Skip to content

I - Mission Critical Classified

Rules and Groups employed by this XCCDF Profile

  • SRG-OS-000480-GPOS-00227

    Group
  • The AIX /etc/syslog.conf file must have a mode of 0640 or less permissive.

    Unauthorized permissions of the /etc/syslog.conf file can lead to the ability for a malicious actor to alter or disrupt system logging activities. This can aid the malicious actor in avoiding detec...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    Group
  • The inetd.conf file on AIX must be group owned by the "system" group.

    Failure to give ownership of sensitive files or utilities to system groups may provide unauthorized users with the potential to access sensitive information or change the system configuration which...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    Group
  • The AIX /etc/inetd.conf file must have a mode of 0640 or less permissive.

    Failure to set proper permissions of sensitive files or utilities may provide unauthorized users with the potential to access sensitive information or change the system configuration which could we...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    Group
  • The AIX /var/spool/cron/atjobs directory must be owned by root or bin.

    Unauthorized ownership of the /var/spool/cron/atjobs directory could permit unauthorized users the ability to alter atjobs and run automated jobs as privileged users. Failure to set proper permissi...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    Group
  • The AIX /var/spool/cron/atjobs directory must be group-owned by cron.

    Unauthorized group ownership of the /var/spool/cron/atjobs directory could permit unauthorized users the ability to alter atjobs and run automated jobs as privileged users. Failure to set proper pe...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    Group
  • The AIX /var/spool/cron/atjobs directory must have a mode of 0640 or less permissive.

    Incorrect permissions of the /var/spool/cron/atjobs directory could permit unauthorized users the ability to alter atjobs and run automated jobs as privileged users. Failure to set proper permissio...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    Group
  • The AIX cron and crontab directories must be group-owned by cron.

    Incorrect group ownership of the cron or crontab directories could permit unauthorized users the ability to alter cron jobs and run automated jobs as privileged users. Failure to give ownership of ...
    Rule Medium Severity
  • SRG-OS-000001-GPOS-00001

    Group
  • AIX /etc/security/mkuser.sys.custom file must not exist unless it is needed for customizing a new user account.

    The "/etc/security/mkuser.sys.custom" is called by "/etc/security/mkuser.sys" to customize the new user account when a new user is created, or a user is logging into the system without a home direc...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules