SRG-OS-000423-GPOS-00187 Controls

STIG IDVersionTitleProduct
ALMA-09-042700V1R2All AlmaLinux OS 9 networked systems must have the OpenSSH client installed.
APPL-14-002062V2R3The macOS system must disable Bluetooth when no approved device is connected.
APPL-15-002062V1R3The macOS system must disable Bluetooth when no approved device is connected.
OL07-00-040300V3R2The Oracle Linux operating system must be configured so that all networked systems have SSH installed.
OL07-00-040310V3R2The Oracle Linux operating system must be configured so that all networked systems use SSH for confidentiality and integrity of transmitted and received information as well as information during preparation for transmission.
OL08-00-040159V2R4All OL 8 networked systems must have SSH installed.
OL08-00-040160V2R4All OL 8 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
OL09-00-000250V1R1OL 9 networked systems must have SSH installed.
OL09-00-000251V1R1OL 9 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
OL09-00-002342V1R1OL 9 must force a frequent session key renegotiation for SSH connections to the server.
OL09-00-002421V1R1OL 9 must implement DOD-approved encryption in the bind package.
RHEL-07-040300V3R9The Red Hat Enterprise Linux operating system must be configured so that all networked systems have SSH installed.
RHEL-07-040310V3R9The Red Hat Enterprise Linux operating system must be configured so that all networked systems use SSH for confidentiality and integrity of transmitted and received information as well as information during preparation for transmission.
RHEL-08-040160V2R3All RHEL 8 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
RHEL-08-040159V2R3All RHEL 8 networked systems must have SSH installed.
RHEL-09-255010V2R4All RHEL 9 networked systems must have SSH installed.
RHEL-09-255015V2R4All RHEL 9 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
RHEL-09-255090V2R4RHEL 9 must force a frequent session key renegotiation for SSH connections to the server.
RHEL-09-672050V2R4RHEL 9 must implement DOD-approved encryption in the bind package.
SLES-12-030100V3R2All networked SUSE operating systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
SLES-15-010530V2R4All networked SUSE operating systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
UBTU-18-010420V2R15The Ubuntu operating system must use SSH to protect the confidentiality and integrity of transmitted information unless otherwise protected by alternative physical safeguards, such as, at a minimum, a Protected Distribution System (PDS).
UBTU-20-010042V2R1The Ubuntu operating system must use SSH to protect the confidentiality and integrity of transmitted information.
UBTU-22-255010V2R4Ubuntu 22.04 LTS must have SSH installed.
UBTU-22-255015V2R4Ubuntu 22.04 LTS must use SSH to protect the confidentiality and integrity of transmitted information.
UBTU-24-100800V1R1Ubuntu 24.04 LTS must have SSH installed.
UBTU-24-100810V1R1Ubuntu 24.04 LTS must use SSH to protect the confidentiality and integrity of transmitted information.
WN10-SO-000035V3R4Outgoing secure channel traffic must be encrypted or signed.
WN10-SO-000040V3R4Outgoing secure channel traffic must be encrypted when possible.
WN10-SO-000045V3R4Outgoing secure channel traffic must be signed when possible.
WN10-SO-000060V3R4The system must be configured to require a strong session key.
WN10-SO-000100V3R4The Windows SMB client must be configured to always perform SMB packet signing.
WN10-SO-000120V3R4The Windows SMB server must be configured to always perform SMB packet signing.
WN11-SO-000035V2R3Outgoing secure channel traffic must be encrypted or signed.
WN11-SO-000040V2R3Outgoing secure channel traffic must be encrypted.
WN11-SO-000045V2R3Outgoing secure channel traffic must be signed.
WN11-SO-000060V2R3The system must be configured to require a strong session key.
WN11-SO-000100V2R3The Windows SMB client must be configured to always perform SMB packet signing.
WN11-SO-000120V2R3The Windows SMB server must be configured to always perform SMB packet signing.
WN16-DC-000320V2R9Domain controllers must require LDAP access signing.
WN16-SO-000080V2R9The setting Domain member: Digitally encrypt or sign secure channel data (always) must be configured to Enabled.
WN16-SO-000090V2R9The setting Domain member: Digitally encrypt secure channel data (when possible) must be configured to enabled.
WN16-SO-000100V2R9The setting Domain member: Digitally sign secure channel data (when possible) must be configured to Enabled.
WN16-SO-000130V2R9Windows Server 2016 must be configured to require a strong session key.
WN16-SO-000190V2R9The setting Microsoft network client: Digitally sign communications (always) must be configured to Enabled.
WN16-SO-000200V2R9The setting Microsoft network client: Digitally sign communications (if server agrees) must be configured to Enabled.
WN16-SO-000230V2R9The setting Microsoft network server: Digitally sign communications (always) must be configured to Enabled.
WN16-SO-000240V2R9The setting Microsoft network server: Digitally sign communications (if client agrees) must be configured to Enabled.
WN19-DC-000320V3R4Windows Server 2019 domain controllers must require LDAP access signing.
WN19-SO-000060V3R4Windows Server 2019 setting Domain member: Digitally encrypt or sign secure channel data (always) must be configured to Enabled.
WN19-SO-000070V3R4Windows Server 2019 setting Domain member: Digitally encrypt secure channel data (when possible) must be configured to enabled.
WN19-SO-000080V3R4Windows Server 2019 setting Domain member: Digitally sign secure channel data (when possible) must be configured to Enabled.
WN19-SO-000110V3R4Windows Server 2019 must be configured to require a strong session key.
WN19-SO-000160V3R4Windows Server 2019 setting Microsoft network client: Digitally sign communications (always) must be configured to Enabled.
WN19-SO-000170V3R4Windows Server 2019 setting Microsoft network client: Digitally sign communications (if server agrees) must be configured to Enabled.
WN19-SO-000190V3R4Windows Server 2019 setting Microsoft network server: Digitally sign communications (always) must be configured to Enabled.
WN19-SO-000200V3R4Windows Server 2019 setting Microsoft network server: Digitally sign communications (if client agrees) must be configured to Enabled.
WN22-DC-000320V2R4Windows Server 2022 domain controllers must require LDAP access signing.
WN22-SO-000060V2R4Windows Server 2022 setting Domain member: Digitally encrypt or sign secure channel data (always) must be configured to Enabled.
WN22-SO-000070V2R4Windows Server 2022 setting Domain member: Digitally encrypt secure channel data (when possible) must be configured to Enabled.
WN22-SO-000080V2R4Windows Server 2022 setting Domain member: Digitally sign secure channel data (when possible) must be configured to Enabled.
WN22-SO-000110V2R4Windows Server 2022 must be configured to require a strong session key.
WN22-SO-000160V2R4Windows Server 2022 setting Microsoft network client: Digitally sign communications (always) must be configured to Enabled.
WN22-SO-000170V2R4Windows Server 2022 setting Microsoft network client: Digitally sign communications (if server agrees) must be configured to Enabled.
WN22-SO-000190V2R4Windows Server 2022 setting Microsoft network server: Digitally sign communications (always) must be configured to Enabled.
WN22-SO-000200V2R4Windows Server 2022 setting Microsoft network server: Digitally sign communications (if client agrees) must be configured to Enabled.