Skip to content

II - Mission Support Public

Rules and Groups employed by this XCCDF Profile

  • AIX must not respond to ICMPv6 echo requests sent to a broadcast address.

    <VulnDiscussion>Responding to broadcast ICMP echo requests facilitates network mapping and provides a vector for amplification attacks.</V...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00228

    <GroupDescription></GroupDescription>
    Group
  • AIX must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.

    &lt;VulnDiscussion&gt;Setting the most restrictive default permissions ensures that when new accounts are created they do not have unnecessary acce...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00229

    <GroupDescription></GroupDescription>
    Group
  • There must be no .rhosts, .shosts, hosts.equiv, or shosts.equiv files on the AIX system.

    &lt;VulnDiscussion&gt;Trust files are convenient, but when used in conjunction with the remote login services, they can allow unauthenticated acces...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules