STIGQter STIGQter: STIG Summary: Cloud Computing Mission Owner Operating System Security Requirements Guide Version: 1 Release: 3 Benchmark Date: 13 Aug 2025:

The Mission Owner must select and configure an Impact Level 4/5 cloud service offering (CSO) listed in the DISA Provisional Authorization (PA) DOD Cloud Catalog when hosting Controlled Unclassified Information (CUI).

DISA Rule

SV-259885r959010_rule

Vulnerability Number

V-259885

Group Title

SRG-OS-000480

Rule Version

SRG-OS-000480-CLD-000031

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

This applies to Impact Level 4/5.
FedRAMP Moderate, High.

For CUI information, select and configure a CSO listed in the DISA PA DOD Cloud Catalog for use with Impact Level 4/5 or higher.

Specify in the Service Level Agreement (SLA) with the cloud service provider (CSP) and any third-party providers compliance with applicable STIG configurations.

Check Contents

If the implementation is categorized as Impact Level 2 or 6, this is not applicable.

Review the approval documentation and the DISA PA Cloud Catalog. For clouds hosting CUI information, verify the CSO is listed as Impact Level 4 or 5.

If CUI is being hosted in the Infrastructure as a Service (IaaS)/Platform as a Service (PaaS) and the CSO is not listed in the DISA PA DOD Cloud Catalog as Impact Level 4 or 5, this is a finding.

Vulnerability Number

V-259885

Documentable

False

Rule Version

SRG-OS-000480-CLD-000031

Severity Override Guidance

If the implementation is categorized as Impact Level 2 or 6, this is not applicable.

Review the approval documentation and the DISA PA Cloud Catalog. For clouds hosting CUI information, verify the CSO is listed as Impact Level 4 or 5.

If CUI is being hosted in the Infrastructure as a Service (IaaS)/Platform as a Service (PaaS) and the CSO is not listed in the DISA PA DOD Cloud Catalog as Impact Level 4 or 5, this is a finding.

Check Content Reference

M

Target Key

5584