STIGQter STIGQter: STIG Summary: VMware vSphere 8.0 vCenter Security Technical Implementation Guide Version: 2 Release: 4 Benchmark Date: 01 Jul 2026:

The vCenter Server must have new Key Encryption Keys (KEKs) reissued at regular intervals for vSAN encrypted datastore(s).

DISA Rule

SV-258954r1003610_rule

Vulnerability Number

V-258954

Group Title

SRG-APP-000516

Rule Version

VCSA-80-000287

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If vSAN encryption is in use, ensure a regular rekey procedure is in place.

To generate new encryption keys for vSAN, do the following:

From the vSphere Client, go to Host and Clusters.

Select the vCenter Server >> Select the cluster >> Configure >> vSAN >> Services >> Data Services.

Select "Generate New Encryption Keys" and optionally generate new DEKs and click "Generate".

Check Contents

If vSAN is not in use, this is not applicable.

Interview the system administrator (SA) to determine that a procedure has been put in place to perform a shallow rekey of all vSAN encrypted datastores at regular, site-defined intervals.

VMware recommends a 60-day rekey task, but this interval must be defined by the SA and the ISSO.

If vSAN encryption is not in use, this is not a finding.

If vSAN encryption is in use and a regular rekey procedure is not in place, this is a finding.

Vulnerability Number

V-258954

Documentable

False

Rule Version

VCSA-80-000287

Severity Override Guidance

If vSAN is not in use, this is not applicable.

Interview the system administrator (SA) to determine that a procedure has been put in place to perform a shallow rekey of all vSAN encrypted datastores at regular, site-defined intervals.

VMware recommends a 60-day rekey task, but this interval must be defined by the SA and the ISSO.

If vSAN encryption is not in use, this is not a finding.

If vSAN encryption is in use and a regular rekey procedure is not in place, this is a finding.

Check Content Reference

M

Target Key

5573