STIGUI
V-282487CAT II — Medium severitySV-282487r1200441_rule

TOSS 5 must control remote access methods.

Rule version TOSS-05-000195 · STIG v1 · 2026-08-20

Discussion

To prevent unauthorized device connection, unauthorized information transfer, or unauthorized tunneling (i.e., embedding of data types within data types), organizations must disable or restrict unused or unnecessary physical and logical ports/protocols on information systems.

Operating systems are capable of providing a wide variety of functions and services. Some of the functions and services provided by default may not be necessary to support essential organizational operations. Additionally, it is sometimes convenient to provide multiple services from a single component (e.g., VPN and IPS); however, doing so increases risk over limiting the services provided by one component.

To support the requirements and principles of least functionality, the operating system must support the organizational requirements, providing only essential capabilities and limiting the use of ports, protocols, and/or services to only those required, authorized, and approved to conduct official business.

Check

Inspect the list of enabled firewall ports and verify they are configured correctly using the following command:

$ sudo firewall-cmd --list-all 

Ask the system administrator for the site or program Ports, Protocols, and Services Management Component Local Service Assessment (PPSM CLSA). Verify the services allowed by the firewall match the PPSM CLSA, or other applicable documentation approved by the information system security officer (ISSO).

If there are additional ports, protocols, or services that are not in the PPSM CLSA, or there are ports, protocols, or services that are prohibited by the PPSM Category Assurance List (CAL), or there are no firewall rules configured, this is a finding.

Fix

Configure TOSS 5 to allow approved settings and/or running services to comply with the PPSM CLSA for the site or program and the PPSM CAL, or other applicable documentation approved by the ISSO.

To open a port for a service, configure "firewalld" using the following command:

$ sudo firewall-cmd --permanent --add-port=port_number/tcp or $ sudo firewall-cmd --permanent --add-service=service_name

Identifiers

Group ID
V-282487
Group title
SRG-OS-000096-GPOS-00050
Rule ID
SV-282487r1200441_rule
Check ID
C-87048r1200439_chk
Fix ID
F-86953r1200440_fix