SRG-OS-000423-GPOS-00187 Controls

STIG IDVersionTitleProduct
RHEL-08-040160V1R6All RHEL 8 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
RHEL-08-040159V1R6All RHEL 8 networked systems must have SSH installed.
SLES-15-010530V1R4All networked SUSE operating systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
WN19-DC-000320V3R1Windows Server 2019 domain controllers must require LDAP access signing.
WN19-SO-000060V3R1Windows Server 2019 setting Domain member: Digitally encrypt or sign secure channel data (always) must be configured to Enabled.
WN19-SO-000070V3R1Windows Server 2019 setting Domain member: Digitally encrypt secure channel data (when possible) must be configured to enabled.
WN19-SO-000080V3R1Windows Server 2019 setting Domain member: Digitally sign secure channel data (when possible) must be configured to Enabled.
WN19-SO-000110V3R1Windows Server 2019 must be configured to require a strong session key.
WN19-SO-000160V3R1Windows Server 2019 setting Microsoft network client: Digitally sign communications (always) must be configured to Enabled.
WN19-SO-000170V3R1Windows Server 2019 setting Microsoft network client: Digitally sign communications (if server agrees) must be configured to Enabled.
WN19-SO-000190V3R1Windows Server 2019 setting Microsoft network server: Digitally sign communications (always) must be configured to Enabled.
WN19-SO-000200V3R1Windows Server 2019 setting Microsoft network server: Digitally sign communications (if client agrees) must be configured to Enabled.
UBTU-18-010420V2R12The Ubuntu operating system must use SSH to protect the confidentiality and integrity of transmitted information unless otherwise protected by alternative physical safeguards, such as, at a minimum, a Protected Distribution System (PDS).
UBTU-20-010042V1R6The Ubuntu operating system must use SSH to protect the confidentiality and integrity of transmitted information.
APPL-14-002062V1R1The macOS system must disable Bluetooth when no approved device is connected.
OL07-00-040300V3R1The Oracle Linux operating system must be configured so that all networked systems have SSH installed.
OL07-00-040310V3R1The Oracle Linux operating system must be configured so that all networked systems use SSH for confidentiality and integrity of transmitted and received information as well as information during preparation for transmission.
RHEL-07-040300V3R6The Red Hat Enterprise Linux operating system must be configured so that all networked systems have SSH installed.
RHEL-07-040310V3R6The Red Hat Enterprise Linux operating system must be configured so that all networked systems use SSH for confidentiality and integrity of transmitted and received information as well as information during preparation for transmission.
SLES-12-030100V3R1All networked SUSE operating systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
APPL-15-002062V1R1The macOS system must disable Bluetooth when no approved device is connected.
ALMA-09-042700V1R1All AlmaLinux OS 9 networked systems must have the OpenSSH client installed.
OL08-00-040159V1R6All OL 8 networked systems must have SSH installed.
OL08-00-040160V1R6All OL 8 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
OL09-00-000250V1R1OL 9 networked systems must have SSH installed.
OL09-00-000251V1R1OL 9 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
OL09-00-002342V1R1OL 9 must force a frequent session key renegotiation for SSH connections to the server.
OL09-00-002421V1R1OL 9 must implement DOD-approved encryption in the bind package.
UBTU-24-100800V1R1Ubuntu 24.04 LTS must have SSH installed.
UBTU-24-100810V1R1Ubuntu 24.04 LTS must use SSH to protect the confidentiality and integrity of transmitted information.
UBTU-22-255010V1R1Ubuntu 22.04 LTS must have SSH installed.
UBTU-22-255015V1R1Ubuntu 22.04 LTS must use SSH to protect the confidentiality and integrity of transmitted information.
WN11-SO-000035V1R6Outgoing secure channel traffic must be encrypted or signed.
WN11-SO-000040V1R6Outgoing secure channel traffic must be encrypted.
WN11-SO-000045V1R6Outgoing secure channel traffic must be signed.
WN11-SO-000060V1R6The system must be configured to require a strong session key.
WN11-SO-000100V1R6The Windows SMB client must be configured to always perform SMB packet signing.
WN11-SO-000120V1R6The Windows SMB server must be configured to always perform SMB packet signing.
RHEL-09-255010V2R5All RHEL 9 networked systems must have SSH installed.
RHEL-09-255015V2R5All RHEL 9 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
RHEL-09-255090V2R5RHEL 9 must force a frequent session key renegotiation for SSH connections to the server.
RHEL-09-672050V2R5RHEL 9 must implement DOD-approved encryption in the bind package.
WN10-SO-000035V3R1Outgoing secure channel traffic must be encrypted or signed.
WN10-SO-000040V3R1Outgoing secure channel traffic must be encrypted when possible.
WN10-SO-000045V3R1Outgoing secure channel traffic must be signed when possible.
WN10-SO-000060V3R1The system must be configured to require a strong session key.
WN10-SO-000100V3R1The Windows SMB client must be configured to always perform SMB packet signing.
WN10-SO-000120V3R1The Windows SMB server must be configured to always perform SMB packet signing.
WN16-DC-000320V2R9Domain controllers must require LDAP access signing.
WN16-SO-000080V2R9The setting Domain member: Digitally encrypt or sign secure channel data (always) must be configured to Enabled.
WN16-SO-000090V2R9The setting Domain member: Digitally encrypt secure channel data (when possible) must be configured to enabled.
WN16-SO-000100V2R9The setting Domain member: Digitally sign secure channel data (when possible) must be configured to Enabled.
WN16-SO-000130V2R9Windows Server 2016 must be configured to require a strong session key.
WN16-SO-000190V2R9The setting Microsoft network client: Digitally sign communications (always) must be configured to Enabled.
WN16-SO-000200V2R9The setting Microsoft network client: Digitally sign communications (if server agrees) must be configured to Enabled.
WN16-SO-000230V2R9The setting Microsoft network server: Digitally sign communications (always) must be configured to Enabled.
WN16-SO-000240V2R9The setting Microsoft network server: Digitally sign communications (if client agrees) must be configured to Enabled.
WN22-DC-000320V2R5Windows Server 2022 domain controllers must require LDAP access signing.
WN22-SO-000060V2R5Windows Server 2022 setting Domain member: Digitally encrypt or sign secure channel data (always) must be configured to Enabled.
WN22-SO-000070V2R5Windows Server 2022 setting Domain member: Digitally encrypt secure channel data (when possible) must be configured to Enabled.
WN22-SO-000080V2R5Windows Server 2022 setting Domain member: Digitally sign secure channel data (when possible) must be configured to Enabled.
WN22-SO-000110V2R5Windows Server 2022 must be configured to require a strong session key.
WN22-SO-000160V2R5Windows Server 2022 setting Microsoft network client: Digitally sign communications (always) must be configured to Enabled.
WN22-SO-000170V2R5Windows Server 2022 setting Microsoft network client: Digitally sign communications (if server agrees) must be configured to Enabled.
WN22-SO-000190V2R5Windows Server 2022 setting Microsoft network server: Digitally sign communications (always) must be configured to Enabled.
WN22-SO-000200V2R5Windows Server 2022 setting Microsoft network server: Digitally sign communications (if client agrees) must be configured to Enabled.