| Checked | Name | Title |
|---|
| ☐ | SV-256375r958398_rule | Access to the ESXi host must be limited by enabling lockdown mode. |
| ☐ | SV-256376r959010_rule | The ESXi host must verify the DCUI.Access list. |
| ☐ | SV-256377r959010_rule | The ESXi host must verify the exception users list for lockdown mode. |
| ☐ | SV-256378r958406_rule | Remote logging for ESXi hosts must be configured. |
| ☐ | SV-256379r958388_rule | The ESXi host must enforce the limit of three consecutive invalid logon attempts by a user. |
| ☐ | SV-256380r958736_rule | The ESXi host must enforce an unlock timeout of 15 minutes after a user account is locked out. |
| ☐ | SV-256381r958390_rule | The ESXi host must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the system via the Direct Console User Interface (DCUI). |
| ☐ | SV-256382r958390_rule | The ESXi host must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the system via Secure Shell (SSH). |
| ☐ | SV-256383r958390_rule | The ESXi host SSH daemon must be configured with the DOD logon banner. |
| ☐ | SV-256384r958408_rule | The ESXi host Secure Shell (SSH) daemon must use FIPS 140-2 validated cryptographic modules to protect the confidentiality of remote access sessions. |
| ☐ | SV-256385r984206_rule | The ESXi host Secure Shell (SSH) daemon must ignore ".rhosts" files. |
| ☐ | SV-256386r959010_rule | The ESXi host Secure Shell (SSH) daemon must not allow host-based authentication. |
| ☐ | SV-256387r959010_rule | The ESXi host Secure Shell (SSH) daemon must not allow authentication using an empty password. |
| ☐ | SV-256388r959010_rule | The ESXi host Secure Shell (SSH) daemon must not permit user environment settings. |
| ☐ | SV-256389r959010_rule | The ESXi host Secure Shell (SSH) daemon must perform strict mode checking of home directory configuration files. |
| ☐ | SV-256390r959010_rule | The ESXi host Secure Shell (SSH) daemon must not allow compression or must only allow compression after successful authentication. |
| ☐ | SV-256391r959010_rule | The ESXi host Secure Shell (SSH) daemon must be configured to not allow gateway ports. |
| ☐ | SV-256392r959010_rule | The ESXi host Secure Shell (SSH) daemon must be configured to not allow X11 forwarding. |
| ☐ | SV-256393r959010_rule | The ESXi host Secure Shell (SSH) daemon must not permit tunnels. |
| ☐ | SV-256394r959010_rule | The ESXi host Secure Shell (SSH) daemon must set a timeout count on idle sessions. |
| ☐ | SV-256395r959010_rule | The ESXi host Secure Shell (SSH) daemon must set a timeout interval on idle sessions. |
| ☐ | SV-256396r958412_rule | The ESXi host must produce audit records containing information to establish what type of events occurred. |
| ☐ | SV-256397r984191_rule | The ESXi host must be configured with a sufficiently complex password policy. |
| ☐ | SV-256398r984204_rule | The ESXi host must prohibit the reuse of passwords within five iterations. |
| ☐ | SV-256399r958478_rule | The ESXi host must disable the Managed Object Browser (MOB). |
| ☐ | SV-256400r958478_rule | The ESXi host must be configured to disable nonessential capabilities by disabling Secure Shell (SSH). |
| ☐ | SV-256401r958478_rule | The ESXi host must disable ESXi Shell unless needed for diagnostics or troubleshooting. |
| ☐ | SV-256402r958482_rule | The ESXi host must use Active Directory for local user authentication. |
| ☐ | SV-256403r958482_rule | ESXi hosts using Host Profiles and/or Auto Deploy must use the vSphere Authentication Proxy to protect passwords when adding themselves to Active Directory. |
| ☐ | SV-256404r958482_rule | Active Directory ESX Admin group membership must not be used when adding ESXi hosts to Active Directory. |
| ☐ | SV-256405r970703_rule | The ESXi host must set a timeout to automatically disable idle shell sessions after two minutes. |
| ☐ | SV-256406r970703_rule | The ESXi host must terminate shell services after 10 minutes. |
| ☐ | SV-256407r970703_rule | The ESXi host must log out of the console UI after two minutes. |
| ☐ | SV-256408r958752_rule | The ESXi host must enable a persistent log location for all locally stored logs. |
| ☐ | SV-256409r1038976_rule | The ESXi host must configure NTP time synchronization. |
| ☐ | SV-256410r984242_rule | The ESXi Image Profile and vSphere Installation Bundle (VIB) acceptance levels must be verified. |
| ☐ | SV-256411r958908_rule | The ESXi host must protect the confidentiality and integrity of transmitted information by isolating vMotion traffic. |
| ☐ | SV-256412r958908_rule | The ESXi host must protect the confidentiality and integrity of transmitted information by protecting ESXi management traffic. |
| ☐ | SV-256413r958908_rule | The ESXi host must protect the confidentiality and integrity of transmitted information by isolating IP-based storage traffic. |
| ☐ | SV-256414r959010_rule | Simple Network Management Protocol (SNMP) must be configured properly on the ESXi host. |
| ☐ | SV-256415r959010_rule | The ESXi host must enable bidirectional Challenge-Handshake Authentication Protocol (CHAP) authentication for Internet Small Computer Systems Interface (iSCSI) traffic. |
| ☐ | SV-256416r959010_rule | The ESXi host must disable Inter-Virtual Machine (VM) Transparent Page Sharing. |
| ☐ | SV-256417r959010_rule | The ESXi host must configure the firewall to restrict access to services running on the host. |
| ☐ | SV-256418r959010_rule | The ESXi host must configure the firewall to block network traffic by default. |
| ☐ | SV-256419r959010_rule | The ESXi host must enable Bridge Protocol Data Units (BPDU) filter on the host to prevent being locked out of physical switch ports with Portfast and BPDU Guard enabled. |
| ☐ | SV-256420r959010_rule | All port groups on standard switches must be configured to reject forged transmits. |
| ☐ | SV-256421r959010_rule | All port groups on standard switches must be configured to reject guest Media Access Control (MAC) address changes. |
| ☐ | SV-256422r959010_rule | All port groups on standard switches must be configured to reject guest promiscuous mode requests. |
| ☐ | SV-256423r959010_rule | Use of the dvFilter network application programming interfaces (APIs) must be restricted. |
| ☐ | SV-256424r959010_rule | All port groups on standard switches must be configured to a value other than that of the native virtual local area network (VLAN). |
| ☐ | SV-256425r959010_rule | All port groups on standard switches must not be configured to virtual local area network (VLAN) 4095 unless Virtual Guest Tagging (VGT) is required. |
| ☐ | SV-256426r959010_rule | All port groups on standard switches must not be configured to virtual local area network (VLAN) values reserved by upstream physical switches. |
| ☐ | SV-256427r959010_rule | The ESXi host must not provide root/administrator-level access to Common Information Model (CIM)-based hardware monitoring tools or other third-party applications. |
| ☐ | SV-256428r959010_rule | The ESXi host must have all security patches and updates installed. |
| ☐ | SV-256429r959010_rule | The ESXi host must exclusively enable Transport Layer Security (TLS) 1.2 for all endpoints. |
| ☐ | SV-256430r959010_rule | The ESXi host must enable Secure Boot. |
| ☐ | SV-256431r1067573_rule | The ESXi host must use DOD-approved certificates. |
| ☐ | SV-256432r959010_rule | The ESXi host must not suppress warnings that the local or remote shell sessions are enabled. |
| ☐ | SV-256433r959010_rule | The ESXi host must not suppress warnings about unmitigated hyperthreading vulnerabilities. |
| ☐ | SV-256434r959010_rule | The ESXi host Secure Shell (SSH) daemon must disable port forwarding. |
| ☐ | SV-256435r959010_rule | The ESXi host OpenSLP service must be disabled. |
| ☐ | SV-256436r959010_rule | The ESXi host must enable audit logging. |
| ☐ | SV-256437r959010_rule | The ESXi host must enable strict x509 verification for SSL syslog endpoints. |
| ☐ | SV-256438r959010_rule | The ESXi host must verify certificates for SSL syslog endpoints. |
| ☐ | SV-256439r959010_rule | The ESXi host must enable volatile key destruction. |
| ☐ | SV-256440r959010_rule | The ESXi host must configure a session timeout for the vSphere API. |
| ☐ | SV-256441r959010_rule | The ESXi Host Client must be configured with a session timeout. |
| ☐ | SV-256442r958408_rule | The ESXi host rhttpproxy daemon must use FIPS 140-2 validated cryptographic modules to protect the confidentiality of remote access sessions. |
| ☐ | SV-256443r959010_rule | The ESXi host must be configured with an appropriate maximum password age. |
| ☐ | SV-256444r959010_rule | The ESXi host must not be configured to override virtual machine (VM) configurations. |
| ☐ | SV-256445r959010_rule | The ESXi host must not be configured to override virtual machine (VM) logger settings. |
| ☐ | SV-256446r959010_rule | The ESXi host must require TPM-based configuration encryption. |
| ☐ | SV-256447r959010_rule | The ESXi host must implement Secure Boot enforcement. |
| ☐ | SV-256448r1051419_rule | The ESXi Common Information Model (CIM) service must be disabled. |
| ☐ | SV-256449r959006_rule | The ESXi host SSH daemon must be configured to only use FIPS 140-2 validated ciphers. |