SRG-OS-000096-GPOS-00050 Controls

STIG IDVersionTitleProduct
ALMA-09-031700V1R2AlmaLinux OS 9 must have the firewalld package installed.
OL07-00-040100V3R2The Oracle Linux operating system must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management Component Local Service Assessment (PPSM CLSA) and vulnerability assessments.
OL08-00-040030V2R4OL 8 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.
OL09-00-000220V1R1OL 9 must have the firewalld package installed.
OL09-00-000221V1R1OL 9 must be configured so that the firewalld service is active.
OL09-00-000222V1R1OL 9 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.
OL09-00-000223V1R1OL 9 must control remote access methods.
OL09-00-002320V1R1OL 9 must disable the chrony daemon from acting as a server.
OL09-00-002321V1R1OL 9 must disable network management of the chrony daemon.
RHEL-07-040100V3R9The Red Hat Enterprise Linux operating system must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management Component Local Service Assessment (PPSM CLSA) and vulnerability assessments.
RHEL-08-040030V2R3RHEL 8 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.
RHEL-09-251010V2R4RHEL 9 must have the firewalld package installed.
RHEL-09-251015V2R4The firewalld service on RHEL 9 must be active.
RHEL-09-251035V2R4RHEL 9 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.
RHEL-09-252025V2R4RHEL 9 must disable the chrony daemon from acting as a server.
RHEL-09-252030V2R4RHEL 9 must disable network management of the chrony daemon.
SLES-12-030030V3R2The SUSE operating system must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.
SLES-15-010220V2R4The SUSE operating system must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.
UBTU-18-010504V2R15The Ubuntu operating system must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.
UBTU-20-010407V2R1The Ubuntu operating system must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.
UBTU-22-251030V2R4Ubuntu 22.04 LTS must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.
UBTU-24-300041V1R1Ubuntu 24.04 LTS must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL) and vulnerability assessments.
WN10-00-000105V3R4Simple Network Management Protocol (SNMP) must not be installed on the system.
WN10-00-000115V3R4The Telnet Client must not be installed on the system.
WN10-00-000120V3R4The TFTP Client must not be installed on the system.
WN10-00-000107V3R4Copilot in Windows must be disabled for Windows 10.
WN11-00-000105V2R3Simple Network Management Protocol (SNMP) must not be installed on the system.
WN11-00-000115V2R3The Telnet Client must not be installed on the system.
WN11-00-000120V2R3The TFTP Client must not be installed on the system.
WN11-00-000125V2R3Copilot in Windows must be disabled for Windows 11
WN16-00-000360V2R9The Microsoft FTP service must not be installed unless required.
WN16-00-000390V2R9The Telnet Client must not be installed.
WN19-00-000330V3R4Windows Server 2019 must not have the Microsoft FTP service installed unless required by the organization.
WN19-00-000360V3R4Windows Server 2019 must not have the Telnet Client installed.
WN22-00-000330V2R4Windows Server 2022 must not have the Microsoft FTP service installed unless required by the organization.
WN22-00-000360V2R4Windows Server 2022 must not have the Telnet Client installed.