STIGhub
STIGs
RMF Controls
Compare
← CM-7 (9) — Least Functionality
CCI-003959
Definition
Prohibit the use or connection of unauthorized hardware components.
Parent Control
CM-7 (9)
Least Functionality
Configuration Management
Linked STIG Checks (21)
V-268139
CAT II
NixOS must enable USBguard.
Anduril NixOS Security Technical Implementation Guide
V-268567
CAT II
The macOS system must authorize USB devices before allowing connection.
Apple macOS 15 (Sequoia) Security Technical Implementation Guide
V-277177
CAT II
The macOS system must authorize USB devices before allowing connection.
Apple macOS 26 (Tahoe) Security Technical Implementation Guide
V-260540
CAT II
Ubuntu 22.04 LTS must disable automatic mounting of Universal Serial Bus (USB) mass storage driver.
Canonical Ubuntu 22.04 LTS Security Technical Implementation Guide
V-270718
CAT II
Ubuntu 24.04 LTS must disable automatic mounting of Universal Serial Bus (USB) mass storage driver.
Canonical Ubuntu 24.04 LTS Security Technical Implementation Guide
V-269357
CAT II
AlmaLinux OS 9 must be configured to disable USB mass storage.
Cloud Linux AlmaLinux OS 9 Security Technical Implementation Guide
V-263651
CAT II
The operating system must prohibit the use or connection of unauthorized hardware components.
General Purpose Operating System Security Requirements Guide
V-277983
CAT II
Windows Server 2025 must prohibit the use or connection of unauthorized hardware components.
Microsoft Windows Server 2025 Security Technical Implementation Guide
V-248837
CAT II
OL 8 must be configured to disable the ability to use USB mass storage devices.
Oracle Linux 8 Security Technical Implementation Guide
V-248862
CAT II
OL 8 must have the USBGuard installed.
Oracle Linux 8 Security Technical Implementation Guide
V-248864
CAT II
OL 8 must enable the USBGuard.
Oracle Linux 8 Security Technical Implementation Guide
V-280963
CAT II
RHEL 10 must have the USBGuard package enabled.
Red Hat Enterprise Linux 10 Security Technical Implementation Guide
V-258034
CAT II
RHEL 9 must be configured to disable USB mass storage.
Red Hat Enterprise Linux 9 Security Technical Implementation Guide
V-258035
CAT II
RHEL 9 must have the USBGuard package installed.
Red Hat Enterprise Linux 9 Security Technical Implementation Guide
V-258036
CAT II
RHEL 9 must have the USBGuard package enabled.
Red Hat Enterprise Linux 9 Security Technical Implementation Guide
V-275631
CAT II
Ubuntu OS must disable automatic mounting of Universal Serial Bus (USB) mass storage driver.
Riverbed NetIM OS Security Technical Implementation Guide
V-253082
CAT II
TOSS must be configured to disable USB mass storage.
Tri-Lab Operating System Stack (TOSS) 4 Security Technical Implementation Guide
V-282501
CAT II
TOSS 5 must be configured to disable USB mass storage.
Tri-Lab Operating System Stack (TOSS) 5 Security Technical Implementation Guide
V-282593
CAT II
TOSS 5 must have the USBGuard package installed.
Tri-Lab Operating System Stack (TOSS) 5 Security Technical Implementation Guide
V-282594
CAT II
TOSS 5 must have the USBGuard package enabled.
Tri-Lab Operating System Stack (TOSS) 5 Security Technical Implementation Guide
V-264316
CAT II
The VMM must prohibit the use or connection of unauthorized hardware components.
Virtual Machine Manager Security Requirements Guide