STIGQter STIGQter: STIG Summary: VMware vSphere 7.0 vCenter Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 24 Jan 2024:

The vCenter Server must have new Key Encryption Keys (KEKs) reissued at regular intervals for vSAN encrypted datastore(s).

DISA Rule

SV-256367r885712_rule

Vulnerability Number

V-256367

Group Title

SRG-APP-000516

Rule Version

VCSA-70-000287

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If vSAN encryption is in use, ensure a regular rekey procedure is in place.

Check Contents

If vSAN is not in use, this is not applicable.

Interview the system administrator (SA) to determine that a procedure has been put in place to perform a shallow rekey of all vSAN encrypted datastores at regular, site-defined intervals.

VMware recommends a 60-day rekey task, but this interval must be defined by the SA and the information system security officer (ISSO).

If vSAN encryption is not in use, this is not a finding.

If vSAN encryption is in use and a regular rekey procedure is not in place, this is a finding.

Vulnerability Number

V-256367

Documentable

False

Rule Version

VCSA-70-000287

Severity Override Guidance

If vSAN is not in use, this is not applicable.

Interview the system administrator (SA) to determine that a procedure has been put in place to perform a shallow rekey of all vSAN encrypted datastores at regular, site-defined intervals.

VMware recommends a 60-day rekey task, but this interval must be defined by the SA and the information system security officer (ISSO).

If vSAN encryption is not in use, this is not a finding.

If vSAN encryption is in use and a regular rekey procedure is not in place, this is a finding.

Check Content Reference

M

Target Key

5517