STIGQter STIGQter: STIG Summary: Cloud Computing Mission Owner Operating System Security Requirements Guide Version: 1 Release: 3 Benchmark Date: 13 Aug 2025:

The Mission Owner must configure the customer service portal credentials for least privilege.

DISA Rule

SV-259872r958362_rule

Vulnerability Number

V-259872

Group Title

SRG-OS-000001

Rule Version

SRG-OS-000001-CLD-000010

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

This applies to all Impact Levels.
FedRAMP Moderate, High.

Appoint an individual or entity to manage portal services. Application and enclave administrators should also be appointed.

Configure access for these individuals to access and configure services and virtual instances.

Check Contents

Review the site's approval documentation to verify that an individual or entity has been appointed to manage the cloud management service portal. This may be a group or contracted service. Verify the cloud service offering has been configured to allow only these individuals for portal service and virtual instance configuration.

If the Mission Owner has not configured the customer service portal credentials and the Mission Owner application/system privileged accounts for least privilege, this is a finding.

Vulnerability Number

V-259872

Documentable

False

Rule Version

SRG-OS-000001-CLD-000010

Severity Override Guidance

Review the site's approval documentation to verify that an individual or entity has been appointed to manage the cloud management service portal. This may be a group or contracted service. Verify the cloud service offering has been configured to allow only these individuals for portal service and virtual instance configuration.

If the Mission Owner has not configured the customer service portal credentials and the Mission Owner application/system privileged accounts for least privilege, this is a finding.

Check Content Reference

M

Target Key

5584