STIGQter STIGQter: STIG Summary: Virtual Machine Manager Security Requirements Guide Version: 2 Release: 4 Benchmark Date: 01 Jul 2026:

The VMM must enforce attribute-based access control policy over defined subjects and objects based upon organization-defined attributes to assume access permissions.

DISA Rule

SV-279015r1227262_rule

Vulnerability Number

V-279015

Group Title

SRG-OS-000835

Rule Version

SRG-OS-000835-VMM-000280

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the VMM to enforce attribute-based access control policy over defined subjects and objects based upon organization-defined attributes to assume access permissions.

Check Contents

Verify the VMM is configured to enforce attribute-based access control policy over defined subjects and objects based upon organization-defined attributes to assume access permissions.

If the VMM does not enforce attribute-based access control policy over defined subjects and objects based upon organization-defined attributes to assume access permissions, this is a finding.

Vulnerability Number

V-279015

Documentable

False

Rule Version

SRG-OS-000835-VMM-000280

Severity Override Guidance

Verify the VMM is configured to enforce attribute-based access control policy over defined subjects and objects based upon organization-defined attributes to assume access permissions.

If the VMM does not enforce attribute-based access control policy over defined subjects and objects based upon organization-defined attributes to assume access permissions, this is a finding.

Check Content Reference

M

Target Key

2924