STIGQter STIGQter: STIG Summary:

Axonius Federal Systems Ax-OS Security Technical Implementation Guide

Version: 1

Release: 2 Benchmark Date: 05 Jan 2026

CheckedNameTitle
SV-276001r1122653_ruleAx-OS must limit the number of concurrent sessions to 10 for all accounts and/or account types.
SV-276002r1122656_ruleAx-OS must automatically terminate a graphical user interface (GUI) user session after 15 minutes.
SV-276003r1122659_ruleAx-OS must automatically terminate a Secure Shell (SSH) user session after 15 minutes.
SV-276004r1122662_ruleAx-OS must implement DOD-approved encryption to protect the confidentiality of remote access sessions.
SV-276005r1122665_ruleAx-OS must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
SV-276006r1122668_ruleAx-OS must display the Standard Mandatory DOD Notice and Consent Banner before granting access to Ax-OS.
SV-276007r1122671_ruleAx-OS must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the Toolbox.
SV-276008r1122674_ruleAx-OS password manager must be disabled.
SV-276009r1122677_ruleAx-OS must use multifactor authentication for network access to the customer account.
SV-276010r1122680_ruleAx-OS must use multifactor authentication for network access to the files account.
SV-276011r1123259_ruleAx-OS must use multifactor authentication for network access to nonprivileged accounts.
SV-276012r1156548_ruleAx-OS must have no local accounts for the user interface.
SV-276013r1122689_ruleAx-OS must protect the authenticity of communications sessions.
SV-276014r1122692_ruleAx-OS must off-load audit records onto a different system or media than the system being audited.
SV-276015r1122695_ruleAx-OS must implement privileged access authorization to all information systems and infrastructure components for selected organization-defined vulnerability scanning activities.
SV-276016r1123260_ruleAx-OS must compare the internal system clocks on an organization-defined frequency with an organization-defined authoritative time source.