STIGQter STIGQter: STIG Summary: Red Hat Enterprise Linux 10 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

RHEL 10 must have the USBGuard package enabled.

DISA Rule

SV-280963r1165244_rule

Vulnerability Number

V-280963

Group Title

SRG-OS-000378-GPOS-00163

Rule Version

RHEL-10-200561

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure RHEL 10 to have the USBGuard service enabled by running the following command:

$ sudo systemctl enable --now usbguard

Check Contents

Note: If the system is virtual machine with no virtual or physical USB peripherals attached, this is not applicable.

Verify RHEL 10 has USBGuard enabled with the following command:

$ systemctl is-active usbguard
active

If USBGuard is not active, ask the SA to indicate how unauthorized peripherals are being blocked.

If there is no evidence that unauthorized peripherals are being blocked before establishing a connection, this is a finding.

Vulnerability Number

V-280963

Documentable

False

Rule Version

RHEL-10-200561

Severity Override Guidance

Note: If the system is virtual machine with no virtual or physical USB peripherals attached, this is not applicable.

Verify RHEL 10 has USBGuard enabled with the following command:

$ systemctl is-active usbguard
active

If USBGuard is not active, ask the SA to indicate how unauthorized peripherals are being blocked.

If there is no evidence that unauthorized peripherals are being blocked before establishing a connection, this is a finding.

Check Content Reference

M

Target Key

5733