U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Tri-Lab Operating System Stack (TOSS) 4 STIG Benchmark Ver 2, Rel 2 Checklist Details (Checklist Revisions)

Checklist Highlights

Checklist Name:
Tri-Lab Operating System Stack (TOSS) 4 STIG Benchmark
Checklist ID:
1064
Version:
Ver 2, Rel 2
Type:
Compliance
Review Status:
Final
Authority:
Governmental Authority: Defense Information Systems Agency
Original Publication Date:
07/25/2023

Checklist Summary:

The Tri-Lab Operating System Stack (TOSS) 4 Security Technical Implementation Guide (STIG) is published as a tool to improve the security of Department of Defense (DOD) information systems. The requirements were developed from the General Purpose Operating System Security Requirements Guide (GPOS SRG). The vulnerabilities discussed in this document are applicable to TOSS 4 Server installations. This document is meant for use in conjunction with the Enclave, Network Infrastructure, Secure Remote Computing, and appropriate application STIGs.

Checklist Role:

  • Operating System

Known Issues:

Not provided.

Target Audience:

Parties within the DOD and federal government’s computing environments can obtain the applicable STIG from the DOD Cyber Exchange website at https://cyber.mil/. This site contains the latest copies of STIGs, SRGs, and other related security information.

Target Operational Environment:

  • Managed
  • Specialized Security-Limited Functionality (SSLF)

Testing Information:

Not provided.

Regulatory Compliance:

All technical NIST SP 800-53 requirements were considered while developing this STIG. Requirements that are applicable and configurable will be included in the final STIG. A report marked Controlled Unclassified Information (CUI) will be available for items that did not meet requirements. This report will be available to component authorizing official (AO) personnel for risk assessment purposes by request via email to: [email protected].

Comments/Warnings/Miscellaneous:

Comments or proposed revisions to this document should be sent via email to the following address: [email protected]. DISA will coordinate all change requests with the relevant DOD organizations before inclusion in this document. Approved changes will be made in accordance with the DISA maintenance release schedule.

Disclaimer:

Not provided.

Product Support:

Not provided.

Point of Contact:

[email protected]

Sponsor:

Not provided.

Licensing:

Not provided.

Change History:

new checklist - 7/25/23
Change to NEW - 8/28/23
Updated resource per DISA - 10/26/23
updated URLs - 1/26/24
Updated Version, Resources and SHA - 08/08/2024
Resource Title Updated, Resource Sunset - 08/21/2024
Updated Checklist Version and Resources - 12/09/24
Updated Checklist Title and SCAP 1.3 Resource - 12/12/2024 
Updated General Summary - 08/20/2025

Dependency/Requirements:

URL Description

References:

Reference URL Description

NIST checklist record last modified on 08/20/2025