STIGQter STIGQter: STIG Summary: AvePoint Fly Server Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

Fly Server must enforce a role-based access control (RBAC) policy over defined subjects and objects.

DISA Rule

SV-284007r1207111_rule

Vulnerability Number

V-284007

Group Title

SRG-APP-000329

Rule Version

FLYS-00-000805

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

RBAC hierarchy is to be defined by the AO. Separation of duties must be configured.

Configure the Fly Server Role settings:
- Log on to Fly Server Manager with an admin account.
- On the Management >> Role Manager tab, configure two or more roles.

Configure the role assignments:
- On the Management >> Account Manager tab, assign a unique role to two or more users. Add users if necessary.

Check Contents

RBAC hierarchy is to be defined by the authorizing official (AO). Separation of duties must be configured.

Check the Fly Server Role settings:
- Log on to Fly Server Manager with an admin account.
- On the Management >> Role Manager tab, view the configured roles.

If only one role exists, this is a finding.

Check the role assignments:
- On the Management >> Account Manager tab, view the Role column.

If only one role is assigned, this is a finding.

If only one user exists in the list of users, this is a finding.

Vulnerability Number

V-284007

Documentable

False

Rule Version

FLYS-00-000805

Severity Override Guidance

RBAC hierarchy is to be defined by the authorizing official (AO). Separation of duties must be configured.

Check the Fly Server Role settings:
- Log on to Fly Server Manager with an admin account.
- On the Management >> Role Manager tab, view the configured roles.

If only one role exists, this is a finding.

Check the role assignments:
- On the Management >> Account Manager tab, view the Role column.

If only one role is assigned, this is a finding.

If only one user exists in the list of users, this is a finding.

Check Content Reference

M

Target Key

5747