| Checked | Name | Title |
|---|
| ☐ | SV-256318r919041_rule | The vCenter Server must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination using remote access. |
| ☐ | SV-256319r885568_rule | The vCenter Server must enforce the limit of three consecutive invalid login attempts by a user. |
| ☐ | SV-256320r885571_rule | The vCenter Server must display the Standard Mandatory DOD Notice and Consent Banner before login. |
| ☐ | SV-256321r885574_rule | The vCenter Server must produce audit records containing information to establish what type of events occurred. |
| ☐ | SV-256322r885577_rule | vCenter Server plugins must be verified. |
| ☐ | SV-256323r885580_rule | The vCenter Server must uniquely identify and authenticate users or processes acting on behalf of users. |
| ☐ | SV-256324r885583_rule | The vCenter Server must require multifactor authentication. |
| ☐ | SV-256325r885586_rule | The vCenter Server passwords must be at least 15 characters in length. |
| ☐ | SV-256326r885589_rule | The vCenter Server must prohibit password reuse for a minimum of five generations. |
| ☐ | SV-256327r885592_rule | The vCenter Server passwords must contain at least one uppercase character. |
| ☐ | SV-256328r885595_rule | The vCenter Server passwords must contain at least one lowercase character. |
| ☐ | SV-256329r885598_rule | The vCenter Server passwords must contain at least one numeric character. |
| ☐ | SV-256330r885601_rule | The vCenter Server passwords must contain at least one special character. |
| ☐ | SV-256331r885604_rule | The vCenter Server must enable FIPS-validated cryptography. |
| ☐ | SV-256332r885607_rule | The vCenter Server must enforce a 60-day maximum password lifetime restriction. |
| ☐ | SV-256333r919043_rule | The vCenter Server must enable revocation checking for certificate-based authentication. |
| ☐ | SV-256334r885613_rule | The vCenter Server must terminate vSphere Client sessions after 10 minutes of inactivity. |
| ☐ | SV-256335r885616_rule | The vCenter Server users must have the correct roles assigned. |
| ☐ | SV-256336r885619_rule | The vCenter Server must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial-of-service (DoS) attacks by enabling Network I/O Control (NIOC). |
| ☐ | SV-256337r885622_rule | The vCenter Server must provide an immediate real-time alert to the system administrator (SA) and information system security officer (ISSO), at a minimum, on every Single Sign-On (SSO) account action. |
| ☐ | SV-256338r885625_rule | The vCenter Server must set the interval for counting failed login attempts to at least 15 minutes. |
| ☐ | SV-256339r885628_rule | The vCenter Server must be configured to send logs to a central log server. |
| ☐ | SV-256340r885631_rule | vCenter must provide an immediate real-time alert to the system administrator (SA) and information system security officer (ISSO), at a minimum, of all audit failure events requiring real-time alerts. |
| ☐ | SV-256341r892804_rule | The vCenter Server must compare internal information system clocks at least every 24 hours with an authoritative time server. |
| ☐ | SV-256342r885637_rule | The vCenter Server Machine Secure Sockets Layer (SSL) certificate must be issued by a DOD certificate authority. |
| ☐ | SV-256343r885640_rule | The vCenter Server must disable the Customer Experience Improvement Program (CEIP). |
| ☐ | SV-256344r885643_rule | The vCenter server must enforce SNMPv3 security features where SNMP is required. |
| ☐ | SV-256345r885646_rule | The vCenter server must disable SNMPv1/2 receivers. |
| ☐ | SV-256346r885649_rule | The vCenter Server must require an administrator to unlock an account locked due to excessive login failures. |
| ☐ | SV-256347r885652_rule | The vCenter Server must disable the distributed virtual switch health check. |
| ☐ | SV-256348r942488_rule | The vCenter Server must set the distributed port group Forged Transmits policy to "Reject". |
| ☐ | SV-256349r885658_rule | The vCenter Server must set the distributed port group Media Access Control (MAC) Address Change policy to "Reject". |
| ☐ | SV-256350r942490_rule | The vCenter Server must set the distributed port group Promiscuous Mode policy to "Reject". |
| ☐ | SV-256351r885664_rule | The vCenter Server must only send NetFlow traffic to authorized collectors. |
| ☐ | SV-256352r885667_rule | The vCenter Server must configure all port groups to a value other than that of the native virtual local area network (VLAN). |
| ☐ | SV-256353r885670_rule | The vCenter Server must not configure VLAN Trunking unless Virtual Guest Tagging (VGT) is required and authorized. |
| ☐ | SV-256354r885673_rule | The vCenter Server must not configure all port groups to virtual local area network (VLAN) values reserved by upstream physical switches. |
| ☐ | SV-256355r885676_rule | The vCenter Server must configure the "vpxuser" auto-password to be changed every 30 days. |
| ☐ | SV-256356r885679_rule | The vCenter Server must configure the "vpxuser" password to meet length policy. |
| ☐ | SV-256357r885682_rule | The vCenter Server must be isolated from the public internet but must still allow for patch notification and delivery. |
| ☐ | SV-256358r885685_rule | The vCenter Server must use unique service accounts when applications connect to vCenter. |
| ☐ | SV-256359r885688_rule | The vCenter Server must protect the confidentiality and integrity of transmitted information by isolating Internet Protocol (IP)-based storage traffic. |
| ☐ | SV-256360r885691_rule | The vCenter server must be configured to send events to a central log server. |
| ☐ | SV-256361r885694_rule | The vCenter Server must disable or restrict the connectivity between vSAN Health Check and public Hardware Compatibility List (HCL) by use of an external proxy server. |
| ☐ | SV-256362r885697_rule | The vCenter Server must configure the vSAN Datastore name to a unique name. |
| ☐ | SV-256363r885700_rule | The vCenter Server must disable Username/Password and Windows Integrated Authentication. |
| ☐ | SV-256364r919045_rule | The vCenter Server must restrict access to the default roles with cryptographic permissions. |
| ☐ | SV-256365r919040_rule | The vCenter Server must restrict access to cryptographic permissions. |
| ☐ | SV-256366r885709_rule | The vCenter Server must have Mutual Challenge Handshake Authentication Protocol (CHAP) configured for vSAN Internet Small Computer System Interface (iSCSI) targets. |
| ☐ | SV-256367r885712_rule | The vCenter Server must have new Key Encryption Keys (KEKs) reissued at regular intervals for vSAN encrypted datastore(s). |
| ☐ | SV-256368r885715_rule | The vCenter Server must use secure Lightweight Directory Access Protocol (LDAPS) when adding an LDAP identity source. |
| ☐ | SV-256369r885718_rule | The vCenter Server must use a limited privilege account when adding a Lightweight Directory Access Protocol (LDAP) identity source. |
| ☐ | SV-256370r885721_rule | The vCenter Server must limit membership to the "SystemConfiguration.BashShellAdministrators" Single Sign-On (SSO) group. |
| ☐ | SV-256371r885724_rule | The vCenter Server must limit membership to the "TrustedAdmins" Single Sign-On (SSO) group. |
| ☐ | SV-256372r885727_rule | The vCenter server configuration must be backed up on a regular basis. |
| ☐ | SV-256373r885730_rule | vCenter task and event retention must be set to at least 30 days. |
| ☐ | SV-256374r919046_rule | vCenter Native Key Providers must be backed up with a strong password. |