SRG-OS-000028-GPOS-00009 Controls

STIG IDVersionTitleProduct
ALMA-09-002000V1R4AlmaLinux OS 9 must be able to directly initiate a session lock for all connection types using smart card when the smart card is removed.AlmaLinux OS 9
ALMA-09-002110V1R4AlmaLinux OS 9 must prevent a user from overriding the disabling of the graphical user smart card removal action.AlmaLinux OS 9
APPL-13-000001V1R5The macOS system must be configured to prevent Apple Watch from terminating a session lock.macOS 13 - Ventura
APPL-13-000002V1R5The macOS system must retain the session lock until the user reestablishes access using established identification and authentication procedures.macOS 13 - Ventura
APPL-13-000003V1R5The macOS system must initiate the session lock no more than five seconds after a screen saver is started.macOS 13 - Ventura
APPL-14-000001V2R4The macOS system must prevent Apple Watch from terminating a session lock.macOS 14 - Sonoma
APPL-14-000002V2R4The macOS system must enforce screen saver password.macOS 14 - Sonoma
APPL-14-000003V2R4The macOS system must enforce session lock no more than five seconds after screen saver is started.macOS 14 - Sonoma
APPL-14-002090V2R4The macOS system must disable TouchID for unlocking the device.macOS 14 - Sonoma
APPL-15-000001V1R5The macOS system must prevent Apple Watch from terminating a session lock.macOS 15 - Sequoia
APPL-15-000002V1R5The macOS system must enforce screen saver password.macOS 15 - Sequoia
APPL-15-000003V1R5The macOS system must enforce session lock no more than five seconds after screen saver is started.macOS 15 - Sequoia
APPL-15-002090V1R5The macOS system must disable TouchID for unlocking the device.macOS 15 - Sequoia
OL07-00-010060V3R3The Oracle Linux operating system must enable a user session lock until that user re-establishes access using established identification and authentication procedures.Oracle Linux 7
OL08-00-020030V2R6OL 8 must enable a user session lock until that user reestablishes access using established identification and authentication procedures for graphical user sessions.Oracle Linux 8
OL08-00-020043V2R6OL 8 must enable a user session lock until that user reestablishes access using established identification and authentication procedures for command line sessions.Oracle Linux 8
OL08-00-020050V2R6OL 8 must be able to initiate directly a session lock for all connection types using smartcard when the smartcard is removed.Oracle Linux 8
OL09-00-002123V1R3OL 9 must prevent a user from overriding the screensaver lock-enabled setting for the graphical user interface.Oracle Linux 9
OL09-00-002126V1R3OL 9 must prevent a user from overriding the disabling of the graphical user smart card removal action.Oracle Linux 9
OL09-00-002160V1R3OL 9 must be able to directly initiate a session lock for all connection types using smart card when the smart card is removed.Oracle Linux 9
RHEL-07-010060V3R9The Red Hat Enterprise Linux operating system must enable a user session lock until that user re-establishes access using established identification and authentication procedures.Red Hat Enterprise Linux 7
RHEL-08-020030V2R5RHEL 8 must enable a user session lock until that user re-establishes access using established identification and authentication procedures for graphical user sessions.Red Hat Enterprise Linux 8
RHEL-08-020050V2R5RHEL 8 must be able to initiate directly a session lock for all connection types using smartcard when the smartcard is removed.Red Hat Enterprise Linux 8
RHEL-09-271045V2R6RHEL 9 must be able to initiate directly a session lock for all connection types using smart card when the smart card is removed.Red Hat Enterprise Linux 9
RHEL-09-271050V2R6RHEL 9 must prevent a user from overriding the disabling of the graphical user smart card removal action.Red Hat Enterprise Linux 9
RHEL-09-271055V2R6RHEL 9 must enable a user session lock until that user re-establishes access using established identification and authentication procedures for graphical user sessions.Red Hat Enterprise Linux 9
RHEL-09-271060V2R6RHEL 9 must prevent a user from overriding the screensaver lock-enabled setting for the graphical user interface.Red Hat Enterprise Linux 9
SLES-12-010060V3R2The SUSE operating system must be able to lock the graphical user interface (GUI).SUSE Linux Enterprise 12
SLES-12-010070V3R2The SUSE operating system must utilize vlock to allow for session locking.SUSE Linux Enterprise 12
SLES-15-010100V2R4The SUSE operating system must be able to lock the graphical user interface (GUI).SUSE Linux Enterprise 15
SLES-15-010110V2R4The SUSE operating system must utilize vlock to allow for session locking.SUSE Linux Enterprise 15
TOSS-04-020020V2R3TOSS must retain a user's session lock until that user reestablishes access using established identification and authentication procedures.Tri-Lab Operating System Stack
UBTU-18-010401V2R15The Ubuntu operating system must retain a users session lock until that user reestablishes access using established identification and authentication procedures.Ubuntu 18.04
UBTU-20-010004V2R3The Ubuntu operating system must retain a user's session lock until that user reestablishes access using established identification and authentication procedures.Ubuntu 20.04
UBTU-22-271020V2R6Ubuntu 22.04 LTS must retain a user's session lock until that user reestablishes access using established identification and authentication procedures.Ubuntu 22.04
UBTU-24-200040V1R1Ubuntu 24.04 LTS must retain a user's session lock until the user reestablishes access using established identification and authentication procedures.Ubuntu 24.04
WN10-CC-000365V3R4Windows 10 must be configured to prevent Windows apps from being activated by voice while the system is locked.Microsoft Windows 10
WN11-CC-000365V2R5Windows 11 must be configured to prevent Windows apps from being activated by voice while the system is locked.Microsoft Windows 11
WN19-SO-000120V3R6Windows Server 2019 machine inactivity limit must be set to 15 minutes or less, locking the system with the screen saver.Microsoft Windows Server 2019
WN22-SO-000120V2R6Windows Server 2022 machine inactivity limit must be set to 15 minutes or less, locking the system with the screen saver.Microsoft Windows Server 2022