STIGQter STIGQter: STIG Summary: Cloud Linux AlmaLinux OS 9 Security Technical Implementation Guide Version: 1 Release: 7 Benchmark Date: 01 Jul 2026:

Cameras must be disabled or covered when not in use.

DISA Rule

SV-269349r1050232_rule

Vulnerability Number

V-269349

Group Title

SRG-OS-000095-GPOS-00049

Rule Version

ALMA-09-030490

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To configure the system to prevent the uvcvideo kernel module from being loaded, run the following command:

$ cat << EOF | tee /etc/modprobe.d/uvcvideo.conf
install uvcvideo /bin/false
blacklist uvcvideo
EOF

Check Contents

Verify the operating system disables the ability to load the uvcvideo kernel module:

$ grep -r uvcvideo /etc/modprobe.conf /etc/modprobe.d/*

/etc/modprobe.d/uvcvideo.conf:install uvcvideo /bin/false
/etc/modprobe.d/uvcvideo.conf:blacklist uvcvideo

If the command does not return any output, or either line is commented out, and the collaborative computing device has not been authorized for use, this is a finding.

If a built-in camera is not protected with a cover or is not physically disabled, this is a finding.

For an external camera, if there is not a method for the operator to manually disconnect the camera (e.g., unplug, power off) at the end of collaborative computing sessions, this is a finding.

If the device or operating system does not have a camera installed, this requirement is not applicable.

Vulnerability Number

V-269349

Documentable

False

Rule Version

ALMA-09-030490

Severity Override Guidance

Verify the operating system disables the ability to load the uvcvideo kernel module:

$ grep -r uvcvideo /etc/modprobe.conf /etc/modprobe.d/*

/etc/modprobe.d/uvcvideo.conf:install uvcvideo /bin/false
/etc/modprobe.d/uvcvideo.conf:blacklist uvcvideo

If the command does not return any output, or either line is commented out, and the collaborative computing device has not been authorized for use, this is a finding.

If a built-in camera is not protected with a cover or is not physically disabled, this is a finding.

For an external camera, if there is not a method for the operator to manually disconnect the camera (e.g., unplug, power off) at the end of collaborative computing sessions, this is a finding.

If the device or operating system does not have a camera installed, this requirement is not applicable.

Check Content Reference

M

Target Key

5664