Installation guide
Chapter 3. Requirements Protogate Freeway Requirements Specification (SRS)
Notes An operating system release is considered supported if the vendor continues to provide
security patches for the product. With an unsupported release, it will not be possible to
resolve security issues discovered in the system software.
3.8.2. GEN000120 - Supported Components
Summary Vendor-recommended software patches and updates, and system security patches and
updates, must be installed and up-to-date.
Notes Timely patching is critical for maintaining the operational availability, confidentiality, and
integrity of Information Technology (IT) systems. However, failure to keep operating system
and application software patched is a common mistake made by IT professionals. New
patches are released daily, and it is often difficult for even experienced system administrators
to keep abreast of all the new patches. When new weaknesses in an operating system exist,
patches are usually made available by the vendor to resolve the problems. If the most recent
recommended updates and security patches are not installed, unauthorized users may take
advantage of weaknesses present in the unpatched software. The lack of prompt attention to
patching could result in a system compromise.
3.8.3. GEN000240 - Network Time-Server
Summary The system clock must be synchronized to an authoritative DoD time source.
Notes To assure the accuracy of the system clock, it must be synchronized with an authoritative time
source within DoD. Many system functions, including time-based login and activity
restrictions, automated reports, system logs, and audit records depend on an accurate system
clock. If there is no confidence in the correctness of the system clock, time-based functions
may not operate as intended and records may be of diminished value. Authoritative time
sources include authorized time servers within the enclave that synchronize with upstream
authoritative sources. Specific requirements for the upstream synchronization of Network
Time Protocol (NTP) servers are covered in the Network Other Devices STIG. For systems
located on isolated or closed networks, it is not necessary to synchronize with a global
authoritative time source. If a global authoritative time source is not available to systems on
an isolated network, a local authoritative time source must be established on this network and
used by the systems connected to this network. This is necessary to provide the ability to
correlate events and allow for the correct operation of time-dependent protocols between
systems on the isolated network. If the system is completely isolated (no connections to
networks or other systems), time synchronization is not required as no correlation of events
between systems will be necessary. If the system is completely isolated, this requirement is
not applicable.
14 Protogate DC-900-2021A