| Checked | Name | Title |
|---|
| ☐ | SV-276001r1122653_rule | Ax-OS must limit the number of concurrent sessions to 10 for all accounts and/or account types. |
| ☐ | SV-276002r1122656_rule | Ax-OS must automatically terminate a graphical user interface (GUI) user session after 15 minutes. |
| ☐ | SV-276003r1122659_rule | Ax-OS must automatically terminate a Secure Shell (SSH) user session after 15 minutes. |
| ☐ | SV-276004r1122662_rule | Ax-OS must implement DOD-approved encryption to protect the confidentiality of remote access sessions. |
| ☐ | SV-276005r1122665_rule | Ax-OS must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies. |
| ☐ | SV-276006r1122668_rule | Ax-OS must display the Standard Mandatory DOD Notice and Consent Banner before granting access to Ax-OS. |
| ☐ | SV-276007r1122671_rule | Ax-OS must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the Toolbox. |
| ☐ | SV-276008r1122674_rule | Ax-OS password manager must be disabled. |
| ☐ | SV-276009r1122677_rule | Ax-OS must use multifactor authentication for network access to the customer account. |
| ☐ | SV-276010r1122680_rule | Ax-OS must use multifactor authentication for network access to the files account. |
| ☐ | SV-276011r1123259_rule | Ax-OS must use multifactor authentication for network access to nonprivileged accounts. |
| ☐ | SV-276012r1156548_rule | Ax-OS must have no local accounts for the user interface. |
| ☐ | SV-276013r1122689_rule | Ax-OS must protect the authenticity of communications sessions. |
| ☐ | SV-276014r1122692_rule | Ax-OS must off-load audit records onto a different system or media than the system being audited. |
| ☐ | SV-276015r1122695_rule | Ax-OS must implement privileged access authorization to all information systems and infrastructure components for selected organization-defined vulnerability scanning activities. |
| ☐ | SV-276016r1123260_rule | Ax-OS must compare the internal system clocks on an organization-defined frequency with an organization-defined authoritative time source. |