STIGQter STIGQter: STIG Summary: Axonius Federal Systems Ax-OS Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Ax-OS must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.

DISA Rule

SV-276005r1122665_rule

Vulnerability Number

V-276005

Group Title

SRG-APP-000033

Rule Version

AXOS-00-000025

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Role-Based Access Control hierarchy is to be defined by the AO. Separation of duties must be configured.

Select the gear icon (System Settings) >> Access Management >> LDAP & SAML.

Depending on the multifactor type configured, under LDAP or SAML, locate "User Assignment Settings".

Assign two or more roles as defined by the AO and tie them to an LDAP/SAML user or group.

Check Contents

Role-Based Access Control hierarchy is to be defined by the authorizing official (AO). Separation of duties must be configured.

Select the gear icon (System Settings) >> Access Management >> LDAP & SAML.

Depending on the multifactor type configured, under LDAP or SAML, locate "User Assignment Settings".

If only one assigned role exists, this is a finding.

Vulnerability Number

V-276005

Documentable

False

Rule Version

AXOS-00-000025

Severity Override Guidance

Role-Based Access Control hierarchy is to be defined by the authorizing official (AO). Separation of duties must be configured.

Select the gear icon (System Settings) >> Access Management >> LDAP & SAML.

Depending on the multifactor type configured, under LDAP or SAML, locate "User Assignment Settings".

If only one assigned role exists, this is a finding.

Check Content Reference

M

Target Key

5710