STIGQter STIGQter: STIG Summary: Tri-Lab Operating System Stack (TOSS) 5 Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Mar 2026:

TOSS 5 must display the Standard Mandatory DOD or other applicable U.S. Government agency Notice and Consent Banner before granting local or remote access to the system via a graphical user login.

DISA Rule

SV-282368r1200084_rule

Vulnerability Number

V-282368

Group Title

SRG-OS-000023-GPOS-00006

Rule Version

TOSS-05-000262

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure TOSS 5 to display the Standard Mandatory DOD or other applicable U.S. Government agency Notice and Consent Banner before granting access to the system via a graphical user login.

Create a database to contain the systemwide graphical user login settings (if it does not already exist) using the following command:

$ sudo touch /etc/dconf/db/local.d/01-banner-message

Add the following lines to the [org/gnome/login-screen] section of the "/etc/dconf/db/local.d/01-banner-message":

[org/gnome/login-screen]

banner-message-enable=true

Run the following command to update the database:

$ sudo dconf update

Check Contents

Verify TOSS 5 displays a banner before granting access to the operating system via a graphical user login.

Note: This requirement assumes the use of the TOSS 5 default graphical user interface—the GNOME desktop environment. If the system does not have a graphical user interface installed, this requirement is not applicable.

Determine if the operating system displays a banner at the login screen using the following command:

$ sudo grep banner-message-enable /etc/dconf/db/local.d/*

banner-message-enable=true

If "banner-message-enable" is set to "false", is commented out, or is missing, this is a finding.

Vulnerability Number

V-282368

Documentable

False

Rule Version

TOSS-05-000262

Severity Override Guidance

Verify TOSS 5 displays a banner before granting access to the operating system via a graphical user login.

Note: This requirement assumes the use of the TOSS 5 default graphical user interface—the GNOME desktop environment. If the system does not have a graphical user interface installed, this requirement is not applicable.

Determine if the operating system displays a banner at the login screen using the following command:

$ sudo grep banner-message-enable /etc/dconf/db/local.d/*

banner-message-enable=true

If "banner-message-enable" is set to "false", is commented out, or is missing, this is a finding.

Check Content Reference

M

Target Key

5738