STIGQter STIGQter: STIG Summary: Cloud Computing Mission Owner Operating System Security Requirements Guide Version: 1 Release: 3 Benchmark Date: 13 Aug 2025:

The Infrastructure as a Service (IaaS)/Platform as a Service (PaaS)/Software as a Service (SaaS) must register the service/application with the DOD DMZ/IAP allowlist for internet-facing inbound and outbound traffic.

DISA Rule

SV-259880r958808_rule

Vulnerability Number

V-259880

Group Title

SRG-OS-000370

Rule Version

SRG-OS-000370-CLD-000050

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

This applies to all Impact Levels.
FedRAMP Moderate, High.

Coordinate with the cybersecurity service provider (CSSP) during cloud architecture development to ensure required security-relevant data will be accessible via the cloud service provider/cloud service offering, third-party security service subscription, and/or native application programming interface capability.

Register the IaaS/PaaS/SaaS service/application with the DOD allowlist for both inbound and outbound traffic. Configure the DOD allowlist with the ports and protocols needed to support applications and services used in the cloud environment.

Check Contents

Request the cloud service Provisional Authorization (PA) and registration documentation.

Verify the IaaS/PaaS/software is registered in the service/application with the DOD DMZ/IAP allowlist for both inbound and outbound traffic when traffic will cross the IAPs.

If the system/service/application is not registered with the DOD DMZ/IAP allowlist for both inbound and outbound internet-facing traffic, this is a finding.

Vulnerability Number

V-259880

Documentable

False

Rule Version

SRG-OS-000370-CLD-000050

Severity Override Guidance

Request the cloud service Provisional Authorization (PA) and registration documentation.

Verify the IaaS/PaaS/software is registered in the service/application with the DOD DMZ/IAP allowlist for both inbound and outbound traffic when traffic will cross the IAPs.

If the system/service/application is not registered with the DOD DMZ/IAP allowlist for both inbound and outbound internet-facing traffic, this is a finding.

Check Content Reference

M

Target Key

5584