STIGQter STIGQter: STIG Summary:

General Purpose Operating System Security Requirements Guide

Version: 3

Release: 3 Benchmark Date: 28 Oct 2025

CheckedNameTitle
☐SV-203591r958362_ruleThe operating system must provide automated mechanisms for supporting account management functions.
☐SV-203592r958364_ruleThe operating system must automatically remove or disable temporary user accounts after 72 hours.
☐SV-203593r958368_ruleThe operating system must audit all account creations.
☐SV-203594r958388_ruleThe operating system must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.
☐SV-203595r958390_ruleThe operating system must display the Standard Mandatory DoD Notice and Consent Banner before granting local or remote access to the system.
☐SV-203596r958392_ruleThe operating system must display the Standard Mandatory DoD Notice and Consent Banner until users acknowledge the usage conditions and take explicit actions to log on for further access.
☐SV-203597r958398_ruleThe operating system must limit the number of concurrent sessions to ten for all accounts and/or account types.
☐SV-203598r958400_ruleThe operating system must retain a users session lock until that user reestablishes access using established identification and authentication procedures.
☐SV-203599r958402_ruleThe operating system must initiate a session lock after a 15-minute period of inactivity for all connection types.
☐SV-203600r982194_ruleThe operating system must provide the capability for users to directly initiate a session lock for all connection types.
☐SV-203601r958404_ruleThe operating system must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
☐SV-203602r958406_ruleThe operating system must monitor remote access methods.
☐SV-203603r958408_ruleThe operating system must implement DoD-approved encryption to protect the confidentiality of remote access sessions.
☐SV-203604r958412_ruleThe operating system must produce audit records containing information to establish what type of events occurred.
☐SV-203605r958414_ruleThe operating system must produce audit records containing information to establish when (date and time) the events occurred.
☐SV-203606r958416_ruleThe operating system must produce audit records containing information to establish where the events occurred.
☐SV-203607r958418_ruleThe operating system must produce audit records containing information to establish the source of the events.
☐SV-203608r958420_ruleThe operating system must produce audit records containing information to establish the outcome of the events.
☐SV-203609r958422_ruleThe operating system must generate audit records containing the full-text recording of privileged commands.
☐SV-203610r958422_ruleThe operating system must produce audit records containing the individual identities of group account users.
☐SV-203611r958424_ruleThe operating system must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
☐SV-203613r958428_ruleThe operating system must provide the capability to centrally review and analyze audit records from multiple components within the system.
☐SV-203614r958430_ruleThe operating system must provide the capability to filter audit records for events of interest based upon all audit fields within audit records.
☐SV-203615r958432_ruleThe operating system must use internal system clocks to generate time stamps for audit records.
☐SV-203616r958434_ruleThe operating system must protect audit information from unauthorized read access.
☐SV-203617r958436_ruleThe operating system must protect audit information from unauthorized modification.
☐SV-203618r958438_ruleThe operating system must protect audit information from unauthorized deletion.
☐SV-203619r958442_ruleThe operating system must provide audit record generation capability for DoD-defined auditable events for all operating system components.
☐SV-203620r958444_ruleThe operating system must allow only the ISSM (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.
☐SV-203621r958446_ruleThe operating system must generate audit records when successful/unsuccessful attempts to access privileges occur.
☐SV-203622r958448_ruleThe operating system, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
☐SV-203623r958450_ruleThe operating system, for PKI-based authentication, must enforce authorized access to the corresponding private key.
☐SV-203624r958452_ruleThe operating system must map the authenticated identity to the user or group account for PKI-based authentication.
☐SV-203625r982195_ruleThe operating system must enforce password complexity by requiring that at least one uppercase character be used.
☐SV-203626r982196_ruleThe operating system must enforce password complexity by requiring that at least one lowercase character be used.
☐SV-203627r982197_ruleThe operating system must enforce password complexity by requiring that at least one numeric character be used.
☐SV-203628r982198_ruleThe operating system must require the change of at least 50 percent of the total number of characters when passwords are changed.
☐SV-203629r982199_ruleThe operating system must store only encrypted representations of passwords.
☐SV-203630r987796_ruleThe operating system must transmit only encrypted representations of passwords.
☐SV-203631r982188_ruleOperating systems must enforce 24 hours/1 day as the minimum password lifetime.
☐SV-203632r1038967_ruleOperating systems must enforce a 60-day maximum password lifetime restriction.
☐SV-203634r982202_ruleThe operating system must enforce a minimum 15-character password length.
☐SV-203635r958470_ruleThe operating system must obscure feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals.
☐SV-203636r1137691_ruleThe operating system must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
☐SV-203637r958478_ruleThe operating system must be configured to disable non-essential capabilities.
☐SV-203638r958480_ruleThe operating system must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.
☐SV-203639r958482_ruleThe operating system must uniquely identify and must authenticate organizational users (or processes acting on behalf of organizational users).
☐SV-203640r958484_ruleThe operating system must use multifactor authentication for network access to privileged accounts.
☐SV-203641r958486_ruleThe operating system must use multifactor authentication for network access to non-privileged accounts.
☐SV-203642r982203_ruleThe operating system must use multifactor authentication for local access to privileged accounts.
☐SV-203643r982204_ruleThe operating system must use multifactor authentication for local access to nonprivileged accounts.
☐SV-203644r982205_ruleThe operating system must require individuals to be authenticated with an individual authenticator prior to using a group authenticator.
☐SV-203645r958494_ruleThe operating system must implement replay-resistant authentication mechanisms for network access to privileged accounts.
☐SV-203646r982206_ruleThe operating system must implement replay-resistant authentication mechanisms for network access to nonprivileged accounts.
☐SV-203647r958498_ruleThe operating system must uniquely identify peripherals before establishing a connection.
☐SV-203648r982189_ruleThe operating system must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.
☐SV-203649r971535_ruleThe operating system must use mechanisms meeting the requirements of applicable federal laws, Executive orders, directives, policies, regulations, standards, and guidance for authentication to a cryptographic module.
☐SV-203650r958504_ruleThe operating system must uniquely identify and must authenticate non-organizational users (or processes acting on behalf of non-organizational users).
☐SV-203651r958506_ruleThe operating system must provide an audit reduction capability that supports on-demand reporting requirements.
☐SV-203652r958508_ruleThe information system must automatically remove or disable emergency accounts after the crisis is resolved or 72 hours.
☐SV-203653r958510_ruleThe operating system must employ strong authenticators in the establishment of nonlocal maintenance and diagnostic sessions.
☐SV-203655r1117266_ruleThe operating system must separate user functionality (including user interface services) from operating system management functionality.
☐SV-203656r958518_ruleThe operating system must isolate security functions from nonsecurity functions.
☐SV-203657r1137695_ruleOperating systems must prevent unauthorized and unintended information transfer via shared system resources.
☐SV-203658r958528_ruleThe operating system must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of Denial of Service (DoS) attacks.
☐SV-203659r970703_ruleThe operating system must terminate all network connections associated with a communications session at the end of the session, or as follows: for in-band management sessions (privileged sessions), the session must be terminated after 10 minutes of inactivity; and for user sessions (non-privileged session), the session must be terminated after 15 minutes of inactivity, except to fulfill documented and validated mission requirements.
☐SV-203660r958550_ruleThe operating system must fail to a secure state if system initialization fails, shutdown fails, or aborts fail.
☐SV-203661r958552_ruleThe operating system must protect the confidentiality and integrity of all information at rest.
☐SV-203663r958564_ruleThe operating system must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
☐SV-203664r958566_ruleThe operating system must reveal error messages only to authorized users.
☐SV-203665r958586_ruleAny publically accessible connection to the operating system must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the system.
☐SV-203666r991551_ruleThe operating system must audit all account modifications.
☐SV-203667r991552_ruleThe operating system must audit all account disabling actions.
☐SV-203668r991553_ruleThe operating system must audit all account removal actions.
☐SV-203669r991554_ruleThe operating system must implement cryptography to protect the integrity of remote access sessions.
☐SV-203670r991555_ruleThe operating system must initiate session audits at system start-up.
☐SV-203671r991556_ruleThe operating system must produce audit records containing information to establish the identity of any individual or process associated with the event.
☐SV-203672r991557_ruleThe operating system must protect audit tools from unauthorized access.
☐SV-203673r991558_ruleThe operating system must protect audit tools from unauthorized modification.
☐SV-203674r991559_ruleThe operating system must protect audit tools from unauthorized deletion.
☐SV-203675r991560_ruleThe operating system must limit privileges to change software resident within software libraries.
☐SV-203676r991561_ruleThe operating system must enforce password complexity by requiring that at least one special character be used.
☐SV-203677r991562_ruleIn the event of a system failure, the operating system must preserve any information necessary to determine cause of failure and any information necessary to return to operations with least disruption to mission processes.
☐SV-203678r991563_ruleThe operating system must notify system administrators and ISSOs when accounts are created.
☐SV-203679r991564_ruleThe operating system must notify system administrators and ISSOs when accounts are modified.
☐SV-203680r991565_ruleThe operating system must notify system administrators and ISSOs when accounts are disabled.
☐SV-203681r991566_ruleThe operating system must notify system administrators and ISSOs when accounts are removed.
☐SV-203682r991567_ruleThe operating system must use cryptographic mechanisms to protect the integrity of audit tools.
☐SV-203683r958636_ruleThe operating system must automatically terminate a user session after inactivity time-outs have expired or at shutdown.
☐SV-203684r958638_ruleThe operating system must provide a logoff capability for user-initiated communications sessions when requiring user access authentication.
☐SV-203685r958640_ruleThe operating system must display an explicit logoff message to users indicating the reliable termination of authenticated communications sessions.
☐SV-203686r958672_ruleThe operating system must control remote access methods.
☐SV-203687r958674_ruleThe operating system must provide the capability to immediately disconnect or disable remote access to the operating system.
☐SV-203688r991568_ruleThe operating system must protect wireless access to and from the system using encryption.
☐SV-203689r991569_ruleThe operating system must protect wireless access to the system using authentication of users and/or devices.
☐SV-203690r958684_ruleThe operating system must audit all account enabling actions.
☐SV-203691r982207_ruleThe operating system must notify system administrators (SAs) and information system security officers (ISSOs) of account enabling actions.
☐SV-203692r958702_ruleThe operating system must allow operating system admins to pass information to any other operating system admin or user.
☐SV-203693r958702_ruleThe operating system must allow operating system admins to grant their privileges to other operating system admins.
☐SV-203694r958702_ruleThe operating system must allow operating system admins to change security attributes on users, the operating system, or the operating systems components.
☐SV-203695r958726_ruleThe operating system must prevent nonprivileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.
☐SV-203696r958730_ruleThe operating system must prevent all software from executing at higher privilege levels than users executing the software.
☐SV-203697r958732_ruleThe operating system must audit the execution of privileged functions.
☐SV-203698r958736_ruleThe operating system must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts in 15 minutes occur.
☐SV-203699r971541_ruleThe operating system must provide the capability for assigned IMOs/ISSOs or designated SAs to change the auditing to be performed on all operating system components, based on all selectable event criteria in near real time.
☐SV-203700r958752_ruleThe operating system must allocate audit record storage capacity to store at least one week's worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
☐SV-203701r958754_ruleThe operating system must offload audit records onto a different system or media from the system being audited.
☐SV-203702r971542_ruleThe operating system must immediately notify the SA and ISSO (at a minimum) when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity.
☐SV-203703r958758_ruleThe operating system must provide an immediate real-time alert to the SA and ISSO, at a minimum, of all audit failure events requiring real-time alerts.
☐SV-203704r958766_ruleThe operating system must provide an audit reduction capability that supports on-demand audit review and analysis.
☐SV-203705r958768_ruleThe operating system must provide an audit reduction capability that supports after-the-fact investigations of security incidents.
☐SV-203706r958770_ruleThe operating system must provide a report generation capability that supports on-demand audit review and analysis.
☐SV-203707r958772_ruleThe operating system must provide a report generation capability that supports on-demand reporting requirements.
☐SV-203708r958774_ruleThe operating system must provide a report generation capability that supports after-the-fact investigations of security incidents.
☐SV-203709r958776_ruleThe operating system must not alter original content or time ordering of audit records when it provides an audit reduction capability.
☐SV-203710r987795_ruleThe operating system must not alter original content or time ordering of audit records when it provides a report generation capability.
☐SV-203711r1038944_ruleThe operating system must, for networked systems, compare internal information system clocks at least every 24 hours with an authoritative time source.
☐SV-203712r982209_ruleThe operating system must synchronize internal information system clocks to the authoritative time source when the time difference is greater than one second.
☐SV-203713r958786_ruleThe operating system must record time stamps for audit records that meet a minimum granularity of one second for a minimum degree of precision.
☐SV-203714r958788_ruleThe operating system must record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).
☐SV-203715r958790_ruleThe operating system must enforce dual authorization for movement and/or deletion of all audit information, when such movement or deletion is not part of an authorized automatic process.
☐SV-203716r982210_ruleThe operating system must prohibit user installation of system software without explicit privileged status.
☐SV-203717r958794_ruleThe operating system must notify designated personnel if baseline configurations are changed in an unauthorized manner.
☐SV-203718r958796_ruleThe operating system must enforce access restrictions.
☐SV-203719r982211_ruleThe operating system must audit the enforcement actions used to restrict access associated with changes to the system.
☐SV-203720r982212_ruleThe operating system must prevent the installation of patches, service packs, device drivers, or operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.
☐SV-203721r958804_ruleThe operating system must prevent program execution in accordance with local policies regarding software program usage and restrictions and/or rules authorizing the terms and conditions of software program usage.
☐SV-203722r958808_ruleThe operating system must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
☐SV-203723r1050789_ruleThe operating system must require users to reauthenticate for privilege escalation.
☐SV-203724r1050790_ruleThe operating system must require users to reauthenticate when changing roles.
☐SV-203725r1050791_ruleThe operating system must require users to reauthenticate when changing authenticators.
☐SV-203727r982216_ruleThe operating system must implement multifactor authentication for remote access to privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access.
☐SV-203728r958816_ruleThe operating system must accept Personal Identity Verification (PIV) credentials.
☐SV-203729r958818_ruleThe operating system must electronically verify Personal Identity Verification (PIV) credentials.
☐SV-203730r958820_ruleThe operating system must authenticate peripherals before establishing a connection.
☐SV-203731r971545_ruleThe operating system must authenticate all endpoint devices before establishing a local, remote, and/or network connection using bidirectional authentication that is cryptographically based.
☐SV-203733r958828_ruleThe operating system must prohibit the use of cached authenticators after one day.
☐SV-203734r982217_ruleThe operating system, for PKI-based authentication, must implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network.
☐SV-203735r958846_ruleThe operating system must audit all activities performed during nonlocal maintenance and diagnostic sessions.
☐SV-203736r958848_ruleThe operating system must implement cryptographic mechanisms to protect the integrity of nonlocal maintenance and diagnostic communications, when used for nonlocal maintenance sessions.
☐SV-203737r958850_ruleThe operating system must implement cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications, when used for nonlocal maintenance sessions.
☐SV-203738r958852_ruleThe operating system must verify remote disconnection at the termination of nonlocal maintenance and diagnostic sessions, when used for nonlocal maintenance sessions.
☐SV-203739r987791_ruleThe operating system must implement NSA-approved cryptography to protect classified information in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
☐SV-203744r958868_ruleThe operating system must only allow the use of DoD PKI-established certificate authorities for authentication in the establishment of protected sessions to the operating system.
☐SV-203745r958870_ruleThe operating system must implement cryptographic mechanisms to prevent unauthorized modification of all information at rest on all operating system components.
☐SV-203746r958872_ruleThe operating system must implement cryptographic mechanisms to prevent unauthorized disclosure of all information at rest on all operating system components.
☐SV-203747r958902_ruleThe operating system must protect against or limit the effects of Denial of Service (DoS) attacks by ensuring the operating system is implementing rate-limiting measures on impacted network interfaces.
☐SV-203748r958908_ruleThe operating system must protect the confidentiality and integrity of transmitted information.
☐SV-203749r1117271_ruleThe operating system must implement cryptographic mechanisms to prevent unauthorized disclosure of information and/or detect changes to information during transmission unless otherwise protected by alternative physical safeguards, such as, at a minimum, a Protected Distribution System (PDS).
☐SV-203750r958912_ruleThe operating system must maintain the confidentiality and integrity of information during preparation for transmission.
☐SV-203751r958914_ruleThe operating system must maintain the confidentiality and integrity of information during reception.
☐SV-203752r958926_ruleThe operating system must behave in a predictable and documented manner that reflects organizational and system objectives when invalid inputs are received.
☐SV-203753r958928_ruleThe operating system must implement non-executable data to protect its memory from unauthorized code execution.
☐SV-203754r958928_ruleThe operating system must implement address space layout randomization to protect its memory from unauthorized code execution.
☐SV-203755r958936_ruleThe operating system must remove all software components after updated versions have been installed.
☐SV-203756r958944_ruleThe operating system must verify correct operation of all security functions.
☐SV-203757r958946_ruleThe operating system must perform verification of the correct operation of security functions: upon system start-up and/or restart; upon command by a user with privileged access; and/or every 30 days.
☐SV-203758r958948_ruleThe operating system must shut down the information system, restart the information system, and/or notify the system administrator when anomalies in the operation of any security functions are discovered.
☐SV-203759r991570_ruleThe operating system must generate audit records when successful/unsuccessful attempts to access security objects occur.
☐SV-203760r991571_ruleThe operating system must generate audit records when successful/unsuccessful attempts to access categories of information (e.g., classification levels) occur.
☐SV-203761r991572_ruleThe operating system must generate audit records when successful/unsuccessful attempts to modify privileges occur.
☐SV-203762r991573_ruleThe operating system must generate audit records when successful/unsuccessful attempts to modify security objects occur.
☐SV-203763r991574_ruleThe operating system must generate audit records when successful/unsuccessful attempts to modify categories of information (e.g., classification levels) occur.
☐SV-203764r991575_ruleThe operating system must generate audit records when successful/unsuccessful attempts to delete privileges occur.
☐SV-203765r991576_ruleThe operating system must generate audit records when successful/unsuccessful attempts to delete security levels occur.
☐SV-203766r991577_ruleThe operating system must generate audit records when successful/unsuccessful attempts to delete security objects occur.
☐SV-203767r991578_ruleThe operating system must generate audit records when successful/unsuccessful logon attempts occur.
☐SV-203768r991579_ruleThe operating system must generate audit records for privileged activities or other system-level access.
☐SV-203769r991580_ruleThe audit system must be configured to audit the loading and unloading of dynamic kernel modules.
☐SV-203770r991581_ruleThe operating system must generate audit records showing starting and ending time for user access to the system.
☐SV-203771r991582_ruleThe operating system must generate audit records when concurrent logons to the same account occur from different sources.
☐SV-203772r991583_ruleThe operating system must generate audit records when successful/unsuccessful accesses to objects occur.
☐SV-203773r991584_ruleThe operating system must generate audit records for all direct access to the information system.
☐SV-203774r991585_ruleThe operating system must generate audit records for all account creations, modifications, disabling, and termination events.
☐SV-203775r991586_ruleThe operating system must generate audit records for all kernel module load, unload, and restart actions, and also for all program initiations.
☐SV-203776r1137699_ruleThe operating system must implement NIST FIPS-validated cryptography for the following: to provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
☐SV-203777r959008_ruleThe operating system must, at a minimum, off-load audit data from interconnected systems in real time and off-load audit data from standalone systems weekly.
☐SV-203778r991587_ruleThe operating system must prevent the use of dictionary words for passwords.
☐SV-203779r991588_ruleThe operating system must enforce a delay of at least 4 seconds between logon prompts following a failed logon attempt.
☐SV-203780r991589_ruleThe operating system must be configured in accordance with the security configuration settings based on DoD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs.
☐SV-203781r991590_ruleThe operating system must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.
☐SV-203782r991591_ruleThe operating system must not allow an unattended or automatic logon to the system.
☐SV-203783r991592_ruleThe operating system must limit the ability of non-privileged users to grant other users direct access to the contents of their home directories/folders.
☐SV-203784r991593_ruleThe operating system must enable an application firewall, if available.
☐SV-252688r958358_ruleThe operating system must protect the confidentiality and integrity of communications with wireless peripherals.
☐SV-259333r1137708_ruleThe operating system must install security-relevant software updates within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, STIGs).
☐SV-263650r982553_ruleThe operating system must disable accounts when the accounts are no longer associated to a user.
☐SV-263651r982555_ruleThe operating system must prohibit the use or connection of unauthorized hardware components.
☐SV-263652r982557_ruleThe operating system must implement multifactor authentication for local, network, and/or remote access to privileged accounts and/or nonprivileged accounts such that the device meets organization-defined strength of mechanism requirements.
☐SV-263653r982229_ruleThe operating system must, for password-based authentication, verify when users create or update passwords the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a).
☐SV-263654r982232_ruleThe operating system must for password-based authentication, require immediate selection of a new password upon account recovery.
☐SV-263655r982235_ruleThe operating system must for password-based authentication, allow user selection of long passwords and passphrases, including spaces and all printable characters.
☐SV-263656r982238_ruleThe operating system must, for password-based authentication, employ automated tools to assist the user in selecting strong password authenticators.
☐SV-263657r982559_ruleThe operating system must accept only external credentials that are NIST-compliant.
☐SV-263658r982561_ruleThe operating system must monitor the use of maintenance tools that execute with increased privilege.
☐SV-263659r982563_ruleThe operating system must include only approved trust anchors in trust stores or certificate stores managed by the organization.
☐SV-263660r982565_ruleThe operating system must provide protected storage for cryptographic keys with organization-defined safeguards and/or hardware protected key store.
☐SV-263661r982567_ruleThe operating system must synchronize system clocks within and between systems or system components.
☐SV-278973r1137694_ruleThe operating system must separate user functionality (including user interface services) from operating system management functionality.
☐SV-278974r1137698_ruleThe operating system must enforce a role-based access control (RBAC) policy over defined subjects and objects.
☐SV-278975r1137702_ruleThe operating system must use a FIPS-validated cryptographic module to provision digital signatures.
☐SV-278976r1137705_ruleThe operating system must enforce attribute-based access control policy over defined subjects and objects based upon organization-defined attributes to assume access permissions.
☐SV-278977r1137711_ruleThe operating system must be a version supported by the vendor.