Nutanix Acropolis STIG Compliance Checklist
19 items · Security · Hard difficulty · 2 hours
Harden Nutanix Acropolis to DISA STIG standards with this step-by-step checklist.
-
Download the Nutanix Acropolis STIG from DISA
Obtain the latest STIG package (XCCDF) from the DoD Cyber Exchange or public site.
-
Test STIG settings in a representative lab environment
Validate functionality before applying to production to avoid service disruption.
-
Inventory Nutanix components and record installed versions
Create a baseline list of clusters, nodes, CVMs, AOS, AHV, Prism, and Files versions.
-
List AOS versions for each cluster
Record AOS release/build per cluster for patch planning.
-
List AHV versions on each host
Note AHV/hypervisor builds to identify required updates.
-
List CVM and Prism versions and IPs
Capture CVM and Prism Element/Central versions and management endpoints.
-
Patch AOS, AHV, CVM, and Prism to approved versions
Apply vendor-approved patches and security updates during maintenance windows.
-
Review and implement DISA STIG configuration settings
Map STIG controls to platform settings and implement required controls.
-
Change default accounts and enforce strong passwords
Disable or rename defaults; enforce password complexity and rotation.
-
Enable role-based access control (RBAC) and least privilege
Create roles for admins, operators, and auditors with minimal privileges.
-
Enforce TLS with valid certificates for Prism and CVM interfaces
Replace self-signed certs with CA-signed certs and disable weak ciphers.
-
Restrict management access via IP allowlists and network segmentation
Limit Prism/CVM access to management network and trusted IP ranges.
-
Disable or remove unused services and ports on AHV/CVM
Close unnecessary ports and stop unused services to reduce attack surface.
-
Configure syslog and forward logs to a centralized SIEM
Send system, audit, and security logs to an approved central collector.
-
Enable auditing and retain logs per DoD retention policy
Ensure audit trails are enabled and retention meets policy requirements.
-
Ensure NTP is configured and synchronized across the cluster
Point to approved NTP servers to maintain time consistency for logs and auth.
-
Backup configuration and create a cluster recovery plan
Export and store Prism and CVM configs; document restore procedures.
-
Scan for known CVEs and apply remediation or mitigations
Use vendor advisories and vulnerability scanners; prioritize critical fixes.
-
Document deviations, risks, and obtain AO-approved waivers
Record justification and approvals for any non-applicable or risky settings.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.