STIGQter STIGQter: STIG Summary: Virtual Machine Manager Security Requirements Guide Version: 2 Release: 4 Benchmark Date: 01 Jul 2026:

The VMM must install security-relevant software updates within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, STIGs).

DISA Rule

SV-279016r1138019_rule

Vulnerability Number

V-279016

Group Title

SRG-OS-000439

Rule Version

SRG-OS-000439-VMM-001765

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Install security-relevant software updates on the VMM within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, STIGs).

Check Contents

Verify security-relevant software updates are installed on the VMM within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, STIGs).

If security-relevant software updates are not installed on the VMM within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, STIGs), this is a finding.

Vulnerability Number

V-279016

Documentable

False

Rule Version

SRG-OS-000439-VMM-001765

Severity Override Guidance

Verify security-relevant software updates are installed on the VMM within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, STIGs).

If security-relevant software updates are not installed on the VMM within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, STIGs), this is a finding.

Check Content Reference

M

Target Key

2924