SRG-OS-000368-GPOS-00154 Controls

STIG ID Version Title Product
OL07-00-021024 V2R10 The Oracle Linux operating system must mount /dev/shm with secure options.
WN10-CC-000180 V3R1 Autoplay must be turned off for non-volume devices.
WN10-CC-000185 V3R1 The default autorun behavior must be configured to prevent autorun commands.
WN10-CC-000190 V3R1 Autoplay must be disabled for all drives.
RHEL-09-231045 V1R2 RHEL 9 must prevent device files from being interpreted on file systems that contain user home directories.
RHEL-09-231050 V1R2 RHEL 9 must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories.
RHEL-09-231095 V1R2 RHEL 9 must mount /boot with the nodev option.
RHEL-09-231100 V1R2 RHEL 9 must prevent files with the setuid and setgid bit set from being executed on the /boot directory.
RHEL-09-231105 V1R2 RHEL 9 must prevent files with the setuid and setgid bit set from being executed on the /boot/efi directory.
RHEL-09-231110 V1R2 RHEL 9 must mount /dev/shm with the nodev option.
RHEL-09-231115 V1R2 RHEL 9 must mount /dev/shm with the noexec option.
RHEL-09-231120 V1R2 RHEL 9 must mount /dev/shm with the nosuid option.
RHEL-09-231125 V1R2 RHEL 9 must mount /tmp with the nodev option.
RHEL-09-231130 V1R2 RHEL 9 must mount /tmp with the noexec option.
RHEL-09-231135 V1R2 RHEL 9 must mount /tmp with the nosuid option.
RHEL-09-231140 V1R2 RHEL 9 must mount /var with the nodev option.
RHEL-09-231145 V1R2 RHEL 9 must mount /var/log with the nodev option.
RHEL-09-231150 V1R2 RHEL 9 must mount /var/log with the noexec option.
RHEL-09-231155 V1R2 RHEL 9 must mount /var/log with the nosuid option.
RHEL-09-231160 V1R2 RHEL 9 must mount /var/log/audit with the nodev option.
RHEL-09-231165 V1R2 RHEL 9 must mount /var/log/audit with the noexec option.
RHEL-09-231170 V1R2 RHEL 9 must mount /var/log/audit with the nosuid option.
RHEL-09-231175 V1R2 RHEL 9 must mount /var/tmp with the nodev option.
RHEL-09-231180 V1R2 RHEL 9 must mount /var/tmp with the noexec option.
RHEL-09-231185 V1R2 RHEL 9 must mount /var/tmp with the nosuid option.
RHEL-09-271030 V1R2 RHEL 9 must disable the graphical user interface autorun function unless required.
WN16-CC-000250 V2R7 AutoPlay must be turned off for non-volume devices.
WN16-CC-000260 V2R7 The default AutoRun behavior must be configured to prevent AutoRun commands.
WN16-CC-000270 V2R7 AutoPlay must be disabled for all drives.
RHEL-07-021024 V3R9 The Red Hat Enterprise Linux operating system must mount /dev/shm with secure options.
OL08-00-040120 V1R2 OL 8 must mount "/dev/shm" with the "nodev" option.
OL08-00-040121 V1R2 OL 8 must mount "/dev/shm" with the "nosuid" option.
OL08-00-040122 V1R2 OL 8 must mount "/dev/shm" with the "noexec" option.
OL08-00-040123 V1R2 OL 8 must mount "/tmp" with the "nodev" option.
OL08-00-040124 V1R2 OL 8 must mount "/tmp" with the "nosuid" option.
OL08-00-040125 V1R2 OL 8 must mount "/tmp" with the "noexec" option.
OL08-00-040126 V1R2 OL 8 must mount "/var/log" with the "nodev" option.
OL08-00-040127 V1R2 OL 8 must mount "/var/log" with the "nosuid" option.
OL08-00-040128 V1R2 OL 8 must mount "/var/log" with the "noexec" option.
OL08-00-040129 V1R2 OL 8 must mount "/var/log/audit" with the "nodev" option.
OL08-00-040130 V1R2 OL 8 must mount "/var/log/audit" with the "nosuid" option.
OL08-00-040131 V1R2 OL 8 must mount "/var/log/audit" with the "noexec" option.
OL08-00-040132 V1R2 OL 8 must mount "/var/tmp" with the "nodev" option.
OL08-00-040133 V1R2 OL 8 must mount "/var/tmp" with the "nosuid" option.
OL08-00-040134 V1R2 OL 8 must mount "/var/tmp" with the "noexec" option.
OL08-00-040135 V1R2 The OL 8 "fapolicy" module must be installed.
OL08-00-040136 V1R2 The OL 8 "fapolicy" module must be enabled.
OL08-00-040137 V1R2 The OL 8 fapolicy module must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
WN19-CC-000210 V3R1 Windows Server 2019 Autoplay must be turned off for non-volume devices.
WN19-CC-000220 V3R1 Windows Server 2019 default AutoRun behavior must be configured to prevent AutoRun commands.
WN19-CC-000230 V3R1 Windows Server 2019 AutoPlay must be disabled for all drives.
UBTU-20-010439 V1R5 The Ubuntu operating system must be configured to use AppArmor.
WN22-CC-000210 V1R5 Windows Server 2022 Autoplay must be turned off for nonvolume devices.
WN22-CC-000220 V1R5 Windows Server 2022 default AutoRun behavior must be configured to prevent AutoRun commands.
WN22-CC-000230 V1R5 Windows Server 2022 AutoPlay must be disabled for all drives.
UBTU-18-010441 V2R10 The Ubuntu operating system must be configured to use AppArmor.
UBTU-22-431015 V1R1 Ubuntu 22.04 LTS must be configured to use AppArmor.
RHEL-08-040120 V1R2 RHEL 8 must mount /dev/shm with the nodev option.
RHEL-08-040121 V1R2 RHEL 8 must mount /dev/shm with the nosuid option.
RHEL-08-040122 V1R2 RHEL 8 must mount /dev/shm with the noexec option.
RHEL-08-040123 V1R2 RHEL 8 must mount /tmp with the nodev option.
RHEL-08-040124 V1R2 RHEL 8 must mount /tmp with the nosuid option.
RHEL-08-040125 V1R2 RHEL 8 must mount /tmp with the noexec option.
RHEL-08-040126 V1R2 RHEL 8 must mount /var/log with the nodev option.
RHEL-08-040127 V1R2 RHEL 8 must mount /var/log with the nosuid option.
RHEL-08-040128 V1R2 RHEL 8 must mount /var/log with the noexec option.
RHEL-08-040129 V1R2 RHEL 8 must mount /var/log/audit with the nodev option.
RHEL-08-040130 V1R2 RHEL 8 must mount /var/log/audit with the nosuid option.
RHEL-08-040131 V1R2 RHEL 8 must mount /var/log/audit with the noexec option.
RHEL-08-040132 V1R2 RHEL 8 must mount /var/tmp with the nodev option.
RHEL-08-040133 V1R2 RHEL 8 must mount /var/tmp with the nosuid option.
RHEL-08-040134 V1R2 RHEL 8 must mount /var/tmp with the noexec option.
RHEL-08-040135 V1R2 The RHEL 8 fapolicy module must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
WN11-CC-000180 V1R5 Autoplay must be turned off for non-volume devices.
WN11-CC-000185 V1R5 The default autorun behavior must be configured to prevent autorun commands.
WN11-CC-000190 V1R5 Autoplay must be disabled for all drives.