STIGQter STIGQter: STIG Summary: Tri-Lab Operating System Stack (TOSS) 4 Security Technical Implementation Guide Version: 2 Release: 6 Benchmark Date: 01 Jul 2026:

TOSS must disable IEEE 1394 (FireWire) Support.

DISA Rule

SV-253071r958478_rule

Vulnerability Number

V-253071

Group Title

SRG-OS-000095-GPOS-00049

Rule Version

TOSS-04-040160

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the operating system to disable the ability to use the firewire-core kernel module.

Add or update the following lines in the file "/etc/modprobe.d/blacklist.conf":

install firewire-core /bin/false
blacklist firewire-core

Reboot the system for the settings to take effect.

Check Contents

Verify the operating system disables the ability to load the firewire-core kernel module.

$ sudo grep -r firewire-core /etc/modprobe.d/* | grep install

install firewire-core /bin/false

If the command does not return any output, or the line is commented out, and use of the firewire-core protocol is not documented with the Information System Security Officer (ISSO) as an operational requirement, this is a finding.

Verify the operating system disables the ability to use the firewire-core kernel module.

Check to see if the firewire-core kernel module is disabled with the following command:

$ sudo grep -r firewire-core /etc/modprobe.d/* | grep "blacklist"

blacklist firewire-core

If the command does not return any output or the output is not "blacklist firewire-core", and use of the firewire-core kernel module is not documented with the Information System Security Officer (ISSO) as an operational requirement, this is a finding.

Vulnerability Number

V-253071

Documentable

False

Rule Version

TOSS-04-040160

Severity Override Guidance

Verify the operating system disables the ability to load the firewire-core kernel module.

$ sudo grep -r firewire-core /etc/modprobe.d/* | grep install

install firewire-core /bin/false

If the command does not return any output, or the line is commented out, and use of the firewire-core protocol is not documented with the Information System Security Officer (ISSO) as an operational requirement, this is a finding.

Verify the operating system disables the ability to use the firewire-core kernel module.

Check to see if the firewire-core kernel module is disabled with the following command:

$ sudo grep -r firewire-core /etc/modprobe.d/* | grep "blacklist"

blacklist firewire-core

If the command does not return any output or the output is not "blacklist firewire-core", and use of the firewire-core kernel module is not documented with the Information System Security Officer (ISSO) as an operational requirement, this is a finding.

Check Content Reference

M

Target Key

5469