U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

OS SRG (UNIX) Version 1, Release 2 Checklist Details (Checklist Revisions)

Supporting Resources:

Target:

Target CPE Name
Apple Mac OS X 10.5 cpe:/o:apple:mac_os_x:10.5 (View CVEs)
FreeBSD cpe:/o:freebsd:freebsd (View CVEs)
HP HP-UX cpe:/o:hp:hp-ux (View CVEs)
HP HP-UX 10.20 cpe:/o:hp:hp-ux:10.20 (View CVEs)
HP HP-UX 11 cpe:/o:hp:hp-ux:11 (View CVEs)
IBM AIX 4.3 cpe:/o:ibm:aix:4.3 (View CVEs)
IBM AIX 4.3.2 cpe:/o:ibm:aix:4.3.2 (View CVEs)
IBM AIX 4.3.3 cpe:/o:ibm:aix:4.3.3 (View CVEs)
IBM AIX 5 cpe:/o:ibm:aix:5 (View CVEs)
IBM AIX 5.1 cpe:/o:ibm:aix:5.1 (View CVEs)
IBM AIX 5.3 cpe:/o:ibm:aix:5.3 (View CVEs)
IBM AIX 5L cpe:/o:ibm:aix:5l (View CVEs)
IBM AIX 6.1 cpe:/o:ibm:aix:6.1 (View CVEs)
NetBSD cpe:/o:netbsd:netbsd (View CVEs)
OpenBSD cpe:/o:openbsd:openbsd (View CVEs)
Oracle SunOS cpe:/o:oracle:sunos (View CVEs)
Sun Solaris cpe:/o:sun:solaris (View CVEs)

Checklist Highlights

Checklist Name:
OS SRG (UNIX)
Checklist ID:
357
Version:
Version 1, Release 2
Type:
Compliance
Review Status:
Under Review
Authority:
Governmental Authority: Defense Information Systems Agency
Original Publication Date:
01/31/2011

Checklist Summary:

This UNIX Technology Overview, along with the Operating System (OS) Security Requirements Guide (SRG) (UNIX Version) and associated Security Technical Implementation Guides (STIGs), provides the technical security policies, requirements, and implementation details for applying security concepts to UNIX systems. The OS SRG (UNIX Version) contains general requirements for operating systems as well as specific requirements for UNIX operating systems. This SRG may be used as a guide for enhancing the security configuration of any UNIX-like system. The Generic UNIX STIG contains all requirements present in the OS SRG (UNIX Version) and, additionally, contains check and fix procedures that are expected to be applicable to most UNIX-like systems.

Checklist Role:

  • Operating System

Known Issues:

Not provided.

Target Audience:

These requirements are designed to assist Security Managers (SMs), Information Assurance Managers (IAMs), IAOs, and System Administrators (SAs) with configuring and maintaining security controls in a UNIX environment.

Target Operational Environment:

  • Managed
  • Specialized Security-Limited Functionality (SSLF)

Testing Information:

Not provided.

Regulatory Compliance:

DoDD 8500.1 and DoDI 8500.2

Comments/Warnings/Miscellaneous:

Not provided.

Disclaimer:

The OS SRG (UNIX Version) and the Generic UNIX STIG provide requirements applicable to all UNIX platforms and should be used when no product-specific STIG is available. As the OS SRG (UNIX Version) contains no procedures and the Generic UNIX STIG does not include product-specific procedures, the use of these documents will require additional effort on the part of the SA or the reviewer for obtaining specific procedures from vendor documentation.

Product Support:

Comments or proposed revisions to this document should be sent via e-mail to [email protected]. DISA Field Security Operations (FSO) will coordinate all change requests with the relevant DoD organizations before inclusion in this document.

Point of Contact:

[email protected]

Sponsor:

Not provided.

Licensing:

Not provided.

Change History:

Version 1, Release 1 - 19 November 2010

Dependency/Requirements:

URL Description
http://iase.disa.mil/stigs/Documents/unclassified_os_srg_unix_release_memo.pdf OS SRG (UNIX) Release Memo

References:

Reference URL Description

NIST checklist record last modified on 11/21/2011


* This checklist is still undergoing review for inclusion into the NCP.