Skip to content

VMware vSphere 8.0 vCenter Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • The vCenter Server must use secure Lightweight Directory Access Protocol (LDAPS) when adding an LDAP identity source.

    <VulnDiscussion>LDAP is an industry standard protocol for querying directory services such as Active Directory. This protocol can operate in ...
    Rule Medium Severity
  • SRG-APP-000516

    <GroupDescription></GroupDescription>
    Group
  • SRG-APP-000516

    <GroupDescription></GroupDescription>
    Group
  • The vCenter Server must limit membership to the "SystemConfiguration.BashShellAdministrators" Single Sign-On (SSO) group.

    &lt;VulnDiscussion&gt;vCenter SSO integrates with PAM in the underlying Photon operating system so members of the "SystemConfiguration.BashShellAdm...
    Rule Medium Severity
  • SRG-APP-000516

    <GroupDescription></GroupDescription>
    Group
  • The vCenter Server must limit membership to the "TrustedAdmins" Single Sign-On (SSO) group.

    &lt;VulnDiscussion&gt;The vSphere "TrustedAdmins" group grants additional rights to administer the vSphere Trust Authority feature. To force accou...
    Rule Medium Severity
  • SRG-APP-000516

    <GroupDescription></GroupDescription>
    Group
  • The vCenter server configuration must be backed up on a regular basis.

    &lt;VulnDiscussion&gt;vCenter server is the control plane for the vSphere infrastructure and all the workloads it hosts. As such, vCenter is usuall...
    Rule Medium Severity
  • SRG-APP-000516

    <GroupDescription></GroupDescription>
    Group
  • The vCenter server must have task and event retention set to at least 30 days.

    &lt;VulnDiscussion&gt;vCenter tasks and events contain valuable historical actions, useful in troubleshooting availability issues and for incident ...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules