SRG-OS-000423-GPOS-00187 Controls

STIG IDVersionTitleProduct
ALMA-09-042700V1R4All AlmaLinux OS 9 networked systems must have the OpenSSH client installed.AlmaLinux OS 9
APPL-14-002062V2R4The macOS system must disable Bluetooth when no approved device is connected.macOS 14 - Sonoma
APPL-15-002062V1R5The macOS system must disable Bluetooth when no approved device is connected.macOS 15 - Sequoia
OL07-00-040300V3R3The Oracle Linux operating system must be configured so that all networked systems have SSH installed.Oracle Linux 7
OL07-00-040310V3R3The Oracle Linux operating system must be configured so that all networked systems use SSH for confidentiality and integrity of transmitted and received information as well as information during preparation for transmission.Oracle Linux 7
OL08-00-040159V2R6All OL 8 networked systems must have SSH installed.Oracle Linux 8
OL08-00-040160V2R6All OL 8 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.Oracle Linux 8
OL09-00-000250V1R3OL 9 networked systems must have SSH installed.Oracle Linux 9
OL09-00-000251V1R3OL 9 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.Oracle Linux 9
OL09-00-002342V1R3OL 9 must force a frequent session key renegotiation for SSH connections to the server.Oracle Linux 9
OL09-00-002421V1R3OL 9 must implement DOD-approved encryption in the bind package.Oracle Linux 9
RHEL-07-040300V3R9The Red Hat Enterprise Linux operating system must be configured so that all networked systems have SSH installed.Red Hat Enterprise Linux 7
RHEL-07-040310V3R9The Red Hat Enterprise Linux operating system must be configured so that all networked systems use SSH for confidentiality and integrity of transmitted and received information as well as information during preparation for transmission.Red Hat Enterprise Linux 7
RHEL-08-040160V2R5All RHEL 8 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.Red Hat Enterprise Linux 8
RHEL-08-040159V2R5All RHEL 8 networked systems must have SSH installed.Red Hat Enterprise Linux 8
RHEL-09-255010V2R6All RHEL 9 networked systems must have SSH installed.Red Hat Enterprise Linux 9
RHEL-09-255015V2R6All RHEL 9 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.Red Hat Enterprise Linux 9
RHEL-09-255090V2R6RHEL 9 must force a frequent session key renegotiation for SSH connections to the server.Red Hat Enterprise Linux 9
RHEL-09-672050V2R6RHEL 9 must implement DOD-approved encryption in the bind package.Red Hat Enterprise Linux 9
SLES-12-030100V3R2All networked SUSE operating systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.SUSE Linux Enterprise 12
SLES-15-010530V2R4All networked SUSE operating systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.SUSE Linux Enterprise 15
TOSS-04-010280V2R3All TOSS networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.Tri-Lab Operating System Stack
UBTU-18-010420V2R15The Ubuntu operating system must use SSH to protect the confidentiality and integrity of transmitted information unless otherwise protected by alternative physical safeguards, such as, at a minimum, a Protected Distribution System (PDS).Ubuntu 18.04
UBTU-20-010042V2R3The Ubuntu operating system must use SSH to protect the confidentiality and integrity of transmitted information.Ubuntu 20.04
UBTU-22-255010V2R6Ubuntu 22.04 LTS must have SSH installed.Ubuntu 22.04
UBTU-22-255015V2R6Ubuntu 22.04 LTS must use SSH to protect the confidentiality and integrity of transmitted information.Ubuntu 22.04
UBTU-24-100800V1R1Ubuntu 24.04 LTS must have SSH installed.Ubuntu 24.04
UBTU-24-100810V1R1Ubuntu 24.04 LTS must use SSH to protect the confidentiality and integrity of transmitted information.Ubuntu 24.04
WN10-SO-000035V3R4Outgoing secure channel traffic must be encrypted or signed.Microsoft Windows 10
WN10-SO-000040V3R4Outgoing secure channel traffic must be encrypted when possible.Microsoft Windows 10
WN10-SO-000045V3R4Outgoing secure channel traffic must be signed when possible.Microsoft Windows 10
WN10-SO-000060V3R4The system must be configured to require a strong session key.Microsoft Windows 10
WN10-SO-000100V3R4The Windows SMB client must be configured to always perform SMB packet signing.Microsoft Windows 10
WN10-SO-000120V3R4The Windows SMB server must be configured to always perform SMB packet signing.Microsoft Windows 10
WN11-SO-000035V2R5Outgoing secure channel traffic must be encrypted or signed.Microsoft Windows 11
WN11-SO-000040V2R5Outgoing secure channel traffic must be encrypted.Microsoft Windows 11
WN11-SO-000045V2R5Outgoing secure channel traffic must be signed.Microsoft Windows 11
WN11-SO-000060V2R5The system must be configured to require a strong session key.Microsoft Windows 11
WN11-SO-000100V2R5The Windows SMB client must be configured to always perform SMB packet signing.Microsoft Windows 11
WN11-SO-000120V2R5The Windows SMB server must be configured to always perform SMB packet signing.Microsoft Windows 11
WN16-DC-000320V2R9Domain controllers must require LDAP access signing.Microsoft Windows Server 2016
WN16-SO-000080V2R9The setting Domain member: Digitally encrypt or sign secure channel data (always) must be configured to Enabled.Microsoft Windows Server 2016
WN16-SO-000090V2R9The setting Domain member: Digitally encrypt secure channel data (when possible) must be configured to enabled.Microsoft Windows Server 2016
WN16-SO-000100V2R9The setting Domain member: Digitally sign secure channel data (when possible) must be configured to Enabled.Microsoft Windows Server 2016
WN16-SO-000130V2R9Windows Server 2016 must be configured to require a strong session key.Microsoft Windows Server 2016
WN16-SO-000190V2R9The setting Microsoft network client: Digitally sign communications (always) must be configured to Enabled.Microsoft Windows Server 2016
WN16-SO-000200V2R9The setting Microsoft network client: Digitally sign communications (if server agrees) must be configured to Enabled.Microsoft Windows Server 2016
WN16-SO-000230V2R9The setting Microsoft network server: Digitally sign communications (always) must be configured to Enabled.Microsoft Windows Server 2016
WN16-SO-000240V2R9The setting Microsoft network server: Digitally sign communications (if client agrees) must be configured to Enabled.Microsoft Windows Server 2016
WN19-DC-000320V3R6Windows Server 2019 domain controllers must require LDAP access signing.Microsoft Windows Server 2019
WN19-SO-000060V3R6Windows Server 2019 setting Domain member: Digitally encrypt or sign secure channel data (always) must be configured to Enabled.Microsoft Windows Server 2019
WN19-SO-000070V3R6Windows Server 2019 setting Domain member: Digitally encrypt secure channel data (when possible) must be configured to enabled.Microsoft Windows Server 2019
WN19-SO-000080V3R6Windows Server 2019 setting Domain member: Digitally sign secure channel data (when possible) must be configured to Enabled.Microsoft Windows Server 2019
WN19-SO-000110V3R6Windows Server 2019 must be configured to require a strong session key.Microsoft Windows Server 2019
WN19-SO-000160V3R6Windows Server 2019 setting Microsoft network client: Digitally sign communications (always) must be configured to Enabled.Microsoft Windows Server 2019
WN19-SO-000170V3R6Windows Server 2019 setting Microsoft network client: Digitally sign communications (if server agrees) must be configured to Enabled.Microsoft Windows Server 2019
WN19-SO-000190V3R6Windows Server 2019 setting Microsoft network server: Digitally sign communications (always) must be configured to Enabled.Microsoft Windows Server 2019
WN19-SO-000200V3R6Windows Server 2019 setting Microsoft network server: Digitally sign communications (if client agrees) must be configured to Enabled.Microsoft Windows Server 2019
WN22-DC-000320V2R6Windows Server 2022 domain controllers must require LDAP access signing.Microsoft Windows Server 2022
WN22-SO-000060V2R6Windows Server 2022 setting Domain member: Digitally encrypt or sign secure channel data (always) must be configured to Enabled.Microsoft Windows Server 2022
WN22-SO-000070V2R6Windows Server 2022 setting Domain member: Digitally encrypt secure channel data (when possible) must be configured to Enabled.Microsoft Windows Server 2022
WN22-SO-000080V2R6Windows Server 2022 setting Domain member: Digitally sign secure channel data (when possible) must be configured to Enabled.Microsoft Windows Server 2022
WN22-SO-000110V2R6Windows Server 2022 must be configured to require a strong session key.Microsoft Windows Server 2022
WN22-SO-000160V2R6Windows Server 2022 setting Microsoft network client: Digitally sign communications (always) must be configured to Enabled.Microsoft Windows Server 2022
WN22-SO-000170V2R6Windows Server 2022 setting Microsoft network client: Digitally sign communications (if server agrees) must be configured to Enabled.Microsoft Windows Server 2022
WN22-SO-000190V2R6Windows Server 2022 setting Microsoft network server: Digitally sign communications (always) must be configured to Enabled.Microsoft Windows Server 2022
WN22-SO-000200V2R6Windows Server 2022 setting Microsoft network server: Digitally sign communications (if client agrees) must be configured to Enabled.Microsoft Windows Server 2022