Nutanix Acropolis STIG (Y26M01) Implementation Checklist
20 items · Security · Medium difficulty · 1 day
Step-by-step checklist to implement the Nutanix Acropolis STIG (Y26M01).
-
Download the Nutanix Acropolis STIG (Y26M01)
Get the official STIG from DoD Cyber Exchange or public.cyber.mil if no CAC.
-
Inventory Nutanix components and versions (AOS, AHV, CVM, Prism, Files)
Record exact versions and CPE identifiers for each component.
-
Identify applicable CPE targets and map STIG rules
Match STIG controls to relevant components (AOS, AHV, CVM, Prism, Files).
-
Deploy a representative test environment
Mirror production topology to validate changes safely.
-
Backup current cluster configuration and data
Export configs and snapshots so you can rollback if needed.
-
Apply STIG settings in the test environment
Implement recommended configuration changes from the STIG in test first.
-
Review and document functional impacts after testing
Note features affected and test application behavior for each change.
-
Obtain Authorizing Official (AO) approval for accepted deviations
Record formally any risk acceptance for settings you cannot implement.
-
Patch AOS, AHV, Prism, and CVMs to supported versions
Apply vendor patches to remediate vulnerabilities and meet STIG baselines.
-
Harden CVM and Prism access controls
Lock down management plane access, credentials, and admin interfaces.
-
Restrict SSH access to CVMs to approved management IPs
Use ACLs or firewall rules to limit admin SSH access.
-
Enable role-based access control and MFA in Prism
Assign least-privilege roles and require multifactor authentication.
-
Disable unused services and close unnecessary ports on AHV and CVM
Turn off services not required for operation to reduce attack surface.
-
Enable and centralize logging and monitoring
Forward logs to Prism Central or a SIEM for retention and alerting.
-
Configure secure networking (microsegmentation, VLANs, firewall rules)
Use segmentation to isolate management, storage, and tenant traffic.
-
Encrypt data at rest and in transit
Enable available storage and network encryption features per STIG.
-
Run vulnerability scans and check for CVEs against mapped CPEs
Use vulnerability scanners and vendor advisories to identify issues.
-
Document configuration changes and create a rollback plan
Keep change records, test rollback steps, and store backups securely.
-
Schedule regular STIG compliance audits and patch cycles
Define cadence for re-audit, patching, and reporting requirements.
-
Maintain STIG sources and operational contacts
Record DoD STIG URLs, contact emails, and support points for quick reference.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.