STIGQter STIGQter: STIG Summary: Cloud Computing Mission Owner Operating System Security Requirements Guide Version: 1 Release: 3 Benchmark Date: 13 Aug 2025:

The Mission owner must obtain Authorizing Official (AO) authorization for each cloud service offering (CSO) implemented in support of production or development environments prior to operational use.

DISA Rule

SV-259883r959010_rule

Vulnerability Number

V-259883

Group Title

SRG-OS-000480

Rule Version

SRG-OS-000480-CLD-000025

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

This applies to all Impact Levels.
FedRAMP Moderate, High.

Obtain AO authorization for each CSO implemented in support of production or development environments prior to operational use.

Check Contents

Review the approval documentation. Verify the ATO indicates the component level AO has authorized the use of the CSO.

If the Mission Owner's AO has not authorized the use of the CSO, this is a finding.

Vulnerability Number

V-259883

Documentable

False

Rule Version

SRG-OS-000480-CLD-000025

Severity Override Guidance

Review the approval documentation. Verify the ATO indicates the component level AO has authorized the use of the CSO.

If the Mission Owner's AO has not authorized the use of the CSO, this is a finding.

Check Content Reference

M

Target Key

5584