| Checked | Name | Title |
|---|
| ☐ | SV-278380r1172745_rule | NGINX must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types. |
| ☐ | SV-278381r1171895_rule | NGINX must use TLS 1.2, at a minimum, to protect data confidentiality using remote access. |
| ☐ | SV-278382r1171898_rule | The NGINX service account must be configured to not have shell access. |
| ☐ | SV-278383r1171901_rule | The NGINX service account must be configured to not have admin group access. |
| ☐ | SV-278384r1171904_rule | NGINX must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the application. |
| ☐ | SV-278385r1171907_rule | NGINX must provide audit records for DOD-defined auditable events. |
| ☐ | SV-278386r1171910_rule | NGINX must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited. |
| ☐ | SV-278387r1172701_rule | NGINX must prevent the execution of unapproved modules. |
| ☐ | SV-278388r1171916_rule | NGINX must protect audit information from unauthorized access. |
| ☐ | SV-278389r1172704_rule | NGINX must be configured to prohibit or restrict using ports, protocols, and/or services. |
| ☐ | SV-278390r1172747_rule | NGINX must implement replay-resistant authentication mechanisms for network access. |
| ☐ | SV-278391r1171925_rule | NGINX must be configured to use a Certificate Revocation List (CRL) for certificate path validation and revocation. (Online Certificate Status Protocol [OCSP] is the preferred configuration.) |
| ☐ | SV-278392r1171928_rule | NGINX, when using PKI-based authentication, must enforce authorized access to the corresponding private key. |
| ☐ | SV-278393r1171931_rule | NGINX must identify prohibited mobile code. |
| ☐ | SV-278394r1171934_rule | NGINX must restrict the ability of individuals to launch denial-of-service (DoS) attacks against other information systems. |
| ☐ | SV-278395r1172748_rule | NGINX must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries. |
| ☐ | SV-278396r1172699_rule | NGINX must off-load audit records to a central log server. |
| ☐ | SV-278397r1171943_rule | NGINX must restrict access to configuration files. |
| ☐ | SV-278398r1171946_rule | NGINX must be configured with a deny-all, permit-by-exception policy to allow the execution of authorized software programs. |
| ☐ | SV-278399r1172775_rule | NGINX must be configured to require SSL sessions to reauthenticate no longer than 15 minutes. |
| ☐ | SV-278400r1172752_rule | NGINX must accept Personal Identity Verification (PIV) credentials. |
| ☐ | SV-278401r1171955_rule | NGINX must be configured to expire cached authenticators after an organization-defined time period. |
| ☐ | SV-278402r1171958_rule | NGINX must be configured to pass security attributes to proxies. |
| ☐ | SV-278403r1171961_rule | NGINX must only allow using DOD approved certificate authorities for PKI. |
| ☐ | SV-278404r1171964_rule | NGINX must protect against denial-of-service (DoS) attacks. |
| ☐ | SV-278405r1171967_rule | NGINX must be configured to use FIPS-approved algorithms to protect the confidentiality and integrity of transmitted information. |
| ☐ | SV-278406r1171970_rule | NGINX must be configured to use Online Certificate Status Protocol (OCSP) for certificate path validation and revocation. (OCSP is the preferred configuration.) |
| ☐ | SV-278407r1172754_rule | NGINX must be configured to use a FIPS-validated cryptographic module for confidentiality and integrity. |
| ☐ | SV-278408r1171976_rule | The NGINX service account must be configured to lock changes to the password. |
| ☐ | SV-278409r1171979_rule | NGINX must separate API maintenance sessions from other network sessions within the system by logically separated communications paths. |
| ☐ | SV-278410r1172694_rule | NGINX must generate, manage, and protect from disclosure and misuse the cryptographic keys that protect access tokens. |
| ☐ | SV-278411r1172756_rule | NGINX must revoke access tokens in accordance with organization-defined identification and authentication policy. |