STIGQter STIGQter: STIG Summary: VMW vSphere 6.5 vCenter Server for Windows Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 22 Jan 2021:

The vCenter Server for Windows must minimize access to the vCenter server.

DISA Rule

SV-216849r612237_rule

Vulnerability Number

V-216849

Group Title

SRG-APP-000516

Rule Version

VCWN-65-000027

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Remove all unnecessary users and/or groups from the local administrators group of the vCenter server.

Check Contents

Login to the vCenter server and verify the only local administrators group contains users and/or groups that contain vCenter Administrators.

If the local administrators group contains users and/or groups that are not vCenter Administrators such as "Domain Admins", this is a finding.

Vulnerability Number

V-216849

Documentable

False

Rule Version

VCWN-65-000027

Severity Override Guidance

Login to the vCenter server and verify the only local administrators group contains users and/or groups that contain vCenter Administrators.

If the local administrators group contains users and/or groups that are not vCenter Administrators such as "Domain Admins", this is a finding.

Check Content Reference

M

Target Key

4030

Comments