SRG-OS-000423-GPOS-00187 Controls

STIG IDVersionTitleProduct
ALMA-09-042700V1R1All AlmaLinux OS 9 networked systems must have the OpenSSH client installed.
UBTU-18-010420V2R15The Ubuntu operating system must use SSH to protect the confidentiality and integrity of transmitted information unless otherwise protected by alternative physical safeguards, such as, at a minimum, a Protected Distribution System (PDS).
UBTU-20-010042V1R9The Ubuntu operating system must use SSH to protect the confidentiality and integrity of transmitted information.
UBTU-24-100800V1R1Ubuntu 24.04 LTS must have SSH installed.
UBTU-24-100810V1R1Ubuntu 24.04 LTS must use SSH to protect the confidentiality and integrity of transmitted information.
WN22-DC-000320V2R1Windows Server 2022 domain controllers must require LDAP access signing.
WN22-SO-000060V2R1Windows Server 2022 setting Domain member: Digitally encrypt or sign secure channel data (always) must be configured to Enabled.
WN22-SO-000070V2R1Windows Server 2022 setting Domain member: Digitally encrypt secure channel data (when possible) must be configured to Enabled.
WN22-SO-000080V2R1Windows Server 2022 setting Domain member: Digitally sign secure channel data (when possible) must be configured to Enabled.
WN22-SO-000110V2R1Windows Server 2022 must be configured to require a strong session key.
WN22-SO-000160V2R1Windows Server 2022 setting Microsoft network client: Digitally sign communications (always) must be configured to Enabled.
WN22-SO-000170V2R1Windows Server 2022 setting Microsoft network client: Digitally sign communications (if server agrees) must be configured to Enabled.
WN22-SO-000190V2R1Windows Server 2022 setting Microsoft network server: Digitally sign communications (always) must be configured to Enabled.
WN22-SO-000200V2R1Windows Server 2022 setting Microsoft network server: Digitally sign communications (if client agrees) must be configured to Enabled.
WN10-SO-000035V2R8Outgoing secure channel traffic must be encrypted or signed.
WN10-SO-000040V2R8Outgoing secure channel traffic must be encrypted when possible.
WN10-SO-000045V2R8Outgoing secure channel traffic must be signed when possible.
WN10-SO-000060V2R8The system must be configured to require a strong session key.
WN10-SO-000100V2R8The Windows SMB client must be configured to always perform SMB packet signing.
WN10-SO-000120V2R8The Windows SMB server must be configured to always perform SMB packet signing.
APPL-15-002062V1R1The macOS system must disable Bluetooth when no approved device is connected.
APPL-14-002062V2R1The macOS system must disable Bluetooth when no approved device is connected.
WN11-SO-000035V2R1Outgoing secure channel traffic must be encrypted or signed.
WN11-SO-000040V2R1Outgoing secure channel traffic must be encrypted.
WN11-SO-000045V2R1Outgoing secure channel traffic must be signed.
WN11-SO-000060V2R1The system must be configured to require a strong session key.
WN11-SO-000100V2R1The Windows SMB client must be configured to always perform SMB packet signing.
WN11-SO-000120V2R1The Windows SMB server must be configured to always perform SMB packet signing.
UBTU-22-255010V2R1Ubuntu 22.04 LTS must have SSH installed.
UBTU-22-255015V2R1Ubuntu 22.04 LTS must use SSH to protect the confidentiality and integrity of transmitted information.
RHEL-08-040160V1R9All RHEL 8 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
RHEL-08-040159V1R9All RHEL 8 networked systems must have SSH installed.
RHEL-07-040300V3R8The Red Hat Enterprise Linux operating system must be configured so that all networked systems have SSH installed.
RHEL-07-040310V3R8The Red Hat Enterprise Linux operating system must be configured so that all networked systems use SSH for confidentiality and integrity of transmitted and received information as well as information during preparation for transmission.
RHEL-09-255010V2R1All RHEL 9 networked systems must have SSH installed.
RHEL-09-255015V2R1All RHEL 9 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
RHEL-09-255090V2R1RHEL 9 must force a frequent session key renegotiation for SSH connections to the server.
RHEL-09-672050V2R1RHEL 9 must implement DOD-approved encryption in the bind package.
OL09-00-000250V1R1OL 9 networked systems must have SSH installed.
OL09-00-000251V1R1OL 9 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
OL09-00-002342V1R1OL 9 must force a frequent session key renegotiation for SSH connections to the server.
OL09-00-002421V1R1OL 9 must implement DOD-approved encryption in the bind package.
WN16-DC-000320V2R10Domain controllers must require LDAP access signing.
WN16-SO-000080V2R10The setting Domain member: Digitally encrypt or sign secure channel data (always) must be configured to Enabled.
WN16-SO-000090V2R10The setting Domain member: Digitally encrypt secure channel data (when possible) must be configured to enabled.
WN16-SO-000100V2R10The setting Domain member: Digitally sign secure channel data (when possible) must be configured to Enabled.
WN16-SO-000130V2R10Windows Server 2016 must be configured to require a strong session key.
WN16-SO-000190V2R10The setting Microsoft network client: Digitally sign communications (always) must be configured to Enabled.
WN16-SO-000200V2R10The setting Microsoft network client: Digitally sign communications (if server agrees) must be configured to Enabled.
WN16-SO-000230V2R10The setting Microsoft network server: Digitally sign communications (always) must be configured to Enabled.
WN16-SO-000240V2R10The setting Microsoft network server: Digitally sign communications (if client agrees) must be configured to Enabled.
SLES-15-010530V1R9All networked SUSE operating systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
SLES-12-030100V2R13All networked SUSE operating systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
OL07-00-040300V2R14The Oracle Linux operating system must be configured so that all networked systems have SSH installed.
OL07-00-040310V2R14The Oracle Linux operating system must be configured so that all networked systems use SSH for confidentiality and integrity of transmitted and received information as well as information during preparation for transmission.
WN19-DC-000320V2R8Windows Server 2019 domain controllers must require LDAP access signing.
WN19-SO-000060V2R8Windows Server 2019 setting Domain member: Digitally encrypt or sign secure channel data (always) must be configured to Enabled.
WN19-SO-000070V2R8Windows Server 2019 setting Domain member: Digitally encrypt secure channel data (when possible) must be configured to enabled.
WN19-SO-000080V2R8Windows Server 2019 setting Domain member: Digitally sign secure channel data (when possible) must be configured to Enabled.
WN19-SO-000110V2R8Windows Server 2019 must be configured to require a strong session key.
WN19-SO-000160V2R8Windows Server 2019 setting Microsoft network client: Digitally sign communications (always) must be configured to Enabled.
WN19-SO-000170V2R8Windows Server 2019 setting Microsoft network client: Digitally sign communications (if server agrees) must be configured to Enabled.
WN19-SO-000190V2R8Windows Server 2019 setting Microsoft network server: Digitally sign communications (always) must be configured to Enabled.
WN19-SO-000200V2R8Windows Server 2019 setting Microsoft network server: Digitally sign communications (if client agrees) must be configured to Enabled.
OL08-00-040159V1R9All OL 8 networked systems must have SSH installed.
OL08-00-040160V1R9All OL 8 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.