Skip to content

GPOS SRG: General Purpose Operating System Security Requirements Guide

This General Purpose Operating System (GPOS) Security Requirements Guide (SRG) provides the technical security policies and requirements for applying security concepts to systems. This SRG specifies security requirements for commercial-off-the-shelf (COTS) or government- off-the-shelf (GOTS) general purpose operating systems (GPOSs) in networked environments. An operating system conformant to this SRG may be operated as a server system within a data center or a client system used directly by one or more human users. This guide assumes operation within a single security domain. Cross-domain solution (CDS) and Multi-Level Security (MLS) requirements are beyond the scope of this guide.

Scheme
public.cyber.mil /stigs/downloads/
Published by
DoD Cyber Exchange (sponsored by DISA: Defense Information Systems Agency)
  • SRG-OS-000392-GPOS-00172

    The operating system must audit all activities performed during nonlocal maintenance and diagnostic sessions.
  • SRG-OS-000393-GPOS-00173

    The operating system must implement cryptographic mechanisms to protect the integrity of nonlocal maintenance and diagnostic communications, when u...
  • SRG-OS-000394-GPOS-00174

    The operating system must implement cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications, ...
  • SRG-OS-000395-GPOS-00175

    The operating system must verify remote disconnection at the termination of nonlocal maintenance and diagnostic sessions, when used for nonlocal ma...
  • SRG-OS-000396-GPOS-00176

    The operating system must implement NSA-approved cryptography to protect classified information in accordance with applicable federal laws, Executi...
  • SRG-OS-000403-GPOS-00182

    The operating system must only allow the use of DoD PKI-established certificate authorities for authentication in the establishment of protected se...
  • SRG-OS-000404-GPOS-00183

    The operating system must implement cryptographic mechanisms to prevent unauthorized modification of all information at rest on all operating syste...
  • SRG-OS-000405-GPOS-00184

    The operating system must implement cryptographic mechanisms to prevent unauthorized disclosure of all information at rest on all operating system ...
  • SRG-OS-000420-GPOS-00186

    The operating system must protect against or limit the effects of Denial of Service (DoS) attacks by ensuring the operating system is implementing ...
  • SRG-OS-000423-GPOS-00187

    The operating system must protect the confidentiality and integrity of transmitted information.

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules