Skip to content

GPOS SRG: General Purpose Operating System Security Requirements Guide

This General Purpose Operating System (GPOS) Security Requirements Guide (SRG) provides the technical security policies and requirements for applying security concepts to systems. This SRG specifies security requirements for commercial-off-the-shelf (COTS) or government- off-the-shelf (GOTS) general purpose operating systems (GPOSs) in networked environments. An operating system conformant to this SRG may be operated as a server system within a data center or a client system used directly by one or more human users. This guide assumes operation within a single security domain. Cross-domain solution (CDS) and Multi-Level Security (MLS) requirements are beyond the scope of this guide.

Scheme
public.cyber.mil /stigs/downloads/
Published by
DoD Cyber Exchange (sponsored by DISA: Defense Information Systems Agency)
  • SRG-OS-000107-GPOS-00054

    The operating system must use multifactor authentication for local access to privileged accounts.
  • SRG-OS-000108-GPOS-00055

    The operating system must use multifactor authentication for local access to nonprivileged accounts.
  • SRG-OS-000108-GPOS-00057

  • SRG-OS-000108-GPOS-00058

  • SRG-OS-000109-GPOS-00056

    The operating system must require individuals to be authenticated with an individual authenticator prior to using a group authenticator.
  • SRG-OS-000114-GPOS-00059

    The operating system must uniquely identify peripherals before establishing a connection.
  • SRG-OS-000118-GPOS-00060

    The operating system must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.
  • SRG-OS-000120-GPOS-00061

    The operating system must use mechanisms meeting the requirements of applicable federal laws, Executive orders, directives, policies, regulations, ...
  • SRG-OS-000121-GPOS-00062

    The operating system must uniquely identify and must authenticate non-organizational users (or processes acting on behalf of non-organizational use...
  • SRG-OS-000122-GPOS-00063

    The operating system must provide an audit reduction capability that supports on-demand reporting requirements.

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules