STIGQter STIGQter: STIG Summary: VMware vSphere 6.7 vCenter Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 09 Mar 2021:

The vCenter Server must minimize access to the vCenter server.

DISA Rule

SV-243128r719627_rule

Vulnerability Number

V-243128

Group Title

SRG-APP-000516

Rule Version

VCTR-67-000073

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Remove all unnecessary users and/or groups from the local administrators group of the vCenter server.

Check Contents

Note: For vCenter Server Appliance, this is not applicable.

Login to the vCenter server and verify the only local administrators group contains users and/or groups that contain vCenter Administrators.

If the local administrators group contains users and/or groups that are not vCenter Administrators such as "Domain Admins", this is a finding.

Vulnerability Number

V-243128

Documentable

False

Rule Version

VCTR-67-000073

Severity Override Guidance

Note: For vCenter Server Appliance, this is not applicable.

Login to the vCenter server and verify the only local administrators group contains users and/or groups that contain vCenter Administrators.

If the local administrators group contains users and/or groups that are not vCenter Administrators such as "Domain Admins", this is a finding.

Check Content Reference

M

Target Key

5399

Comments