CIS AIX 5.3/6.1 L2 v1.1.0

Audit Details

Name: CIS AIX 5.3/6.1 L2 v1.1.0

Updated: 11/6/2024

Authority: CIS

Plugin: Unix

Revision: 1.30

Estimated Item Count: 213

File Details

Filename: CIS_AIX_5.3_6.1_v1.1.0_Level_II.audit

Size: 194 kB

MD5: a67aecb9168eb8ff57d34983ce1221a9
SHA256: bfacdd7b8e02f0d2c09159cd00780299e37f06a488f74ac065090df941da36fa

Audit Items

DescriptionCategories
1.1.11 - /etc/security/login.cfg - 'pwd_algorithm = ssha256 (AIX 5.3 TL7+ only)'

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND INFORMATION INTEGRITY

1.2.9 - System account lockdown - 'adm login=false rlogin=false'
1.2.9 - System account lockdown - 'bin login=false rlogin=false'

ACCESS CONTROL

1.2.9 - System account lockdown - 'daemon login=false rlogin=false'

ACCESS CONTROL

1.2.9 - System account lockdown - 'lpd login=false rlogin=false'

ACCESS CONTROL

1.2.9 - System account lockdown - 'nobody login=false rlogin=false'

ACCESS CONTROL

1.2.9 - System account lockdown - 'sys login=false rlogin=false'

CONFIGURATION MANAGEMENT

1.2.9 - System account lockdown - 'uucp login=false rlogin=false'

ACCESS CONTROL

1.3.1 - /etc/inittab - 'qdaemon has been disabled'

CONFIGURATION MANAGEMENT

1.3.2 - /etc/inittab - 'lpd has been disabled'

CONFIGURATION MANAGEMENT

1.3.3 - /etc/inittab - 'piobe has been disabled'

CONFIGURATION MANAGEMENT

1.3.4 - /etc/inittab - 'dt has been disabled'

CONFIGURATION MANAGEMENT

1.3.5 - /etc/inittab - 'rcnfs has been disabled'

CONFIGURATION MANAGEMENT

1.3.6 - /etc/rc.tcpip - 'sendmail has been disabled'

CONFIGURATION MANAGEMENT

1.3.7 - /etc/rc.tcpip - 'snmpd has been disabled'

CONFIGURATION MANAGEMENT

1.3.8 - /etc/rc.tcpip - 'dhcpcd has been disabled'

CONFIGURATION MANAGEMENT

1.3.9 - /etc/rc.tcpip - 'dhcprd has been disabled'

CONFIGURATION MANAGEMENT

1.3.10 - /etc/rc.tcpip - 'dhcpsd has been disabled'

CONFIGURATION MANAGEMENT

1.3.11 - /etc/rc.tcpip - 'autoconf6 has been disabled'

CONFIGURATION MANAGEMENT

1.3.12 - /etc/rc.tcpip - 'gated has been disabled'

CONFIGURATION MANAGEMENT

1.3.13 - /etc/rc.tcpip - 'mrouted has been disabled'

CONFIGURATION MANAGEMENT

1.3.14 - /etc/rc.tcpip - 'named has been disabled'

CONFIGURATION MANAGEMENT

1.3.15 - /etc/rc.tcpip - 'routed has been disabled'

CONFIGURATION MANAGEMENT

1.3.16 - /etc/rc.tcpip - 'rwhod has been disabled'

CONFIGURATION MANAGEMENT

1.3.17 - /etc/rc.tcpip - 'timed has been disabled'

CONFIGURATION MANAGEMENT

1.3.18 - /etc/rc.tcpip - 'dpid2 has been disabled'

CONFIGURATION MANAGEMENT

1.3.19 - /etc/rc.tcpip - 'hostmibd has been disabled'

CONFIGURATION MANAGEMENT

1.3.20 - /etc/rc.tcpip - 'snmpmibd has been disabled'

CONFIGURATION MANAGEMENT

1.3.21 - /etc/rc.tcpip - 'aixmibd has been disabled'

CONFIGURATION MANAGEMENT

1.3.22 - /etc/rc.tcpip - 'ndpd-host has been disabled'

CONFIGURATION MANAGEMENT

1.3.23 - /etc/rc.tcpip - 'ndpd-router has been disabled'

CONFIGURATION MANAGEMENT

1.3.24 - /etc/inetd.conf - 'telnet has been disabled'

CONFIGURATION MANAGEMENT

1.3.25 - /etc/inetd.conf - 'exec has been disabled'

CONFIGURATION MANAGEMENT

1.3.26 - /etc/inetd.conf - 'daytime-tcp has been disabled'

CONFIGURATION MANAGEMENT

1.3.26 - /etc/inetd.conf - 'daytime-udp has been disabled'

CONFIGURATION MANAGEMENT

1.3.27 - /etc/inetd.conf - 'shell has been disabled'

CONFIGURATION MANAGEMENT

1.3.28 - /etc/inetd.conf - 'cmsd has been disabled'

CONFIGURATION MANAGEMENT

1.3.29 - /etc/inetd.conf - 'ttdbserver has been disabled'

CONFIGURATION MANAGEMENT

1.3.30 - /etc/inetd.conf - 'uucp has been disabled'

CONFIGURATION MANAGEMENT

1.3.31 - /etc/inetd.conf - 'time-tcp has been disabled'

CONFIGURATION MANAGEMENT

1.3.31 - /etc/inetd.conf - 'time-udp has been disabled'

CONFIGURATION MANAGEMENT

1.3.32 - /etc/inetd.conf - 'login has been disabled'

CONFIGURATION MANAGEMENT

1.3.33 - /etc/inetd.conf - 'talk has been disabled'

CONFIGURATION MANAGEMENT

1.3.34 - /etc/inetd.conf - 'ntalk has been disabled'

CONFIGURATION MANAGEMENT

1.3.35 - /etc/inetd.conf - 'ftp has been disabled'

CONFIGURATION MANAGEMENT

1.3.36 - /etc/inetd.conf - 'chargen-tcp has been disabled'

CONFIGURATION MANAGEMENT

1.3.36 - /etc/inetd.conf - 'chargen-udp has been disabled'

CONFIGURATION MANAGEMENT

1.3.37 - /etc/inetd.conf - 'discard-tcp has been disabled'

CONFIGURATION MANAGEMENT

1.3.37 - /etc/inetd.conf - 'discard-udp has been disabled'

CONFIGURATION MANAGEMENT

1.3.38 - /etc/inetd.conf - 'dtspc has been disabled'

CONFIGURATION MANAGEMENT