Skip to content

IBM AIX 7.x Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • The AIX /etc/syslog.conf file must be owned by root.

    &lt;VulnDiscussion&gt;Unauthorized ownership of the /etc/syslog.conf file can lead to the ability for a malicious actor to alter or disrupt system ...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • The AIX /etc/syslog.conf file must be group-owned by system.

    &lt;VulnDiscussion&gt;Unauthorized group ownership of the /etc/syslog.conf file can lead to the ability for a malicious actor to alter or disrupt s...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • The AIX /etc/syslog.conf file must have a mode of 0640 or less permissive.

    &lt;VulnDiscussion&gt;Unauthorized permissions of the /etc/syslog.conf file can lead to the ability for a malicious actor to alter or disrupt syste...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • The inetd.conf file on AIX must be group owned by the "system" group.

    &lt;VulnDiscussion&gt;Failure to give ownership of sensitive files or utilities to system groups may provide unauthorized users with the potential ...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • The AIX /etc/inetd.conf file must have a mode of 0640 or less permissive.

    &lt;VulnDiscussion&gt;Failure to set proper permissions of sensitive files or utilities may provide unauthorized users with the potential to access...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • The AIX /var/spool/cron/atjobs directory must be owned by root or bin.

    &lt;VulnDiscussion&gt;Unauthorized ownership of the /var/spool/cron/atjobs directory could permit unauthorized users the ability to alter atjobs an...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • The AIX /var/spool/cron/atjobs directory must be group-owned by cron.

    &lt;VulnDiscussion&gt;Unauthorized group ownership of the /var/spool/cron/atjobs directory could permit unauthorized users the ability to alter atj...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • The AIX /var/spool/cron/atjobs directory must have a mode of 0640 or less permissive.

    &lt;VulnDiscussion&gt;Incorrect permissions of the /var/spool/cron/atjobs directory could permit unauthorized users the ability to alter atjobs and...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • The AIX cron and crontab directories must be group-owned by cron.

    &lt;VulnDiscussion&gt;Incorrect group ownership of the cron or crontab directories could permit unauthorized users the ability to alter cron jobs a...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules