SRG-OS-000096-GPOS-00050 Controls

STIG IDVersionTitleProduct
RHEL-08-040030V1R6RHEL 8 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.
SLES-15-010220V1R4The SUSE operating system must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.
WN19-00-000330V3R1Windows Server 2019 must not have the Microsoft FTP service installed unless required by the organization.
WN19-00-000360V3R1Windows Server 2019 must not have the Telnet Client installed.
UBTU-18-010504V2R12The Ubuntu operating system must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.
UBTU-20-010407V1R6The Ubuntu operating system must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.
APPL-13-002021V1R5The macOS system must be configured to disable sending diagnostic and usage data to Apple.
APPL-13-002022V1R5The macOS system must be configured to disable Remote Apple Events.
OL07-00-040100V3R1The Oracle Linux operating system must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management Component Local Service Assessment (PPSM CLSA) and vulnerability assessments.
RHEL-07-040100V3R6The Red Hat Enterprise Linux operating system must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management Component Local Service Assessment (PPSM CLSA) and vulnerability assessments.
SLES-12-030030V3R1The SUSE operating system must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.
ALMA-09-031700V1R1AlmaLinux OS 9 must have the firewalld package installed.
OL08-00-040030V1R6OL 8 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.
OL09-00-000220V1R1OL 9 must have the firewalld package installed.
OL09-00-000221V1R1OL 9 must be configured so that the firewalld service is active.
OL09-00-000222V1R1OL 9 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.
OL09-00-000223V1R1OL 9 must control remote access methods.
OL09-00-002320V1R1OL 9 must disable the chrony daemon from acting as a server.
OL09-00-002321V1R1OL 9 must disable network management of the chrony daemon.
UBTU-24-300041V1R1Ubuntu 24.04 LTS must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL) and vulnerability assessments.
UBTU-22-251030V1R1Ubuntu 22.04 LTS must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.
WN11-00-000105V1R6Simple Network Management Protocol (SNMP) must not be installed on the system.
WN11-00-000115V1R6The Telnet Client must not be installed on the system.
WN11-00-000120V1R6The TFTP Client must not be installed on the system.
RHEL-09-251010V2R5RHEL 9 must have the firewalld package installed.
RHEL-09-251015V2R5The firewalld service on RHEL 9 must be active.
RHEL-09-251035V2R5RHEL 9 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.
RHEL-09-252025V2R5RHEL 9 must disable the chrony daemon from acting as a server.
RHEL-09-252030V2R5RHEL 9 must disable network management of the chrony daemon.
WN10-00-000105V3R1Simple Network Management Protocol (SNMP) must not be installed on the system.
WN10-00-000115V3R1The Telnet Client must not be installed on the system.
WN10-00-000120V3R1The TFTP Client must not be installed on the system.
WN16-00-000360V2R9The Microsoft FTP service must not be installed unless required.
WN16-00-000390V2R9The Telnet Client must not be installed.
WN22-00-000330V2R5Windows Server 2022 must not have the Microsoft FTP service installed unless required by the organization.
WN22-00-000360V2R5Windows Server 2022 must not have the Telnet Client installed.