STIGQter STIGQter: STIG Summary:

Anduril NixOS Security Technical Implementation Guide

Version: 1

Release: 2 Benchmark Date: 01 Oct 2025

CheckedNameTitle
SV-268078r1130947_ruleNixOS must enable the built-in firewall.
SV-268079r1130948_ruleNixOS emergency or temporary user accounts must be provisioned with an expiration time of 72 hours or less.
SV-268080r1130951_ruleNixOS must enable the audit daemon.
SV-268081r1130954_ruleNixOS must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.
SV-268082r1130957_ruleNixOS must be configured to display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a command line user logon.
SV-268083r1130960_ruleNixOS must be configured to display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via an SSH logon.
SV-268084r1130963_ruleNixOS must be configured to display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a graphical user logon.
SV-268085r1130966_ruleNixOS must be configured to limit the number of concurrent sessions to 10 for all accounts and/or account types.
SV-268086r1130969_ruleNixOS must initiate a session lock after a 10-minute period of inactivity for graphical user logon.
SV-268087r1130972_ruleNixOS must provide the capability for users to directly initiate a session lock for all connection types.
SV-268088r1130975_ruleNixOS must monitor remote access methods.
SV-268089r1130978_ruleNixOS must implement DOD-approved encryption to protect the confidentiality of remote access sessions.
SV-268090r1130981_ruleThe NixOS audit package must be installed.
SV-268091r1130983_ruleNixOS must generate audit records for all usage of privileged commands.
SV-268092r1130985_ruleNixOS must enable auditing of processes that start prior to the audit daemon.
SV-268093r1130988_ruleNixOS must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.
SV-268094r1130990_ruleSuccessful/unsuccessful uses of the mount syscall in NixOS must generate an audit record.
SV-268095r1130992_ruleSuccessful/unsuccessful uses of the rename, unlink, rmdir, renameat, and unlinkat system calls in NixOS must generate an audit record.
SV-268096r1130994_ruleSuccessful/unsuccessful uses of the init_module, finit_module, and delete_module system calls in NixOS must generate an audit record.
SV-268097r1130996_ruleNixOS must generate an audit record for successful/unsuccessful modifications to the cron configuration.
SV-268098r1130998_ruleNixOS must generate an audit record for successful/unsuccessful uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls.
SV-268099r1131000_ruleSuccessful/unsuccessful uses of the chown, fchown, fchownat, and lchown system calls in NixOS must generate an audit record.
SV-268100r1131002_ruleSuccessful/unsuccessful uses of the chmod, fchmod, and fchmodat system calls in NixOS must generate an audit record.
SV-268101r1131004_ruleNixOS must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume reaches 75 percent utilization.
SV-268102r1131006_ruleNixOS must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume reaches 90 percent utilization.
SV-268103r1131008_ruleNixOS must take action when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity.
SV-268104r1131010_ruleNixOS must take action when allocated audit record storage volume reaches 90 percent of the repository maximum audit record storage capacity.
SV-268105r1131012_ruleThe NixOS audit system must take appropriate action when the audit storage volume is full.
SV-268106r1131014_ruleThe NixOS audit system must take appropriate action when an audit processing failure occurs.
SV-268107r1131017_ruleNixOS must have the packages required for offloading audit logs installed and running.
SV-268108r1131020_ruleThe NixOS audit records must be off-loaded onto a different system or storage media from the system being audited.
SV-268109r1131023_ruleNixOS must authenticate the remote logging server for off-loading audit logs.
SV-268110r1131025_ruleNixOS audit daemon must generate logs that are group-owned by root.
SV-268111r1039221_ruleNixOS audit directory and logs must be owned by root to prevent unauthorized read access.
SV-268112r1039224_ruleNixOS audit directory and logs must be group-owned by root to prevent unauthorized read access.
SV-268113r1039227_ruleNixOS audit log directory must have a mode of 0700 or less permissive.
SV-268114r1039230_ruleNixOS audit logs must have a mode of 0600 or less permissive.
SV-268115r1131028_ruleNixOS journald directory and logs must be owned by root to prevent unauthorized read access.
SV-268116r1131031_ruleNixOS journald directory and logs must be group-owned by systemd-journald to prevent unauthorized read access.
SV-268117r1131034_ruleNixOS systemd-journald directory must have a mode of 2755 or less permissive.
SV-268118r1131037_ruleNixOS systemd-journald logs must have a mode of 0640 or less permissive.
SV-268119r1131040_ruleNixOS audit system must protect logon UIDs from unauthorized change.
SV-268120r1131043_ruleNixOS audit configuration files must have a mode of 444 or less permissive.
SV-268121r1131046_ruleNixOS system configuration file directories must have a mode of "0755" or less permissive.
SV-268122r1131049_ruleNixOS system configuration files and directories must be owned by root.
SV-268123r1131052_ruleNixOS system configuration files and directories must be group-owned by root.
SV-268124r1131055_ruleNixOS, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
SV-268125r1039263_ruleNixOS must enforce authorized access to the corresponding private key for PKI-based authentication.
SV-268126r1131057_ruleNixOS must enforce password complexity by requiring that at least one uppercase character be used.
SV-268127r1131059_ruleNixOS must enforce password complexity by requiring that at least one lowercase character be used.
SV-268128r1131061_ruleNixOS must enforce password complexity by requiring that at least one numeric character be used.
SV-268129r1131063_ruleNixOS must require the change of at least 50 percent of the total number of characters when passwords are changed.
SV-268130r1131065_ruleNixOS must store only encrypted representations of passwords.
SV-268131r1131067_ruleNixOS must not have the telnet package installed.
SV-268132r1131069_ruleNixOS must enforce 24 hours/one day as the minimum password lifetime.
SV-268133r1131071_ruleNixOS must enforce a 60-day maximum password lifetime restriction.
SV-268134r1131073_ruleNixOS must enforce a minimum 15-character password length.
SV-268135r1039293_ruleNixOS must uniquely identify and must authenticate organizational users (or processes acting on behalf of organizational users).
SV-268136r1131076_ruleNixOS must use multifactor authentication for network access to privileged accounts.
SV-268137r1131078_ruleNixOS must not allow direct login to the root account via SSH.
SV-268138r1131081_ruleNixOS must not allow direct login to the root account.
SV-268139r1131083_ruleNixOS must enable USBguard.
SV-268140r1117267_ruleA sticky bit must be set on all NixOS public directories to prevent unauthorized and unintended information transferred via shared system resources.
SV-268141r1131085_ruleNixOS must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial-of-service (DoS) attacks.
SV-268142r1131087_ruleNixOS must terminate all SSH connections after 10 minutes of becoming unresponsive.
SV-268143r1131089_ruleNixOS must terminate all SSH connections after becoming unresponsive.
SV-268144r1039320_ruleNixOS must protect the confidentiality and integrity of all information at rest.
SV-268145r1131091_ruleNixOS must enforce password complexity by requiring that at least one special character be used.
SV-268146r1131093_ruleNixOS must protect wireless access to and from the system using encryption.
SV-268147r1131095_ruleNixOS must protect wireless access to the system using authentication of users and/or devices.
SV-268148r1131097_ruleNixOS must prevent all software from executing at higher privilege levels than users executing the software.
SV-268149r1131099_ruleNixOS must, for networked systems, compare internal information system clocks at least every 24 hours with a server which is synchronized to one of the redundant United States Naval Observatory (USNO) time servers, or a time server designated for the appropriate DOD network (NIPRNet/SIPRNet), and/or the Global Positioning System (GPS).
SV-268150r1131101_ruleNixOS must synchronize internal information system clocks to the authoritative time source when the time difference is greater than one second.
SV-268151r1131103_ruleNixOS must have time synchronization enabled.
SV-268152r1131105_ruleNixOS must prohibit user installation of system software without explicit privileged status.
SV-268153r1131108_ruleNixOS must notify designated personnel if baseline configurations are changed in an unauthorized manner.
SV-268154r1131111_ruleNixOS must prevent the installation of patches, service packs, device drivers, or operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.
SV-268155r1131113_ruleNixOS must require users to reauthenticate for privilege escalation.
SV-268156r1131116_ruleNixOS must require users to reauthenticate when changing roles.
SV-268157r1131119_ruleNixOS must implement cryptographic mechanisms to protect the integrity of nonlocal maintenance and diagnostic communications, when used for nonlocal maintenance sessions.
SV-268158r1131121_ruleNixOS must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring the operating system is implementing rate-limiting measures on impacted network interfaces.
SV-268159r1131124_ruleNixOS must protect the confidentiality and integrity of transmitted information.
SV-268160r1131126_ruleNixOS must implement nonexecutable data to protect its memory from unauthorized code execution.
SV-268161r1131128_ruleNixOS must implement address space layout randomization to protect its memory from unauthorized code execution.
SV-268163r1131131_ruleNixOS must generate audit records when successful/unsuccessful attempts to modify security objects occur.
SV-268164r1131133_ruleNixOS must generate audit records when successful/unsuccessful attempts to delete privileges occur.
SV-268165r1131135_ruleNixOS must generate audit records when successful/unsuccessful attempts to delete security objects occur.
SV-268166r1131137_ruleNixOS must generate audit records when concurrent logons to the same account occur from different sources.
SV-268167r1131139_ruleNixOS must generate audit records for all account creations, modifications, disabling, and termination events.
SV-268168r1131141_ruleNixOS must implement NIST FIPS-validated cryptography for the following: to provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
SV-268169r1131144_ruleNixOS must prevent the use of dictionary words for passwords.
SV-268170r1131146_ruleNixOS must enable the use of pwquality.
SV-268171r1134782_ruleNixOS must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
SV-268172r1131152_ruleNixOS must not allow an unattended or automatic logon to the system via the console.
SV-268173r1131154_ruleNixOS must be configured to use AppArmor.
SV-268174r1131156_ruleNixOS must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.
SV-268175r1131158_ruleNixOS must employ approved cryptographic hashing algorithms for all stored passwords.
SV-268176r1131160_ruleNixOS must employ strong authenticators in the establishment of nonlocal maintenance and diagnostic sessions.
SV-268177r1131162_ruleNixOS must implement multifactor authentication for remote access to privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access.
SV-268178r1131164_ruleNixOS must prohibit the use of cached authenticators after one day.
SV-268179r1131166_ruleFor PKI-based authentication, NixOS must implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network.
SV-268180r1117152_ruleNixOS must run a supported release of the operating system.
SV-268181r1131169_ruleNixOS must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.