STIGQter STIGQter: STIG Summary: Cloud Computing Mission Owner Operating System Security Requirements Guide Version: 1 Release: 3 Benchmark Date: 13 Aug 2025:

For storage service offerings, the Mission Owner must configure or ensure the cloud instance uses encryption to protect all DOD files housed in the cloud instance.

DISA Rule

SV-259881r958870_rule

Vulnerability Number

V-259881

Group Title

SRG-OS-000404

Rule Version

SRG-OS-000404-CLD-000080

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

This applies to Impact Levels 4/5/6 and applies to Impact Level 2 where the Mission Owner has control of the environment.
FedRAMP Moderate, High.

Configure the cloud instance to use encryption to protect all DOD files housed in the virtual storage service.

Check Contents

Unless the information owner requires encryption and KMS, for Impact Level 2 public cloud with nonprivileged user access to publicly releasable information, this is not applicable.

Verify the cloud storage service is configured to use encryption and KMS to protect all DOD files housed in the virtual storage service.

If the cloud storage service is not configured to use encryption to protect all DOD files housed in the virtual storage service, this is a finding.

Vulnerability Number

V-259881

Documentable

False

Rule Version

SRG-OS-000404-CLD-000080

Severity Override Guidance

Unless the information owner requires encryption and KMS, for Impact Level 2 public cloud with nonprivileged user access to publicly releasable information, this is not applicable.

Verify the cloud storage service is configured to use encryption and KMS to protect all DOD files housed in the virtual storage service.

If the cloud storage service is not configured to use encryption to protect all DOD files housed in the virtual storage service, this is a finding.

Check Content Reference

M

Target Key

5584