STIGQter STIGQter: STIG Summary:

Tri-Lab Operating System Stack (TOSS) 4 Security Technical Implementation Guide

Version: 2

Release: 6 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-252911r958390_ruleTOSS must display the Standard Mandatory DoD Notice and Consent Banner or equivalent US Government Agency Notice and Consent Banner before granting local or remote access to the system.
SV-252912r1016298_ruleTOSS, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
SV-252913r958450_ruleTOSS, for PKI-based authentication, must enforce authorized access to the corresponding private key.
SV-252914r1137691_ruleTOSS must require authentication upon booting into emergency or rescue modes.
SV-252915r1016299_ruleTOSS must not permit direct logons to the root account using remote access from outside of the system via SSH.
SV-252916r958498_ruleThe TOSS file system automounter must be disabled unless required.
SV-252917r971535_ruleThe TOSS pam_unix.so module must be configured in the password-auth file to use a FIPS 140-2-approved cryptographic hashing algorithm for system authentication.
SV-252918r971535_ruleThe TOSS pam_unix.so module must be configured in the system-auth file to use a FIPS 140-2-approved cryptographic hashing algorithm for system authentication.
SV-252919r1190841_ruleThe TOSS operating system must implement DOD-approved encryption in the OpenSSL package.
SV-252920r958518_ruleTOSS must use a Linux Security Module configured to enforce limits on system services.
SV-252921r1137695_ruleTOSS must prevent unauthorized and unintended information transfer via shared system resources.
SV-252922r958528_ruleThe TOSS operating system must be configured to use TCP syncookies.
SV-252923r958586_ruleTOSS must display the Standard Mandatory DoD Notice and Consent Banner or equivalent US Government Agency Notice and Consent Banner before granting local or remote access to the system via a ssh logon.
SV-252924r1190843_ruleThe TOSS operating system must implement DOD-approved encryption to protect the confidentiality of SSH connections.
SV-252925r1190838_ruleThe TOSS operating system must implement DOD-approved TLS encryption in the GnuTLS package.
SV-252926r991554_ruleThe TOSS SSH daemon must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-2 validated cryptographic hash algorithms.
SV-252927r991562_ruleThe TOSS operating system must be configured to preserve log records from failure events.
SV-252928r1038944_ruleTOSS must, for networked systems, compare internal information system clocks at least every 24 hours with a server which is synchronized to one of the redundant United States Naval Observatory (USNO) time servers, or a time server designated for the appropriate DOD network (NIPRNet/SIPRNet), and/or the Global Positioning System (GPS).
SV-252929r958794_ruleThe TOSS file integrity tool must notify the system administrator when changes to the baseline configuration or anomalies in the operation of any security functions are discovered within an organizationally defined frequency.
SV-252930r1016301_ruleTOSS must prevent the installation of patches, service packs, device drivers, or operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.
SV-252931r1050791_ruleTOSS must require reauthentication when using the "sudo" command.
SV-252932r1016303_ruleTOSS must have the packages required for multifactor authentication installed.
SV-252933r958828_ruleTOSS must prohibit the use of cached authentications after one day.
SV-252934r958908_ruleAll TOSS networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
SV-252935r991589_ruleFor TOSS systems using Domain Name Servers (DNS) resolution, at least two name servers must be configured.
SV-252936r991589_ruleThe debug-shell systemd service must be disabled on TOSS.
SV-252937r991589_ruleThe root account must be the only account having unrestricted access to the TOSS system.
SV-252938r1155810_ruleThe systemd Ctrl-Alt-Delete burst key sequence in TOSS must be disabled.
SV-252939r991589_ruleThere must be no ".shosts" files on The TOSS operating system.
SV-252940r991589_ruleTOSS must not allow blank or null passwords in the system-auth file.
SV-252941r991589_ruleTOSS must not be performing packet forwarding unless the system is a router.
SV-252942r991589_ruleThe TOSS SSH daemon must not allow authentication using known host's authentication.
SV-252944r991589_ruleThe TOSS SSH daemon must not allow Kerberos authentication, except to fulfill documented and validated mission requirements.
SV-252945r991591_ruleTOSS must not allow an unattended or automatic logon to the system.
SV-252946r1190835_ruleTOSS must enforce the limit of five consecutive invalid logon attempts by a user during a 15-minute time period.
SV-252947r958398_ruleTOSS must limit the number of concurrent sessions to 256 for all accounts and/or account types.
SV-252948r1016304_ruleTOSS must retain a user's session lock until that user reestablishes access using established identification and authentication procedures.
SV-252949r1155813_ruleTOSS must automatically lock graphical user sessions after 10 minutes of inactivity.
SV-252950r958452_ruleTOSS must map the authenticated identity to the user or group account for PKI-based authentication.
SV-252951r958482_ruleTOSS duplicate User IDs (UIDs) must not exist for interactive users.
SV-252952r1016305_ruleTOSS must use multifactor authentication for network and local access to privileged and nonprivileged accounts.
SV-252953r1016306_ruleTOSS must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.
SV-252954r958508_ruleTOSS must automatically remove or disable emergency accounts after the crisis is resolved or 72 hours.
SV-252955r958566_ruleTOSS must reveal error messages only to authorized users.
SV-252956r991568_ruleTOSS must protect wireless access to the system using authentication of users and/or devices.
SV-252957r958736_ruleTOSS must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts in 15 minutes occur.
SV-252958r1050789_ruleTOSS must require users to reauthenticate for privilege escalation.
SV-252959r1050790_ruleTOSS must require users to provide a password for privilege escalation.
SV-252960r991589_ruleAll TOSS local interactive user accounts must be assigned a home directory upon creation.
SV-252961r991589_ruleAll TOSS local interactive user home directories must be group-owned by the home directory owner's primary group.
SV-252962r991589_ruleAll TOSS local interactive users must have a home directory assigned in the /etc/passwd file.
SV-252963r991589_ruleThe x86 Ctrl-Alt-Delete key sequence in TOSS must be disabled if a graphical user interface is installed.
SV-252964r991589_ruleTOSS must disable the user list at logon for graphical user interfaces.
SV-252965r991589_ruleTOSS must display the date and time of the last successful account logon upon an SSH logon.
SV-252966r991589_ruleTOSS must not allow accounts configured with blank or null passwords.
SV-252967r991589_ruleTOSS must not have unnecessary accounts.
SV-252968r991590_ruleTOSS must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.
SV-252969r1190845_ruleAll TOSS local interactive user home directories must have mode 0750 or less permissive.
SV-252970r991592_ruleAll TOSS local interactive user home directories must be owned by root.
SV-252971r991592_ruleAll TOSS local interactive user home directories must be owned by the user's primary group.
SV-252972r958368_ruleTOSS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
SV-252973r1016309_ruleTOSS audit records must contain information to establish what type of events occurred, when the events occurred, the source of events, where events occurred, and the outcome of events.
SV-252974r958422_ruleTOSS must generate audit records containing the full-text recording of privileged commands.
SV-252975r958424_ruleTOSS must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
SV-252976r1038966_ruleTOSS must take appropriate action when an audit processing failure occurs.
SV-252977r958434_ruleTOSS audit logs must have a mode of 0600 or less permissive to prevent unauthorized read access.
SV-252978r958434_ruleTOSS audit log directory must have a mode of 0700 or less permissive to prevent unauthorized read access.
SV-252979r958434_ruleTOSS audit logs must be owned by user root to prevent unauthorized read access.
SV-252980r958434_ruleTOSS audit logs must be owned by group root to prevent unauthorized read access.
SV-252981r958434_ruleTOSS audit log directory must be owned by user root to prevent unauthorized read access.
SV-252982r958434_ruleTOSS audit log directory must be owned by group root to prevent unauthorized read access.
SV-252983r958434_ruleThe TOSS audit system must protect auditing rules from unauthorized change.
SV-252984r958434_ruleThe TOSS audit system must protect logon UIDs from unauthorized change.
SV-252985r958412_ruleSuccessful/unsuccessful uses of the "chage" command in TOSS must generate an audit record.
SV-252986r958412_ruleSuccessful/unsuccessful uses of the "chcon" command in TOSS must generate an audit record.
SV-252987r958412_ruleSuccessful/unsuccessful uses of the ssh-agent in TOSS must generate an audit record.
SV-252988r958412_ruleSuccessful/unsuccessful uses of the "passwd" command in TOSS must generate an audit record.
SV-252989r958412_ruleSuccessful/unsuccessful uses of postdrop in TOSS must generate an audit record.
SV-252990r958412_ruleSuccessful/unsuccessful uses of postqueue in TOSS must generate an audit record.
SV-252991r958412_ruleSuccessful/unsuccessful uses of setsebool in TOSS must generate an audit record.
SV-252992r958412_ruleSuccessful/unsuccessful uses of the ssh-keysign in TOSS must generate an audit record.
SV-252993r958412_ruleSuccessful/unsuccessful uses of the "setfacl" command in RTOSS must generate an audit record.
SV-252994r958412_ruleSuccessful/unsuccessful uses of the "pam_timestamp_check" command in TOSS must generate an audit record.
SV-252995r958412_ruleSuccessful/unsuccessful uses of the "newgrp" command in TOSS must generate an audit record.
SV-252996r958412_ruleSuccessful/unsuccessful uses of the "init_module" command in TOSS must generate an audit record.
SV-252997r958412_ruleSuccessful/unsuccessful uses of the "rename" command in TOSS must generate an audit record.
SV-252998r958412_ruleSuccessful/unsuccessful uses of the "renameat" command in TOSS must generate an audit record.
SV-252999r958412_ruleSuccessful/unsuccessful uses of the "rmdir" command in TOSS must generate an audit record.
SV-253000r958412_ruleSuccessful/unsuccessful uses of the "unlink" command in TOSS must generate an audit record.
SV-253001r958412_ruleSuccessful/unsuccessful uses of the "unlinkat" command in TOSS must generate an audit record.
SV-253002r958412_ruleSuccessful/unsuccessful uses of the "finit_module" command in TOSS must generate an audit record.
SV-253003r958412_ruleSuccessful/unsuccessful uses of the "delete_module" command in TOSS must generate an audit record.
SV-253004r958412_ruleSuccessful/unsuccessful uses of the "crontab" command in TOSS must generate an audit record.
SV-253005r958412_ruleSuccessful/unsuccessful uses of the "chsh" command in TOSS must generate an audit record.
SV-253006r958412_ruleSuccessful/unsuccessful uses of setfiles in TOSS must generate an audit record.
SV-253007r958412_ruleSuccessful/unsuccessful uses of the "chacl" command in TOSS must generate an audit record.
SV-253008r958444_ruleTOSS must allow only the Information System Security Manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.
SV-253009r958446_ruleSuccessful/unsuccessful uses of the chmod system call in TOSS must generate an audit record.
SV-253010r958446_ruleSuccessful/unsuccessful uses of the chown system call in TOSS must generate an audit record.
SV-253011r958446_ruleSuccessful/unsuccessful uses of the creat system call in TOSS must generate an audit record.
SV-253012r958446_ruleSuccessful/unsuccessful uses of the fchmod system call in TOSS must generate an audit record.
SV-253013r958446_ruleSuccessful/unsuccessful uses of the fchmodat system call in TOSS must generate an audit record.
SV-253014r958446_ruleSuccessful/unsuccessful uses of the fchown system call in TOSS must generate an audit record.
SV-253015r958446_ruleSuccessful/unsuccessful uses of the fchownat system call in TOSS must generate an audit record.
SV-253016r958446_ruleSuccessful/unsuccessful uses of the ftruncate system call system call in TOSS must generate an audit record.
SV-253017r958446_ruleSuccessful/unsuccessful uses of the lchown system call in TOSS must generate an audit record.
SV-253018r958446_ruleSuccessful/unsuccessful uses of the open system call in TOSS must generate an audit record.
SV-253019r958446_ruleSuccessful/unsuccessful uses of the open_by_handle_at system call system call in TOSS must generate an audit record.
SV-253020r958446_ruleSuccessful/unsuccessful uses of the openat system call in TOSS must generate an audit record.
SV-253021r958446_ruleSuccessful/unsuccessful uses of the truncate system call in TOSS must generate an audit record.
SV-253022r991557_ruleTOSS audit tools must be owned by "root".
SV-253023r991567_ruleTOSS must use cryptographic mechanisms to protect the integrity of audit tools.
SV-253024r958684_ruleTOSS must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/group".
SV-253025r958684_ruleTOSS must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/gshadow".
SV-253026r958684_ruleTOSS must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/passwd".
SV-253027r958684_ruleTOSS must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/security/opasswd".
SV-253028r958684_ruleTOSS must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/sudoers".
SV-253029r958684_ruleTOSS must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/sudoers.d/".
SV-253030r958730_ruleThe TOSS audit system must prevent all software from executing at higher privilege levels than users executing the software and the audit system must be configured to audit the execution of privileged functions.
SV-253031r958752_ruleTOSS must allocate audit record storage capacity to store at least one week's worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
SV-253032r958754_ruleThe TOSS audit records must be offloaded onto a different system or storage media from the system being audited.
SV-253033r958754_ruleTOSS must label all off-loaded audit logs before sending them to the central log server.
SV-253034r991570_ruleThe TOSS audit system must be configured to audit any usage of the "fsetxattr" system call.
SV-253035r991570_ruleThe TOSS audit system must be configured to audit any usage of the "lsetxattr" system call.
SV-253036r991577_ruleSuccessful/unsuccessful uses of the fremovexattr system call in TOSS must generate an audit record.
SV-253037r991577_ruleSuccessful/unsuccessful uses of the "lremovexattr" system call in TOSS must generate an audit record.
SV-253038r991577_ruleSuccessful/unsuccessful uses of the "removexattr" system call in TOSS must generate an audit record.
SV-253039r991578_ruleSuccessful/unsuccessful modifications to the "lastlog" file in TOSS must generate an audit record.
SV-253040r991579_ruleSuccessful/unsuccessful uses of "semanage" in TOSS must generate an audit record.
SV-253041r991579_ruleSuccessful/unsuccessful uses of the "gpasswd" command in TOSS must generate an audit record.
SV-253042r991579_ruleSuccessful/unsuccessful uses of the "mount" command in TOSS must generate an audit record.
SV-253043r991579_ruleSuccessful/unsuccessful uses of the "mount" syscall in TOSS must generate an audit record.
SV-253044r991579_ruleSuccessful/unsuccessful uses of the "su" command in TOSS must generate an audit record.
SV-253045r991579_ruleSuccessful/unsuccessful uses of the "umount" command in TOSS must generate an audit record.
SV-253046r991579_ruleSuccessful/unsuccessful uses of the "unix_update" in TOSS must generate an audit record.
SV-253047r991579_ruleSuccessful/unsuccessful uses of the "usermod" command in TOSS must generate an audit record.
SV-253048r991579_ruleSuccessful/unsuccessful uses of "unix_chkpwd" in TOSS must generate an audit record.
SV-253049r991579_ruleSuccessful/unsuccessful uses of "userhelper" in TOSS must generate an audit record.
SV-253050r991580_ruleSuccessful/unsuccessful uses of the "kmod" command in TOSS must generate an audit record.
SV-253051r991589_ruleThe auditd service must be running in TOSS.
SV-253052r991589_ruleThe TOSS audit system must audit local events.
SV-253053r991589_ruleTOSS must resolve audit information before writing to disk.
SV-253054r991589_ruleTOSS must have the packages required for offloading audit logs installed.
SV-253055r991589_ruleTOSS must have the packages required for encrypting offloaded audit logs installed.
SV-253056r958406_ruleTOSS must monitor remote access methods.
SV-253057r958408_ruleTOSS must force a frequent session key renegotiation for SSH connections by the client.
SV-253058r958408_ruleTOSS must force a frequent session key renegotiation for SSH connections to the server.
SV-253059r958408_ruleTOSS must implement NIST FIPS-validated cryptography for the following: to provision digital signatures; to generate cryptographic hashes; and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
SV-253060r1016310_ruleTOSS must enforce password complexity by requiring that at least one uppercase character be used.
SV-253061r1016311_ruleTOSS must enforce password complexity by requiring that at least one lowercase character be used.
SV-253062r1016312_ruleTOSS must enforce password complexity by requiring that at least one numeric character be used.
SV-253063r1016313_ruleTOSS must require the change of at least eight characters when passwords are changed.
SV-253064r1016314_ruleTOSS must store only encrypted representations of passwords.
SV-253065r987796_ruleTOSS must not have the rsh-server package installed.
SV-253066r1016315_ruleTOSS must enforce 24 hours/one day as the minimum password lifetime.
SV-253067r1038967_ruleTOSS must enforce a 60-day maximum password lifetime restriction.
SV-253069r1016317_ruleTOSS must enforce a minimum 15-character password length.
SV-253070r958478_ruleTOSS must cover or disable the built-in or attached camera when not in use.
SV-253071r958478_ruleTOSS must disable IEEE 1394 (FireWire) Support.
SV-253072r958478_ruleTOSS must disable mounting of cramfs.
SV-253073r958478_ruleTOSS must disable network management of the chrony daemon.
SV-253074r958478_ruleTOSS must disable the asynchronous transfer mode (ATM) protocol.
SV-253075r958478_ruleTOSS must disable the controller area network (CAN) protocol.
SV-253076r958478_ruleTOSS must disable the stream control transmission (SCTP) protocol.
SV-253077r958478_ruleTOSS must disable the transparent inter-process communication (TIPC) protocol.
SV-253078r958478_ruleTOSS must not have any automated bug reporting tools installed.
SV-253079r958478_ruleTOSS must not have the sendmail package installed.
SV-253080r958478_ruleTOSS must not have the telnet-server package installed.
SV-253081r958480_ruleTOSS must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.
SV-253082r986606_ruleTOSS must be configured to disable USB mass storage.
SV-253083r986603_ruleTOSS must be configured so that all network connections associated with SSH traffic are terminated at the end of the session or after 10 minutes of inactivity, except to fulfill documented and validated mission requirements.
SV-253084r958518_ruleTOSS must have policycoreutils package installed.
SV-253085r1207691_ruleAll TOSS local disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at-rest protection.
SV-253086r991560_ruleTOSS must limit privileges to change software resident within software libraries.
SV-253087r1016318_ruleTOSS must enforce password complexity by requiring that at least one special character be used.
SV-253088r958672_ruleA firewall must be installed on TOSS.
SV-253089r958754_ruleTOSS must take appropriate action when the internal event queue is full.
SV-253090r958816_ruleTOSS must accept Personal Identity Verification (PIV) credentials.
SV-253091r958848_ruleTOSS must implement DoD-approved encryption in the OpenSSL package.
SV-253092r958902_ruleA firewall must be able to protect against or limit the effects of Denial of Service (DoS) attacks by ensuring TOSS can implement rate-limiting measures on impacted network interfaces.
SV-253093r958928_ruleTOSS must implement non-executable data to protect its memory from unauthorized code execution.
SV-253094r958936_ruleYUM must remove all software components after updated versions have been installed on TOSS.
SV-253095r958944_ruleTOSS must enable the "SELinux" targeted policy.
SV-253096r991587_ruleTOSS must prevent the use of dictionary words for passwords.
SV-253097r991588_ruleTOSS must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
SV-253098r991589_ruleA File Transfer Protocol (FTP) server package must not be installed unless mission essential on TOSS.
SV-253099r991589_ruleAll TOSS local files and directories must have a valid group owner.
SV-253100r991589_ruleAll TOSS local files and directories must have a valid owner.
SV-253101r991589_ruleCron logging must be implemented in TOSS.
SV-253102r1134939_ruleIf the Trivial File Transfer Protocol (TFTP) server is required, the TOSS TFTP daemon must be configured to operate in secure mode.
SV-253103r991589_ruleThe graphical display manager must not be installed on TOSS unless approved.
SV-253104r991589_ruleThe TOSS file integrity tool must be configured to verify Access Control Lists (ACLs).
SV-253105r991589_ruleThe TOSS file integrity tool must be configured to verify extended attributes.
SV-253106r991589_ruleThe TOSS SSH daemon must perform strict mode checking of home directory configuration files.
SV-253107r991589_ruleThe TOSS SSH private host key files must have mode 0600 or less permissive.
SV-253108r991589_ruleThe TOSS SSH public host key files must have mode 0644 or less permissive.
SV-253109r991589_ruleThe x86 Ctrl-Alt-Delete key sequence must be disabled on TOSS.
SV-253110r991589_ruleTOSS must be a vendor-supported release.
SV-253111r991589_ruleTOSS must be configured to prevent unrestricted mail relaying.
SV-253112r991589_ruleTOSS must define default permissions for logon and non-logon shells.
SV-253113r991589_ruleTOSS must disable access to network bpf syscall from unprivileged processes.
SV-253114r991589_ruleTOSS must enable hardening for the Berkeley Packet Filter Just-in-time compiler.
SV-253115r991589_ruleTOSS must enable the hardware random number generator entropy gatherer service.
SV-253116r991589_ruleTOSS must ensure the SSH server uses strong entropy.
SV-253117r991589_ruleTOSS must have the packages required to use the hardware random number generator entropy gatherer service.
SV-253118r991589_ruleTOSS must ignore IPv4 Internet Control Message Protocol (ICMP) redirect messages.
SV-253119r991589_ruleTOSS must ignore IPv6 Internet Control Message Protocol (ICMP) redirect messages.
SV-253120r991589_ruleTOSS must not accept router advertisements on all IPv6 interfaces by default.
SV-253121r991589_ruleTOSS must not accept router advertisements on all IPv6 interfaces.
SV-253122r991589_ruleTOSS must not allow blank or null passwords in the password-auth file.
SV-253123r991589_ruleTOSS must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default.
SV-253124r991589_ruleTOSS must not forward IPv4 source-routed packets by default.
SV-253125r991589_ruleTOSS must not forward IPv4 source-routed packets.
SV-253126r991589_ruleTOSS must not forward IPv6 source-routed packets by default.
SV-253127r991589_ruleTOSS must not forward IPv6 source-routed packets.
SV-253128r991589_ruleTOSS must not respond to Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.
SV-253129r991589_ruleTOSS must not send Internet Control Message Protocol (ICMP) redirects.
SV-253130r991589_ruleTOSS must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted.
SV-253131r991589_ruleTOSS must prevent IPv6 Internet Control Message Protocol (ICMP) redirect messages from being accepted.
SV-253132r991589_ruleTOSS must restrict exposed kernel pointer addresses access.
SV-253133r991589_ruleTOSS must restrict privilege elevation to authorized personnel.
SV-253134r991589_ruleTOSS must use reverse path filtering on all IPv4 interfaces.
SV-253135r991589_ruleTOSS network interfaces must not be in promiscuous mode.
SV-253136r958702_ruleTOSS must enable kernel parameters to enforce discretionary access control on symlinks.
SV-253137r958702_ruleTOSS must enable kernel parameters to enforce discretionary access control on hardlinks.