Nutanix AOS must be configured to run SCMA daily.
An XCCDF Rule
Description
<VulnDiscussion>The Nutanix platform leverages the use of the Security Configuration Management Automation (SCMA) framework to ensure secure configurations have not been altered from their desired state. If the SCMA framework is not run on a daily basis, changes to the secure baseline could be made, compromising multiple security functions and features on the operating system.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-254194r846670_rule
- Severity
- Medium
- References
- Updated
Remediation - Manual Procedure
Set the SCMA framework to check the baseline daily:
$ sudo ncli cluster edit-cvm-security-params schedule=daily