Item Search

NameAudit NamePluginCategory
5.224 - Power Mgmt - Password Wake on BatteryDISA Windows Vista STIG v6r41Windows

IDENTIFICATION AND AUTHENTICATION

5.225 - Power Mgmt - Password Wake When Plugged InDISA Windows Vista STIG v6r41Windows

IDENTIFICATION AND AUTHENTICATION

5.240 - Windows Explorer - Shell Protocol Protected ModeDISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

DG0009-ORACLE11 - Access to DBMS software files and directories should not be granted to unauthorized users - 'umask < 0022'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

ACCESS CONTROL

DG0125-ORACLE11 - DBMS account passwords should be set to expire every 60 days or more frequently - 'Database password expiration < 60 days'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

IDENTIFICATION AND AUTHENTICATION

DG0130-ORACLE11 - DBMS passwords should not be stored in compiled, encoded or encrypted batch jobs or compiled, encoded or encrypted application source code.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

IDENTIFICATION AND AUTHENTICATION

GEN000020 - The system must require authentication upon booting into single-user and maintenance modes.DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN000120 - System security patches and updates must be installed and up-to-date.DISA STIG AIX 5.3 v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

GEN000241 - The system clock must be synchronized continuously, or at least daily - 'NTP daemon is started at boot'DISA STIG AIX 5.3 v1r2Unix

CONFIGURATION MANAGEMENT

GEN000290 - The system must not have unnecessary accounts - 'games does not exsit'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN000290 - The system must not have unnecessary accounts - 'gopher does not exsit'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN000290 - The system must not have unnecessary accounts - 'uucp does not exsit'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN000400 - The Department of Defense (DoD) login banner must be displayed immediately prior to, or as part of, console login prompts.DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN000410 - The FTPS/FTP service on the system must be configured with the DoD login banner - '/etc/herald permissions are 644'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN000440 - Successful and unsuccessful logins and logouts must be logged - 'unsuccessful logins are being logged'DISA STIG AIX 5.3 v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN000480 - The delay between login prompts following a failed login attempt must be at least 4 seconds.DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN000500 - Graphical desktop environments provided by the system must automatically lock after 15 minutes of inactivity.DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN000920 - The root account's home directory (other than /) must have mode 0700 - Not ApplicableDISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN000960 - The root account must not have world-writable directories in its executable search path.DISA STIG AIX 5.3 v1r2Unix

CONFIGURATION MANAGEMENT

GEN001140 - System files and directories must not have uneven access permissions - '/sbin'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001140 - System files and directories must not have uneven access permissions - '/usr/bin'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001140 - System files and directories must not have uneven access permissions - '/usr/sbin'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001260 - System log files must have mode 0640 or less permissive - '/var/adm/*'DISA STIG AIX 5.3 v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

GEN001270 - System log files must not have extended ACLs, except as needed to support authorized software.DISA STIG AIX 5.3 v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

GEN001340 - NIS/NIS+/yp files must be group-owned by sys, bin, other, or system - '/usr/lib/nis/*'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001360 - The NIS/NIS+/yp files must have mode 0755 or less permissive - '/usr/lib/nis/*'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001365 - The /etc/resolv.conf file must not have an extended ACL.DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001374 - The /etc/nsswitch.conf file must not have an extended ACL.DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001410 - The /etc/security/passwd file must be group-owned by security, bin, sys, or system.DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001480 - All users' home directories must have mode 0750 or less permissive.DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001570 - All files and directories contained in user home directories must not have extended ACLs.DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001580 - All run control scripts must have mode 0755 or less permissive.DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001680 - All system start-up files must be group-owned by sys, bin, other, or system.DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001720 - All global initialization files must have mode 0644 or less permissive - '/etc/profile'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001730 - All global initialization files must not have extended ACLs - '/etc/.login'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001730 - All global initialization files must not have extended ACLs - '/etc/environment'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001730 - All global initialization files must not have extended ACLs - '/etc/profile'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001740 - All global initialization files must be owned by root - '/etc/bashrc'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001760 - All global initialization files must be group-owned by sys, bin, system, or security - '/etc/csh.login'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001760 - All global initialization files must be group-owned by sys, bin, system, or security - '/etc/environment'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001760 - All global initialization files must be group-owned by sys, bin, system, or security - '/etc/profile'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001760 - All global initialization files must be group-owned by sys, bin, system, or security - '/etc/security/environ'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001840 - All global initialization files' executable search paths must contain only absolute paths - '/etc/.login'DISA STIG AIX 5.3 v1r2Unix

CONFIGURATION MANAGEMENT

GEN001840 - All global initialization files' executable search paths must contain only absolute paths - '/etc/bashrc'DISA STIG AIX 5.3 v1r2Unix

CONFIGURATION MANAGEMENT

GEN001870 - Local initialization files must be group-owned by the user's primary group or root - '~/.emacs'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001880 - All local initialization files must have mode 0740 or less permissive - '~/.cshrc'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001880 - All local initialization files must have mode 0740 or less permissive - '~/.login'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001880 - All local initialization files must have mode 0740 or less permissive - '~/.profile'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001890 - Local initialization files must not have extended ACLs - '.logout'DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001902 - Local initialization files' lists of preloaded libraries must contain only absolute paths.DISA STIG AIX 5.3 v1r2Unix

CONFIGURATION MANAGEMENT