Skip to content

I - Mission Critical Public

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000516

    Group
  • The vCenter Server must use secure Lightweight Directory Access Protocol (LDAPS) when adding an LDAP identity source.

    LDAP is an industry standard protocol for querying directory services such as Active Directory. This protocol can operate in clear text or over a Secure Sockets Layer (SSL)/Transport Layer Security...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The vCenter Server must limit membership to the "SystemConfiguration.BashShellAdministrators" Single Sign-On (SSO) group.

    vCenter SSO integrates with PAM in the underlying Photon operating system so members of the "SystemConfiguration.BashShellAdministrators" SSO group can log on to the operating system without needin...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The vCenter Server must limit membership to the "TrustedAdmins" Single Sign-On (SSO) group.

    The vSphere "TrustedAdmins" group grants additional rights to administer the vSphere Trust Authority feature. To force accountability and nonrepudiation, the SSO group "TrustedAdmins" must be seve...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The vCenter server configuration must be backed up on a regular basis.

    vCenter server is the control plane for the vSphere infrastructure and all the workloads it hosts. As such, vCenter is usually a highly critical system in its own right. Backups of vCenter can now ...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The vCenter server must have task and event retention set to at least 30 days.

    vCenter tasks and events contain valuable historical actions, useful in troubleshooting availability issues and for incident forensics. While vCenter events are sent to central log servers in real ...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The vCenter server Native Key Provider must be backed up with a strong password.

    The vCenter Native Key Provider feature was introduced in 7.0 U2 and acts as a key provider for encryption-based capabilities such as encrypted virtual machines without requiring an external KMS so...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The vCenter server must require authentication for published content libraries.

    In the vSphere Client, you can create a local or a subscribed content library. By using content libraries, you can store and manage content in one vCenter Server instance. Alternatively, you can di...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The vCenter server must enable the OVF security policy for content libraries.

    In the vSphere Client, you can create a local or a subscribed content library. By using content libraries, you can store and manage content in one vCenter Server instance. Alternatively, you can di...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The vCenter Server must separate authentication and authorization for administrators.

    Many organizations do both authentication and authorization using a centralized directory service such as Active Directory. Attackers who compromise an identity source can often add themselves to a...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The vCenter Server must disable CDP/LLDP on distributed switches.

    The vSphere Distributed Virtual Switch can participate in Cisco Discovery Protocol (CDP) or Link Layer Discovery Protocol (LLDP), as a listener, advertiser, or both. The information is sensitive, i...
    Rule Low Severity
  • SRG-APP-000516

    Group
  • The vCenter Server must remove unauthorized port mirroring sessions on distributed switches.

    The vSphere Distributed Virtual Switch can enable port mirroring sessions allowing traffic to be mirrored from one source to a destination. If port mirroring is configured unknowingly this could al...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The vCenter Server must not override port group settings at the port level on distributed switches.

    Port-level configuration overrides are disabled by default. Once enabled, this allows for different security settings to be set from what is established at the Port Group level. If overrides are no...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The vCenter Server must reset port configuration when virtual machines are disconnected.

    Port-level configuration overrides are disabled by default. Once enabled, this allows for different security settings to be set from what is established at the Port Group level. If overrides are no...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The vCenter Server must disable Secure Shell (SSH) access.

    vCenter Server is delivered as an appliance, and intended to be managed through the VAMI, vSphere Client, and APIs. SSH is a troubleshooting and support tool and should only be enabled when necessa...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The vCenter Server must enable data in transit encryption for vSAN.

    Transit encryption must be enabled to prevent unauthorized disclosure information and to protect the confidentiality of organizational information. vSAN data-in-transit encryption has the followin...
    Rule Medium Severity
  • SRG-APP-000014

    Group
  • The vCenter Server must use DOD-approved encryption to protect the confidentiality of network sessions.

    Using older unauthorized versions or incorrectly configuring protocol negotiation makes the gateway vulnerable to known and unknown attacks that exploit vulnerabilities in this protocol. In vCente...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The vCenter Server must disable accounts used for Integrated Windows Authentication (IWA).

    If not used for their intended purpose, default accounts must be disabled. vCenter ships with several default accounts, two of which are specific to IWA and SASL/Kerberos authentication. If other m...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules