Check: SRG-OS-000745-VMM-000210
Virtual Machine Manager SRG:
SRG-OS-000745-VMM-000210
(in versions v2 r2 through v2 r1)
Title
The VMM must accept only external credentials that are NIST-compliant. (Cat II impact)
Discussion
Acceptance of only NIST-compliant external authenticators applies to organizational systems that are accessible to the public (e.g., public-facing websites). External authenticators are issued by nonfederal government entities and are compliant with [SP 800-63B]. Approved external authenticators meet or exceed the minimum federal government-wide technical, security, privacy, and organizational maturity requirements. Meeting or exceeding federal requirements allows federal government relying parties to trust external authenticators in connection with an authentication transaction at a specified authenticator assurance level.
Check Content
Verify the VMM is configured to accept only external credentials that are NIST-compliant. If the VMM is not configured to accept only external credentials that are NIST-compliant, this is a finding.
Fix Text
Configure the VMM to accept only external credentials that are NIST-compliant.
Additional Identifiers
Rule ID: SV-264322r984281_rule
Vulnerability ID: V-264322
Group Title: SRG-OS-000745
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-004083 |
Accept only external credentials that are NIST compliant. |
Controls
Number | Title |
---|---|
No controls are assigned to this check |