STIGQter STIGQter: STIG Summary:

VMware vSphere 7.0 VAMI Security Technical Implementation Guide

Version: 1

Release: 2 Benchmark Date: 26 Jul 2023

CheckedNameTitle
SV-256645r888457_ruleVAMI must limit the number of simultaneous requests.
SV-256646r888460_ruleVAMI must be configured with FIPS 140-2 compliant ciphers for HTTPS connections.
SV-256647r888463_ruleVAMI must use cryptography to protect the integrity of remote sessions.
SV-256648r888466_ruleVAMI must be configured to monitor remote access.
SV-256649r888469_ruleVAMI must generate log records for system startup and shutdown.
SV-256650r888472_ruleVAMI must produce log records containing sufficient information to establish what type of events occurred.
SV-256651r918984_ruleVAMI log files must only be accessible by privileged users.
SV-256652r888478_ruleThe rsyslog must be configured to monitor VAMI logs.
SV-256653r888481_ruleVAMI server binaries and libraries must be verified for their integrity.
SV-256654r888484_ruleVAMI must only load allowed server modules.
SV-256655r888487_ruleVAMI must have Multipurpose Internet Mail Extensions (MIME) that invoke operating system shell programs disabled.
SV-256656r888490_ruleVAMI must explicitly disable Multipurpose Internet Mail Extensions (MIME) mime mappings based on "Content-Type".
SV-256657r888493_ruleVAMI must remove all mappings to unused scripts.
SV-256658r918987_ruleVAMI must have resource mappings set to disable the serving of certain file types.
SV-256659r888499_ruleVAMI must not have the Web Distributed Authoring (WebDAV) servlet installed.
SV-256660r888502_ruleVAMI must prevent hosted applications from exhausting system resources.
SV-256661r888505_ruleVAMI must protect the keystore from unauthorized access.
SV-256662r888508_ruleVAMI must protect against or limit the effects of HTTP types of denial-of-service (DoS) attacks.
SV-256663r888511_ruleVAMI must set the encoding for all text Multipurpose Internet Mail Extensions (MIME) types to UTF-8.
SV-256664r888514_ruleVAMI must disable directory browsing.
SV-256665r888517_ruleVAMI must not be configured to use "mod_status".
SV-256666r888520_ruleVAMI must have debug logging disabled.
SV-256667r888523_ruleVAMI must be protected from being stopped by a nonprivileged user.
SV-256668r888526_ruleVAMI must implement Transport Layer Security (TLS) 1.2 exclusively.
SV-256669r888529_ruleVAMI must force clients to select the most secure cipher.
SV-256670r888532_ruleVAMI must disable client-initiated Transport Layer Security (TLS) renegotiation.
SV-256671r888535_ruleVAMI must be configured to hide the server type and version in client responses.
SV-256672r888538_ruleVAMI must enable FIPS mode.