Check: ANIX-00-002160
Anduril NixOS STIG:
ANIX-00-002160
(in version v1 r1)
Title
NixOS must run a supported release of the operating system. (Cat II impact)
Discussion
Security flaws with operating systems are discovered daily. Vendors are constantly updating and patching their products to address newly discovered security vulnerabilities. Organizations (including any contractor to the organization) are required to promptly install security-relevant software updates (e.g., patches, service packs, and hot fixes). Flaws discovered during security assessments, continuous monitoring, incident response activities, or information system error handling must also be addressed expeditiously.
Check Content
Verify NixOS is running a supported version with the following command: $ nixos-version 23.11.20231129.057f9ae (Tapir) If the NixOS is not running a supported version, this is a finding.
Fix Text
Update to a supported version of the operating system.
Additional Identifiers
Rule ID: SV-268180r1039428_rule
Vulnerability ID: V-268180
Group Title: SRG-OS-000439-GPOS-00195
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002605 |
Install security-relevant software updates within an organization-defined time period of the release of the updates. |
Controls
Number | Title |
---|---|
SI-2 |
Flaw Remediation |