SV-258954r1003610_rule
V-258954
SRG-APP-000516
VCSA-80-000287
CAT II
10
If vSAN encryption is in use, ensure a regular rekey procedure is in place.
To generate new encryption keys for vSAN, do the following:
From the vSphere Client, go to Host and Clusters.
Select the vCenter Server >> Select the cluster >> Configure >> vSAN >> Services >> Data Services.
Select "Generate New Encryption Keys" and optionally generate new DEKs and click "Generate".
If vSAN is not in use, this is not applicable.
Interview the system administrator (SA) to determine that a procedure has been put in place to perform a shallow rekey of all vSAN encrypted datastores at regular, site-defined intervals.
VMware recommends a 60-day rekey task, but this interval must be defined by the SA and the ISSO.
If vSAN encryption is not in use, this is not a finding.
If vSAN encryption is in use and a regular rekey procedure is not in place, this is a finding.
V-258954
False
VCSA-80-000287
If vSAN is not in use, this is not applicable.
Interview the system administrator (SA) to determine that a procedure has been put in place to perform a shallow rekey of all vSAN encrypted datastores at regular, site-defined intervals.
VMware recommends a 60-day rekey task, but this interval must be defined by the SA and the ISSO.
If vSAN encryption is not in use, this is not a finding.
If vSAN encryption is in use and a regular rekey procedure is not in place, this is a finding.
M
5573