STIGQter STIGQter: STIG Summary:

VMware NSX-T Manager NDM Security Technical Implementation Guide

Version: 1

Release: 3 Benchmark Date: 26 Jul 2023

CheckedNameTitle
SV-251778r879530_ruleNSX-T Manager must restrict the use of configuration, administration, and the execution of privileged commands to authorized personnel based on organization-defined roles.
SV-251779r879546_ruleThe NSX-T Manager must be configured to enforce the limit of three consecutive invalid logon attempts, after which time it must block any login attempt for 15 minutes.
SV-251780r919231_ruleThe NSX-T Manager must enforce a minimum 15-character password length.
SV-251781r916342_ruleThe NSX-T Manager must terminate the device management session at the end of the session or after 10 minutes of inactivity.
SV-251782r879746_ruleThe NSX-T Manager must be configured to synchronize internal information system clocks using redundant authoritative time sources.
SV-251783r879747_ruleThe NSX-T Manager must record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC).
SV-251784r879773_ruleThe NSX-T Manager must prohibit the use of cached authenticators after an organization-defined time period.
SV-251785r879806_ruleThe NSX-T Manager must be configured to protect against known types of denial-of-service (DoS) attacks by employing organization-defined security safeguards.
SV-251786r879870_ruleThe NSX-T Manager must generate audit records when successful/unsuccessful attempts to delete administrator privileges occur.
SV-251787r879886_ruleThe NSX-T Manager must be configured to send logs to a central log server.
SV-251788r879887_ruleThe NSX-T Manager must generate log records for the info level to capture the DoD-required auditable events.
SV-251789r916111_ruleThe NSX-T Manager must integrate with either VMware Identity Manager (vIDM) or VMware Workspace ONE Access.
SV-251790r916221_ruleThe NSX-T Manager must be configured to conduct backups on an organizationally defined schedule.
SV-251791r879887_ruleThe NSX-T Manager must support organizational requirements to conduct backups of information system documentation, including security-related documentation, when changes occur or weekly, whichever is sooner.
SV-251792r879887_ruleThe NSX-T Manager must obtain its public key certificates from an approved DoD certificate authority.
SV-251793r916114_ruleThe NSX-T Manager must be configured to send log data to a central log server for the purpose of forwarding alerts to the administrators and the Information System Security Officer (ISSO).
SV-251794r879887_ruleThe NSX-T Manager must be running a release that is currently supported by the vendor.
SV-251795r879588_ruleThe NSX-T Manager must not provide environment information to third parties.
SV-251796r879588_ruleThe NSX-T Manager must disable SSH.
SV-251797r879588_ruleThe NSX-T Manager must disable unused local accounts.
SV-251798r879588_ruleThe NSX-T Manager must disable TLS 1.1 and enable TLS 1.2.
SV-251799r879588_ruleThe NSX-T Manager must disable SNMP v2.
SV-251800r879588_ruleThe NSX-T Manager must enable the global FIPS compliance mode for load balancers.