Skip to content

GPOS SRG: General Purpose Operating System Security Requirements Guide

This General Purpose Operating System (GPOS) Security Requirements Guide (SRG) provides the technical security policies and requirements for applying security concepts to systems. This SRG specifies security requirements for commercial-off-the-shelf (COTS) or government- off-the-shelf (GOTS) general purpose operating systems (GPOSs) in networked environments. An operating system conformant to this SRG may be operated as a server system within a data center or a client system used directly by one or more human users. This guide assumes operation within a single security domain. Cross-domain solution (CDS) and Multi-Level Security (MLS) requirements are beyond the scope of this guide.

Scheme
public.cyber.mil /stigs/downloads/
Published by
DoD Cyber Exchange (sponsored by DISA: Defense Information Systems Agency)
  • SRG-OS-000075-GPOS-00043

    Operating systems must enforce 24 hours/1 day as the minimum password lifetime.
  • SRG-OS-000076-GPOS-00044

    Operating systems must enforce a 60-day maximum password lifetime restriction.
  • SRG-OS-000077-GPOS-00045

  • SRG-OS-000078-GPOS-00046

    The operating system must enforce a minimum 15-character password length.
  • SRG-OS-000080-GPOS-00048

    The operating system must enforce approved authorizations for logical access to information and system resources in accordance with applicable acce...
  • SRG-OS-000095-GPOS-00049

    The operating system must be configured to disable non-essential capabilities.
  • SRG-OS-000096-GPOS-00050

    The operating system must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the PPSM CAL...
  • SRG-OS-000104-GPOS-00051

    The operating system must uniquely identify and must authenticate organizational users (or processes acting on behalf of organizational users).
  • SRG-OS-000105-GPOS-00052

    The operating system must use multifactor authentication for network access to privileged accounts.
  • SRG-OS-000106-GPOS-00053

    The operating system must use multifactor authentication for network access to non-privileged accounts.

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules