STIGQter STIGQter: STIG Summary: VMW vRealize Automation 7.x vAMI Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Sep 2018:

The vAMI account credentials must protected by site policies.

DISA Rule

SV-100891r1_rule

Vulnerability Number

V-90241

Group Title

SRG-APP-000315-AS-000094

Rule Version

VRAU-VA-000385

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Develop and implement a site procedure to control access credentials for the vAMI.

Check Contents

Interview the ISSO and/or the SA.

Determine if access credentials for the vAMI are controlled by a site policy.

If a site policy does not exist, or is not being followed, this is a finding.

Vulnerability Number

V-90241

Documentable

False

Rule Version

VRAU-VA-000385

Severity Override Guidance

Interview the ISSO and/or the SA.

Determine if access credentials for the vAMI are controlled by a site policy.

If a site policy does not exist, or is not being followed, this is a finding.

Check Content Reference

M

Target Key

3449

Comments