U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

CIS IBM AIX 5.3 - AIX 6.1 Benchmark 1.1.0 Checklist Details (Checklist Revisions)

Supporting Resources:

Target:

Target CPE Name
IBM AIX 5.3 cpe:/o:ibm:aix:5.3 (View CVEs)
IBM AIX 6.1 cpe:/o:ibm:aix:6.1 (View CVEs)

Checklist Highlights

Checklist Name:
CIS IBM AIX 5.3 - AIX 6.1 Benchmark
Checklist ID:
334
Version:
1.1.0
Type:
Compliance
Review Status:
Final
Authority:
Third Party: Center for Internet Security (CIS)
Original Publication Date:
12/21/2010

Checklist Summary:

This document, Security Configuration Benchmark for AIX 5.3 and AIX 6.1, provides prescriptive guidance for establishing a secure configuration posture for AIX versions 5.3 and 6.1 running on the Power Systems platform. This guide was tested against AIX 5.3 TL-05 / TL-07 and AIX 6.1 TL-01, installed from IBM base installation media. To obtain the latest version of this guide, please visit http://cisecurity.org. If you have questions, comments, or have identified ways to improve this guide, please write us at feedback@cisecurity.org.

Checklist Role:

  • Server Operating System

Known Issues:

Not provided

Target Audience:

IBM AIX IT Professionals

Target Operational Environment:

  • Managed
  • Specialized Security-Limited Functionality (SSLF)

Testing Information:

Tested on AIX 5.3 TL-05 / TL-07 and AIX 6.1 TL-01

Regulatory Compliance:

Not provided

Comments/Warnings/Miscellaneous:

Not provided

Disclaimer:

By using the Products and/or the Recommendations, I and/or my organization ("we") agree and acknowledge that: No network, system, device, hardware, software or component can be made fully secure; We are using the Products and the Recommendations solely at our own risk; We are not compensating CIS to assume any liabilities associated with our use of the Products or the Recommendations, even risks that result from CIS's negligence or failure to perform; We have the sole responsibility to evaluate the risks and benefits of the Products and Recommendations to us and to adapt the Products and the Recommendations to our particular circumstances and requirements; Neither CIS, nor any CIS Party (defined below) has any responsibility to make any corrections, updates, upgrades or bug fixes or to notify us if it chooses at it sole option to do so; and Neither CIS nor any CIS Party has or will have any liability to us whatsoever (whether based in contract, tort, strict liability or otherwise) for any direct, indirect, incidental, consequential, or special damages (including without limitation loss of profits, loss of sales, loss of or damage to reputation, loss of customers, loss of software, data, information or emails, loss of privacy, loss of use of any computer or other equipment, business interruption, wasted management or other staff resources or claims of any kind against us from third parties) arising out of or in any way connected with our use of or our inability to use any of the Products or Recommendations (even if CIS has been advised of the possibility of such damages), including without limitation any liability associated with infringement of intellectual property, defects, bugs, errors, omissions, viruses, worms, backdoors, Trojan horses or other harmful items.

Product Support:

No support agreement with product vendor

Point of Contact:

feedback@cisecurity.org

Sponsor:

Not provided

Licensing:

Copyrighted

Change History:



					

Dependency/Requirements:

URL Description
http://publib.boulder.ibm.com/infocenter/pseries/v5r3/index.jsp?topic=/com.ibm.aix.security/doc/security/aix_sec_expert_aud_policy_settings.htm AIX Security Expert AIX Audit Policy (AIX 5.3 Infocentre Mar 09)
http://publib.boulder.ibm.com/infocenter/pseries/v5r3/index.jsp?topic=/com.ibm.aix.security/doc/security/aix_sec_expert_etcinetdconf_settings.htm AIX Security Expert /etc/inetd.conf Setting (AIX 5.3 Infocenter Feb 09)
http://publib.boulder.ibm.com/infocenter/pseries/v5r3/index.jsp?topic=/com.ibm.aix.security/doc/security/aix_sec_expert_etcinittab_entries.htm AIX Security Expert /etc/inittab Settings (AIX 5.3 Infocenter Jan 2009)
http://publib.boulder.ibm.com/infocenter/pseries/v5r3/index.jsp?topic=/com.ibm.aix.security/doc/security/aix_sec_expert_etcrctcpip_services_settings.htm AIX Security Expert /etc/rc.tcpip Settings (AIX 5.3 Infocenter Jan 2009)
http://publib.boulder.ibm.com/infocenter/pseries/v5r3/index.jsp?topic=/com.ibm.aix.security/doc/security/aix_sec_expert_login_policy_settings.htm AIX Security Expert Login Policy (AIX 5.3 Infocenter Jan 2009)
http://publib.boulder.ibm.com/infocenter/pseries/v5r3/index.jsp?topic=/com.ibm.aix.security/doc/security/aix_sec_expert_misc.htm AIX Security Expert Misc Changes (AIX 5.3 Infocentre Mar 09)
http://publib.boulder.ibm.com/infocenter/pseries/v5r3/index.jsp?topic=/com.ibm.aix.security/doc/security/aix_sec_expert_pwd_policy_settings.htm AIX Security Expert Password Policy (AIX 5.3 Infocenter Jan 2009)
http://publib.boulder.ibm.com/infocenter/pseries/v5r3/index.jsp?topic=/com.ibm.aix.security/doc/security/aix_sec_expert_remov_unnec_services.htm AIX Security Expert Disabling Remote Services (AIX 5.3 Infocenter Feb 09)
http://publib.boulder.ibm.com/infocenter/pseries/v5r3/index.jsp?topic=/com.ibm.aix.security/doc/security/aix_sec_expert_removal_nonauth_access.htm AIX Security Expert Automated Authentication (AIX 5.3 Infocenter Feb 09)
http://publib.boulder.ibm.com/infocenter/pseries/v5r3/index.jsp?topic=/com.ibm.aix.security/doc/security/aix_sec_expert_tuning_network_opts.htm AIX Security Expert TCP/IP Hardening (AIX 5.3 Infocenter Mar 09)
http://publib.boulder.ibm.com/infocenter/systems/index.jsp?topic=/com.ibm.aix.security/doc/security/aix_sec_expert_aud_policy_settings.htm&tocNode=toc:front/front.cmb/0/0/11/2/11/ AIX Security Expert AIX Audit Policy (AIX 6.1 Infocentre Mar 09)
http://publib.boulder.ibm.com/infocenter/systems/index.jsp?topic=/com.ibm.aix.security/doc/security/aix_sec_expert_etcinetdconf_settings.htm&tocNode=toc:front/front.cmb/0/0/11/2/14/ AIX Security Expert /etc/inetd.conf Setting (AIX 6.1 Infocenter Feb 09)
http://publib.boulder.ibm.com/infocenter/systems/index.jsp?topic=/com.ibm.aix.security/doc/security/aix_sec_expert_etcinittab_entries.htm&tocNode=toc:front/front.cmb/0/0/11/2/12/ AIX Security Expert /etc/inittab Settings (AIX 6.1 Infocenter Jan 2009)
http://publib.boulder.ibm.com/infocenter/systems/index.jsp?topic=/com.ibm.aix.security/doc/security/aix_sec_expert_etcrctcpip_services_settings.htm&tocNode=toc:front/front.cmb/0/0/11/2/13/ AIX Security Expert /etc/rc.tcpip Settings (AIX 6.1 Infocenter Jan 2009)
http://publib.boulder.ibm.com/infocenter/systems/index.jsp?topic=/com.ibm.aix.security/doc/security/aix_sec_expert_misc.htm&tocNode=toc:_nt/front.cmb/0/0/11/2/20/ AIX Security Expert Misc Changes (AIX 6.1 Infocentre Mar 09)
http://publib.boulder.ibm.com/infocenter/systems/index.jsp?topic=/com.ibm.aix.security/doc/security/aix_sec_expert_pwd_policy_settings.htm AIX Security Expert Password Policy (AIX 6.1 Infocenter Jan 2009)
http://publib.boulder.ibm.com/infocenter/systems/index.jsp?topic=/com.ibm.aix.security/doc/security/aix_sec_expert_remov_unnec_services.htm&tocNode=toc:front/front.cmb/0/0/11/2/16/ AIX Security Expert Disabling Remote Services (AIX 6.1 Infocenter Feb 09)
http://publib.boulder.ibm.com/infocenter/systems/index.jsp?topic=/com.ibm.aix.security/doc/security/aix_sec_expert_removal_nonauth_access.htm&tocNode=toc:front/front.cmb/0/0/11/2/17/ AIX Security Expert Automated Authentication (AIX 6.1 Infocenter Feb 09)
http://publib.boulder.ibm.com/infocenter/systems/index.jsp?topic=/com.ibm.aix.security/doc/security/aix_sec_expert_tuning_network_opts.htm&tocNode=toc:front/front.cmb/0/0/11/2/18/ AIX Security Expert TCP/IP Hardening (AIX 6.1 Infocenter Mar 09)
http://publib.boulder.ibm.com/infocenter/systems/topic/com.ibm.aix.security/doc/security/aix_sec_expert_login_policy_settings.htm?tocNode=toc:front/front.cmb/0/0/11/2/10/ AIX Security Expert Login Policy (AIX 6.1 Infocenter Jan 2009)
http://www.ibm.com/developerworks/eserver/articles/openssh_updated.html OpenSSH Configuration
http://www.openssh.org/ OpenSSH Configuration
http://www.redbooks.ibm.com/redbooks/pdfs/sg246396.pdf AIX 5L Auditing and Accounting (Redbook) SG24-6396-00
http://www.redbooks.ibm.com/redbooks/pdfs/sg247430.pdf AIX 6 Advanced Security Features (Redbook) SG24-7430-00
http://www.redbooks.ibm.com/redbooks/pdfs/sg247463.pdf AIX 5.3 Differences Guide (Redbook) SG24-7463-00
http://www.redbooks.ibm.com/redbooks/pdfs/sg247559.pdf AIX 6.1 Differences Guide (Redbook) SG24-7559-00
http://www14.software.ibm.com/webapp/set2/sas/f/best/home.html IBM AIX Operating System Service Strategy Details and Best Practices Dec 2008 (As of Dec 28th 2008)

References:

Reference URL Description

NIST checklist record last modified on 06/03/2013