STIGQter STIGQter: STIG Summary: VMware NSX-T Manager NDM Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 26 Jul 2023:

NSX-T Manager must restrict the use of configuration, administration, and the execution of privileged commands to authorized personnel based on organization-defined roles.

DISA Rule

SV-251778r879530_rule

Vulnerability Number

V-251778

Group Title

SRG-APP-000033-NDM-000212

Rule Version

TNDM-3X-000010

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

View the SSP to determine the required organization-defined roles and the least privilege policies required for each role. For example, audit administrator, crypto administrator, system administrator, etc. Assign users to roles based on SSP and least privileges. Carefully assign capabilities to each role based on SSP role assignments. To create a new role with reduced permissions, do the following:

From the NSX-T Manager web interface, go to System >> Users and Roles >> Roles. Click "Add Role", provide a name and the required permissions, and then click "Save".

To update user or group permissions to an existing role with reduced permissions, do the following:

From the NSX-T Manager web interface, go to System >> Users and Roles >> User Role Assignment. Click the menu dropdown next to the target user or group and select "Edit". Remove the existing role, select the new one, and then click "Save".

Check Contents

From the NSX-T Manager web interface, go to System >> Users and Roles >> User Role Assignment.

View each user and group and verify the role assigned to it.

Application service account and user required privileges must be documented.

If any user/group or service account are assigned to roles with privileges that are beyond those assigned by the SSP, this is a finding.

Vulnerability Number

V-251778

Documentable

False

Rule Version

TNDM-3X-000010

Severity Override Guidance

From the NSX-T Manager web interface, go to System >> Users and Roles >> User Role Assignment.

View each user and group and verify the role assigned to it.

Application service account and user required privileges must be documented.

If any user/group or service account are assigned to roles with privileges that are beyond those assigned by the SSP, this is a finding.

Check Content Reference

M

Target Key

5449