STIGQter STIGQter: STIG Summary: Tri-Lab Operating System Stack (TOSS) 5 Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Mar 2026:

TOSS 5 must enable the "SELinux" targeted policy.

DISA Rule

SV-282613r1201304_rule

Vulnerability Number

V-282613

Group Title

SRG-OS-000445-GPOS-00199

Rule Version

TOSS-05-000024

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the operating system to verify correct operation of all security functions.

Set the "SELinuxtype" to the "targeted" policy by modifying the "/etc/selinux/config" file to have the following line:

SELINUXTYPE=targeted

Restart the system for the changes to take effect.

Check Contents

Note: At lower classification levels (CUI, Secret) where vast amounts of data are processed and a performance impact is occurring, an authorizing official can consider this requirement not applicable.

Check that TOSS verifies correct operation of all security functions.

Determine if "SELinux" is active and is enforcing the targeted policy using the following command:

$ sudo sestatus

SELinux status: enabled
SELinuxfs mount: /sys/fs/selinux
SELinux root directory: /etc/selinux
Loaded policy name: targeted
Current mode: enforcing
Mode from config file: enforcing
Policy MLS status: enabled
Policy deny_unknown status: allowed
Memory protection checking: actual (secure)
Max kernel policy version: 33

If the "Loaded policy name" is not set to "targeted", this is a finding.

Verify the "/etc/selinux/config" file is configured with the "SELINUXTYPE" of "targeted":

$ sudo grep -i "selinuxtype" /etc/selinux/config | grep -v '^#'
SELINUXTYPE = targeted

If no results are returned, or "SELINUXTYPE" is not set to "targeted", this is a finding.

Vulnerability Number

V-282613

Documentable

False

Rule Version

TOSS-05-000024

Severity Override Guidance

Note: At lower classification levels (CUI, Secret) where vast amounts of data are processed and a performance impact is occurring, an authorizing official can consider this requirement not applicable.

Check that TOSS verifies correct operation of all security functions.

Determine if "SELinux" is active and is enforcing the targeted policy using the following command:

$ sudo sestatus

SELinux status: enabled
SELinuxfs mount: /sys/fs/selinux
SELinux root directory: /etc/selinux
Loaded policy name: targeted
Current mode: enforcing
Mode from config file: enforcing
Policy MLS status: enabled
Policy deny_unknown status: allowed
Memory protection checking: actual (secure)
Max kernel policy version: 33

If the "Loaded policy name" is not set to "targeted", this is a finding.

Verify the "/etc/selinux/config" file is configured with the "SELINUXTYPE" of "targeted":

$ sudo grep -i "selinuxtype" /etc/selinux/config | grep -v '^#'
SELINUXTYPE = targeted

If no results are returned, or "SELINUXTYPE" is not set to "targeted", this is a finding.

Check Content Reference

M

Target Key

5738