| Checked | Name | Title |
|---|
| ☐ | SV-279527r1192379_rule | Nutanix VMM must be configured to remove ypserv. |
| ☐ | SV-279528r1192544_rule | Nutanix OS must limit the number of concurrent sessions to 10 for all accounts and/or account types. |
| ☐ | SV-279529r1192546_rule | Nutanix OS must set the value of "lock-after-time" to 890 seconds for remote access sessions. |
| ☐ | SV-279530r1192590_rule | Nutanix OS must configure the ClientAliveInterval to "600" and ClientAliveCountMax to "1". |
| ☐ | SV-279531r1192591_rule | Nutanix OS must monitor SSH access. |
| ☐ | SV-279532r1192283_rule | Nutanix OS must configure the firewall to control remote access methods. |
| ☐ | SV-279533r1192035_rule | Nutanix OS must implement DOD-approved encryption to protect the confidentiality of SSH sessions. |
| ☐ | SV-279534r1192285_rule | Nutanix OS must implement cryptography to protect the integrity of remote access sessions by using only HMACs employing FIPS 140-3-approved algorithms. |
| ☐ | SV-279535r1192593_rule | Nutanix OS must implement cryptography to protect the integrity of remote access session by setting the systemwide policy to use FIPS mode. |
| ☐ | SV-279536r1192381_rule | Nutanix OS must implement TLS to protect the integrity and confidentiality of remote access and nonlocal maintenance and diagnostic sessions. |
| ☐ | SV-279537r1192383_rule | Nutanix OS must implement cryptography to protect the integrity of remote access sessions. |
| ☐ | SV-279538r1192550_rule | Nutanix OS must implement cryptography to protect the integrity and confidentiality of remote access and nonlocal maintenance and diagnostic sessions. |
| ☐ | SV-279539r1192552_rule | Nutanix OS must automatically remove or disable temporary user accounts after 72 hours. |
| ☐ | SV-279540r1192387_rule | Nutanix OS must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity. |
| ☐ | SV-279541r1192389_rule | Nutanix OS must audit all account change actions. |
| ☐ | SV-279542r1192391_rule | Nutanix VMM must encrypt the boot password for root. |
| ☐ | SV-279543r1192595_rule | Nutanix OS must enable kernel parameters to enforce Discretionary Access Control (DAC) on hardlinks. |
| ☐ | SV-279544r1192057_rule | Nutanix OS must enable kernel parameters to enforce discretionary access control on symlinks. |
| ☐ | SV-279545r1192393_rule | Nutanix OS must audit the execution of privileged functions. |
| ☐ | SV-279546r1192554_rule | Nutanix OS must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period. |
| ☐ | SV-279547r1192395_rule | Nutanix OS must display the Standard Mandatory DOD Notice and Consent Banner for SSH access. |
| ☐ | SV-279548r1192062_rule | Nutanix OS must display the Standard Mandatory DOD Notice and Consent Banner until users acknowledge the usage conditions and take explicit actions to log on for further access. |
| ☐ | SV-279549r1192397_rule | Nutanix OS must provide audit record generation capability for DOD-defined auditable events for account changes. |
| ☐ | SV-279550r1192399_rule | Nutanix OS must configure /etc/audit/audit.rules to generate audit records for account access actions. |
| ☐ | SV-279551r1192401_rule | Nutanix OS must configure /etc/audit/audit.rules to generate audit records for account deletion actions. |
| ☐ | SV-279552r1192403_rule | Nutanix OS must provide audit record generation for successful and unsuccessful uses of the init_module and finit_module system calls. |
| ☐ | SV-279553r1192405_rule | Nutanix OS must provide audit record generation for successful and unsuccessful attempts to move, remove, or delete files and directories. |
| ☐ | SV-279554r1192407_rule | Nutanix OS must generate audit records when successful/unsuccessful attempts to access security objects occur. |
| ☐ | SV-279555r1192409_rule | Nutanix OS must provide audit record generation capability for all account actions. |
| ☐ | SV-279556r1192411_rule | Nutanix OS must provide audit record generation capability for DOD-defined auditable events for all kernel module load, unload, and restart actions. |
| ☐ | SV-279557r1192413_rule | Nutanix OS must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited. |
| ☐ | SV-279558r1192415_rule | Nutanix OS must generate audit records when successful/unsuccessful attempts to modify security objects and categories of information (e.g., classification levels) occur. |
| ☐ | SV-279559r1192597_rule | Nutanix OS must generate audit records when successful/unsuccessful logon attempts occur. |
| ☐ | SV-279560r1192419_rule | Nutanix OS must generate audit records for privileged activities or other system-level access. |
| ☐ | SV-279561r1192421_rule | The audit system must be configured to audit the loading and unloading of dynamic kernel modules. |
| ☐ | SV-279562r1192301_rule | Nutanix OS must generate audit records when concurrent logons to the same account occur from different sources. |
| ☐ | SV-279563r1192423_rule | Nutanix OS must generate audit records for all account creations, modifications, disabling, and termination events. |
| ☐ | SV-279564r1192080_rule | Nutanix OS must generate audit records for all kernel module load, unload, and restart actions, and also for all program initiations. |
| ☐ | SV-279565r1192081_rule | Nutanix OS must have the audit.x86_64 package installed. |
| ☐ | SV-279566r1192425_rule | Nutanix OS must allocate audit record storage capacity to store at least one week's worth of audit records, when audit records are not immediately sent to a central audit record storage facility. |
| ☐ | SV-279567r1192427_rule | Nutanix OS must be configured to send audit records to a site-specific remote syslog server. |
| ☐ | SV-279568r1192085_rule | Nutanix OS must immediately notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity. |
| ☐ | SV-279569r1192086_rule | Nutanix OS must alert the information system security officer (ISSO) and system administrator (SA) (at a minimum) in the event of an audit processing failure. |
| ☐ | SV-279570r1192430_rule | Nutanix AHV must disable network management of the chrony daemon. |
| ☐ | SV-279571r1192432_rule | Nutanix AHV must disable the chrony daemon from acting like a server. |
| ☐ | SV-279572r1192092_rule | Nutanix AHV must disable the use or cramfs kernel module. |
| ☐ | SV-279573r1192434_rule | Nutanix OS must configure redundant United States Naval Observatory (USNO) time servers, or a time server designated for the appropriate DOD network (NIPRNet/SIPRNet), and/or the Global Positioning System (GPS). |
| ☐ | SV-279574r1192094_rule | Nutanix OS must use cryptographic mechanisms to protect the integrity of audit tools. |
| ☐ | SV-279575r1192436_rule | Nutanix OS must configure audit log permissions for 0600 or less. |
| ☐ | SV-279576r1192616_rule | Nutanix OS must configure the audit log files to be owned by root. |
| ☐ | SV-279577r1192601_rule | Nutanix OS must prevent the installation of patches, service packs, device drivers, or operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization. |
| ☐ | SV-279578r1192443_rule | Nutanix OS must prevent SSH from permitting Generic Security Service Application Program Interface (GSSAPI) authentication. |
| ☐ | SV-279579r1192445_rule | Nutanix AHV must not be configured to allow Kerberos authentication. |
| ☐ | SV-279580r1192309_rule | Nutanix OS must prevent using dictionary words for passwords. |
| ☐ | SV-279581r1192447_rule | Nutanix OS must enforce a delay of at least four seconds between logon prompts following a failed logon attempt. |
| ☐ | SV-279582r1192311_rule | Nutanix OS must set the SCMA framework to check the baseline daily. |
| ☐ | SV-279583r1192449_rule | Nutanix OS must define default permissions for all authenticated users so the user can only read and modify their own files. |
| ☐ | SV-279584r1192313_rule | Nutanix OS must not allow an unattended or automatic logon to the system. |
| ☐ | SV-279585r1192452_rule | Nutanix OS must limit the ability of nonprivileged users to grant other users direct access to the contents of their home directories/folders. |
| ☐ | SV-279586r1192556_rule | Nutanix OS must enable an application firewall. |
| ☐ | SV-279587r1192454_rule | Nutanix OS must mount /dev/shm with secure options. |
| ☐ | SV-279588r1192456_rule | Nutanix OS must mount /tmp with secure options. |
| ☐ | SV-279589r1192458_rule | Nutanix OS must mount /var/log/audit with secure options. |
| ☐ | SV-279590r1192460_rule | Nutanix OS must mount /var/tmp with secure options. |
| ☐ | SV-279591r1192462_rule | Nutanix OS must mount /var/log with secure options. |
| ☐ | SV-279592r1192602_rule | Nutanix OS must have the fapolicyd.service installed and active. |
| ☐ | SV-279593r1192467_rule | Nutanix OS must be configured to remove rsh-server. |
| ☐ | SV-279594r1192470_rule | Nutanix OS must be configured to remove telnet-server. |
| ☐ | SV-279595r1192473_rule | Nutanix OS must be configured to remove abrt. |
| ☐ | SV-279596r1192475_rule | Nutanix OS must be configured to remove sendmail. |
| ☐ | SV-279597r1192559_rule | Nutanix OS must be configured to prohibit or restrict using functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assurance List (CAL) and vulnerability assessments. |
| ☐ | SV-279598r1192561_rule | Nutanix OS must require users to reauthenticate for privilege escalation. |
| ☐ | SV-279599r1192563_rule | Nutanix OS must require users to reauthenticate for privilege escalation. |
| ☐ | SV-279600r1192481_rule | Nutanix OS must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users). |
| ☐ | SV-279601r1192483_rule | Nutanix OS must not install autofs.service. |
| ☐ | SV-279602r1192485_rule | Nutanix OS must disable the ability to use USB mass storage devices. |
| ☐ | SV-279603r1192618_rule | Nutanix VMM must, for password-based authentication, verify that when users create or update passwords, the passwords are not found on the list of commonly used, expected, or compromised passwords. |
| ☐ | SV-279604r1192604_rule | Nutanix OS must store only encrypted representations of passwords. |
| ☐ | SV-279605r1192605_rule | Nutanix OS must enforce password complexity by requiring that at least one uppercase character be used. |
| ☐ | SV-279606r1192492_rule | Nutanix OS must enforce password complexity by requiring at least one lowercase character be used. |
| ☐ | SV-279607r1192494_rule | Nutanix OS must enforce password complexity by requiring that at least one numeric character be used. |
| ☐ | SV-279608r1192322_rule | Nutanix OS must require the change of at least 50 percent of the total number of characters when passwords are changed. |
| ☐ | SV-279609r1192569_rule | Operating systems must enforce 24 hours/1 day as the minimum password lifetime. |
| ☐ | SV-279610r1192571_rule | Operating systems must enforce a 60-day maximum password lifetime restriction. |
| ☐ | SV-279611r1192328_rule | Nutanix OS must enforce a minimum 15-character password length. |
| ☐ | SV-279612r1192607_rule | Nutanix OS must enforce password complexity by requiring that at least one special character be used. |
| ☐ | SV-279613r1192499_rule | Nutanix OS must configure pam_uni.so module to use SHA-512 for authentication to a cryptographic module. |
| ☐ | SV-279614r1192501_rule | Nutanix OS must audit all activities performed during nonlocal maintenance and diagnostic sessions. |
| ☐ | SV-279619r1192185_rule | Nutanix OS must implement cryptographic mechanisms to protect the integrity of nonlocal maintenance and diagnostic communications, when used for nonlocal maintenance sessions. |
| ☐ | SV-279620r1192503_rule | Nutanix OS must employ strong authenticators in the establishment of nonlocal maintenance and diagnostic sessions. |
| ☐ | SV-279621r1192336_rule | Nutanix OS must protect the confidentiality and integrity of all information at rest. |
| ☐ | SV-279622r1192573_rule | Nutanix OS must provide protected storage for cryptographic keys with organization-defined safeguards and/or hardware protected key store. |
| ☐ | SV-279623r1192507_rule | Nutanix OS must isolate security functions from nonsecurity functions. |
| ☐ | SV-279624r1192609_rule | Operating systems must prevent unauthorized and unintended information transfer via shared system resources. |
| ☐ | SV-279625r1192338_rule | Nutanix OS must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial-of-service (DoS) attacks. |
| ☐ | SV-279626r1192509_rule | Nutanix OS must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring the operating system is implementing rate-limiting measures on impacted network interfaces. |
| ☐ | SV-279627r1192610_rule | Nutanix OS must protect the confidentiality and integrity of communications with wireless peripherals. |
| ☐ | SV-279628r1192513_rule | Nutanix OS must install and use SSH for remote access. |
| ☐ | SV-279629r1192207_rule | Nutanix OS must restrict the message log access permissions to reveal error messages only to authorized users. |
| ☐ | SV-279630r1192515_rule | Nutanix OS must restrict the /var/log directory access permissions to reveal error messages only to authorized users. |
| ☐ | SV-279631r1192517_rule | Nutanix OS must implement nonexecutable data to protect its memory from unauthorized code execution. |
| ☐ | SV-279632r1192612_rule | Nutanix OS must implement address space layout randomization to protect its memory from unauthorized code execution. |
| ☐ | SV-279633r1192521_rule | Nutanix OS must remove all software components after updated versions have been installed. |
| ☐ | SV-279667r1192524_rule | Nutanix AHV must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries. |
| ☐ | SV-279685r1192527_rule | Nutanix AHV must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring the operating system is implementing rate-limiting measures on impacted network interfaces. |
| ☐ | SV-279686r1192615_rule | Nutanix AHV must store only encrypted representations of passwords. |