STIGQter STIGQter: STIG Summary: Xylok Security Suite 20.x Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Xylok Security Suite must not allow local user or groups.

DISA Rule

SV-269581r1054095_rule

Vulnerability Number

V-269581

Group Title

SRG-APP-000328

Rule Version

XYLK-20-000137

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Delete unused or local groups/users.

1. As a logged in administrator in Xylok, navigate to User Menu <username> >> Database Admin >> Users.
2. Select User(s) to delete.
3. Click on down arrow in "Action".
4. Select "Delete selected users"
5. Click "Go".
6. Click "Yes, I'm sure".
7. Delete Group.
8. As a logged in administrator in Xylok, navigate to User Menu <username> >> Database Admin >> Groups.
9. Select Group(s) to delete.
10. Click on down arrow in "Action".
11. Select "Delete selected users".
12. Click "Go".
13. Click "Yes, I'm sure".

Check Contents

Verify the local accounts and groups are associated with AD and that user privileges are correct. Check accounts as a logged in administrator in Xylok.

1. Verify there are no local users. Navigate to User Menu <username> >> Database Admin >> Users.
If any local user(s) exist or users(s) are not current in AD, this is a finding.
If any users have privileged access that do not require that access, this is a finding.
2. Verify there are no removed or local groups. Navigate to User Menu <username> >> Database Admin >> Groups .
Verify the only groups exist are created by AD and are currently being used by AD.
If any groups exist that are not actively being used by AD, this is a finding.

Vulnerability Number

V-269581

Documentable

False

Rule Version

XYLK-20-000137

Severity Override Guidance

Verify the local accounts and groups are associated with AD and that user privileges are correct. Check accounts as a logged in administrator in Xylok.

1. Verify there are no local users. Navigate to User Menu <username> >> Database Admin >> Users.
If any local user(s) exist or users(s) are not current in AD, this is a finding.
If any users have privileged access that do not require that access, this is a finding.
2. Verify there are no removed or local groups. Navigate to User Menu <username> >> Database Admin >> Groups .
Verify the only groups exist are created by AD and are currently being used by AD.
If any groups exist that are not actively being used by AD, this is a finding.

Check Content Reference

M

Target Key

5665