STIGQter STIGQter: STIG Summary:

Nutanix Acropolis GPOS Security Technical Implementation Guide

Version: 1

Release: 1 Benchmark Date: 26 Jan 2026

CheckedNameTitle
SV-279527r1192379_ruleNutanix VMM must be configured to remove ypserv.
SV-279528r1192544_ruleNutanix OS must limit the number of concurrent sessions to 10 for all accounts and/or account types.
SV-279529r1192546_ruleNutanix OS must set the value of "lock-after-time" to 890 seconds for remote access sessions.
SV-279530r1192590_ruleNutanix OS must configure the ClientAliveInterval to "600" and ClientAliveCountMax to "1".
SV-279531r1192591_ruleNutanix OS must monitor SSH access.
SV-279532r1192283_ruleNutanix OS must configure the firewall to control remote access methods.
SV-279533r1192035_ruleNutanix OS must implement DOD-approved encryption to protect the confidentiality of SSH sessions.
SV-279534r1192285_ruleNutanix OS must implement cryptography to protect the integrity of remote access sessions by using only HMACs employing FIPS 140-3-approved algorithms.
SV-279535r1192593_ruleNutanix OS must implement cryptography to protect the integrity of remote access session by setting the systemwide policy to use FIPS mode.
SV-279536r1192381_ruleNutanix OS must implement TLS to protect the integrity and confidentiality of remote access and nonlocal maintenance and diagnostic sessions.
SV-279537r1192383_ruleNutanix OS must implement cryptography to protect the integrity of remote access sessions.
SV-279538r1192550_ruleNutanix OS must implement cryptography to protect the integrity and confidentiality of remote access and nonlocal maintenance and diagnostic sessions.
SV-279539r1192552_ruleNutanix OS must automatically remove or disable temporary user accounts after 72 hours.
SV-279540r1192387_ruleNutanix OS must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.
SV-279541r1192389_ruleNutanix OS must audit all account change actions.
SV-279542r1192391_ruleNutanix VMM must encrypt the boot password for root.
SV-279543r1192595_ruleNutanix OS must enable kernel parameters to enforce Discretionary Access Control (DAC) on hardlinks.
SV-279544r1192057_ruleNutanix OS must enable kernel parameters to enforce discretionary access control on symlinks.
SV-279545r1192393_ruleNutanix OS must audit the execution of privileged functions.
SV-279546r1192554_ruleNutanix OS must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.
SV-279547r1192395_ruleNutanix OS must display the Standard Mandatory DOD Notice and Consent Banner for SSH access.
SV-279548r1192062_ruleNutanix OS must display the Standard Mandatory DOD Notice and Consent Banner until users acknowledge the usage conditions and take explicit actions to log on for further access.
SV-279549r1192397_ruleNutanix OS must provide audit record generation capability for DOD-defined auditable events for account changes.
SV-279550r1192399_ruleNutanix OS must configure /etc/audit/audit.rules to generate audit records for account access actions.
SV-279551r1192401_ruleNutanix OS must configure /etc/audit/audit.rules to generate audit records for account deletion actions.
SV-279552r1192403_ruleNutanix OS must provide audit record generation for successful and unsuccessful uses of the init_module and finit_module system calls.
SV-279553r1192405_ruleNutanix OS must provide audit record generation for successful and unsuccessful attempts to move, remove, or delete files and directories.
SV-279554r1192407_ruleNutanix OS must generate audit records when successful/unsuccessful attempts to access security objects occur.
SV-279555r1192409_ruleNutanix OS must provide audit record generation capability for all account actions.
SV-279556r1192411_ruleNutanix OS must provide audit record generation capability for DOD-defined auditable events for all kernel module load, unload, and restart actions.
SV-279557r1192413_ruleNutanix OS must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.
SV-279558r1192415_ruleNutanix OS must generate audit records when successful/unsuccessful attempts to modify security objects and categories of information (e.g., classification levels) occur.
SV-279559r1192597_ruleNutanix OS must generate audit records when successful/unsuccessful logon attempts occur.
SV-279560r1192419_ruleNutanix OS must generate audit records for privileged activities or other system-level access.
SV-279561r1192421_ruleThe audit system must be configured to audit the loading and unloading of dynamic kernel modules.
SV-279562r1192301_ruleNutanix OS must generate audit records when concurrent logons to the same account occur from different sources.
SV-279563r1192423_ruleNutanix OS must generate audit records for all account creations, modifications, disabling, and termination events.
SV-279564r1192080_ruleNutanix OS must generate audit records for all kernel module load, unload, and restart actions, and also for all program initiations.
SV-279565r1192081_ruleNutanix OS must have the audit.x86_64 package installed.
SV-279566r1192425_ruleNutanix OS must allocate audit record storage capacity to store at least one week's worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
SV-279567r1192427_ruleNutanix OS must be configured to send audit records to a site-specific remote syslog server.
SV-279568r1192085_ruleNutanix OS must immediately notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity.
SV-279569r1192086_ruleNutanix OS must alert the information system security officer (ISSO) and system administrator (SA) (at a minimum) in the event of an audit processing failure.
SV-279570r1192430_ruleNutanix AHV must disable network management of the chrony daemon.
SV-279571r1192432_ruleNutanix AHV must disable the chrony daemon from acting like a server.
SV-279572r1192092_ruleNutanix AHV must disable the use or cramfs kernel module.
SV-279573r1192434_ruleNutanix OS must configure redundant United States Naval Observatory (USNO) time servers, or a time server designated for the appropriate DOD network (NIPRNet/SIPRNet), and/or the Global Positioning System (GPS).
SV-279574r1192094_ruleNutanix OS must use cryptographic mechanisms to protect the integrity of audit tools.
SV-279575r1192436_ruleNutanix OS must configure audit log permissions for 0600 or less.
SV-279576r1192616_ruleNutanix OS must configure the audit log files to be owned by root.
SV-279577r1192601_ruleNutanix OS must prevent the installation of patches, service packs, device drivers, or operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.
SV-279578r1192443_ruleNutanix OS must prevent SSH from permitting Generic Security Service Application Program Interface (GSSAPI) authentication.
SV-279579r1192445_ruleNutanix AHV must not be configured to allow Kerberos authentication.
SV-279580r1192309_ruleNutanix OS must prevent using dictionary words for passwords.
SV-279581r1192447_ruleNutanix OS must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
SV-279582r1192311_ruleNutanix OS must set the SCMA framework to check the baseline daily.
SV-279583r1192449_ruleNutanix OS must define default permissions for all authenticated users so the user can only read and modify their own files.
SV-279584r1192313_ruleNutanix OS must not allow an unattended or automatic logon to the system.
SV-279585r1192452_ruleNutanix OS must limit the ability of nonprivileged users to grant other users direct access to the contents of their home directories/folders.
SV-279586r1192556_ruleNutanix OS must enable an application firewall.
SV-279587r1192454_ruleNutanix OS must mount /dev/shm with secure options.
SV-279588r1192456_ruleNutanix OS must mount /tmp with secure options.
SV-279589r1192458_ruleNutanix OS must mount /var/log/audit with secure options.
SV-279590r1192460_ruleNutanix OS must mount /var/tmp with secure options.
SV-279591r1192462_ruleNutanix OS must mount /var/log with secure options.
SV-279592r1192602_ruleNutanix OS must have the fapolicyd.service installed and active.
SV-279593r1192467_ruleNutanix OS must be configured to remove rsh-server.
SV-279594r1192470_ruleNutanix OS must be configured to remove telnet-server.
SV-279595r1192473_ruleNutanix OS must be configured to remove abrt.
SV-279596r1192475_ruleNutanix OS must be configured to remove sendmail.
SV-279597r1192559_ruleNutanix OS must be configured to prohibit or restrict using functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assurance List (CAL) and vulnerability assessments.
SV-279598r1192561_ruleNutanix OS must require users to reauthenticate for privilege escalation.
SV-279599r1192563_ruleNutanix OS must require users to reauthenticate for privilege escalation.
SV-279600r1192481_ruleNutanix OS must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
SV-279601r1192483_ruleNutanix OS must not install autofs.service.
SV-279602r1192485_ruleNutanix OS must disable the ability to use USB mass storage devices.
SV-279603r1192618_ruleNutanix VMM must, for password-based authentication, verify that when users create or update passwords, the passwords are not found on the list of commonly used, expected, or compromised passwords.
SV-279604r1192604_ruleNutanix OS must store only encrypted representations of passwords.
SV-279605r1192605_ruleNutanix OS must enforce password complexity by requiring that at least one uppercase character be used.
SV-279606r1192492_ruleNutanix OS must enforce password complexity by requiring at least one lowercase character be used.
SV-279607r1192494_ruleNutanix OS must enforce password complexity by requiring that at least one numeric character be used.
SV-279608r1192322_ruleNutanix OS must require the change of at least 50 percent of the total number of characters when passwords are changed.
SV-279609r1192569_ruleOperating systems must enforce 24 hours/1 day as the minimum password lifetime.
SV-279610r1192571_ruleOperating systems must enforce a 60-day maximum password lifetime restriction.
SV-279611r1192328_ruleNutanix OS must enforce a minimum 15-character password length.
SV-279612r1192607_ruleNutanix OS must enforce password complexity by requiring that at least one special character be used.
SV-279613r1192499_ruleNutanix OS must configure pam_uni.so module to use SHA-512 for authentication to a cryptographic module.
SV-279614r1192501_ruleNutanix OS must audit all activities performed during nonlocal maintenance and diagnostic sessions.
SV-279619r1192185_ruleNutanix OS must implement cryptographic mechanisms to protect the integrity of nonlocal maintenance and diagnostic communications, when used for nonlocal maintenance sessions.
SV-279620r1192503_ruleNutanix OS must employ strong authenticators in the establishment of nonlocal maintenance and diagnostic sessions.
SV-279621r1192336_ruleNutanix OS must protect the confidentiality and integrity of all information at rest.
SV-279622r1192573_ruleNutanix OS must provide protected storage for cryptographic keys with organization-defined safeguards and/or hardware protected key store.
SV-279623r1192507_ruleNutanix OS must isolate security functions from nonsecurity functions.
SV-279624r1192609_ruleOperating systems must prevent unauthorized and unintended information transfer via shared system resources.
SV-279625r1192338_ruleNutanix OS must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial-of-service (DoS) attacks.
SV-279626r1192509_ruleNutanix OS must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring the operating system is implementing rate-limiting measures on impacted network interfaces.
SV-279627r1192610_ruleNutanix OS must protect the confidentiality and integrity of communications with wireless peripherals.
SV-279628r1192513_ruleNutanix OS must install and use SSH for remote access.
SV-279629r1192207_ruleNutanix OS must restrict the message log access permissions to reveal error messages only to authorized users.
SV-279630r1192515_ruleNutanix OS must restrict the /var/log directory access permissions to reveal error messages only to authorized users.
SV-279631r1192517_ruleNutanix OS must implement nonexecutable data to protect its memory from unauthorized code execution.
SV-279632r1192612_ruleNutanix OS must implement address space layout randomization to protect its memory from unauthorized code execution.
SV-279633r1192521_ruleNutanix OS must remove all software components after updated versions have been installed.
SV-279667r1192524_ruleNutanix AHV must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
SV-279685r1192527_ruleNutanix AHV must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring the operating system is implementing rate-limiting measures on impacted network interfaces.
SV-279686r1192615_ruleNutanix AHV must store only encrypted representations of passwords.