STIGQter STIGQter: STIG Summary: Nutanix Acropolis GPOS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Jan 2026:

Nutanix OS must provide protected storage for cryptographic keys with organization-defined safeguards and/or hardware protected key store.

DISA Rule

SV-279622r1192573_rule

Vulnerability Number

V-279622

Group Title

SRG-OS-000780-GPOS-00240

Rule Version

NXAC-OS-000191

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Hardware TPM modules consist of a hardware chip that is built into the motherboard of the physical server. If no TPM module exists, then a new physical server is required.

For AHV, if the TPM module exists but is not "trusted' then something has been modified within AHV and the system must be rebuilt from source to correct this issue.

Check Contents

Verify that the Nutanix OS hardware consists of a hardware TPM module installed and loaded using the following command.

$ sudo lsmod | grep -i tpm
tpm 77824 1 trusted
rng_core 16384 1 tpm

If no lines are returned or if the TPM does not indicate "trusted", this is a finding.

Vulnerability Number

V-279622

Documentable

False

Rule Version

NXAC-OS-000191

Severity Override Guidance

Verify that the Nutanix OS hardware consists of a hardware TPM module installed and loaded using the following command.

$ sudo lsmod | grep -i tpm
tpm 77824 1 trusted
rng_core 16384 1 tpm

If no lines are returned or if the TPM does not indicate "trusted", this is a finding.

Check Content Reference

M

Target Key

5730