I - Mission Critical Public
Rules and Groups employed by this XCCDF Profile
-
SRG-OS-000480-GPOS-00227
Group -
The AIX /etc/hosts file must be group-owned by system.
Unauthorized group ownership of the /etc/hosts file can lead to the ability for a malicious actor to redirect traffic to servers of their choice. It is also possible to use the /etc/hosts file to b...Rule Medium Severity -
SRG-OS-000480-GPOS-00227
Group -
The AIX /etc/hosts file must have a mode of 0640 or less permissive.
Unauthorized permissions of the /etc/hosts file can lead to the ability for a malicious actor to redirect traffic to servers of their choice. It is also possible to use the /etc/hosts file to block...Rule Medium Severity -
SRG-OS-000480-GPOS-00227
Group -
AIX cron and crontab directories must have a mode of 0640 or less permissive.
Incorrect permissions of the cron or crontab directories could permit unauthorized users the ability to alter cron jobs and run automated jobs as privileged users. Failure to set proper permissions...Rule Medium Severity -
SRG-OS-000480-GPOS-00227
Group -
The AIX /etc/syslog.conf file must be owned by root.
Unauthorized ownership of the /etc/syslog.conf file can lead to the ability for a malicious actor to alter or disrupt system logging activities. This can aid the malicious actor in avoiding detecti...Rule Medium Severity -
SRG-OS-000480-GPOS-00227
Group -
The AIX /etc/syslog.conf file must be group-owned by system.
Unauthorized group ownership of the /etc/syslog.conf file can lead to the ability for a malicious actor to alter or disrupt system logging activities. This can aid the malicious actor in avoiding d...Rule Medium Severity -
SRG-OS-000480-GPOS-00227
Group -
The AIX /etc/syslog.conf file must have a mode of 0640 or less permissive.
Unauthorized permissions of the /etc/syslog.conf file can lead to the ability for a malicious actor to alter or disrupt system logging activities. This can aid the malicious actor in avoiding detec...Rule Medium Severity -
SRG-OS-000480-GPOS-00227
Group -
The inetd.conf file on AIX must be group owned by the "system" group.
Failure to give ownership of sensitive files or utilities to system groups may provide unauthorized users with the potential to access sensitive information or change the system configuration which...Rule Medium Severity -
SRG-OS-000480-GPOS-00227
Group -
The AIX /etc/inetd.conf file must have a mode of 0640 or less permissive.
Failure to set proper permissions of sensitive files or utilities may provide unauthorized users with the potential to access sensitive information or change the system configuration which could we...Rule Medium Severity -
SRG-OS-000480-GPOS-00227
Group -
The AIX /var/spool/cron/atjobs directory must be owned by root or bin.
Unauthorized ownership of the /var/spool/cron/atjobs directory could permit unauthorized users the ability to alter atjobs and run automated jobs as privileged users. Failure to set proper permissi...Rule Medium Severity -
SRG-OS-000480-GPOS-00227
Group -
The AIX /var/spool/cron/atjobs directory must be group-owned by cron.
Unauthorized group ownership of the /var/spool/cron/atjobs directory could permit unauthorized users the ability to alter atjobs and run automated jobs as privileged users. Failure to set proper pe...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.