Skip to content

II - Mission Support Public

Rules and Groups employed by this XCCDF Profile

  • SRG-OS-000107-VMM-000530

    Group
  • The ESXi host Secure Shell (SSH) daemon must ignore .rhosts files.

    SSH trust relationships mean a compromise on one host can allow an attacker to move trivially to other hosts. SSH can emulate the behavior of the obsolete "rsh" command in allowing users to enable ...
    Rule Medium Severity
  • SRG-OS-000163-VMM-000700

    Group
  • The ESXi host must set a timeout to automatically end idle shell sessions after fifteen minutes.

    If a user forgets to log out of their local or remote ESXi Shell session, the idle connection will remain open indefinitely and increase the likelihood of inappropriate host access via session hija...
    Rule Medium Severity
  • SRG-OS-000257-VMM-000910

    Group
  • The ESXi host must implement Secure Boot enforcement.

    Secure Boot is part of the UEFI firmware standard. With UEFI Secure Boot enabled, a host refuses to load any UEFI driver or app unless the operating system bootloader has a valid digital signature....
    Rule Medium Severity
  • SRG-OS-000278-VMM-001000

    Group
  • The ESXi host must enable Secure Boot.

    Secure Boot is part of the Unified Extensible Firmware Interface (UEFI) firmware standard. With UEFI Secure Boot enabled, a host refuses to load any UEFI driver or app unless the operating system b...
    Rule Medium Severity
  • SRG-OS-000329-VMM-001180

    Group
  • The ESXi host must enforce an unlock timeout of 15 minutes after a user account is locked out.

    By enforcing a reasonable unlock timeout after multiple failed logon attempts, the risk of unauthorized access via user password guessing, otherwise known as brute forcing, is reduced. Users must w...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules