Skip to content

Solaris 11 X86 Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • The centralized process core dump data directory must be owned by root.

    <VulnDiscussion>Process core dumps contain the memory in use by the process when it crashed. Any data the process was handling may be contain...
    Rule Medium Severity
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group
  • SRG-OS-000324

    <GroupDescription></GroupDescription>
    Group
  • SRG-OS-000215

    <GroupDescription></GroupDescription>
    Group
  • SRG-OS-000425

    <GroupDescription></GroupDescription>
    Group
  • The centralized process core dump data directory must be group-owned by root, bin, or sys.

    &lt;VulnDiscussion&gt;Process core dumps contain the memory in use by the process when it crashed. Any data the process was handling may be contain...
    Rule Medium Severity
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group
  • The centralized process core dump data directory must have mode 0700 or less permissive.

    &lt;VulnDiscussion&gt;Process core dumps contain the memory in use by the process when it crashed. Any data the process was handling may be contain...
    Rule Medium Severity
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group
  • Kernel core dumps must be disabled unless needed.

    &lt;VulnDiscussion&gt;Kernel core dumps may contain the full contents of system memory at the time of the crash. Kernel core dumps may consume a co...
    Rule Medium Severity
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group
  • The kernel core dump data directory must be owned by root.

    &lt;VulnDiscussion&gt;Kernel core dumps may contain the full contents of system memory at the time of the crash. As the system memory may contain s...
    Rule Medium Severity
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group
  • The kernel core dump data directory must be group-owned by root.

    &lt;VulnDiscussion&gt;Kernel core dumps may contain the full contents of system memory at the time of the crash. As the system memory may contain s...
    Rule Medium Severity
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group
  • The kernel core dump data directory must have mode 0700 or less permissive.

    &lt;VulnDiscussion&gt;Kernel core dumps may contain the full contents of system memory at the time of the crash. As the system memory may contain s...
    Rule Medium Severity
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group
  • System BIOS or system controllers supporting password protection must have administrator accounts/passwords configured, and no others. (Intel)

    &lt;VulnDiscussion&gt;A system's BIOS or system controller handles the initial startup of a system and its configuration must be protected from una...
    Rule Low Severity
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules