STIGQter STIGQter: STIG Summary: Tri-Lab Operating System Stack (TOSS) 5 Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Mar 2026:

TOSS 5 must have the USBGuard package enabled.

DISA Rule

SV-282594r1200762_rule

Vulnerability Number

V-282594

Group Title

SRG-OS-000378-GPOS-00163

Rule Version

TOSS-05-000286

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Enable the USBGuard service using the following command:

$ sudo systemctl enable --now usbguard

Check Contents

Verify TOSS 5 has USBGuard enabled using the following command:

$ systemctl is-active usbguard

active

If usbguard is not active, ask the SA to indicate how unauthorized peripherals are blocked.

If there is no evidence that unauthorized peripherals are being blocked before establishing a connection, this is a finding.

Vulnerability Number

V-282594

Documentable

False

Rule Version

TOSS-05-000286

Severity Override Guidance

Verify TOSS 5 has USBGuard enabled using the following command:

$ systemctl is-active usbguard

active

If usbguard is not active, ask the SA to indicate how unauthorized peripherals are blocked.

If there is no evidence that unauthorized peripherals are being blocked before establishing a connection, this is a finding.

Check Content Reference

M

Target Key

5738