must prevent local applications from generating source-routed packets.UnixDISA STIG AIX 6.1 v1r14
GEN003607 - The system must not accept source-routed IPv4 packets - 'net.ipv4.conf.all.accept_source_route'UnixDISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit
GEN003607 - The system must not accept source-routed IPv4 packets - 'net.ipv4.conf.all.accept_source_route'UnixDISA STIG for Oracle Linux 5 v2r1
GEN003607 - The system must not accept source-routed IPv4 packets - 'net.ipv4.conf.default.accept_source_route'UnixDISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit
GEN003607 - The system must not accept source-routed IPv4 packets - 'net.ipv4.conf.default.accept_source_route'UnixDISA STIG for Oracle Linux 5 v2r1
GEN003607 - The system must not accept source-routed IPv4 packets.UnixDISA STIG AIX 6.1 v1r14
GEN003607 - The system must not accept source-routed IPv4 packets.UnixDISA STIG AIX 5.3 v1r2
GEN003608 - Proxy Address Resolution Protocol (Proxy ARP) must not be enabled on the system.UnixDISA STIG for Oracle Linux 5 v2r1
GEN003608 - Proxy ARP must not be enabled on the system.UnixDISA STIG AIX 6.1 v1r14
GEN003608 - Proxy ARP must not be enabled on the system.UnixDISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit
GEN003608 - Proxy ARP must not be enabled on the system.UnixDISA STIG AIX 5.3 v1r2
GEN003609 - The system must ignore IPv4 ICMP redirect messages - 'net.ipv4.conf.all.accept_redirects'UnixDISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit
GEN003609 - The system must ignore IPv4 ICMP redirect messages - 'net.ipv4.conf.default.accept_redirects'UnixDISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit
GEN003609 - The system must ignore IPv4 ICMP redirect messages.UnixDISA STIG AIX 6.1 v1r14
GEN003609 - The system must ignore IPv4 ICMP redirect messages.UnixDISA STIG AIX 5.3 v1r2
GEN003609 - The system must ignore IPv4 Internet Control Message Protocol (ICMP) redirect messages - 'net.ipv4.conf.all.accept_redirects'UnixDISA STIG for Oracle Linux 5 v2r1
GEN003609 - The system must ignore IPv4 Internet Control Message Protocol (ICMP) redirect messages - 'net.ipv4.conf.default.accept_redirects'UnixDISA STIG for Oracle Linux 5 v2r1
GEN003610 - The system must not send IPv4 ICMP redirects - 'net.ipv4.conf.all.send_redirects'UnixDISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit
GEN003610 - The system must not send IPv4 ICMP redirects - 'net.ipv4.conf.default.send_redirects'UnixDISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit
GEN003610 - The system must not send IPv4 ICMP redirects.UnixDISA STIG AIX 6.1 v1r14
GEN003610 - The system must not send IPv4 ICMP redirects.UnixDISA STIG AIX 5.3 v1r2
GEN003610 - The system must not send IPv4 Internet Control Message Protocol (ICMP) redirects - 'net.ipv4.conf.all.send_redirects'UnixDISA STIG for Oracle Linux 5 v2r1
GEN003610 - The system must not send IPv4 Internet Control Message Protocol (ICMP) redirects - 'net.ipv4.conf.default.send_redirects'UnixDISA STIG for Oracle Linux 5 v2r1
GEN003619 - The system must not be configured for network bridging.UnixDISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit
GEN003619 - The system must not be configured for network bridging.UnixDISA STIG for Oracle Linux 5 v2r1
GEN003860 - The system must not have the finger service active.UnixDISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit
GEN003860 - The system must not have the finger service active.UnixDISA STIG AIX 5.3 v1r2