GPOS SRG: General Purpose Operating System Security Requirements Guide
This General Purpose Operating System (GPOS) Security Requirements Guide (SRG) provides the technical security policies and requirements for applying security concepts to systems. This SRG specifies security requirements for commercial-off-the-shelf (COTS) or government- off-the-shelf (GOTS) general purpose operating systems (GPOSs) in networked environments. An operating system conformant to this SRG may be operated as a server system within a data center or a client system used directly by one or more human users. This guide assumes operation within a single security domain. Cross-domain solution (CDS) and Multi-Level Security (MLS) requirements are beyond the scope of this guide.
-
SRG-OS-000358-GPOS-00145
The operating system must record time stamps for audit records that meet a minimum granularity of one second for a minimum degree of precision. -
SRG-OS-000359-GPOS-00146
The operating system must record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT). -
SRG-OS-000363-GPOS-00150
The operating system must notify designated personnel if baseline configurations are changed in an unauthorized manner. -
SRG-OS-000364-GPOS-00151
The operating system must enforce access restrictions. -
SRG-OS-000365-GPOS-00152
The operating system must audit the enforcement actions used to restrict access associated with changes to the system. -
SRG-OS-000366-GPOS-00153
The operating system must prevent the installation of patches, service packs, device drivers, or operating system components without verification t... -
SRG-OS-000368-GPOS-00154
The operating system must prevent program execution in accordance with local policies regarding software program usage and restrictions and/or rule... -
SRG-OS-000370-GPOS-00155
The operating system must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs. -
SRG-OS-000373-GPOS-00156
The operating system must require users to reauthenticate for privilege escalation. -
SRG-OS-000373-GPOS-00157
The operating system must require users to reauthenticate when changing roles.
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.