III - Administrative Sensitive
Rules and Groups employed by this XCCDF Profile
-
SRG-APP-000516
<GroupDescription></GroupDescription>Group -
The vCenter Server must limit membership to the "SystemConfiguration.BashShellAdministrators" Single Sign-On (SSO) group.
<VulnDiscussion>vCenter SSO integrates with PAM in the underlying Photon operating system so members of the "SystemConfiguration.BashShellAdm...Rule Medium Severity -
SRG-APP-000516
<GroupDescription></GroupDescription>Group -
The vCenter Server must limit membership to the "TrustedAdmins" Single Sign-On (SSO) group.
<VulnDiscussion>The vSphere "TrustedAdmins" group grants additional rights to administer the vSphere Trust Authority feature. To force accou...Rule Medium Severity -
SRG-APP-000516
<GroupDescription></GroupDescription>Group -
The vCenter server configuration must be backed up on a regular basis.
<VulnDiscussion>vCenter server is the control plane for the vSphere infrastructure and all the workloads it hosts. As such, vCenter is usuall...Rule Medium Severity -
SRG-APP-000516
<GroupDescription></GroupDescription>Group -
The vCenter server must have task and event retention set to at least 30 days.
<VulnDiscussion>vCenter tasks and events contain valuable historical actions, useful in troubleshooting availability issues and for incident ...Rule Medium Severity -
SRG-APP-000516
<GroupDescription></GroupDescription>Group -
The vCenter server Native Key Provider must be backed up with a strong password.
<VulnDiscussion>The vCenter Native Key Provider feature was introduced in 7.0 U2 and acts as a key provider for encryption-based capabilities...Rule Medium Severity -
SRG-APP-000516
<GroupDescription></GroupDescription>Group -
The vCenter server must require authentication for published content libraries.
<VulnDiscussion>In the vSphere Client, you can create a local or a subscribed content library. By using content libraries, you can store and ...Rule Medium Severity -
SRG-APP-000516
<GroupDescription></GroupDescription>Group -
The vCenter server must enable the OVF security policy for content libraries.
<VulnDiscussion>In the vSphere Client, you can create a local or a subscribed content library. By using content libraries, you can store and ...Rule Medium Severity -
SRG-APP-000516
<GroupDescription></GroupDescription>Group -
The vCenter Server must separate authentication and authorization for administrators.
<VulnDiscussion>Many organizations do both authentication and authorization using a centralized directory service such as Active Directory. A...Rule Medium Severity -
SRG-APP-000516
<GroupDescription></GroupDescription>Group -
The vCenter Server must disable CDP/LLDP on distributed switches.
<VulnDiscussion>The vSphere Distributed Virtual Switch can participate in Cisco Discovery Protocol (CDP) or Link Layer Discovery Protocol (LL...Rule Low Severity -
SRG-APP-000516
<GroupDescription></GroupDescription>Group -
The vCenter Server must remove unauthorized port mirroring sessions on distributed switches.
<VulnDiscussion>The vSphere Distributed Virtual Switch can enable port mirroring sessions allowing traffic to be mirrored from one source to ...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.