Skip to content

GPOS SRG: General Purpose Operating System Security Requirements Guide

This General Purpose Operating System (GPOS) Security Requirements Guide (SRG) provides the technical security policies and requirements for applying security concepts to systems. This SRG specifies security requirements for commercial-off-the-shelf (COTS) or government- off-the-shelf (GOTS) general purpose operating systems (GPOSs) in networked environments. An operating system conformant to this SRG may be operated as a server system within a data center or a client system used directly by one or more human users. This guide assumes operation within a single security domain. Cross-domain solution (CDS) and Multi-Level Security (MLS) requirements are beyond the scope of this guide.

Scheme
public.cyber.mil /stigs/downloads/
Published by
DoD Cyber Exchange (sponsored by DISA: Defense Information Systems Agency)
  • SRG-OS-000358-GPOS-00145

    The operating system must record time stamps for audit records that meet a minimum granularity of one second for a minimum degree of precision.
  • SRG-OS-000359-GPOS-00146

    The operating system must record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).
  • SRG-OS-000363-GPOS-00150

    The operating system must notify designated personnel if baseline configurations are changed in an unauthorized manner.
  • SRG-OS-000364-GPOS-00151

    The operating system must enforce access restrictions.
  • SRG-OS-000365-GPOS-00152

    The operating system must audit the enforcement actions used to restrict access associated with changes to the system.
  • SRG-OS-000366-GPOS-00153

    The operating system must prevent the installation of patches, service packs, device drivers, or operating system components without verification t...
  • SRG-OS-000368-GPOS-00154

    The operating system must prevent program execution in accordance with local policies regarding software program usage and restrictions and/or rule...
  • SRG-OS-000370-GPOS-00155

    The operating system must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
  • SRG-OS-000373-GPOS-00156

    The operating system must require users to reauthenticate for privilege escalation.
  • SRG-OS-000373-GPOS-00157

    The operating system must require users to reauthenticate when changing roles.

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules