STIGQter STIGQter: STIG Summary: Nutanix Acropolis Application Server Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Jan 2026:

Nutanix AOS must implement cryptographic mechanisms to prevent unauthorized access to data at rest.

DISA Rule

SV-279448r1192364_rule

Vulnerability Number

V-279448

Group Title

SRG-APP-000428-AS-000265

Rule Version

NXAC-AS-000048

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Nutanix VM application server to enable data-at-rest encryption.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to "Data-at-Rest Encryption".
4. Select "Edit configuration".
5. Select either the cluster local KMS or an external KMS.
6. Click "Protect" and confirm by typing "ENCRYPT".

Check Contents

Confirm the Nutanix VM application server is configured to enable data-at-rest encryption.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to "Data-at-Rest Encryption".
4. Verify software encryption is enabled.

If encryption is not enabled, this is a finding.

Vulnerability Number

V-279448

Documentable

False

Rule Version

NXAC-AS-000048

Severity Override Guidance

Confirm the Nutanix VM application server is configured to enable data-at-rest encryption.

1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Navigate to "Data-at-Rest Encryption".
4. Verify software encryption is enabled.

If encryption is not enabled, this is a finding.

Check Content Reference

M

Target Key

5729