STIGQter STIGQter: STIG Summary: VMware vSphere 8.0 vCenter Security Technical Implementation Guide Version: 2 Release: 4 Benchmark Date: 01 Jul 2026:

The vCenter server configuration must be backed up on a regular basis.

DISA Rule

SV-258958r961863_rule

Vulnerability Number

V-258958

Group Title

SRG-APP-000516

Rule Version

VCSA-80-000292

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Option 1:

Implement and document a VMware-supported storage/image-based backup schedule.

Option 2:

To configure vCenter native backup functionality, open the VAMI by navigating to https://<vCenter server>:5480.

Log in with local operating system administrative credentials or with an SSO account that is a member of the "SystemConfiguration.BashShellAdministrator" group.

Select "Backup" on the left navigation pane.

On the resulting pane on the right, click "Configure" (or "Edit" for an existing configuration).

Enter site-specific information for the backup job.

Ensure "Schedule" is set to "Daily". Limiting the number of retained backups is recommended but not required.

Click "Create".

Check Contents

Option 1:

If vCenter is backed up in a traditional manner, at the storage array level, interview the SA to determine configuration and schedule.

Option 2:

For vCenter native backup functionality, open the Virtual Appliance Management Interface (VAMI) by navigating to https://<vCenter server>:5480.

Log in with local operating system administrative credentials or with a Single Sign-On (SSO) account that is a member of the "SystemConfiguration.BashShellAdministrator" group.

Select "Backup" on the left navigation pane.

On the resulting pane on the right, verify the "Status" is "Enabled".

Click "Status" to expand the backup details.

If vCenter server backups are not configured and there is no other vCenter backup system, this is a finding.

If the backup configuration is not set to a proper, reachable location or if the schedule is anything less frequent than "Daily", this is a finding.

Vulnerability Number

V-258958

Documentable

False

Rule Version

VCSA-80-000292

Severity Override Guidance

Option 1:

If vCenter is backed up in a traditional manner, at the storage array level, interview the SA to determine configuration and schedule.

Option 2:

For vCenter native backup functionality, open the Virtual Appliance Management Interface (VAMI) by navigating to https://<vCenter server>:5480.

Log in with local operating system administrative credentials or with a Single Sign-On (SSO) account that is a member of the "SystemConfiguration.BashShellAdministrator" group.

Select "Backup" on the left navigation pane.

On the resulting pane on the right, verify the "Status" is "Enabled".

Click "Status" to expand the backup details.

If vCenter server backups are not configured and there is no other vCenter backup system, this is a finding.

If the backup configuration is not set to a proper, reachable location or if the schedule is anything less frequent than "Daily", this is a finding.

Check Content Reference

M

Target Key

5573