STIGQter STIGQter: STIG Summary: Virtual Machine Manager Security Requirements Guide Version: 2 Release: 4 Benchmark Date: 01 Jul 2026:

The VMM must automatically remove or disable emergency accounts after the crisis is resolved or 72 hours.

DISA Rule

SV-207398r958508_rule

Vulnerability Number

V-207398

Group Title

SRG-OS-000123

Rule Version

SRG-OS-000123-VMM-000620

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the VMM such that emergency administrator accounts are automatically removed or disabled after the crisis is resolved or 72 hours.

Check Contents

Verify the VMM is configured such that emergency administrator accounts are automatically removed or disabled after the crisis is resolved or 72 hours.

If it is not, this is a finding.

Vulnerability Number

V-207398

Documentable

False

Rule Version

SRG-OS-000123-VMM-000620

Severity Override Guidance

Verify the VMM is configured such that emergency administrator accounts are automatically removed or disabled after the crisis is resolved or 72 hours.

If it is not, this is a finding.

Check Content Reference

M

Target Key

2924