| Checked | Name | Title |
|---|
| ☐ | SV-268078r1130947_rule | NixOS must enable the built-in firewall. |
| ☐ | SV-268079r1130948_rule | NixOS emergency or temporary user accounts must be provisioned with an expiration time of 72 hours or less. |
| ☐ | SV-268080r1130951_rule | NixOS must enable the audit daemon. |
| ☐ | SV-268081r1130954_rule | NixOS must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period. |
| ☐ | SV-268082r1130957_rule | NixOS must be configured to display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a command line user logon. |
| ☐ | SV-268083r1130960_rule | NixOS must be configured to display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via an SSH logon. |
| ☐ | SV-268084r1130963_rule | NixOS must be configured to display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a graphical user logon. |
| ☐ | SV-268085r1130966_rule | NixOS must be configured to limit the number of concurrent sessions to 10 for all accounts and/or account types. |
| ☐ | SV-268086r1130969_rule | NixOS must initiate a session lock after a 10-minute period of inactivity for graphical user logon. |
| ☐ | SV-268087r1130972_rule | NixOS must provide the capability for users to directly initiate a session lock for all connection types. |
| ☐ | SV-268088r1130975_rule | NixOS must monitor remote access methods. |
| ☐ | SV-268089r1130978_rule | NixOS must implement DOD-approved encryption to protect the confidentiality of remote access sessions. |
| ☐ | SV-268090r1130981_rule | The NixOS audit package must be installed. |
| ☐ | SV-268091r1130983_rule | NixOS must generate audit records for all usage of privileged commands. |
| ☐ | SV-268092r1130985_rule | NixOS must enable auditing of processes that start prior to the audit daemon. |
| ☐ | SV-268093r1130988_rule | NixOS must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon. |
| ☐ | SV-268094r1130990_rule | Successful/unsuccessful uses of the mount syscall in NixOS must generate an audit record. |
| ☐ | SV-268095r1130992_rule | Successful/unsuccessful uses of the rename, unlink, rmdir, renameat, and unlinkat system calls in NixOS must generate an audit record. |
| ☐ | SV-268096r1130994_rule | Successful/unsuccessful uses of the init_module, finit_module, and delete_module system calls in NixOS must generate an audit record. |
| ☐ | SV-268097r1130996_rule | NixOS must generate an audit record for successful/unsuccessful modifications to the cron configuration. |
| ☐ | SV-268098r1130998_rule | NixOS must generate an audit record for successful/unsuccessful uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls. |
| ☐ | SV-268099r1131000_rule | Successful/unsuccessful uses of the chown, fchown, fchownat, and lchown system calls in NixOS must generate an audit record. |
| ☐ | SV-268100r1131002_rule | Successful/unsuccessful uses of the chmod, fchmod, and fchmodat system calls in NixOS must generate an audit record. |
| ☐ | SV-268101r1131004_rule | NixOS must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume reaches 75 percent utilization. |
| ☐ | SV-268102r1131006_rule | NixOS must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume reaches 90 percent utilization. |
| ☐ | SV-268103r1131008_rule | NixOS must take action when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity. |
| ☐ | SV-268104r1131010_rule | NixOS must take action when allocated audit record storage volume reaches 90 percent of the repository maximum audit record storage capacity. |
| ☐ | SV-268105r1131012_rule | The NixOS audit system must take appropriate action when the audit storage volume is full. |
| ☐ | SV-268106r1131014_rule | The NixOS audit system must take appropriate action when an audit processing failure occurs. |
| ☐ | SV-268107r1131017_rule | NixOS must have the packages required for offloading audit logs installed and running. |
| ☐ | SV-268108r1131020_rule | The NixOS audit records must be off-loaded onto a different system or storage media from the system being audited. |
| ☐ | SV-268109r1131023_rule | NixOS must authenticate the remote logging server for off-loading audit logs. |
| ☐ | SV-268110r1131025_rule | NixOS audit daemon must generate logs that are group-owned by root. |
| ☐ | SV-268111r1039221_rule | NixOS audit directory and logs must be owned by root to prevent unauthorized read access. |
| ☐ | SV-268112r1039224_rule | NixOS audit directory and logs must be group-owned by root to prevent unauthorized read access. |
| ☐ | SV-268113r1039227_rule | NixOS audit log directory must have a mode of 0700 or less permissive. |
| ☐ | SV-268114r1039230_rule | NixOS audit logs must have a mode of 0600 or less permissive. |
| ☐ | SV-268115r1131028_rule | NixOS journald directory and logs must be owned by root to prevent unauthorized read access. |
| ☐ | SV-268116r1131031_rule | NixOS journald directory and logs must be group-owned by systemd-journald to prevent unauthorized read access. |
| ☐ | SV-268117r1131034_rule | NixOS systemd-journald directory must have a mode of 2755 or less permissive. |
| ☐ | SV-268118r1131037_rule | NixOS systemd-journald logs must have a mode of 0640 or less permissive. |
| ☐ | SV-268119r1131040_rule | NixOS audit system must protect logon UIDs from unauthorized change. |
| ☐ | SV-268120r1131043_rule | NixOS audit configuration files must have a mode of 444 or less permissive. |
| ☐ | SV-268121r1131046_rule | NixOS system configuration file directories must have a mode of "0755" or less permissive. |
| ☐ | SV-268122r1131049_rule | NixOS system configuration files and directories must be owned by root. |
| ☐ | SV-268123r1131052_rule | NixOS system configuration files and directories must be group-owned by root. |
| ☐ | SV-268124r1131055_rule | NixOS, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor. |
| ☐ | SV-268125r1039263_rule | NixOS must enforce authorized access to the corresponding private key for PKI-based authentication. |
| ☐ | SV-268126r1131057_rule | NixOS must enforce password complexity by requiring that at least one uppercase character be used. |
| ☐ | SV-268127r1131059_rule | NixOS must enforce password complexity by requiring that at least one lowercase character be used. |
| ☐ | SV-268128r1131061_rule | NixOS must enforce password complexity by requiring that at least one numeric character be used. |
| ☐ | SV-268129r1131063_rule | NixOS must require the change of at least 50 percent of the total number of characters when passwords are changed. |
| ☐ | SV-268130r1131065_rule | NixOS must store only encrypted representations of passwords. |
| ☐ | SV-268131r1131067_rule | NixOS must not have the telnet package installed. |
| ☐ | SV-268132r1131069_rule | NixOS must enforce 24 hours/one day as the minimum password lifetime. |
| ☐ | SV-268133r1131071_rule | NixOS must enforce a 60-day maximum password lifetime restriction. |
| ☐ | SV-268134r1131073_rule | NixOS must enforce a minimum 15-character password length. |
| ☐ | SV-268135r1039293_rule | NixOS must uniquely identify and must authenticate organizational users (or processes acting on behalf of organizational users). |
| ☐ | SV-268136r1131076_rule | NixOS must use multifactor authentication for network access to privileged accounts. |
| ☐ | SV-268137r1131078_rule | NixOS must not allow direct login to the root account via SSH. |
| ☐ | SV-268138r1131081_rule | NixOS must not allow direct login to the root account. |
| ☐ | SV-268139r1131083_rule | NixOS must enable USBguard. |
| ☐ | SV-268140r1117267_rule | A sticky bit must be set on all NixOS public directories to prevent unauthorized and unintended information transferred via shared system resources. |
| ☐ | SV-268141r1131085_rule | NixOS must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial-of-service (DoS) attacks. |
| ☐ | SV-268142r1131087_rule | NixOS must terminate all SSH connections after 10 minutes of becoming unresponsive. |
| ☐ | SV-268143r1131089_rule | NixOS must terminate all SSH connections after becoming unresponsive. |
| ☐ | SV-268144r1039320_rule | NixOS must protect the confidentiality and integrity of all information at rest. |
| ☐ | SV-268145r1131091_rule | NixOS must enforce password complexity by requiring that at least one special character be used. |
| ☐ | SV-268146r1131093_rule | NixOS must protect wireless access to and from the system using encryption. |
| ☐ | SV-268147r1131095_rule | NixOS must protect wireless access to the system using authentication of users and/or devices. |
| ☐ | SV-268148r1131097_rule | NixOS must prevent all software from executing at higher privilege levels than users executing the software. |
| ☐ | SV-268149r1131099_rule | NixOS must, for networked systems, compare internal information system clocks at least every 24 hours with a server which is synchronized to one of the redundant United States Naval Observatory (USNO) time servers, or a time server designated for the appropriate DOD network (NIPRNet/SIPRNet), and/or the Global Positioning System (GPS). |
| ☐ | SV-268150r1131101_rule | NixOS must synchronize internal information system clocks to the authoritative time source when the time difference is greater than one second. |
| ☐ | SV-268151r1131103_rule | NixOS must have time synchronization enabled. |
| ☐ | SV-268152r1131105_rule | NixOS must prohibit user installation of system software without explicit privileged status. |
| ☐ | SV-268153r1131108_rule | NixOS must notify designated personnel if baseline configurations are changed in an unauthorized manner. |
| ☐ | SV-268154r1131111_rule | NixOS must prevent the installation of patches, service packs, device drivers, or operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization. |
| ☐ | SV-268155r1131113_rule | NixOS must require users to reauthenticate for privilege escalation. |
| ☐ | SV-268156r1131116_rule | NixOS must require users to reauthenticate when changing roles. |
| ☐ | SV-268157r1131119_rule | NixOS must implement cryptographic mechanisms to protect the integrity of nonlocal maintenance and diagnostic communications, when used for nonlocal maintenance sessions. |
| ☐ | SV-268158r1131121_rule | NixOS must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring the operating system is implementing rate-limiting measures on impacted network interfaces. |
| ☐ | SV-268159r1131124_rule | NixOS must protect the confidentiality and integrity of transmitted information. |
| ☐ | SV-268160r1131126_rule | NixOS must implement nonexecutable data to protect its memory from unauthorized code execution. |
| ☐ | SV-268161r1131128_rule | NixOS must implement address space layout randomization to protect its memory from unauthorized code execution. |
| ☐ | SV-268163r1131131_rule | NixOS must generate audit records when successful/unsuccessful attempts to modify security objects occur. |
| ☐ | SV-268164r1131133_rule | NixOS must generate audit records when successful/unsuccessful attempts to delete privileges occur. |
| ☐ | SV-268165r1131135_rule | NixOS must generate audit records when successful/unsuccessful attempts to delete security objects occur. |
| ☐ | SV-268166r1131137_rule | NixOS must generate audit records when concurrent logons to the same account occur from different sources. |
| ☐ | SV-268167r1131139_rule | NixOS must generate audit records for all account creations, modifications, disabling, and termination events. |
| ☐ | SV-268168r1131141_rule | NixOS must implement NIST FIPS-validated cryptography for the following: to provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards. |
| ☐ | SV-268169r1131144_rule | NixOS must prevent the use of dictionary words for passwords. |
| ☐ | SV-268170r1131146_rule | NixOS must enable the use of pwquality. |
| ☐ | SV-268171r1134782_rule | NixOS must enforce a delay of at least four seconds between logon prompts following a failed logon attempt. |
| ☐ | SV-268172r1131152_rule | NixOS must not allow an unattended or automatic logon to the system via the console. |
| ☐ | SV-268173r1131154_rule | NixOS must be configured to use AppArmor. |
| ☐ | SV-268174r1131156_rule | NixOS must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity. |
| ☐ | SV-268175r1131158_rule | NixOS must employ approved cryptographic hashing algorithms for all stored passwords. |
| ☐ | SV-268176r1131160_rule | NixOS must employ strong authenticators in the establishment of nonlocal maintenance and diagnostic sessions. |
| ☐ | SV-268177r1131162_rule | NixOS must implement multifactor authentication for remote access to privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access. |
| ☐ | SV-268178r1131164_rule | NixOS must prohibit the use of cached authenticators after one day. |
| ☐ | SV-268179r1131166_rule | For PKI-based authentication, NixOS must implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network. |
| ☐ | SV-268180r1117152_rule | NixOS must run a supported release of the operating system. |
| ☐ | SV-268181r1131169_rule | NixOS must define default permissions for all authenticated users in such a way that the user can only read and modify their own files. |