STIGQter STIGQter: STIG Summary:

Red Hat Ansible Automation Controller Application Server Security Technical Implementation Guide

Version: 2

Release: 4 Benchmark Date: 05 Jan 2026

CheckedNameTitle
SV-256896r960735_ruleAutomation Controller must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.
SV-256897r960759_ruleAutomation Controller must use encryption strength in accordance with the categorization of the management data during remote access management sessions.
SV-256898r1107643_ruleAutomation Controller must implement cryptography mechanisms to protect the integrity of information.
SV-256899r960843_ruleThe Automation Controller management interface must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the system.
SV-256900r960864_ruleAutomation Controller must use external log providers that can collect user activity logs in independent, protected repositories to prevent modification or repudiation.
SV-256901r1043188_ruleAutomation Controller must allocate log record storage capacity and shut down by default upon log failure (unless availability is an overriding concern).
SV-256902r1043188_ruleAutomation Controller must be configured to fail over to another system in the event of log subsystem failure.
SV-256903r1155081_ruleAutomation Controller's log files must be accessible by explicitly defined privilege.
SV-256904r960960_ruleAutomation Controller must be capable of reverting to the last known good configuration in the event of failed installations and upgrades.
SV-256905r1051118_ruleAutomation Controller must be configured to use an enterprise user management system.
SV-256906r1015790_ruleAutomation Controller must be configured to authenticate users individually, prior to using a group authenticator.
SV-256907r961029_ruleAutomation Controller must utilize encryption when using LDAP for authentication.
SV-256908r961206_ruleAutomation Controller must use cryptographic mechanisms to protect the integrity of log tools.
SV-256909r1015791_ruleAutomation Controller must compare internal application server clocks at least every 24 hours with an authoritative time source.
SV-256910r961596_ruleAutomation Controller must only allow the use of DOD PKI-established certificate authorities for verification of the establishment of protected sessions.
SV-256911r1137612_ruleAutomation Controller must install security-relevant software updates within the time period directed by an authoritative source (e.g. IAVM, CTOs, DTMs, and STIGs).