STIGQter STIGQter: STIG Summary: Nutanix Acropolis GPOS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Jan 2026:

Nutanix OS must isolate security functions from nonsecurity functions.

DISA Rule

SV-279623r1192507_rule

Vulnerability Number

V-279623

Group Title

SRG-OS-000134-GPOS-00068

Rule Version

NXAC-OS-000192

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. For AOS, Prism Central, and Files, note that the Nutanix OS is designed and engineered to have SELinux preinstalled and set as active. If the package is missing or not active and running, then some corruption has occurred and the OS must be rebuilt.

2. For AHV, verify correct operation of all security functions by setting the "SELinux" status and the "Enforcing" mode by modifying the "/etc/selinux/config" file to have the following line. A reboot is required for the changes to take effect.

SELINUX=enforcing

Check Contents

Nutanix OS is configured by default to run SELinux Policies. Verify Nutanix OS SELinux is set to Enforcing Mode using the following command.

$ sudo getenforce
Enforcing

If "SELinux" is not active and not in "Enforcing" mode, this is a finding.

Vulnerability Number

V-279623

Documentable

False

Rule Version

NXAC-OS-000192

Severity Override Guidance

Nutanix OS is configured by default to run SELinux Policies. Verify Nutanix OS SELinux is set to Enforcing Mode using the following command.

$ sudo getenforce
Enforcing

If "SELinux" is not active and not in "Enforcing" mode, this is a finding.

Check Content Reference

M

Target Key

5730