Skip to content

GPOS SRG: General Purpose Operating System Security Requirements Guide

This General Purpose Operating System (GPOS) Security Requirements Guide (SRG) provides the technical security policies and requirements for applying security concepts to systems. This SRG specifies security requirements for commercial-off-the-shelf (COTS) or government- off-the-shelf (GOTS) general purpose operating systems (GPOSs) in networked environments. An operating system conformant to this SRG may be operated as a server system within a data center or a client system used directly by one or more human users. This guide assumes operation within a single security domain. Cross-domain solution (CDS) and Multi-Level Security (MLS) requirements are beyond the scope of this guide.

Scheme
public.cyber.mil /stigs/downloads/
Published by
DoD Cyber Exchange (sponsored by DISA: Defense Information Systems Agency)
  • SRG-OS-000461-GPOS-00205

    The operating system must generate audit records when successful/unsuccessful attempts to access categories of information (e.g., classification le...
  • SRG-OS-000462-GPOS-00206

    The operating system must generate audit records when successful/unsuccessful attempts to modify privileges occur.
  • SRG-OS-000463-GPOS-00207

    The operating system must generate audit records when successful/unsuccessful attempts to modify security objects occur.
  • SRG-OS-000465-GPOS-00209

    The operating system must generate audit records when successful/unsuccessful attempts to modify categories of information (e.g., classification le...
  • SRG-OS-000466-GPOS-00210

    The operating system must generate audit records when successful/unsuccessful attempts to delete privileges occur.
  • SRG-OS-000467-GPOS-00211

    The operating system must generate audit records when successful/unsuccessful attempts to delete security levels occur.
  • SRG-OS-000468-GPOS-00212

    The operating system must generate audit records when successful/unsuccessful attempts to delete security objects occur.
  • SRG-OS-000470-GPOS-00214

    The operating system must generate audit records when successful/unsuccessful logon attempts occur.
  • SRG-OS-000471-GPOS-00215

    The operating system must generate audit records for privileged activities or other system-level access.
  • SRG-OS-000471-GPOS-00216

    The audit system must be configured to audit the loading and unloading of dynamic kernel modules.

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules