Skip to content

I - Mission Critical Sensitive

Rules and Groups employed by this XCCDF Profile

  • SRG-OS-000095-GPOS-00049

    <GroupDescription></GroupDescription>
    Group
  • The ntalk daemon must be disabled on AIX.

    &lt;VulnDiscussion&gt;This service establishes a two-way communication link between two users, either locally or remotely. Unless required the ntal...
    Rule High Severity
  • SRG-OS-000095-GPOS-00049

    <GroupDescription></GroupDescription>
    Group
  • The chargen daemon must be disabled on AIX.

    &lt;VulnDiscussion&gt;This service is used to test the integrity of TCP/IP packets arriving at the destination. This chargen service is a characte...
    Rule Medium Severity
  • SRG-OS-000095-GPOS-00049

    <GroupDescription></GroupDescription>
    Group
  • The discard daemon must be disabled on AIX.

    &lt;VulnDiscussion&gt;The discard service is used as a debugging and measurement tool. It sets up a listening socket and ignores data that it recei...
    Rule Medium Severity
  • SRG-OS-000095-GPOS-00049

    <GroupDescription></GroupDescription>
    Group
  • The dtspc daemon must be disabled on AIX.

    &lt;VulnDiscussion&gt;The dtspc service deals with the CDE interface of the X11 daemon. It is started automatically by the inetd daemon in response...
    Rule Medium Severity
  • SRG-OS-000095-GPOS-00049

    <GroupDescription></GroupDescription>
    Group
  • The pcnfsd daemon must be disabled on AIX.

    &lt;VulnDiscussion&gt;The pcnfsd service is an authentication and printing program, which uses NFS to provide file transfer services. This service ...
    Rule Medium Severity
  • SRG-OS-000095-GPOS-00049

    <GroupDescription></GroupDescription>
    Group
  • The rstatd daemon must be disabled on AIX.

    &lt;VulnDiscussion&gt;The rstatd service is used to provide kernel statistics and other monitorable parameters pertinent to the system such as: CPU...
    Rule Medium Severity
  • SRG-OS-000095-GPOS-00049

    <GroupDescription></GroupDescription>
    Group
  • The rusersd daemon must be disabled on AIX.

    &lt;VulnDiscussion&gt;The rusersd service runs as root and provides a list of current users active on a system. An attacker may use this service to...
    Rule Medium Severity
  • SRG-OS-000095-GPOS-00049

    <GroupDescription></GroupDescription>
    Group
  • The sprayd daemon must be disabled on AIX.

    &lt;VulnDiscussion&gt;The sprayd service is used as a tool to generate UDP packets for testing and diagnosing network problems. The service must be...
    Rule Medium Severity
  • SRG-OS-000095-GPOS-00049

    <GroupDescription></GroupDescription>
    Group
  • The klogin daemon must be disabled on AIX.

    &lt;VulnDiscussion&gt;The klogin service offers a higher degree of security than traditional rlogin or telnet by eliminating most clear-text passwo...
    Rule Medium Severity
  • SRG-OS-000095-GPOS-00049

    <GroupDescription></GroupDescription>
    Group
  • The kshell daemon must be disabled on AIX.

    &lt;VulnDiscussion&gt;The kshell service offers a higher degree of security than traditional rsh services. However, it still does not use encrypted...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules