STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 5 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to STIGs

Rancher Government Solutions (RGS) Harvester Government GPOS Security Technical Implementation Guide

Version

V1R1

Release Date

Sep 9, 2026

SCAP Benchmark ID

RGS_Harvester_Government_GPOS_STIG

Total Checks

23

Tags

other
CAT I: 4CAT II: 18CAT III: 1

This Security Technical Implementation Guide is published as a tool to improve the security of Department of War (DoW) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.

Export CKLExport CSVExport JSONDownload STIG ZIP

Checks (23)

V-285660MEDIUMHarvester Government must generate audit records for organization-defined auditable events affecting operating system components and security-relevant activities.V-285661MEDIUMHarvester Government must enforce account lockout after a defined number of consecutive unsuccessful authentication attempts.V-285662LOWHarvester Government must enforce security limits for concurrent sessions and core dump generation.V-285663MEDIUMHarvester Government must automatically terminate inactive shell sessions after 15 minutes of inactivity.V-285664MEDIUMHarvester Government must configure the audit subsystem to support audit processing and audit failure handling requirements.V-285665MEDIUMHarvester Government must protect audit information from unauthorized read access.V-285666MEDIUMHarvester Government must enforce password complexity, password lifetime, and authentication policy requirements to protect authenticators from compromise.V-285667MEDIUMHarvester Government must prohibit password reuse for a defined number of generations.V-285668HIGHHarvester Government must enforce approved authorizations for logical access to information and system resources through restrictive default file and directory permissions.V-285669MEDIUMThe operating system must ensure system service accounts are configured as noninteractive accounts and assigned only to required service groups.V-285670MEDIUMThe operating system must restrict the use of system control mechanisms capable of interrupting or altering system operation.V-285671MEDIUMOperating systems must prevent unauthorized and unintended information transfer via shared system resources.V-285672MEDIUMHarvester Government must configure the SSH daemon to use approved cryptographic algorithms and automatically terminate inactive SSH sessions.V-285673MEDIUMAny publicly accessible connection to the operating system must display the Standard Mandatory DoW Notice and Consent Banner before granting access to the system.V-285674HIGHHarvester Government must implement cryptography to protect the integrity of remote access sessions.V-285675HIGHHarvester Government must remove nonsystem users.V-285676HIGHThe operating system must verify the integrity and authenticity of software packages using cryptographic mechanisms prior to installation or update.V-285677MEDIUMHarvester Government must require users to reauthenticate for privilege escalation.V-285678MEDIUMThe operating system must authenticate peripherals before establishing a connection.V-285679MEDIUMHarvester Government must implement nonexecutable data to protect its memory from unauthorized code execution.V-285680MEDIUMThe operating system must implement address space layout randomization to protect its memory from unauthorized code execution.V-285681MEDIUMThe operating system must protect security-relevant configuration files from unauthorized access and modification.V-285682MEDIUMHarvester Government must prohibit the use or connection of unauthorized hardware components.