STIGQter STIGQter: STIG Summary: Nutanix Acropolis Application Server Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Jan 2026:

Nutanix AOS must employ cryptographic mechanisms to ensure confidentiality and integrity of all information at rest when stored offline.

DISA Rule

SV-279447r1192582_rule

Vulnerability Number

V-279447

Group Title

SRG-APP-000231-AS-000156

Rule Version

NXAC-AS-000047

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Nutanix VM application server to use data-at-rest encryption when stored offline.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to "Data-at-Rest Encryption".
4. Select "Edit configuration".
5. Select either the cluster local KMS or an external KMS.
6. Click "Protect" and confirm by typing "ENCRYPT".

Check Contents

Confirm the Nutanix VM application server is set to use data-at-rest encryption when stored offline.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to "Data-at-Rest Encryption".
4. Verify software encryption is enabled.

If software encryption is not enabled, this is a finding.

Vulnerability Number

V-279447

Documentable

False

Rule Version

NXAC-AS-000047

Severity Override Guidance

Confirm the Nutanix VM application server is set to use data-at-rest encryption when stored offline.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to "Data-at-Rest Encryption".
4. Verify software encryption is enabled.

If software encryption is not enabled, this is a finding.

Check Content Reference

M

Target Key

5729