STIGQter STIGQter: STIG Summary: Cloud Computing Mission Owner Operating System Security Requirements Guide Version: 1 Release: 3 Benchmark Date: 13 Aug 2025:

The Mission Owner must configure the Infrastructure as a Service (IaaS)/Platform as a Service (PaaS) to prohibit or restrict the use of functions, ports, protocols, and/or services.

DISA Rule

SV-259874r1132412_rule

Vulnerability Number

V-259874

Group Title

SRG-OS-000096

Rule Version

SRG-OS-000096-CLD-000060

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

This applies to all Impact Levels.
FedRAMP Moderate, High.

For dedicated infrastructure with a DODIN connection (Impact Levels 2–6), configure the IaaS/PaaS virtual firewall that restricts traffic flow inbound and outbound to/from the cloud service to the DODIN connection and block all traffic from all other sources.

To ensure protocols and services are not blocked by the above configuration, register them along with their related UDP/TCP IP ports used by the SaaS service that will traverse the Defense Information Systems Network (DISN) in the DOD PPSM registry. This includes all user and management plane traffic for Impact Levels 4, 5, and 6, as well as management plane traffic for Impact Level 2 if managed/monitored from within a DOD network.

Check Contents

For dedicated infrastructure with a DOD Information Network (DODIN) connection, review the architecture diagrams. This includes all user and management plane traffic for Impact Levels 4, 5, and 6, as well as management plane traffic for Impact Level 2 if managed/monitored from within a DOD network.

Verify that the virtual firewall access control lists that restrict traffic flow inbound and outbound to/from the cloud service to the DODIN connection comply with the boundary requirements. Verify that all traffic from the cloud service provider (CSP) enclave and other sources are blocked by these methods.

If the cloud service offering is not configured to prohibit or restrict the use of functions, ports, protocols, and/or services as defined in the Ports, Protocols, and Services Management (PPSM) Category Assurance List (CAL) and vulnerability assessments, this is a finding.

Vulnerability Number

V-259874

Documentable

False

Rule Version

SRG-OS-000096-CLD-000060

Severity Override Guidance

For dedicated infrastructure with a DOD Information Network (DODIN) connection, review the architecture diagrams. This includes all user and management plane traffic for Impact Levels 4, 5, and 6, as well as management plane traffic for Impact Level 2 if managed/monitored from within a DOD network.

Verify that the virtual firewall access control lists that restrict traffic flow inbound and outbound to/from the cloud service to the DODIN connection comply with the boundary requirements. Verify that all traffic from the cloud service provider (CSP) enclave and other sources are blocked by these methods.

If the cloud service offering is not configured to prohibit or restrict the use of functions, ports, protocols, and/or services as defined in the Ports, Protocols, and Services Management (PPSM) Category Assurance List (CAL) and vulnerability assessments, this is a finding.

Check Content Reference

M

Target Key

5584