SRG-OS-000138-GPOS-00069 Controls

STIG IDVersionTitleProduct
ALMA-09-042150V1R4Any AlmaLinux OS 9 world-writable directories must be owned by root, sys, bin, or an application user.AlmaLinux OS 9
ALMA-09-042260V1R4A sticky bit must be set on all AlmaLinux OS 9 public directories.AlmaLinux OS 9
OL07-00-010375V3R3The Oracle Linux operating system must restrict access to the kernel message buffer.Oracle Linux 7
OL08-00-010190V2R6A sticky bit must be set on all OL 8 public directories to prevent unauthorized and unintended information transferred via shared system resources.Oracle Linux 8
OL08-00-010375V2R6OL 8 must restrict access to the kernel message buffer.Oracle Linux 8
OL08-00-010376V2R6OL 8 must prevent kernel profiling by unprivileged users.Oracle Linux 8
OL09-00-002510V1R3OL 9 must be configured so that a sticky bit must be set on all public directories.Oracle Linux 9
OL09-00-002516V1R3OL 9 world-writable directories must be owned by root, sys, bin, or an application user.Oracle Linux 9
RHEL-07-010375V3R14The Red Hat Enterprise Linux operating system must restrict access to the kernel message buffer.Red Hat Enterprise Linux 7
RHEL-08-010190V2R5A sticky bit must be set on all RHEL 8 public directories to prevent unauthorized and unintended information transferred via shared system resources.Red Hat Enterprise Linux 8
RHEL-08-010375V2R5RHEL 8 must restrict access to the kernel message buffer.Red Hat Enterprise Linux 8
RHEL-08-010376V2R5RHEL 8 must prevent kernel profiling by unprivileged users.Red Hat Enterprise Linux 8
RHEL-09-232245V2R6A sticky bit must be set on all RHEL 9 public directories.Red Hat Enterprise Linux 9
SLES-12-010460V3R2The sticky bit must be set on all SUSE operating system world-writable directories.SUSE Linux Enterprise 12
SLES-12-010375V3R2The SUSE operating system must restrict access to the kernel message buffer.SUSE Linux Enterprise 12
SLES-15-010300V2R4The sticky bit must be set on all SUSE operating system world-writable directories.SUSE Linux Enterprise 15
SLES-15-010375V2R4The SUSE operating system must restrict access to the kernel message buffer.SUSE Linux Enterprise 15
TOSS-04-010100V2R3TOSS must prevent unauthorized and unintended information transfer via shared system resources.Tri-Lab Operating System Stack
UBTU-18-010120V2R15The Ubuntu operating system must set a sticky bit on all public directories to prevent unauthorized and unintended information transferred via shared system resources.Ubuntu 18.04
UBTU-18-010510V2R15The Ubuntu operating system must restrict access to the kernel message buffer.Ubuntu 18.04
UBTU-20-010411V2R3The Ubuntu operating system must set a sticky bit on all public directories to prevent unauthorized and unintended information transferred via shared system resources.Ubuntu 20.04
UBTU-20-010401V2R3The Ubuntu operating system must restrict access to the kernel message buffer.Ubuntu 20.04
UBTU-22-213010V2R6Ubuntu 22.04 LTS must restrict access to the kernel message buffer.Ubuntu 22.04
UBTU-22-232145V2R6Ubuntu 22.04 LTS must set a sticky bit on all public directories to prevent unauthorized and unintended information transferred via shared system resources.Ubuntu 22.04
UBTU-24-600140V1R1Ubuntu 24.04 LTS must restrict access to the kernel message buffer.Ubuntu 24.04
UBTU-24-600150V1R1Ubuntu 24.04 LTS must set a sticky bit on all public directories to prevent unauthorized and unintended information transferred via shared system resources.Ubuntu 24.04
WN10-00-000060V3R4Non system-created file shares on a system must limit access to groups that require it.Microsoft Windows 10
WN10-CC-000155V3R4Solicited Remote Assistance must not be allowed.Microsoft Windows 10
WN10-CC-000275V3R4Local drives must be prevented from sharing with Remote Desktop Session Hosts.Microsoft Windows 10
WN10-EP-000310V3R4Windows 10 Kernel (Direct Memory Access) DMA Protection must be enabled.Microsoft Windows 10
WN10-SO-000150V3R4Anonymous enumeration of shares must be restricted.Microsoft Windows 10
WN10-SO-000165V3R4Anonymous access to Named Pipes and Shares must be restricted.Microsoft Windows 10
WN11-00-000060V2R5Non-system-created file shares on a system must limit access to groups that require it.Microsoft Windows 11
WN11-CC-000155V2R5Solicited Remote Assistance must not be allowed.Microsoft Windows 11
WN11-CC-000275V2R5Local drives must be prevented from sharing with Remote Desktop Session Hosts.Microsoft Windows 11
WN11-SO-000150V2R5Anonymous enumeration of shares must be restricted.Microsoft Windows 11
WN11-SO-000165V2R5Anonymous access to Named Pipes and Shares must be restricted.Microsoft Windows 11
WN16-00-000250V2R9Non-system-created file shares on a system must limit access to groups that require it.Microsoft Windows Server 2016
WN16-CC-000380V2R9Local drives must be prevented from sharing with Remote Desktop Session Hosts.Microsoft Windows Server 2016
WN16-DC-000120V2R9Data files owned by users must be on a different logical partition from the directory server data files.Microsoft Windows Server 2016
WN16-SO-000270V2R9Anonymous enumeration of shares must not be allowed.Microsoft Windows Server 2016
WN16-SO-000300V2R9Anonymous access to Named Pipes and Shares must be restricted.Microsoft Windows Server 2016
WN19-00-000230V3R6Windows Server 2019 non-system-created file shares must limit access to groups that require it.Microsoft Windows Server 2019
WN19-CC-000350V3R6Windows Server 2019 Remote Desktop Services must prevent drive redirection.Microsoft Windows Server 2019
WN19-DC-000120V3R6Windows Server 2019 data files owned by users must be on a different logical partition from the directory server data files.Microsoft Windows Server 2019
WN19-SO-000230V3R6Windows Server 2019 must not allow anonymous enumeration of shares.Microsoft Windows Server 2019
WN19-SO-000250V3R6Windows Server 2019 must restrict anonymous access to Named Pipes and Shares.Microsoft Windows Server 2019
WN22-00-000230V2R6Windows Server 2022 nonsystem-created file shares must limit access to groups that require it.Microsoft Windows Server 2022
WN22-CC-000350V2R6Windows Server 2022 Remote Desktop Services must prevent drive redirection.Microsoft Windows Server 2022
WN22-DC-000120V2R6Windows Server 2022 data files owned by users must be on a different logical partition from the directory server data files.Microsoft Windows Server 2022
WN22-SO-000230V2R6Windows Server 2022 must not allow anonymous enumeration of shares.Microsoft Windows Server 2022
WN22-SO-000250V2R6Windows Server 2022 must restrict anonymous access to Named Pipes and Shares.Microsoft Windows Server 2022