STIGQter STIGQter: STIG Summary:

AvePoint Fly Server Security Technical Implementation Guide

Version: 1

Release: 1 Benchmark Date: 28 Apr 2026

CheckedNameTitle
SV-283924r1206887_ruleFly Server must limit the number of concurrent sessions for all accounts and/or account types.
SV-283925r1206871_ruleFly Server must automatically disable accounts after a 35-day period of account inactivity.
SV-283926r1206132_ruleFly Server must enforce the limit of three consecutive invalid logon attempts by a user during a 15 minute time period.
SV-283927r1206911_ruleFly Server must be configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL) and vulnerability assessments.
SV-283928r1223356_ruleFly Server must use an approved DoW enterprise identity, credential, and access management (ICAM) solution to uniquely identify and authenticate organizational users.
SV-283929r1206891_ruleFly Server must enforce a minimum 15-character password length.
SV-283930r1206893_ruleFly Server must enforce password complexity by requiring that at least one uppercase character be used.
SV-283931r1206876_ruleFly Server must enforce password complexity by requiring that at least one lowercase character be used.
SV-283932r1206878_ruleFly Server must enforce password complexity by requiring that at least one numeric character be used.
SV-283933r1206880_ruleFly Server must enforce password complexity by requiring that at least one special character be used.
SV-283934r1206156_ruleFly Server must require the change of at least eight of the total number of characters when passwords are changed.
SV-283935r1206159_ruleFly Server must enforce 24 hours/1 day as the minimum password lifetime.
SV-283936r1206162_ruleFly Server must terminate sessions after 10 minutes.
SV-283937r1206895_ruleFly Server must notify system administrators (SAs) and the information system security officer (ISSO) for all account-related events.
SV-283938r1223357_ruleFly Server must have no local accounts for the user interface.
SV-283939r1223358_ruleFly Server must have local authentication disabled.
SV-283941r1223361_ruleFly Server must only allow the use of DoW PKI established certificate authorities for verification of the establishment of protected sessions.
SV-283942r1223359_ruleFly Server must be configured to use an enterprise database solution.
SV-284007r1207111_ruleFly Server must enforce a role-based access control (RBAC) policy over defined subjects and objects.
SV-284030r1206442_ruleFly Server must automatically check for updates weekly.
SV-284031r1206445_ruleFly Server must be updated within 30 days of an update release.
SV-284032r1206448_ruleFly Server must be a version supported by the vendor.