STIGQter STIGQter: STIG Summary: Virtual Machine Manager Security Requirements Guide Version: 2 Release: 4 Benchmark Date: 01 Jul 2026:

The VMM must prevent the installation of guest VMs, patches, service packs, device drivers, or VMM components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.

DISA Rule

SV-207472r984242_rule

Vulnerability Number

V-207472

Group Title

SRG-OS-000366

Rule Version

SRG-OS-000366-VMM-001430

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the VMM to prevent the installation of guest VMs, patches, service packs, device drivers, or VMM components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.

Check Contents

Verify the VMM prevents the installation of guest VMs, patches, service packs, device drivers, or VMM components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.

If it does not, this is a finding.

Vulnerability Number

V-207472

Documentable

False

Rule Version

SRG-OS-000366-VMM-001430

Severity Override Guidance

Verify the VMM prevents the installation of guest VMs, patches, service packs, device drivers, or VMM components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.

If it does not, this is a finding.

Check Content Reference

M

Target Key

2924