STIGQter STIGQter: STIG Summary:

Anduril NixOS Security Technical Implementation Guide

Version: 1

Release: 2 Benchmark Date: 01 Oct 2025

CheckedNameTitle
☐SV-268078r1130947_ruleNixOS must enable the built-in firewall.
☐SV-268079r1130948_ruleNixOS emergency or temporary user accounts must be provisioned with an expiration time of 72 hours or less.
☐SV-268080r1130951_ruleNixOS must enable the audit daemon.
☐SV-268081r1130954_ruleNixOS must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.
☐SV-268082r1130957_ruleNixOS must be configured to display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a command line user logon.
☐SV-268083r1130960_ruleNixOS must be configured to display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via an SSH logon.
☐SV-268084r1130963_ruleNixOS must be configured to display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a graphical user logon.
☐SV-268085r1130966_ruleNixOS must be configured to limit the number of concurrent sessions to 10 for all accounts and/or account types.
☐SV-268086r1130969_ruleNixOS must initiate a session lock after a 10-minute period of inactivity for graphical user logon.
☐SV-268087r1130972_ruleNixOS must provide the capability for users to directly initiate a session lock for all connection types.
☐SV-268088r1130975_ruleNixOS must monitor remote access methods.
☐SV-268089r1130978_ruleNixOS must implement DOD-approved encryption to protect the confidentiality of remote access sessions.
☐SV-268090r1130981_ruleThe NixOS audit package must be installed.
☐SV-268091r1130983_ruleNixOS must generate audit records for all usage of privileged commands.
☐SV-268092r1130985_ruleNixOS must enable auditing of processes that start prior to the audit daemon.
☐SV-268093r1130988_ruleNixOS must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.
☐SV-268094r1130990_ruleSuccessful/unsuccessful uses of the mount syscall in NixOS must generate an audit record.
☐SV-268095r1130992_ruleSuccessful/unsuccessful uses of the rename, unlink, rmdir, renameat, and unlinkat system calls in NixOS must generate an audit record.
☐SV-268096r1130994_ruleSuccessful/unsuccessful uses of the init_module, finit_module, and delete_module system calls in NixOS must generate an audit record.
☐SV-268097r1130996_ruleNixOS must generate an audit record for successful/unsuccessful modifications to the cron configuration.
☐SV-268098r1130998_ruleNixOS must generate an audit record for successful/unsuccessful uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls.
☐SV-268099r1131000_ruleSuccessful/unsuccessful uses of the chown, fchown, fchownat, and lchown system calls in NixOS must generate an audit record.
☐SV-268100r1131002_ruleSuccessful/unsuccessful uses of the chmod, fchmod, and fchmodat system calls in NixOS must generate an audit record.
☐SV-268101r1131004_ruleNixOS must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume reaches 75 percent utilization.
☐SV-268102r1131006_ruleNixOS must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume reaches 90 percent utilization.
☐SV-268103r1131008_ruleNixOS must take action when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity.
☐SV-268104r1131010_ruleNixOS must take action when allocated audit record storage volume reaches 90 percent of the repository maximum audit record storage capacity.
☐SV-268105r1131012_ruleThe NixOS audit system must take appropriate action when the audit storage volume is full.
☐SV-268106r1131014_ruleThe NixOS audit system must take appropriate action when an audit processing failure occurs.
☐SV-268107r1131017_ruleNixOS must have the packages required for offloading audit logs installed and running.
☐SV-268108r1131020_ruleThe NixOS audit records must be off-loaded onto a different system or storage media from the system being audited.
☐SV-268109r1131023_ruleNixOS must authenticate the remote logging server for off-loading audit logs.
☐SV-268110r1131025_ruleNixOS audit daemon must generate logs that are group-owned by root.
☐SV-268111r1039221_ruleNixOS audit directory and logs must be owned by root to prevent unauthorized read access.
☐SV-268112r1039224_ruleNixOS audit directory and logs must be group-owned by root to prevent unauthorized read access.
☐SV-268113r1039227_ruleNixOS audit log directory must have a mode of 0700 or less permissive.
☐SV-268114r1039230_ruleNixOS audit logs must have a mode of 0600 or less permissive.
☐SV-268115r1131028_ruleNixOS journald directory and logs must be owned by root to prevent unauthorized read access.
☐SV-268116r1131031_ruleNixOS journald directory and logs must be group-owned by systemd-journald to prevent unauthorized read access.
☐SV-268117r1131034_ruleNixOS systemd-journald directory must have a mode of 2755 or less permissive.
☐SV-268118r1131037_ruleNixOS systemd-journald logs must have a mode of 0640 or less permissive.
☐SV-268119r1131040_ruleNixOS audit system must protect logon UIDs from unauthorized change.
☐SV-268120r1131043_ruleNixOS audit configuration files must have a mode of 444 or less permissive.
☐SV-268121r1131046_ruleNixOS system configuration file directories must have a mode of "0755" or less permissive.
☐SV-268122r1131049_ruleNixOS system configuration files and directories must be owned by root.
☐SV-268123r1131052_ruleNixOS system configuration files and directories must be group-owned by root.
☐SV-268124r1131055_ruleNixOS, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
☐SV-268125r1039263_ruleNixOS must enforce authorized access to the corresponding private key for PKI-based authentication.
☐SV-268126r1131057_ruleNixOS must enforce password complexity by requiring that at least one uppercase character be used.
☐SV-268127r1131059_ruleNixOS must enforce password complexity by requiring that at least one lowercase character be used.
☐SV-268128r1131061_ruleNixOS must enforce password complexity by requiring that at least one numeric character be used.
☐SV-268129r1131063_ruleNixOS must require the change of at least 50 percent of the total number of characters when passwords are changed.
☐SV-268130r1131065_ruleNixOS must store only encrypted representations of passwords.
☐SV-268131r1131067_ruleNixOS must not have the telnet package installed.
☐SV-268132r1131069_ruleNixOS must enforce 24 hours/one day as the minimum password lifetime.
☐SV-268133r1131071_ruleNixOS must enforce a 60-day maximum password lifetime restriction.
☐SV-268134r1131073_ruleNixOS must enforce a minimum 15-character password length.
☐SV-268135r1039293_ruleNixOS must uniquely identify and must authenticate organizational users (or processes acting on behalf of organizational users).
☐SV-268136r1131076_ruleNixOS must use multifactor authentication for network access to privileged accounts.
☐SV-268137r1131078_ruleNixOS must not allow direct login to the root account via SSH.
☐SV-268138r1131081_ruleNixOS must not allow direct login to the root account.
☐SV-268139r1131083_ruleNixOS must enable USBguard.
☐SV-268140r1117267_ruleA sticky bit must be set on all NixOS public directories to prevent unauthorized and unintended information transferred via shared system resources.
☐SV-268141r1131085_ruleNixOS must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial-of-service (DoS) attacks.
☐SV-268142r1131087_ruleNixOS must terminate all SSH connections after 10 minutes of becoming unresponsive.
☐SV-268143r1131089_ruleNixOS must terminate all SSH connections after becoming unresponsive.
☐SV-268144r1039320_ruleNixOS must protect the confidentiality and integrity of all information at rest.
☐SV-268145r1131091_ruleNixOS must enforce password complexity by requiring that at least one special character be used.
☐SV-268146r1131093_ruleNixOS must protect wireless access to and from the system using encryption.
☐SV-268147r1131095_ruleNixOS must protect wireless access to the system using authentication of users and/or devices.
☐SV-268148r1131097_ruleNixOS must prevent all software from executing at higher privilege levels than users executing the software.
☐SV-268149r1131099_ruleNixOS must, for networked systems, compare internal information system clocks at least every 24 hours with a server which is synchronized to one of the redundant United States Naval Observatory (USNO) time servers, or a time server designated for the appropriate DOD network (NIPRNet/SIPRNet), and/or the Global Positioning System (GPS).
☐SV-268150r1131101_ruleNixOS must synchronize internal information system clocks to the authoritative time source when the time difference is greater than one second.
☐SV-268151r1131103_ruleNixOS must have time synchronization enabled.
☐SV-268152r1131105_ruleNixOS must prohibit user installation of system software without explicit privileged status.
☐SV-268153r1131108_ruleNixOS must notify designated personnel if baseline configurations are changed in an unauthorized manner.
☐SV-268154r1131111_ruleNixOS must prevent the installation of patches, service packs, device drivers, or operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.
☐SV-268155r1131113_ruleNixOS must require users to reauthenticate for privilege escalation.
☐SV-268156r1131116_ruleNixOS must require users to reauthenticate when changing roles.
☐SV-268157r1131119_ruleNixOS must implement cryptographic mechanisms to protect the integrity of nonlocal maintenance and diagnostic communications, when used for nonlocal maintenance sessions.
☐SV-268158r1131121_ruleNixOS must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring the operating system is implementing rate-limiting measures on impacted network interfaces.
☐SV-268159r1131124_ruleNixOS must protect the confidentiality and integrity of transmitted information.
☐SV-268160r1131126_ruleNixOS must implement nonexecutable data to protect its memory from unauthorized code execution.
☐SV-268161r1131128_ruleNixOS must implement address space layout randomization to protect its memory from unauthorized code execution.
☐SV-268163r1131131_ruleNixOS must generate audit records when successful/unsuccessful attempts to modify security objects occur.
☐SV-268164r1131133_ruleNixOS must generate audit records when successful/unsuccessful attempts to delete privileges occur.
☐SV-268165r1131135_ruleNixOS must generate audit records when successful/unsuccessful attempts to delete security objects occur.
☐SV-268166r1131137_ruleNixOS must generate audit records when concurrent logons to the same account occur from different sources.
☐SV-268167r1131139_ruleNixOS must generate audit records for all account creations, modifications, disabling, and termination events.
☐SV-268168r1131141_ruleNixOS must implement NIST FIPS-validated cryptography for the following: to provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
☐SV-268169r1131144_ruleNixOS must prevent the use of dictionary words for passwords.
☐SV-268170r1131146_ruleNixOS must enable the use of pwquality.
☐SV-268171r1134782_ruleNixOS must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
☐SV-268172r1131152_ruleNixOS must not allow an unattended or automatic logon to the system via the console.
☐SV-268173r1131154_ruleNixOS must be configured to use AppArmor.
☐SV-268174r1131156_ruleNixOS must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.
☐SV-268175r1131158_ruleNixOS must employ approved cryptographic hashing algorithms for all stored passwords.
☐SV-268176r1131160_ruleNixOS must employ strong authenticators in the establishment of nonlocal maintenance and diagnostic sessions.
☐SV-268177r1131162_ruleNixOS must implement multifactor authentication for remote access to privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access.
☐SV-268178r1131164_ruleNixOS must prohibit the use of cached authenticators after one day.
☐SV-268179r1131166_ruleFor PKI-based authentication, NixOS must implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network.
☐SV-268180r1117152_ruleNixOS must run a supported release of the operating system.
☐SV-268181r1131169_ruleNixOS must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.