Skip to content

I - Mission Critical Public

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000516

    Group
  • The vCenter server Native Key Provider must be backed up with a strong password.

    The vCenter Native Key Provider feature was introduced in 7.0 U2 and acts as a key provider for encryption-based capabilities such as encrypted virtual machines without requiring an external KMS so...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The vCenter server must require authentication for published content libraries.

    In the vSphere Client, you can create a local or a subscribed content library. By using content libraries, you can store and manage content in one vCenter Server instance. Alternatively, you can di...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The vCenter server must enable the OVF security policy for content libraries.

    In the vSphere Client, you can create a local or a subscribed content library. By using content libraries, you can store and manage content in one vCenter Server instance. Alternatively, you can di...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The vCenter Server must separate authentication and authorization for administrators.

    Many organizations do both authentication and authorization using a centralized directory service such as Active Directory. Attackers who compromise an identity source can often add themselves to a...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The vCenter Server must disable CDP/LLDP on distributed switches.

    The vSphere Distributed Virtual Switch can participate in Cisco Discovery Protocol (CDP) or Link Layer Discovery Protocol (LLDP), as a listener, advertiser, or both. The information is sensitive, i...
    Rule Low Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules