GEN006565 - The system package management tool must be used to verify system software periodically.

Information

Verification using the system package management tool can be used to determine that system software has not been tampered with. This requirement is not applicable to systems that do not use package management tools.

Solution

Add a job to the root crontab invoking the system package management tool to verify the integrity of installed packages.

# lppchk -c

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R13_STIG.zip

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-7, CAT|II, CCI|CCI-000698, Group-ID|V-22506, Rule-ID|SV-38958r1_rule, STIG-ID|GEN006565

Plugin: Unix

Control ID: 521a1053ac73bf818279e4c83be87691ea618372bb5168574814cd328822ab78