STIGQter STIGQter: STIG Summary:

IBM AIX 7.x Security Technical Implementation Guide

Version: 3

Release: 3 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-215169r958362_ruleAIX /etc/security/mkuser.sys.custom file must not exist unless it is needed for customizing a new user account.
SV-215170r958364_ruleAIX must automatically remove or disable temporary user accounts after 72 hours or sooner.
SV-215171r958388_ruleAIX must enforce the limit of three consecutive invalid login attempts by a user before the user account is locked and released by an administrator.
SV-215172r958398_ruleAIX must limit the number of concurrent sessions to 10 for all accounts and/or account types.
SV-215173r958448_ruleIf the AIX system is using LDAP for authentication or account information, the LDAP SSL, or TLS connection must require the server provide a certificate and this certificate must have a valid path to a trusted CA.
SV-215174r1009530_ruleIf AIX is using LDAP for authentication or account information, the /etc/ldap.conf file (or equivalent) must not contain passwords.
SV-215175r958482_ruleAll accounts on AIX system must have unique account names.
SV-215176r958482_ruleAll accounts on AIX must be assigned unique User Identification Numbers (UIDs) and must authenticate organizational and non-organizational users (or processes acting on behalf of these users).
SV-215177r958482_ruleThe AIX SYSTEM attribute must not be set to NONE for any account.
SV-215178r1009531_ruleDirect logins to the AIX system must not be permitted to shared accounts, default accounts, application accounts, and utility accounts.
SV-215179r1009532_ruleAIX must use the SSH server to implement replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.
SV-215180r958508_ruleThe AIX system must automatically remove or disable emergency accounts after the crisis is resolved or 72 hours.
SV-215181r958362_ruleThe shipped /etc/security/mkuser.sys file on AIX must not be customized directly.
SV-215182r958362_ruleThe regular users default primary group must be staff (or equivalent) on AIX.
SV-215183r991560_ruleAll system files, programs, and directories must be owned by a system account.
SV-215184r991560_ruleAIX device files and directories must only be writable by users with a system account or as configured by the vendor.
SV-215186r958498_ruleAIX must configure the ttys value for all interactive users.
SV-215187r958400_ruleAIX must provide the lock command to let users retain their session lock until users are reauthenticated.
SV-215188r958400_ruleAIX must provide xlock command in the CDE environment to let users retain their sessions lock until users are reauthenticated.
SV-215189r991589_ruleAIX system must prevent the root account from directly logging in except from the system console.
SV-215190r991589_ruleAll AIX public directories must be owned by root or an application account.
SV-215191r991589_ruleAIX administrative accounts must not run a web browser, except as needed for local service administration.
SV-215192r991589_ruleAIX default system accounts (with the exception of root) must not be listed in the cron.allow file or must be included in the cron.deny file, if cron.allow does not exist.
SV-215193r991589_ruleThe AIX root account must not have world-writable directories in its executable search path.
SV-215194r991589_ruleThe Group Identifiers (GIDs) reserved for AIX system accounts must not be assigned to non-system accounts as their primary group GID.
SV-215195r991589_ruleUIDs reserved for system accounts must not be assigned to non-system accounts on AIX systems.
SV-215196r991589_ruleThe AIX root accounts list of preloaded libraries must be empty.
SV-215197r991591_ruleAIX must not have accounts configured with blank or null passwords.
SV-215198r991592_ruleThe AIX root accounts home directory (other than /) must have mode 0700.
SV-215199r991592_ruleThe AIX root accounts home directory must not have an extended ACL.
SV-215200r958390_ruleAIX must display the Standard Mandatory DoD Notice and Consent Banner before granting local or remote login access to the system.
SV-215201r958390_ruleThe Department of Defense (DoD) login banner must be displayed immediately prior to, or as part of, graphical desktop environment login prompts on AIX.
SV-215202r958390_ruleThe Department of Defense (DoD) login banner must be displayed during SSH, sftp, and scp login sessions on AIX.
SV-215203r958586_ruleAny publically accessible connection to AIX operating system must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the system.
SV-215204r987796_ruleIF LDAP is used, AIX LDAP client must use SSL to authenticate with LDAP server.
SV-215205r958828_ruleIf LDAP authentication is required, AIX must setup LDAP client to refresh user and group caches less than a day.
SV-215206r991589_ruleThe AIX /etc/passwd, /etc/security/passwd, and/or /etc/group files must not contain a plus (+) without defining entries for NIS+ netgroups or LDAP netgroups.
SV-215207r958552_ruleAIX must protect the confidentiality and integrity of all information at rest.
SV-215208r1038944_ruleAIX must provide time synchronization applications that can synchronize the system clock to external time sources at least every 24 hours.
SV-215209r991589_ruleAll AIX NFS anonymous UIDs and GIDs must be configured to values without permissions.
SV-215210r991589_ruleAIX nosuid option must be enabled on all NFS client mounts.
SV-215211r1009534_ruleAIX must be configured to allow users to directly initiate a session lock for all connection types.
SV-215212r958404_ruleAIX CDE must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
SV-215213r958510_ruleAIX must employ strong authenticators in the establishment of nonlocal maintenance and diagnostic sessions.
SV-215214r991554_ruleIf LDAP authentication is required on AIX, SSL must be used between LDAP clients and the LDAP servers to protect the integrity of remote access sessions.
SV-215215r958868_ruleAIX must only allow the use of DoD PKI-established certificate authorities for verification of the establishment of protected sessions.
SV-215216r971535_ruleAIX must implement NIST FIPS-validated cryptography for the following: to provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
SV-215217r1009535_ruleAIX must enforce password complexity by requiring that at least one upper-case character be used.
SV-215218r1009536_ruleAIX must enforce password complexity by requiring that at least one lower-case character be used.
SV-215219r1009537_ruleAIX must enforce password complexity by requiring that at least one numeric character be used.
SV-215220r1009538_ruleAIX must require the change of at least 50% of the total number of characters when passwords are changed.
SV-215221r987796_ruleAIX root passwords must never be passed over a network in clear text form.
SV-215222r1009539_ruleAIX Operating systems must enforce 24 hours/1 day as the minimum password lifetime.
SV-215223r1038967_ruleAIX Operating systems must enforce a 60-day maximum password lifetime restriction.
SV-215225r1009541_ruleAIX must use Loadable Password Algorithm (LPA) password hashing algorithm.
SV-215226r1009542_ruleAIX must enforce a minimum 15-character password length.
SV-215227r1009543_ruleAIX must enforce password complexity by requiring that at least one special character be used.
SV-215229r991587_ruleAIX must prevent the use of dictionary words for passwords.
SV-215230r991589_ruleThe password hashes stored on AIX system must have been generated using a FIPS 140-2 approved cryptographic hashing algorithm.
SV-215231r991589_ruleIf SNMP service is enabled on AIX, the default SNMP password must not be used in the /etc/snmpd.conf config file.
SV-215232r991589_ruleAIX must require passwords to contain no more than three consecutive repeating characters.
SV-215233r958672_ruleAIX must be able to control the ability of remote login for users.
SV-215234r1184573_ruleNFS file systems on AIX must be mounted with the nosuid option unless the NFS file systems contain approved setuid or setgid programs.
SV-215235r991589_ruleAIX removable media, remote file systems, and any file system not containing approved device files must be mounted with the nodev option.
SV-215236r958412_ruleAIX must produce audit records containing information to establish what the date, time, and type of events that occurred.
SV-215237r958416_ruleAIX must produce audit records containing information to establish where the events occurred.
SV-215238r958418_ruleAIX must produce audit records containing information to establish the source and the identity of any individual or process associated with an event.
SV-215239r958420_ruleAIX must produce audit records containing information to establish the outcome of the events.
SV-215240r958422_ruleAIX must produce audit records containing the full-text recording of privileged commands.
SV-215241r958424_ruleAIX must be configured to generate an audit record when 75% of the audit file system is full.
SV-215242r958430_ruleAIX must provide the function to filter audit records for events of interest based upon all audit fields within audit records, support on-demand reporting requirements, and an audit reduction function that supports on-demand audit review and analysis and after-the-fact investigations of security incidents.
SV-215243r958434_ruleAudit logs on the AIX system must be owned by root.
SV-215244r958434_ruleAudit logs on the AIX system must be group-owned by system.
SV-215245r958434_ruleAudit logs on the AIX system must be set to 660 or less permissive.
SV-215246r1013689_ruleAIX must provide audit record generation functionality for DoD-defined auditable events.
SV-215247r991555_ruleAIX must start audit at boot.
SV-215248r991557_ruleAIX audit tools must be owned by root.
SV-215249r991557_ruleAIX audit tools must be group-owned by audit.
SV-215250r991557_ruleAIX audit tools must be set to 4550 or less permissive.
SV-215251r991567_ruleAIX must verify the hash of audit tools.
SV-215252r971541_ruleAIX must provide the function for assigned ISSOs or designated SAs to change the auditing to be performed on all operating system components, based on all selectable event criteria in near real time.
SV-215253r958752_ruleAIX must allocate audit record storage capacity to store at least one weeks worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
SV-215254r958770_ruleAIX must provide a report generation function that supports on-demand audit review and analysis, on-demand reporting requirements, and after-the-fact investigations of security incidents.
SV-215255r958788_ruleAIX must record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).
SV-215256r991589_ruleAIX audit logs must be rotated daily.
SV-215257r987796_ruleThe AIX rexec daemon must not be running.
SV-215258r987796_ruleAIX telnet daemon must not be running.
SV-215259r987796_ruleAIX ftpd daemon must not be running.
SV-215260r1050789_ruleAIX must remove NOPASSWD tag from sudo config files.
SV-215261r1050789_ruleAIX must remove !authenticate option from sudo config files.
SV-215262r991589_ruleAIX must be configured with a default gateway for IPv4 if the system uses IPv4, unless the system is a router.
SV-215263r991589_ruleIP forwarding for IPv4 must not be enabled on AIX unless the system is a router.
SV-215264r991589_ruleAIX must be configured with a default gateway for IPv6 if the system uses IPv6 unless the system is a router.
SV-215265r991589_ruleAIX must not have IP forwarding for IPv6 enabled unless the system is an IPv6 router.
SV-215266r958566_ruleAIX log files must be owned by a system account.
SV-215267r958566_ruleAIX log files must be owned by a system group.
SV-215268r991560_ruleAIX system files, programs, and directories must be group-owned by a system group.
SV-215269r991589_ruleThe inetd.conf file on AIX must be owned by root.
SV-215270r991589_ruleAIX cron and crontab directories must be owned by root or bin.
SV-215271r991589_ruleAIX audio devices must be group-owned by root, sys, bin, or system.
SV-215272r991589_ruleAIX time synchronization configuration file must be owned by root.
SV-215273r991589_ruleAIX time synchronization configuration file must be group-owned by bin, or system.
SV-215274r991589_ruleThe AIX /etc/group file must be owned by root.
SV-215275r991589_ruleThe AIX /etc/group file must be group-owned by security.
SV-215276r991592_ruleAll AIX interactive users home directories must be owned by their respective users.
SV-215277r991592_ruleAll AIX interactive users home directories must be group-owned by the home directory owner primary group.
SV-215278r991592_ruleAll files and directories contained in users home directories on AIX must be group-owned by a group in which the home directory owner is a member.
SV-215279r991560_ruleAIX library files must have mode 0755 or less permissive.
SV-215280r991589_ruleSamba packages must be removed from AIX.
SV-215281r991589_ruleAIX time synchronization configuration file must have mode 0640 or less permissive.
SV-215282r991589_ruleThe AIX /etc/group file must have mode 0644 or less permissive.
SV-215283r1207664_ruleAIX must encrypt user data at rest using AIX Encrypted File System (EFS) if it is required.
SV-215284r958908_ruleAIX must protect the confidentiality and integrity of transmitted information during preparation for transmission and maintain the confidentiality and integrity of information during reception and disable all non-encryption network access methods.
SV-215285r958406_ruleAIX must monitor and record successful remote logins.
SV-215286r958406_ruleAIX must monitor and record unsuccessful remote logins.
SV-215287r991589_ruleOn AIX, the SSH server must not permit root logins using remote access programs.
SV-215288r991589_ruleAll AIX shells referenced in passwd file must be listed in /etc/shells file, except any shells specified for the purpose of preventing logins.
SV-215289r958408_ruleThe AIX SSH server must use SSH Protocol 2.
SV-215290r958636_ruleAIX must config the SSH idle timeout interval.
SV-215291r1009547_ruleAIX must disable Kerberos Authentication in ssh config file to enforce access restrictions.
SV-215292r1050791_ruleIf GSSAPI authentication is not required on AIX, the SSH daemon must disable GSSAPI authentication.
SV-215293r1009549_ruleAIX must setup SSH daemon to disable revoked public keys.
SV-215294r991589_ruleAIX SSH daemon must be configured to only use Message Authentication Codes (MACs) employing FIPS 140-2 approved cryptographic hash algorithms.
SV-215295r1009551_ruleThe AIX SSH daemon must be configured for IP filtering.
SV-215296r991589_ruleThe AIX SSH daemon must not allow compression.
SV-215297r991589_ruleAIX must turn on SSH daemon privilege separation.
SV-215298r991589_ruleAIX must turn on SSH daemon reverse name checking.
SV-215299r991589_ruleAIX SSH daemon must perform strict mode checking of home directory configuration files.
SV-215300r991589_ruleAIX must turn off X11 forwarding for the SSH daemon.
SV-215301r991589_ruleAIX must turn off TCP forwarding for the SSH daemon.
SV-215302r991591_ruleThe AIX SSH daemon must be configured to disable empty passwords.
SV-215303r991591_ruleThe AIX SSH daemon must be configured to disable user .rhosts files.
SV-215304r991591_ruleThe AIX SSH daemon must be configured to not use host-based authentication.
SV-215305r991591_ruleThe AIX SSH daemon must not allow RhostsRSAAuthentication.
SV-215306r991593_ruleIf AIX SSH daemon is required, the SSH daemon must only listen on the approved listening IP addresses.
SV-215308r991589_ruleAIX system must require authentication upon booting into single-user and maintenance modes.
SV-215309r958640_ruleIf bash is used, AIX must display logout messages.
SV-215310r958640_ruleIf Bourne / ksh shell is used, AIX must display logout messages.
SV-215311r958640_ruleIf csh/tcsh shell is used, AIX must display logout messages.
SV-215312r991589_ruleAIX must implement a remote syslog server that is documented using site-defined procedures.
SV-215313r991589_ruleThe AIX syslog daemon must not accept remote messages unless it is a syslog server documented using site-defined procedures.
SV-215314r1009552_ruleAIX must be configured to use syslogd to log events by TCPD.
SV-215315r958444_ruleThe AIX audit configuration files must be owned by root.
SV-215316r958444_ruleThe AIX audit configuration files must be group-owned by audit.
SV-215317r958444_ruleThe AIX audit configuration files must be set to 640 or less permissive.
SV-215318r958402_ruleAIX must automatically lock after 15 minutes of inactivity in the CDE Graphical desktop environment.
SV-215320r1009553_ruleAIX must set inactivity time-out on login sessions and terminate all login sessions after 10 minutes of inactivity.
SV-215321r958450_ruleAIX SSH private host key files must have mode 0600 or less permissive.
SV-215322r987796_ruleAIX must disable /usr/bin/rcp, /usr/bin/rlogin, /usr/bin/rsh, /usr/bin/rexec and /usr/bin/telnet commands.
SV-215323r958566_ruleAIX log files must have mode 0640 or less permissive.
SV-215324r958566_ruleAIX log files must not have extended ACLs, except as needed to support authorized software.
SV-215325r991560_ruleAll system command files must not have extended ACLs.
SV-215326r991560_ruleAll library files must not have extended ACLs.
SV-215327r991589_ruleAIX passwd.nntp file must have mode 0600 or less permissive.
SV-215328r991589_ruleThe AIX /etc/group file must not have an extended ACL.
SV-215329r991589_ruleThe AIX ldd command must be disabled.
SV-215330r991589_ruleAIX NFS server must be configured to restrict file system access to local hosts.
SV-215331r991592_ruleAll AIX users home directories must have mode 0750 or less permissive.
SV-215332r991592_ruleThe AIX user home directories must not have extended ACLs.
SV-215333r958702_ruleAIX must use Trusted Execution (TE) Check policy.
SV-215334r1009554_ruleAIX must disable trivial file transfer protocol.
SV-215335r958804_ruleAIX must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
SV-215336r958936_ruleAIX must remove all software components after updated versions have been installed.
SV-215337r991588_ruleAIX must enforce a delay of at least 4 seconds between login prompts following a failed login attempt.
SV-215338r991589_ruleAIX system must restrict the ability to switch to the root user to members of a defined group.
SV-215339r991589_ruleAll AIX Group Identifiers (GIDs) referenced in the /etc/passwd file must be defined in the /etc/group file.
SV-215340r991589_ruleAll AIX files and directories must have a valid owner.
SV-215341r991589_ruleThe sticky bit must be set on all public directories on AIX systems.
SV-215342r991589_ruleThe AIX global initialization files must contain the mesg -n or mesg n commands.
SV-215343r991589_ruleThe AIX hosts.lpd file must not contain a + character.
SV-215344r991589_ruleAIX sendmail logging must not be set to less than nine in the sendmail.cf file.
SV-215345r991589_ruleAIX run control scripts executable search paths must contain only absolute paths.
SV-215346r987796_ruleThe AIX rsh daemon must be disabled.
SV-215347r987796_ruleThe AIX rlogind service must be disabled.
SV-215348r958478_ruleThe AIX qdaemon must be disabled if local or remote printing is not required.
SV-215349r958478_ruleIf AIX system does not act as a remote print server for other servers, the lpd daemon must be disabled.
SV-215350r958478_ruleIf AIX system does not support either local or remote printing, the piobe service must be disabled.
SV-215351r958478_ruleIf there are no X11 clients that require CDE on AIX, the dt service must be disabled.
SV-215352r958478_ruleIf NFS is not required on AIX, the NFS daemon must be disabled.
SV-215353r958478_ruleIf sendmail is not required on AIX, the sendmail service must be disabled.
SV-215354r958478_ruleIf SNMP is not required on AIX, the snmpd service must be disabled.
SV-215355r958478_ruleThe AIX DHCP client must be disabled.
SV-215356r958478_ruleIf DHCP is not enabled in the network on AIX, the dhcprd daemon must be disabled.
SV-215357r958478_ruleIf IPv6 is not utilized on AIX server, the autoconf6 daemon must be disabled.
SV-215358r958478_ruleIf AIX server is not functioning as a network router, the gated daemon must be disabled.
SV-215359r958478_ruleIf AIX server is not functioning as a multicast router, the mrouted daemon must be disabled.
SV-215360r958478_ruleIf AIX server is not functioning as a DNS server, the named daemon must be disabled.
SV-215361r958478_ruleIf AIX server is not functioning as a network router, the routed daemon must be disabled.
SV-215362r958478_ruleIf rwhod is not required on AIX, the rwhod daemon must be disabled.
SV-215363r958478_ruleThe timed daemon must be disabled on AIX.
SV-215364r958478_ruleIf AIX server does not host an SNMP agent, the dpid2 daemon must be disabled.
SV-215365r958478_ruleIf SNMP is not required on AIX, the snmpmibd daemon must be disabled.
SV-215366r958478_ruleThe aixmibd daemon must be disabled on AIX.
SV-215367r958478_ruleThe ndpd-host daemon must be disabled on AIX.
SV-215368r958478_ruleThe ndpd-router must be disabled on AIX.
SV-215369r958478_ruleThe daytime daemon must be disabled on AIX.
SV-215370r958478_ruleThe cmsd daemon must be disabled on AIX.
SV-215371r958478_ruleThe ttdbserver daemon must be disabled on AIX.
SV-215372r958478_ruleThe uucp (UNIX to UNIX Copy Program) daemon must be disabled on AIX.
SV-215373r958478_ruleThe time daemon must be disabled on AIX.
SV-215374r958478_ruleThe talk daemon must be disabled on AIX.
SV-215375r958478_ruleThe ntalk daemon must be disabled on AIX.
SV-215376r958478_ruleThe chargen daemon must be disabled on AIX.
SV-215377r958478_ruleThe discard daemon must be disabled on AIX.
SV-215378r958478_ruleThe dtspc daemon must be disabled on AIX.
SV-215379r958478_ruleThe pcnfsd daemon must be disabled on AIX.
SV-215380r958478_ruleThe rstatd daemon must be disabled on AIX.
SV-215381r958478_ruleThe rusersd daemon must be disabled on AIX.
SV-215382r958478_ruleThe sprayd daemon must be disabled on AIX.
SV-215383r958478_ruleThe klogin daemon must be disabled on AIX.
SV-215384r958478_ruleThe kshell daemon must be disabled on AIX.
SV-215385r958478_ruleThe rquotad daemon must be disabled on AIX.
SV-215386r958478_ruleThe tftp daemon must be disabled on AIX.
SV-215387r958478_ruleThe imap2 service must be disabled on AIX.
SV-215388r958478_ruleThe pop3 daemon must be disabled on AIX.
SV-215389r958478_ruleThe finger daemon must be disabled on AIX.
SV-215390r958478_ruleThe instsrv daemon must be disabled on AIX.
SV-215391r958478_ruleThe echo daemon must be disabled on AIX.
SV-215392r958478_ruleThe Internet Network News (INN) server must be disabled on AIX.
SV-215393r958480_ruleIf Stream Control Transmission Protocol (SCTP) must be disabled on AIX.
SV-215394r958480_ruleThe Reliable Datagram Sockets (RDS) protocol must be disabled on AIX.
SV-215395r958820_ruleIf automated file system mounting tool is not required on AIX, it must be disabled.
SV-215396r991589_ruleAIX process core dumps must be disabled.
SV-215397r991589_ruleAIX kernel core dumps must be disabled unless needed.
SV-215398r958528_ruleAIX must set Stack Execution Disable (SED) system wide mode to all.
SV-215399r958902_ruleAIX must protect against or limit the effects of Denial of Service (DoS) attacks by ensuring AIX is implementing rate-limiting measures on impacted network interfaces.
SV-215400r958702_ruleAIX must allow admins to send a message to all the users who logged in currently.
SV-215401r958702_ruleAIX must allow admins to send a message to a user who logged in currently.
SV-215402r958408_ruleThe AIX SSH daemon must be configured to only use FIPS 140-2 approved ciphers.
SV-215403r1009555_ruleThe AIX system must have no .netrc files on the system.
SV-215404r1137691_ruleAIX must turn on enhanced Role-Based Access Control (RBAC) to isolate security functions from nonsecurity functions, to grant system privileges to other operating system admins, and prohibit user installation of system software without explicit privileged status.
SV-215405r958478_ruleIf DHCP server is not required on AIX, the DHCP server must be disabled.
SV-215406r958478_ruleThe rwalld daemon must be disabled on AIX.
SV-215407r991562_ruleIn the event of a system failure, AIX must preserve any information necessary to determine cause of failure and any information necessary to return to operations with least disruption to mission processes.
SV-215408r991589_ruleThe /etc/shells file must exist on AIX systems.
SV-215409r991589_ruleAIX public directories must be the only world-writable directories and world-writable files must be located only in public directories.
SV-215410r991589_ruleAIX must be configured to only boot from the system boot device.
SV-215411r991589_ruleAIX must not use removable media as the boot loader.
SV-215412r991589_ruleIf the AIX host is running an SMTP service, the SMTP greeting must not provide version information.
SV-215413r991589_ruleAIX must contain no .forward files.
SV-215414r991589_ruleThe sendmail server must have the debug feature disabled on AIX systems.
SV-215415r991589_ruleSMTP service must not have the EXPN or VRFY features active on AIX systems.
SV-215416r991589_ruleAll global initialization file executable search paths must contain only absolute paths.
SV-215417r991589_ruleThe SMTP service HELP command must not be enabled on AIX.
SV-215418r991589_ruleNIS maps must be protected through hard-to-guess domain names on AIX.
SV-215419r991589_ruleThe AIX systems access control program must be configured to grant or deny system access to specific hosts.
SV-215420r991589_ruleAll AIX files and directories must have a valid group owner.
SV-215421r991589_ruleAIX control scripts library search paths must contain only absolute paths.
SV-215422r991589_ruleThe control script lists of preloaded libraries must contain only absolute paths on AIX systems.
SV-215423r991589_ruleThe global initialization file lists of preloaded libraries must contain only absolute paths on AIX.
SV-215424r991589_ruleThe local initialization file library search paths must contain only absolute paths on AIX.
SV-215425r991589_ruleThe local initialization file lists of preloaded libraries must contain only absolute paths on AIX.
SV-215426r991589_ruleAIX package management tool must be used daily to verify system software.
SV-215427r991589_ruleThe AIX DHCP client must not send dynamic DNS updates.
SV-215428r991589_ruleAIX must not run any routing protocol daemons unless the system is a router.
SV-215429r991589_ruleAIX must not process ICMP timestamp requests.
SV-215430r991589_ruleAIX must not respond to ICMPv6 echo requests sent to a broadcast address.
SV-215431r991590_ruleAIX must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.
SV-215432r991591_ruleThere must be no .rhosts, .shosts, hosts.equiv, or shosts.equiv files on the AIX system.
SV-215433r991591_ruleThe .rhosts file must not be supported in AIX PAM.
SV-215434r991592_ruleThe AIX root user home directory must not be the root directory (/).
SV-215435r991592_ruleAll AIX interactive users must be assigned a home directory in the passwd file and the directory must exist.
SV-215436r1009557_ruleThe AIX operating system must use Multi Factor Authentication.
SV-215437r991589_ruleThe AIX operating system must be configured to authenticate using Multi Factor Authentication.
SV-215438r991589_ruleThe AIX operating system must be configured to use Multi Factor Authentication for remote connections.
SV-215439r991589_ruleAIX must have the have the PowerSC Multi Factor Authentication Product configured.
SV-215440r991589_ruleThe AIX operating system must be configured to use a valid server_ca.pem file.
SV-215441r958816_ruleThe AIX operating system must accept and verify Personal Identity Verification (PIV) credentials.
SV-219057r991589_ruleAIX must employ a deny-all, allow-by-exception firewall policy for allowing connections to other systems.
SV-219956r958754_ruleAIX must be configured so that the audit system takes appropriate action when the audit storage volume is full.
SV-245557r991589_ruleThe AIX /etc/hosts file must be owned by root.
SV-245558r991589_ruleThe AIX /etc/hosts file must be group-owned by system.
SV-245559r991589_ruleThe AIX /etc/hosts file must have a mode of 0640 or less permissive.
SV-245560r991589_ruleAIX cron and crontab directories must have a mode of 0640 or less permissive.
SV-245561r991589_ruleThe AIX /etc/syslog.conf file must be owned by root.
SV-245562r991589_ruleThe AIX /etc/syslog.conf file must be group-owned by system.
SV-245563r991589_ruleThe AIX /etc/syslog.conf file must have a mode of 0640 or less permissive.
SV-245564r991589_ruleThe inetd.conf file on AIX must be group owned by the "system" group.
SV-245565r991589_ruleThe AIX /etc/inetd.conf file must have a mode of 0640 or less permissive.
SV-245566r991589_ruleThe AIX /var/spool/cron/atjobs directory must be owned by root or bin.
SV-245567r991589_ruleThe AIX /var/spool/cron/atjobs directory must be group-owned by cron.
SV-245568r991589_ruleThe AIX /var/spool/cron/atjobs directory must have a mode of 0640 or less permissive.
SV-245569r991589_ruleThe AIX cron and crontab directories must be group-owned by cron.