STIGQter STIGQter: STIG Summary:

Tri-Lab Operating System Stack (TOSS) 5 Security Technical Implementation Guide

Version: 1

Release: 1 Benchmark Date: 26 Mar 2026

CheckedNameTitle
SV-282352r1200036_ruleTOSS 5 must automatically expire temporary accounts within 72 hours.
SV-282353r1200039_ruleTOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.
SV-282354r1201500_ruleTOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory.
SV-282355r1200045_ruleTOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
SV-282356r1200048_ruleTOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
SV-282357r1200051_ruleTOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
SV-282358r1200054_ruleTOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
SV-282359r1200057_ruleTOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
SV-282360r1200060_ruleTOSS 5 must automatically lock an account when three unsuccessful login attempts occur.
SV-282361r1200063_ruleTOSS 5 must automatically lock an account when three unsuccessful login attempts occur during a 15-minute time period.
SV-282362r1200066_ruleTOSS 5 must ensure account lockouts persist.
SV-282363r1200069_ruleTOSS 5 must log username information when unsuccessful login attempts occur.
SV-282364r1200072_ruleTOSS 5 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file.
SV-282365r1200075_ruleTOSS 5 must configure the use of the pam_faillock.so module in the /etc/pam.d/password-auth file.
SV-282366r1200078_ruleTOSS 5 must display the Standard Mandatory DOD or other applicable U.S. Government Notice and Consent Banner before granting local or remote access to the system via a command line user login.
SV-282367r1201610_ruleTOSS 5 must display the Standard Mandatory DOD or other applicable U.S. Government agency Notice and Consent Banner before granting local or remote access to the system via a SSH login.
SV-282368r1200084_ruleTOSS 5 must display the Standard Mandatory DOD or other applicable U.S. Government agency Notice and Consent Banner before granting local or remote access to the system via a graphical user login.
SV-282369r1200087_ruleTOSS 5 must prevent a user from overriding the banner-message-enable setting for the graphical user interface.
SV-282371r1200093_ruleTOSS 5 must limit the number of concurrent sessions to 256 for all accounts and/or account types.
SV-282372r1201380_ruleTOSS 5 must directly initiate a session lock for all connection types when the smart card is removed.
SV-282373r1200099_ruleTOSS 5 must prevent a user from overriding the disabling of the graphical user smart card removal action.
SV-282374r1201498_ruleTOSS 5 must enable a user session lock until that user reestablishes access using established identification and authentication procedures for graphical user sessions.
SV-282375r1200105_ruleTOSS 5 must prevent a user from overriding the screensaver lock-enabled setting for the graphical user interface.
SV-282376r1200108_ruleTOSS 5 must have the tmux package installed.
SV-282377r1200111_ruleTOSS 5 must automatically lock graphical user sessions after 10 minutes of inactivity.
SV-282378r1200114_ruleTOSS 5 must prevent a user from overriding the session idle-delay setting for the graphical user interface.
SV-282379r1200117_ruleTOSS 5 must initiate a session lock for graphical user interfaces when the screensaver is activated.
SV-282380r1200120_ruleTOSS 5 must prevent a user from overriding the session lock-delay setting for the graphical user interface.
SV-282381r1200123_ruleTOSS 5 must automatically exit interactive command shell user sessions after 15 minutes of inactivity.
SV-282382r1200126_ruleTOSS 5 must conceal via the session lock information previously visible on the display with a publicly viewable image.
SV-282383r1200129_ruleTOSS 5 must log SSH connection attempts and failures to the server.
SV-282384r1200132_ruleAll TOSS 5 remote access methods must be monitored.
SV-282385r1200135_ruleTOSS 5 must force a frequent session key renegotiation for SSH connections to the server.
SV-282386r1200138_ruleTOSS 5 IP tunnels must use FIPS 140-3-approved cryptographic algorithms.
SV-282387r1200141_ruleTOSS 5 must enable auditing of processes that start prior to the audit daemon.
SV-282388r1201627_ruleTOSS 5 must audit all uses of the chmod, fchmod, and fchmodat system calls.
SV-282389r1201629_ruleTOSS 5 must audit all uses of the chown, fchown, fchownat, and lchown system calls.
SV-282390r1201503_ruleTOSS 5 must audit all uses of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls.
SV-282391r1201505_ruleTOSS 5 must audit all uses of umount system calls.
SV-282392r1201507_ruleTOSS 5 must audit all uses of the chacl command.
SV-282393r1201509_ruleTOSS 5 must audit all uses of the setfacl command.
SV-282394r1201511_ruleTOSS 5 must audit all uses of the chcon command.
SV-282395r1201513_ruleTOSS 5 must audit all uses of the semanage command.
SV-282396r1201515_ruleTOSS 5 must audit all uses of the setfiles command.
SV-282397r1201517_ruleTOSS 5 must audit all uses of the setsebool command.
SV-282398r1201519_ruleTOSS 5 must audit all uses of the rename, unlink, rmdir, renameat, and unlinkat system calls.
SV-282399r1201521_ruleTOSS 5 must audit all uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls.
SV-282400r1201523_ruleTOSS 5 must audit all uses of the delete_module system call.
SV-282401r1201525_ruleTOSS 5 must audit all uses of the init_module and finit_module system calls.
SV-282402r1201527_ruleTOSS 5 must audit all uses of the chage command.
SV-282403r1201529_ruleTOSS 5 must audit all uses of the chsh command.
SV-282404r1201531_ruleTOSS 5 must audit all uses of the crontab command.
SV-282405r1201533_ruleTOSS 5 must audit all uses of the gpasswd command.
SV-282406r1201535_ruleTOSS 5 must audit all uses of the kmod command.
SV-282407r1201537_ruleTOSS 5 must audit all uses of the newgrp command.
SV-282408r1201539_ruleTOSS 5 must audit all uses of the pam_timestamp_check command.
SV-282409r1201541_ruleTOSS 5 must audit all uses of the passwd command.
SV-282410r1201543_ruleTOSS 5 must audit all uses of the postdrop command.
SV-282411r1201545_ruleTOSS 5 must audit all uses of the postqueue command.
SV-282412r1201547_ruleTOSS 5 must audit all uses of the ssh-agent command.
SV-282413r1201549_ruleTOSS 5 must audit all uses of the ssh-keysign command.
SV-282414r1201551_ruleTOSS 5 must audit all uses of the su command.
SV-282415r1201553_ruleTOSS 5 must audit all uses of the sudo command.
SV-282416r1201555_ruleTOSS 5 must audit all uses of the sudoedit command.
SV-282417r1201557_ruleTOSS 5 must audit all uses of the unix_chkpwd command.
SV-282418r1201559_ruleTOSS 5 must audit all uses of the unix_update command.
SV-282419r1201561_ruleTOSS 5 must audit all uses of the userhelper command.
SV-282420r1201563_ruleTOSS 5 must audit all uses of the usermod command.
SV-282421r1201565_ruleTOSS 5 must audit all uses of the mount command.
SV-282422r1201567_ruleSuccessful/unsuccessful uses of the umount system call in TOSS 5 must generate an audit record.
SV-282423r1201569_ruleSuccessful/unsuccessful uses of the umount2 system call in TOSS 5 must generate an audit record.
SV-282424r1201571_ruleTOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/lastlog.
SV-282425r1201625_ruleTOSS 5 must label all offloaded audit logs before sending them to the central log server.
SV-282426r1200258_ruleTOSS 5 must forward mail from postmaster to the root account using a postfix alias.
SV-282427r1200261_ruleTOSS 5 system administrators (SAs) and/or information system security officer (ISSOs) (at a minimum) must be alerted of an audit processing failure event.
SV-282428r1200264_ruleTOSS 5 must have mail aliases to notify the information system security officer (ISSO) and system administrator (SA) (at a minimum) in the event of an audit processing failure.
SV-282429r1200267_ruleTOSS 5 must take appropriate action when a critical audit processing failure occurs.
SV-282430r1200270_ruleTOSS 5 must periodically flush audit records to disk to prevent the loss of audit records.
SV-282431r1200273_ruleTOSS 5 audit logs must be group-owned by root or by a restricted logging group to prevent unauthorized read access.
SV-282432r1200276_ruleTOSS 5 audit log directory must be owned by root to prevent unauthorized read access.
SV-282433r1200279_ruleTOSS 5 audit logs file must have mode 0600 or less permissive to prevent unauthorized access to the audit log.
SV-282434r1200282_ruleTOSS 5 audit system must protect login user identifiers (UIDs) from unauthorized change.
SV-282435r1200285_ruleTOSS 5 audit system must protect auditing rules from unauthorized change.
SV-282436r1200288_ruleTOSS 5 must enable Linux audit logging for the USBGuard daemon.
SV-282437r1200291_ruleTOSS 5 audit package must be installed.
SV-282438r1200294_ruleTOSS 5 audit service must be enabled.
SV-282439r1200297_ruleThe TOSS 5 audit system must audit local events.
SV-282440r1200300_ruleTOSS 5 must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.
SV-282441r1200303_ruleTOSS 5 /etc/audit/auditd.conf file must have 0640 or less permissive to prevent unauthorized access.
SV-282442r1200306_ruleTOSS 5, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
SV-282443r1200309_ruleTOSS 5, for public key infrastructure (PKI)-based authentication, must enforce authorized access to the corresponding private key.
SV-282444r1200312_ruleTOSS 5 must map the authenticated identity to the user or group account for PKI-based authentication.
SV-282445r1200315_ruleTOSS 5 must ensure the password complexity module in the system-auth file is configured for three retries or less.
SV-282446r1200318_ruleTOSS 5 must ensure the password complexity module is enabled in the password-auth file.
SV-282447r1200321_ruleTOSS 5 must enforce password complexity by requiring at least one uppercase character.
SV-282448r1200324_ruleTOSS 5 must enforce password complexity by requiring that at least one lowercase character be used.
SV-282449r1200327_ruleTOSS 5 must enforce password complexity by requiring that at least one numeric character be used.
SV-282450r1200330_ruleTOSS 5 must enforce password complexity rules for the root account.
SV-282451r1200333_ruleTOSS 5 must require users to change at least eight characters when changing passwords.
SV-282452r1200336_ruleTOSS 5 must limit the maximum number of repeating characters of the same character class to four when passwords are changed.
SV-282453r1200339_ruleTOSS 5 must limit the maximum number of repeating characters to three when passwords are changed.
SV-282454r1200342_ruleTOSS 5 must require the change of at least four character classes when passwords are changed.
SV-282455r1201382_ruleTOSS 5 password-auth must be configured to use a sufficient number of hashing rounds.
SV-282456r1201574_ruleTOSS 5 system-auth must be configured to use a sufficient number of hashing rounds.
SV-282457r1200351_ruleTOSS 5 must be configured so that user and group account administration utilities are configured to store only encrypted representations of passwords.
SV-282458r1200354_ruleTOSS 5 must be configured to use the shadow file to store only encrypted representations of passwords.
SV-282459r1200357_ruleTOSS 5 shadow password suite must be configured to use a sufficient number of hashing rounds.
SV-282460r1200360_ruleTOSS 5 must employ FIPS 140-3-approved cryptographic hashing algorithms for all stored passwords.
SV-282461r1200363_ruleThe TOSS 5 pam_unix.so module must be configured in the password-auth file to use a FIPS 140-3-approved cryptographic hashing algorithm for system authentication.
SV-282462r1200366_ruleTOSS 5 must not have the rsh-server package installed.
SV-282463r1200369_ruleTOSS 5 passwords for new users or password changes must have a 24 hours minimum password lifetime restriction in /etc/login.defs.
SV-282464r1200372_ruleTOSS 5 passwords must have a 24 hours minimum password lifetime restriction in /etc/shadow.
SV-282465r1200375_ruleTOSS 5 user account passwords for new users or password changes must have a 60-day maximum password lifetime restriction in /etc/login.defs.
SV-282466r1200378_ruleTOSS 5 user account passwords must have a 60-day maximum password lifetime restriction.
SV-282467r1200381_ruleTOSS 5 passwords must be created with a minimum of 15 characters.
SV-282468r1200384_ruleTOSS 5 passwords, for new users, must have a minimum of 15 characters.
SV-282470r1201601_ruleTOSS 5 must require a unique superuser name upon booting into single-user and maintenance modes.
SV-282471r1200393_ruleTOSS 5 must require authentication to access emergency mode.
SV-282472r1200396_ruleTOSS 5 must require authentication to access single-user mode.
SV-282473r1200399_ruleTOSS 5 must enable mitigations against processor-based vulnerabilities.
SV-282474r1200402_ruleTOSS 5 must be configured to disable the Asynchronous Transfer Mode (ATM) kernel module.
SV-282475r1200405_ruleTOSS 5 must be configured to disable the Controller Area Network (CAN) kernel module.
SV-282476r1200408_ruleTOSS 5 must be configured to disable the FireWire kernel module.
SV-282477r1200411_ruleTOSS 5 must disable the Stream Control Transmission Protocol (SCTP) kernel module.
SV-282478r1200414_ruleTOSS 5 must disable the Transparent Inter Process Communication (TIPC) kernel module.
SV-282479r1200417_ruleTOSS 5 must not have the ypserv package installed.
SV-282480r1200420_ruleTOSS 5 must not have the rsh-server package installed.
SV-282481r1200423_ruleTOSS 5 must not have the telnet-server package installed.
SV-282482r1200426_ruleTOSS 5 must not have the iprutils package installed.
SV-282483r1200429_ruleTOSS 5 must disable mounting of cramfs.
SV-282484r1201332_ruleTOSS 5 must disable network management of the chrony daemon.
SV-282485r1200435_ruleTOSS 5 must have the firewalld package installed.
SV-282486r1200438_ruleThe firewalld service on TOSS 5 must be active.
SV-282487r1200441_ruleTOSS 5 must control remote access methods.
SV-282488r1200444_ruleTOSS 5 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.
SV-282489r1200447_ruleTOSS 5 duplicate User IDs (UIDs) must not exist for interactive users.
SV-282490r1200450_ruleAll TOSS 5 interactive users must have a primary group that exists.
SV-282491r1200453_ruleTOSS 5 groups must have unique Group ID (GID).
SV-282492r1200456_ruleTOSS 5 must have the openssl-pkcs11 package installed.
SV-282493r1200459_ruleTOSS 5 SSHD must not allow blank or null passwords.
SV-282494r1200462_ruleTOSS 5 must not permit direct logins to the root account using remote access via SSH.
SV-282497r1200471_ruleTOSS 5 file system automount function must be disabled unless required.
SV-282498r1200474_ruleTOSS 5 must disable the graphical user interface automount function unless required.
SV-282499r1200477_ruleTOSS 5 must prevent a user from overriding the disabling of the graphical user interface automount function.
SV-282500r1200480_ruleTOSS 5 must prevent a user from overriding the disabling of the graphical user interface autorun function.
SV-282501r1200483_ruleTOSS 5 must be configured to disable USB mass storage.
SV-282502r1200486_ruleTOSS 5 must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.
SV-282503r1200489_ruleTOSS 5 must use mechanisms meeting the requirements of applicable federal laws, executive orders, directives, policies, regulations, standards, and guidance for authentication to a cryptographic module.
SV-282504r1200492_ruleTOSS 5 must enable the Pluggable Authentication Module (PAM) interface for SSHD.
SV-282505r1200495_ruleTOSS 5 must restrict access to the kernel message buffer.
SV-282506r1200498_ruleTOSS 5 must prevent kernel profiling by nonprivileged users.
SV-282507r1200501_ruleTOSS 5 must restrict exposed kernel pointer addresses access.
SV-282508r1200504_ruleTOSS 5 must disable access to network bpf system call from nonprivileged processes.
SV-282509r1200507_ruleTOSS 5 must restrict usage of ptrace to descendant processes.
SV-282510r1201302_ruleTOSS 5 must use a Linux Security Module configured to enforce limits on system services.
SV-282511r1200513_ruleA sticky bit must be set on all TOSS 5 public directories.
SV-282512r1201342_ruleTOSS 5 must be configured to use TCP syncookies.
SV-282514r1201603_ruleTOSS 5 local disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at rest protection.
SV-282516r1200528_ruleTOSS 5 /var/log directory must have mode 0755 or less permissive.
SV-282517r1200531_ruleTOSS 5 /var/log/messages file must have mode 0640 or less permissive.
SV-282518r1200534_ruleTOSS 5 /var/log directory must be owned by root.
SV-282519r1200537_ruleTOSS 5 /var/log directory must be group-owned by root.
SV-282520r1200540_ruleTOSS 5 /var/log/messages file must be owned by root.
SV-282521r1200543_ruleTOSS 5 /var/log/messages file must be group-owned by root.
SV-282522r1200546_ruleTOSS 5 SSH daemon must be configured to use systemwide crypto policies.
SV-282523r1200549_ruleTOSS 5 must implement DOD or other applicable U.S. Government agency-approved encryption ciphers to protect the confidentiality of SSH client connections.
SV-282524r1201364_ruleTOSS 5 must implement DOD or other applicable U.S. Government agency-approved encryption ciphers to protect the confidentiality of SSH server connections.
SV-282525r1201367_ruleThe TOSS 5 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms.
SV-282526r1201501_ruleTOSS 5 must implement DOD or other applicable U.S. Government agency-approved TLS encryption in the GnuTLS package.
SV-282527r1200561_ruleTOSS 5 must implement DOD or other applicable U.S. Government agency -approved encryption in the OpenSSL package.
SV-282528r1201630_ruleTOSS 5 must implement DOD or other applicable U.S. Government agency-approved TLS encryption in the OpenSSL package.
SV-282529r1200567_ruleTOSS 5 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.
SV-282530r1200570_ruleTOSS 5 must produce audit records containing information to establish the identity of any individual or process associated with the event.
SV-282531r1201577_ruleTOSS 5 audit tools must have a mode of 0755 or less permissive.
SV-282532r1200576_ruleTOSS 5 audit tools must be owned by root.
SV-282533r1201328_ruleTOSS 5 audit tools must be group-owned by root.
SV-282534r1200582_ruleTOSS 5 must use cryptographic mechanisms to protect the integrity of audit tools.
SV-282535r1200585_ruleTOSS 5 system commands must have mode 755 or less permissive.
SV-282536r1201579_ruleTOSS 5 library directories must have mode 755 or less permissive.
SV-282537r1201581_ruleTOSS 5 library files must have mode 755 or less permissive.
SV-282538r1200594_ruleTOSS 5 system commands must be owned by root.
SV-282539r1200597_ruleTOSS 5 system commands must be group-owned by root or a system account.
SV-282540r1201318_ruleTOSS 5 library files must be owned by root.
SV-282541r1201321_ruleTOSS 5 library files must be group-owned by root or a system account.
SV-282542r1201324_ruleTOSS 5 library directories must be owned by root.
SV-282543r1201327_ruleTOSS 5 library directories must be group-owned by root or a system account.
SV-282544r1200612_ruleTOSS 5 must enforce password complexity by requiring at least one special character.
SV-282545r1200615_ruleThe TOSS 5 systemd-journald service must be enabled.
SV-282549r1200627_ruleTOSS 5 must securely compare internal information system clocks at least every 24 hours.
SV-282553r1200639_ruleTOSS 5 must enable kernel parameters to enforce discretionary access control on hardlinks.
SV-282554r1201608_ruleTOSS 5 must enable kernel parameters to enforce discretionary access control (DAC) on symlinks.
SV-282557r1200651_ruleThe systemd Ctrl-Alt-Delete burst key sequence in TOSS 5 must be disabled.
SV-282558r1200654_ruleThe x86 Ctrl-Alt-Delete key sequence must be disabled on TOSS 5.
SV-282559r1200657_ruleThe TOSS 5 debug-shell systemd service must be disabled.
SV-282560r1200660_ruleTOSS 5 must have the sudo package installed.
SV-282561r1200663_ruleTOSS 5 must audit uses of the execve system call.
SV-282562r1201623_ruleTOSS 5 must allocate audit record storage capacity to store at least one week's worth of audit records.
SV-282563r1200669_ruleTOSS 5 must be configured to off-load audit records onto a different system from the system being audited via syslog.
SV-282564r1201619_ruleTOSS 5 must authenticate the remote logging server for off-loading audit logs via rsyslog.
SV-282565r1201620_ruleTOSS 5 must encrypt the transfer of audit records off-loaded onto a different system or media from the system being audited via rsyslog.
SV-282566r1200678_ruleTOSS 5 must encrypt, via the gtls driver, the transfer of audit records off-loaded onto a different system or media from the system being audited via rsyslog.
SV-282567r1200681_ruleTOSS 5 must take appropriate action when the internal event queue is full.
SV-282568r1200684_ruleTOSS 5 audispd-plugins package must be installed.
SV-282569r1200687_ruleTOSS 5 must act when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity.
SV-282570r1200690_ruleTOSS 5 must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume 75 percent utilization.
SV-282571r1200693_ruleTOSS 5 must act when allocated audit record storage volume reaches 95 percent of the audit record storage capacity.
SV-282572r1200696_ruleTOSS 5 must act when allocated audit record storage volume reaches 95 percent of the repository maximum audit record storage capacity.
SV-282574r1200702_ruleTOSS 5 must have the chrony package installed.
SV-282575r1200705_ruleTOSS 5 chronyd service must be enabled.
SV-282578r1200714_ruleTOSS 5 must have the s-nail package installed.
SV-282579r1201582_ruleTOSS 5 must have the Advanced Intrusion Detection Environment (AIDE) package installed.
SV-282580r1201642_ruleTOSS 5 must routinely check the baseline configuration for unauthorized changes and notify the system administrator (SA) when anomalies in the operation of any security functions are discovered.
SV-282581r1200723_ruleTOSS 5 SSH daemon must not allow Kerberos authentication.
SV-282582r1200726_ruleTOSS 5 must ensure cryptographic verification of vendor software packages.
SV-282583r1200729_ruleTOSS 5 must check the GPG signature of software packages originating from external software repositories before installation.
SV-282584r1200732_ruleTOSS 5 must check the GPG signature of locally installed software packages before installation.
SV-282585r1200735_ruleTOSS 5 must have GPG signature verification enabled for all software repositories.
SV-282586r1200738_ruleTOSS 5 subscription-manager package must be installed.
SV-282587r1200741_ruleTOSS 5 must mount /var/tmp with the nosuid option.
SV-282588r1200744_ruleTOSS 5 must disable the graphical user interface autorun function unless required.
SV-282589r1200747_ruleTOSS 5 fapolicy module must be installed.
SV-282590r1200750_ruleTOSS 5 must use the invoking user's password for privilege escalation when using sudo.
SV-282591r1200753_ruleTOSS 5 must have the pcsc-lite package installed.
SV-282592r1200756_ruleTOSS 5 must have the opensc package installed.
SV-282593r1200759_ruleTOSS 5 must have the USBGuard package installed.
SV-282594r1200762_ruleTOSS 5 must have the USBGuard package enabled.
SV-282595r1200765_ruleTOSS 5 must block unauthorized peripherals before establishing a connection.
SV-282597r1200771_ruleTOSS 5 must prohibit the use of cached authenticators after one day.
SV-282598r1200774_ruleTOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/faillock.
SV-282599r1201494_ruleTOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/tallylog.
SV-282601r1200783_ruleTOSS 5 must have the crypto-policies package installed.
SV-282602r1200786_ruleTOSS 5 crypto policy must not be overridden.
SV-282603r1200789_ruleTOSS 5 must implement a systemwide encryption policy.
SV-282605r1200795_ruleTOSS 5 must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring rate-limiting measures on impacted network interfaces are implemented.
SV-282606r1201360_ruleAll TOSS 5 networked systems must have SSH installed.
SV-282607r1200801_ruleAll TOSS 5 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
SV-282608r1200804_ruleTOSS 5 must implement DOD or other applicable U.S. Government agency-approved encryption in the bind package.
SV-282610r1200810_ruleTOSS 5 must implement nonexecutable data to protect its memory from unauthorized code execution.
SV-282611r1200813_ruleTOSS 5 must remove all software components after updated versions have been installed.
SV-282613r1201304_ruleTOSS 5 must enable the "SELinux" targeted policy.
SV-282615r1201495_ruleTOSS 5 crypto policy files must match files shipped with the operating system.
SV-282616r1200828_ruleTOSS 5 must have the rsyslog package installed.
SV-282617r1201621_ruleTOSS 5 must be configured to forward audit records via TCP to a different system or media from the system being audited via rsyslog.
SV-282618r1200834_ruleTOSS 5 must prevent the use of dictionary words for passwords.
SV-282619r1200837_ruleTOSS 5 must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
SV-282620r1200840_ruleTOSS 5 must disable virtual system calls.
SV-282621r1200843_ruleTOSS 5 must clear the page allocator to prevent use-after-free attacks.
SV-282622r1201309_ruleTOSS 5 must disable the kernel.core_pattern.
SV-282623r1201600_ruleTOSS 5 must be a vendor-supported release.
SV-282624r1200852_ruleTOSS 5 vendor packaged system security patches and updates must be installed and up to date.
SV-282625r1200855_ruleThe graphical display manager must not be the default target on TOSS 5 unless approved.
SV-282626r1200858_ruleTOSS 5 must enable the hardware random number generator entropy gatherer service.
SV-282627r1200861_ruleTOSS 5 must disable the ability of systemd to spawn an interactive boot process.
SV-282628r1200864_ruleThe TOSS 5 /boot/grub2/grub.cfg file must be group owned by root.
SV-282629r1200867_ruleThe TOSS 5 /boot/grub2/grub.cfg file must be owned by root.
SV-282630r1200870_ruleTOSS 5 must prevent loading a new kernel for later execution.
SV-282631r1200873_ruleTOSS 5 must disable core dump backtraces.
SV-282632r1200876_ruleTOSS 5 must disable storing core dumps.
SV-282633r1200879_ruleTOSS 5 must disable acquiring, saving, and processing core dumps.
SV-282634r1200882_ruleTOSS 5 must not have the sendmail package installed.
SV-282635r1201602_ruleTOSS 5 must not have the quagga package installed.
SV-282636r1201310_ruleTOSS 5 must have the gnutls-utils package installed.
SV-282637r1200891_ruleTOSS 5 must have the nss-tools package installed.
SV-282638r1200894_ruleTOSS 5 must have the rng-tools package installed.
SV-282639r1200897_ruleTOSS 5 must be configured so that the Network File System (NFS) is configured to use RPCSEC_GSS.
SV-282640r1200900_ruleTOSS 5 must prevent special devices on file systems that are imported via Network File System (NFS).
SV-282641r1200903_ruleTOSS 5 cron configuration directories must have a mode of 0700 or less permissive.
SV-282642r1200906_ruleAll TOSS 5 local initialization files must have mode 0740 or less permissive.
SV-282643r1200909_ruleAll TOSS 5 local interactive user home directories must have mode 0770 or less permissive.
SV-282644r1200912_ruleThe TOSS 5 /etc/group file must have mode 0644 or less permissive to prevent unauthorized access.
SV-282645r1200915_ruleThe TOSS 5 /etc/group- file must have mode 0644 or less permissive to prevent unauthorized access.
SV-282646r1200918_ruleThe TOSS 5 /etc/gshadow file must have mode 0000 or less permissive to prevent unauthorized access.
SV-282647r1200921_ruleThe TOSS 5 /etc/gshadow- file must have mode 0000 or less permissive to prevent unauthorized access.
SV-282648r1201583_ruleThe TOSS 5 /etc/passwd file must have mode 0644 or less permissive to prevent unauthorized access.
SV-282649r1200927_ruleThe TOSS 5 /etc/passwd- file must have mode 0644 or less permissive to prevent unauthorized access.
SV-282650r1200930_ruleThe TOSS 5 /etc/shadow- file must have mode 0000 or less permissive to prevent unauthorized access.
SV-282651r1200933_ruleThe TOSS 5 /etc/group file must be owned by root.
SV-282652r1200936_ruleThe TOSS 5 /etc/group file must be group-owned by root.
SV-282653r1200939_ruleThe TOSS 5 /etc/group- file must be owned by root.
SV-282654r1200942_ruleThe TOSS 5 /etc/group- file must be group-owned by root.
SV-282655r1200945_ruleThe TOSS 5 /etc/gshadow file must be owned by root.
SV-282656r1200948_ruleThe TOSS 5 /etc/gshadow file must be group-owned by root.
SV-282657r1200951_ruleThe TOSS 5 /etc/gshadow- file must be owned by root.
SV-282658r1200954_ruleThe TOSS 5 /etc/gshadow- file must be group-owned by root.
SV-282659r1200957_ruleThe TOSS 5 /etc/passwd file must be owned by root.
SV-282660r1200960_ruleThe TOSS 5 /etc/passwd file must be group-owned by root.
SV-282661r1200963_ruleThe TOSS 5 /etc/passwd- file must be owned by root.
SV-282662r1200966_ruleThe TOSS 5 /etc/passwd- file must be group-owned by root.
SV-282663r1200969_ruleThe TOSS 5 /etc/shadow file must be owned by root.
SV-282664r1200972_ruleThe TOSS 5 /etc/shadow file must be group-owned by root.
SV-282665r1200975_ruleThe TOSS 5 /etc/shadow- file must be owned by root.
SV-282666r1200978_ruleThe TOSS 5 /etc/shadow- file must be group-owned by root.
SV-282667r1200981_ruleThe TOSS 5 cron configuration files directory must be owned by root.
SV-282668r1200984_ruleThe TOSS 5 cron configuration files directory must be group-owned by root.
SV-282669r1200987_ruleAll TOSS 5 world-writable directories must be owned by root, sys, bin, or an application user.
SV-282670r1200990_ruleAll TOSS 5 local files and directories must have a valid group owner.
SV-282671r1200993_ruleAll TOSS 5 local files and directories must have a valid owner.
SV-282672r1200996_ruleTOSS 5 must be configured so that all system device files are correctly labeled to prevent unauthorized modification.
SV-282673r1201585_ruleTOSS 5 /etc/crontab file must have mode 0600.
SV-282674r1201002_ruleThe TOSS 5 /etc/shadow file must have mode 0000 to prevent unauthorized access.
SV-282675r1201005_ruleA TOSS 5 firewall must employ a deny-all, allow-by-exception policy for allowing connections to other systems.
SV-282676r1201008_ruleTOSS 5 network interfaces must not be in promiscuous mode.
SV-282677r1201330_ruleTOSS 5 must enable hardening for the Berkeley Packet Filter (BPF) just-in-time (JIT) compiler.
SV-282678r1201587_ruleTOSS 5 systems using DNS resolution must have at least two name servers configured.
SV-282679r1201334_ruleTOSS 5 must configure a DNS processing mode set in Network Manager.
SV-282680r1201020_ruleTOSS 5 must not have unauthorized IP tunnels configured.
SV-282681r1201023_ruleTOSS 5 must be configured to prevent unrestricted mail relaying.
SV-282682r1201337_ruleIf the Trivial File Transfer Protocol (TFTP) server is required, TOSS 5 TFTP daemon must be configured to operate in secure mode.
SV-282683r1201340_ruleThe TOSS 5 libreswan package must be installed.
SV-282684r1201032_ruleThere must be no .shosts files on TOSS 5.
SV-282685r1201035_ruleTOSS 5 must ignore Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages.
SV-282686r1201038_ruleTOSS 5 must not forward Internet Protocol version 4 (IPv4) source-routed packets.
SV-282687r1201041_ruleTOSS 5 must log IPv4 packets with impossible addresses.
SV-282688r1201044_ruleTOSS 5 must log IPv4 packets with impossible addresses by default.
SV-282689r1201344_ruleTOSS 5 must use reverse path filtering on all IPv4 interfaces.
SV-282690r1201050_ruleTOSS 5 must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted.
SV-282691r1201053_ruleTOSS 5 must not forward IPv4 source-routed packets by default.
SV-282692r1201056_ruleTOSS 5 must use a reverse-path filter for IPv4 network traffic when possible by default.
SV-282693r1201059_ruleTOSS 5 must not respond to Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.
SV-282694r1201062_ruleTOSS 5 must limit the number of bogus Internet Control Message Protocol (ICMP) response errors logs.
SV-282695r1201065_ruleTOSS 5 must not send Internet Control Message Protocol (ICMP) redirects.
SV-282696r1201346_ruleTOSS 5 must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default.
SV-282697r1201349_ruleTOSS 5 must not enable Internet Protocol version 4 (IPv4) packet forwarding unless the system is a router.
SV-282698r1201350_ruleTOSS 5 must not accept router advertisements on all Internet Protocol version 6 (IPv6) interfaces.
SV-282699r1201351_ruleTOSS 5 must ignore Internet Protocol version 6 (IPv6) Internet Control Message Protocol (ICMP) redirect messages.
SV-282700r1201352_ruleTOSS 5 must not forward Internet Protocol version 6 (IPv6) source-routed packets.
SV-282701r1201355_ruleTOSS 5 must not enable Internet Protocol version 6 (IPv6) packet forwarding unless the system is a router.
SV-282702r1201356_ruleTOSS 5 must not accept router advertisements on all Internet Protocol version 6 (IPv6) interfaces by default.
SV-282703r1201358_ruleTOSS 5 must prevent Internet Protocol version 6 (IPv6) Internet Control Message Protocol (ICMP) redirect messages from being accepted.
SV-282704r1201359_ruleTOSS 5 must not forward Internet Protocol version 6 (IPv6) source-routed packets by default.
SV-282705r1201362_ruleTOSS 5 must have the openssh-clients package installed.
SV-282706r1201098_ruleThe TOSS 5 SSH server configuration file must be group-owned by root.
SV-282707r1201101_ruleThe TOSS 5 SSH server configuration file must be owned by root.
SV-282708r1201104_ruleThe TOSS 5 SSH server configuration file must have mode 0600 or less permissive.
SV-282709r1201369_ruleTOSS 5 SSH private host key files must have mode 0640 or less permissive.
SV-282710r1201371_ruleTOSS 5 SSH public host key files must have mode 0644 or less permissive.
SV-282711r1201373_ruleThe TOSS 5 SSH daemon must not allow rhosts authentication.
SV-282712r1201589_ruleThe TOSS 5 SSH daemon must not allow known hosts authentication.
SV-282713r1201377_ruleThe TOSS 5 SSH daemon must perform strict mode checking of home directory configuration files.
SV-282714r1201379_ruleThe TOSS 5 SSH daemon must display the date and time of the last successful account logon upon an SSH logon.
SV-282715r1201125_ruleThe TOSS 5 effective dconf policy must match the policy keyfiles.
SV-282716r1201128_ruleTOSS 5 must disable the ability of a user to restart the system from the login screen.
SV-282717r1201644_ruleTOSS 5 must prevent a user from overriding the disable-restart-buttons setting for the graphical user interface.
SV-282718r1201134_ruleTOSS 5 must disable the ability of a user to accidentally press Ctrl-Alt-Del and cause a system to shut down or reboot.
SV-282719r1201137_ruleTOSS 5 must prevent a user from overriding the Ctrl-Alt-Del sequence settings for the graphical user interface.
SV-282720r1201591_ruleTOSS 5 must disable the user list at logon for graphical user interfaces.
SV-282721r1201143_ruleAll TOSS 5 local interactive user accounts must be assigned a home directory upon creation.
SV-282722r1201146_ruleTOSS 5 must set the umask value to 077 for all local interactive user accounts.
SV-282723r1201149_ruleTOSS 5 system accounts must not have an interactive login shell.
SV-282724r1201152_ruleExecutable search paths within the initialization files of all local interactive TOSS 5 users must only contain paths that resolve to the system default or the users home directory.
SV-282725r1201593_ruleAll TOSS 5 local interactive users must have a home directory assigned in the /etc/passwd file.
SV-282726r1201158_ruleAll TOSS 5 local interactive user home directories defined in the /etc/passwd file must exist.
SV-282727r1201161_ruleAll TOSS 5 local interactive user home directories must be group-owned by the home directory owner's primary group.
SV-282728r1201164_ruleTOSS 5 must not have unauthorized accounts.
SV-282729r1201167_ruleThe root account must be the only account with unrestricted access to TOSS 5 system.
SV-282730r1201170_ruleLocal TOSS 5 initialization files must not execute world-writable programs.
SV-282731r1201173_ruleTOSS 5 must display the date and time of the last successful account logon upon user logon.
SV-282732r1201176_ruleTOSS 5 must have policycoreutils package installed.
SV-282733r1201179_ruleTOSS 5 policycoreutils-python-utils package must be installed.
SV-282734r1201182_ruleTOSS 5 must require reauthentication when using the sudo command.
SV-282735r1201185_ruleTOSS 5 must require users to reauthenticate for privilege escalation.
SV-282736r1201188_ruleTOSS 5 must restrict privilege elevation to authorized personnel.
SV-282737r1201191_ruleTOSS 5 must not allow blank or null passwords.
SV-282738r1201194_ruleTOSS 5 must ensure the password complexity module is enabled in the system-auth file.
SV-282739r1201595_ruleTOSS 5 must require users to provide a password for privilege escalation.
SV-282740r1201200_ruleTOSS 5 must not be configured to bypass password requirements for privilege escalation.
SV-282741r1201203_ruleTOSS 5 must not have accounts configured with blank or null passwords.
SV-282742r1201206_ruleTOSS 5 must use a file integrity tool that is configured to use FIPS 140-3-approved cryptographic hashes for validating file contents and directories.
SV-282743r1201209_ruleTOSS 5 must be configured so that the file integrity tool verifies Access Control Lists (ACLs).
SV-282744r1201212_ruleTOSS 5 must be configured so the file integrity tool verifies extended attributes.
SV-282745r1201645_ruleTOSS 5 must have the packages required for encrypting off-loaded audit logs installed.
SV-282746r1201218_ruleThe rsyslog service on TOSS 5 must be active.
SV-282747r1201386_ruleTOSS 5 must be configured so the rsyslog daemon does not accept log messages from other servers unless the server is being used for log aggregation.
SV-282748r1201388_ruleTOSS 5 must use cron logging.
SV-282749r1201227_ruleThe TOSS 5 audit system must take appropriate action when an error writing to the audit storage volume occurs.
SV-282750r1201230_ruleThe TOSS 5 audit system must take appropriate action when the audit storage volume is full.
SV-282751r1201233_ruleThe TOSS 5 audit system must take appropriate action when the audit files have reached maximum size.
SV-282752r1201236_ruleTOSS 5 must write audit records to disk.
SV-282753r1201612_ruleTOSS 5 must define default permissions for the bash shell.
SV-282754r1201614_ruleTOSS 5 must define default permissions for the c shell.
SV-282755r1201616_ruleTOSS 5 must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.
SV-282756r1201618_ruleTOSS 5 must define default permissions for the system default profile.
SV-282757r1201251_ruleTOSS 5 must not allow an unattended or automatic logon to the system.
SV-282758r1201254_ruleTOSS 5 must not allow users to override SSH environment variables.
SV-282759r1201257_ruleTOSS 5 must not allow unattended or automatic logon via the graphical user interface.
SV-282760r1201260_ruleAll TOSS local interactive user home directories must have mode 0770 or less permissive.
SV-282764r1201597_ruleTOSS 5 must, for password-based authentication, verify when users create or update passwords the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a).
SV-282768r1201307_ruleTOSS 5 must accept only external credentials that are NIST compliant.
SV-282770r1201607_ruleTOSS 5 must include only approved trust anchors in trust stores or certificate stores managed by the organization.
SV-282771r1201293_ruleTOSS 5 must provide protected storage for cryptographic keys with organization-defined safeguards and/or hardware protected key store.
SV-282772r1201296_ruleTOSS 5 must securely compare internal information system clocks at least every 24 hours.