STIGQter STIGQter: STIG Summary: General Purpose Operating System Security Requirements Guide Version: 3 Release: 3 Benchmark Date: 28 Oct 2025:

The operating system must enforce attribute-based access control policy over defined subjects and objects based upon organization-defined attributes to assume access permissions.

DISA Rule

SV-278976r1137705_rule

Vulnerability Number

V-278976

Group Title

SRG-OS-000835

Rule Version

SRG-OS-000835-GPOS-00305

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the operating system to enforce attribute-based access control policy over defined subjects and objects based upon organization-defined attributes to assume access permissions.

Check Contents

Verify the operating system is configured to enforce attribute-based access control policy over defined subjects and objects based upon organization-defined attributes to assume access permissions.

If the operating system is not configured to enforce attribute-based access control policy over defined subjects and objects based upon organization-defined attributes to assume access permissions, this is a finding.

Vulnerability Number

V-278976

Documentable

False

Rule Version

SRG-OS-000835-GPOS-00305

Severity Override Guidance

Verify the operating system is configured to enforce attribute-based access control policy over defined subjects and objects based upon organization-defined attributes to assume access permissions.

If the operating system is not configured to enforce attribute-based access control policy over defined subjects and objects based upon organization-defined attributes to assume access permissions, this is a finding.

Check Content Reference

M

Target Key

2895