STIGQter STIGQter: STIG Summary: VMware vSphere 8.0 vCenter Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 31 Oct 2023:

The vCenter server must enable the OVF security policy for content libraries.

DISA Rule

SV-258962r934544_rule

Vulnerability Number

V-258962

Group Title

SRG-APP-000516

Rule Version

VCSA-80-000296

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the vSphere Client, go to Content Libraries.

Select the target content library.

Select "Actions" then "Edit Settings".

Click the checkbox to "Apply Security Policy". Click "OK".

Note: If you disable the security policy of a content library, you cannot reuse the existing OVF items.

Check Contents

From the vSphere Client, go to Content Libraries.

Review the "Security Policy" column.

If a content library does not have the "OVF default policy" enabled, this is a finding.

Vulnerability Number

V-258962

Documentable

False

Rule Version

VCSA-80-000296

Severity Override Guidance

From the vSphere Client, go to Content Libraries.

Review the "Security Policy" column.

If a content library does not have the "OVF default policy" enabled, this is a finding.

Check Content Reference

M

Target Key

5573