Skip to content

IBM AIX 7.x Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-OS-000069-GPOS-00037

    <GroupDescription></GroupDescription>
    Group
  • SRG-OS-000076-GPOS-00044

    <GroupDescription></GroupDescription>
    Group
  • SRG-OS-000057-GPOS-00027

    <GroupDescription></GroupDescription>
    Group
  • AIX must remove NOPASSWD tag from sudo config files.

    &lt;VulnDiscussion&gt;sudo command does not require reauthentication if NOPASSWD tag is specified in /etc/sudoers config file, or sudoers files in ...
    Rule High Severity
  • SRG-OS-000373-GPOS-00156

    <GroupDescription></GroupDescription>
    Group
  • AIX must not have IP forwarding for IPv6 enabled unless the system is an IPv6 router.

    &lt;VulnDiscussion&gt;If the system is configured for IP forwarding and is not a designated router, it could be used to bypass network security by ...
    Rule Medium Severity
  • SRG-OS-000206-GPOS-00084

    <GroupDescription></GroupDescription>
    Group
  • AIX library files must have mode 0755 or less permissive.

    &lt;VulnDiscussion&gt;Unauthorized access could destroy the integrity of the library files.&lt;/VulnDiscussion&gt;&lt;FalsePositives&gt;&lt;/FalseP...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • Samba packages must be removed from AIX.

    &lt;VulnDiscussion&gt;If the smbpasswd file has a mode more permissive than 0600, the smbpasswd file may be maliciously accessed or modified, poten...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules