STIGQter STIGQter: STIG Summary:

F5 NGINX Security Technical Implementation Guide

Version: 1

Release: 1 Benchmark Date: 25 Nov 2025

CheckedNameTitle
SV-278380r1172745_ruleNGINX must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.
SV-278381r1171895_ruleNGINX must use TLS 1.2, at a minimum, to protect data confidentiality using remote access.
SV-278382r1171898_ruleThe NGINX service account must be configured to not have shell access.
SV-278383r1171901_ruleThe NGINX service account must be configured to not have admin group access.
SV-278384r1171904_ruleNGINX must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the application.
SV-278385r1171907_ruleNGINX must provide audit records for DOD-defined auditable events.
SV-278386r1171910_ruleNGINX must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.
SV-278387r1172701_ruleNGINX must prevent the execution of unapproved modules.
SV-278388r1171916_ruleNGINX must protect audit information from unauthorized access.
SV-278389r1172704_ruleNGINX must be configured to prohibit or restrict using ports, protocols, and/or services.
SV-278390r1172747_ruleNGINX must implement replay-resistant authentication mechanisms for network access.
SV-278391r1171925_ruleNGINX must be configured to use a Certificate Revocation List (CRL) for certificate path validation and revocation. (Online Certificate Status Protocol [OCSP] is the preferred configuration.)
SV-278392r1171928_ruleNGINX, when using PKI-based authentication, must enforce authorized access to the corresponding private key.
SV-278393r1171931_ruleNGINX must identify prohibited mobile code.
SV-278394r1171934_ruleNGINX must restrict the ability of individuals to launch denial-of-service (DoS) attacks against other information systems.
SV-278395r1172748_ruleNGINX must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
SV-278396r1172699_ruleNGINX must off-load audit records to a central log server.
SV-278397r1171943_ruleNGINX must restrict access to configuration files.
SV-278398r1171946_ruleNGINX must be configured with a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
SV-278399r1172775_ruleNGINX must be configured to require SSL sessions to reauthenticate no longer than 15 minutes.
SV-278400r1172752_ruleNGINX must accept Personal Identity Verification (PIV) credentials.
SV-278401r1171955_ruleNGINX must be configured to expire cached authenticators after an organization-defined time period.
SV-278402r1171958_ruleNGINX must be configured to pass security attributes to proxies.
SV-278403r1171961_ruleNGINX must only allow using DOD approved certificate authorities for PKI.
SV-278404r1171964_ruleNGINX must protect against denial-of-service (DoS) attacks.
SV-278405r1171967_ruleNGINX must be configured to use FIPS-approved algorithms to protect the confidentiality and integrity of transmitted information.
SV-278406r1171970_ruleNGINX must be configured to use Online Certificate Status Protocol (OCSP) for certificate path validation and revocation. (OCSP is the preferred configuration.)
SV-278407r1172754_ruleNGINX must be configured to use a FIPS-validated cryptographic module for confidentiality and integrity.
SV-278408r1171976_ruleThe NGINX service account must be configured to lock changes to the password.
SV-278409r1171979_ruleNGINX must separate API maintenance sessions from other network sessions within the system by logically separated communications paths.
SV-278410r1172694_ruleNGINX must generate, manage, and protect from disclosure and misuse the cryptographic keys that protect access tokens.
SV-278411r1172756_ruleNGINX must revoke access tokens in accordance with organization-defined identification and authentication policy.