STIGQter STIGQter: STIG Summary:

Nutanix Acropolis Application Server Security Technical Implementation Guide

Version: 1

Release: 1 Benchmark Date: 26 Jan 2026

CheckedNameTitle
SV-279415r1191367_ruleNutanix AOS must limit the number of concurrent sessions to 10 for all accounts and/or account types.
SV-279416r1191034_ruleNutanix AOS must automatically terminate a user session after a maximum of 15 minutes for nonprivileged users.
SV-279418r1191040_ruleNutanix AOS must have TLS enabled.
SV-279421r1192347_ruleNutanix AOS must configure role mapping.
SV-279422r1191052_ruleNutanix AOS server management interface must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the system.
SV-279423r1191055_ruleNutanix AOS must protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by nonrepudiation.
SV-279424r1191058_ruleNutanix AOS must off-load log records onto a different system or media from the system being logged.
SV-279425r1192580_ruleNutanix Cluster Check (NCC) must be configured to provide alerts to the system administrator (SA) and information system security officer (ISSO), immediately when audit storage reaches 75 percent capacity.
SV-279426r1191064_ruleNutanix AOS must use internal system clocks to generate time stamps for log records.
SV-279427r1191067_ruleNutanix AOS must be configured to protect the application server log files from unauthorized access.
SV-279430r1191372_ruleNutanix AOS must configure the Nutanix Cluster Check (NCC) to alert the information system security officer (ISSO)/information system security manager (ISSM) or designated personnel, at a minimum.
SV-279431r1191079_ruleNutanix AOS must enforce access restrictions associated with changes to configuration and software libraries.
SV-279433r1191374_ruleNutanix AOS must use an enterprise user management system to uniquely identify and authenticate users (or processes acting on behalf of organizational users).
SV-279434r1192622_ruleNutanix AOS must use multifactor authentication for access to privileged and nonprivileged accounts by enabling common access card (CAC) authentication.
SV-279435r1191091_ruleNutanix AOS must use multifactor authentication for local access to privileged accounts.
SV-279438r1191100_ruleNutanix AOS must authenticate users individually prior to using a group authenticator.
SV-279439r1191103_ruleNutanix AOS must use multifactor authentication (MFA) for access to privileged and nonprivileged accounts by enabling client authentication.
SV-279440r1191106_ruleNutanix AOS must use encryption when using LDAP for authentication.
SV-279441r1191109_ruleNutanix VMM must terminate UI network connections associated with a communications session at the end of the session for in-band management sessions (privileged sessions), the session must be terminated after 10 minutes of inactivity.
SV-279442r1192581_ruleNutanix AOS must perform RFC 5280-compliant certification path validation.
SV-279443r1192354_ruleNutanix AOS must accept Federal Identity, Credential, and Access Management (FICAM)-approved third-party credentials.
SV-279444r1192356_ruleNutanix AOS must conform to Federal Identity, Credential, and Access Management (FICAM)-issued profiles.
SV-279445r1192540_ruleNutanix AOS must be configured to use DOD PKI-issued certificates.
SV-279446r1192360_ruleNutanix AOS must protect the confidentiality and integrity of all information at rest.
SV-279447r1192582_ruleNutanix AOS must employ cryptographic mechanisms to ensure confidentiality and integrity of all information at rest when stored offline.
SV-279448r1192364_ruleNutanix AOS must implement cryptographic mechanisms to prevent unauthorized access to data at rest.
SV-279450r1192366_ruleNutanix AOS must configure Network Time Protocol (NTP).
SV-279451r1192368_ruleNutanix AOS must restrict error messages only to authorized users.
SV-279464r1192371_ruleNutanix UI must initiate session logging upon startup.
SV-279486r1192542_ruleNutanix VMM must separate user functionality (including user interface services) from VMM management functionality.
SV-279526r1191364_ruleAll guest VM network communications must be implemented using virtual network devices provisioned and serviced by the VMM.