Skip to content

VMware vSphere 7.0 Virtual Machine Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-OS-000480-VMM-002000

    Group
  • Copy operations must be disabled on the virtual machine (VM).

    Copy and paste operations are disabled by default; however, explicitly disabling this feature will enable audit controls to verify this setting is correct. Copy, paste, drag and drop, or GUI copy/p...
    Rule Low Severity
  • SRG-OS-000480-VMM-002000

    Group
  • Drag and drop operations must be disabled on the virtual machine (VM).

    Copy and paste operations are disabled by default; however, explicitly disabling this feature will enable audit controls to verify this setting is correct. Copy, paste, drag and drop, or GUI copy/p...
    Rule Low Severity
  • SRG-OS-000480-VMM-002000

    Group
  • Paste operations must be disabled on the virtual machine (VM).

    Copy and paste operations are disabled by default; however, explicitly disabling this feature will enable audit controls to verify this setting is correct. Copy, paste, drag and drop, or GUI copy/p...
    Rule Low Severity
  • SRG-OS-000480-VMM-002000

    Group
  • SRG-OS-000480-VMM-002000

    Group
  • Virtual disk wiping must be disabled on the virtual machine (VM).

    Shrinking and wiping (erasing) a virtual disk reclaims unused space in it. If there is empty space in the disk, this process reduces the amount of space the virtual disk occupies on the host drive....
    Rule Medium Severity
  • SRG-OS-000480-VMM-002000

    Group
  • Independent, nonpersistent disks must not be used on the virtual machine (VM).

    The security issue with nonpersistent disk mode is that successful attackers, with a simple shutdown or reboot, might undo or remove any traces they were ever on the machine. To safeguard against t...
    Rule Medium Severity
  • SRG-OS-000480-VMM-002000

    Group
  • SRG-OS-000480-VMM-002000

    Group
  • Unauthorized floppy devices must be disconnected on the virtual machine (VM).

    Ensure no device is connected to a virtual machine if it is not required. For example, floppy, serial, and parallel ports are rarely used for virtual machines in a data center environment, and CD/D...
    Rule Medium Severity
  • SRG-OS-000480-VMM-002000

    Group
  • Unauthorized CD/DVD devices must be disconnected on the virtual machine (VM).

    Ensure no device is connected to a virtual machine if it is not required. For example, floppy, serial, and parallel ports are rarely used for virtual machines in a data center environment, and CD/D...
    Rule Low Severity
  • SRG-OS-000480-VMM-002000

    Group
  • Unauthorized parallel devices must be disconnected on the virtual machine (VM).

    Ensure no device is connected to a virtual machine if it is not required. For example, floppy, serial, and parallel ports are rarely used for virtual machines in a data center environment, and CD/D...
    Rule Medium Severity
  • SRG-OS-000480-VMM-002000

    Group
  • Unauthorized serial devices must be disconnected on the virtual machine (VM).

    Ensure no device is connected to a virtual machine if it is not required. For example, floppy, serial, and parallel ports are rarely used for virtual machines in a datacenter environment, and CD/DV...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules