STIGQter STIGQter: STIG Summary:

VMware vSphere 7.0 vCenter Security Technical Implementation Guide

Version: 1

Release: 3 Benchmark Date: 24 Jan 2024

CheckedNameTitle
SV-256318r919041_ruleThe vCenter Server must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination using remote access.
SV-256319r885568_ruleThe vCenter Server must enforce the limit of three consecutive invalid login attempts by a user.
SV-256320r885571_ruleThe vCenter Server must display the Standard Mandatory DOD Notice and Consent Banner before login.
SV-256321r885574_ruleThe vCenter Server must produce audit records containing information to establish what type of events occurred.
SV-256322r885577_rulevCenter Server plugins must be verified.
SV-256323r885580_ruleThe vCenter Server must uniquely identify and authenticate users or processes acting on behalf of users.
SV-256324r885583_ruleThe vCenter Server must require multifactor authentication.
SV-256325r885586_ruleThe vCenter Server passwords must be at least 15 characters in length.
SV-256326r885589_ruleThe vCenter Server must prohibit password reuse for a minimum of five generations.
SV-256327r885592_ruleThe vCenter Server passwords must contain at least one uppercase character.
SV-256328r885595_ruleThe vCenter Server passwords must contain at least one lowercase character.
SV-256329r885598_ruleThe vCenter Server passwords must contain at least one numeric character.
SV-256330r885601_ruleThe vCenter Server passwords must contain at least one special character.
SV-256331r885604_ruleThe vCenter Server must enable FIPS-validated cryptography.
SV-256332r885607_ruleThe vCenter Server must enforce a 60-day maximum password lifetime restriction.
SV-256333r919043_ruleThe vCenter Server must enable revocation checking for certificate-based authentication.
SV-256334r885613_ruleThe vCenter Server must terminate vSphere Client sessions after 10 minutes of inactivity.
SV-256335r885616_ruleThe vCenter Server users must have the correct roles assigned.
SV-256336r885619_ruleThe vCenter Server must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial-of-service (DoS) attacks by enabling Network I/O Control (NIOC).
SV-256337r885622_ruleThe vCenter Server must provide an immediate real-time alert to the system administrator (SA) and information system security officer (ISSO), at a minimum, on every Single Sign-On (SSO) account action.
SV-256338r885625_ruleThe vCenter Server must set the interval for counting failed login attempts to at least 15 minutes.
SV-256339r885628_ruleThe vCenter Server must be configured to send logs to a central log server.
SV-256340r885631_rulevCenter must provide an immediate real-time alert to the system administrator (SA) and information system security officer (ISSO), at a minimum, of all audit failure events requiring real-time alerts.
SV-256341r892804_ruleThe vCenter Server must compare internal information system clocks at least every 24 hours with an authoritative time server.
SV-256342r885637_ruleThe vCenter Server Machine Secure Sockets Layer (SSL) certificate must be issued by a DOD certificate authority.
SV-256343r885640_ruleThe vCenter Server must disable the Customer Experience Improvement Program (CEIP).
SV-256344r885643_ruleThe vCenter server must enforce SNMPv3 security features where SNMP is required.
SV-256345r885646_ruleThe vCenter server must disable SNMPv1/2 receivers.
SV-256346r885649_ruleThe vCenter Server must require an administrator to unlock an account locked due to excessive login failures.
SV-256347r885652_ruleThe vCenter Server must disable the distributed virtual switch health check.
SV-256348r942488_ruleThe vCenter Server must set the distributed port group Forged Transmits policy to "Reject".
SV-256349r885658_ruleThe vCenter Server must set the distributed port group Media Access Control (MAC) Address Change policy to "Reject".
SV-256350r942490_ruleThe vCenter Server must set the distributed port group Promiscuous Mode policy to "Reject".
SV-256351r885664_ruleThe vCenter Server must only send NetFlow traffic to authorized collectors.
SV-256352r885667_ruleThe vCenter Server must configure all port groups to a value other than that of the native virtual local area network (VLAN).
SV-256353r885670_ruleThe vCenter Server must not configure VLAN Trunking unless Virtual Guest Tagging (VGT) is required and authorized.
SV-256354r885673_ruleThe vCenter Server must not configure all port groups to virtual local area network (VLAN) values reserved by upstream physical switches.
SV-256355r885676_ruleThe vCenter Server must configure the "vpxuser" auto-password to be changed every 30 days.
SV-256356r885679_ruleThe vCenter Server must configure the "vpxuser" password to meet length policy.
SV-256357r885682_ruleThe vCenter Server must be isolated from the public internet but must still allow for patch notification and delivery.
SV-256358r885685_ruleThe vCenter Server must use unique service accounts when applications connect to vCenter.
SV-256359r885688_ruleThe vCenter Server must protect the confidentiality and integrity of transmitted information by isolating Internet Protocol (IP)-based storage traffic.
SV-256360r885691_ruleThe vCenter server must be configured to send events to a central log server.
SV-256361r885694_ruleThe vCenter Server must disable or restrict the connectivity between vSAN Health Check and public Hardware Compatibility List (HCL) by use of an external proxy server.
SV-256362r885697_ruleThe vCenter Server must configure the vSAN Datastore name to a unique name.
SV-256363r885700_ruleThe vCenter Server must disable Username/Password and Windows Integrated Authentication.
SV-256364r919045_ruleThe vCenter Server must restrict access to the default roles with cryptographic permissions.
SV-256365r919040_ruleThe vCenter Server must restrict access to cryptographic permissions.
SV-256366r885709_ruleThe vCenter Server must have Mutual Challenge Handshake Authentication Protocol (CHAP) configured for vSAN Internet Small Computer System Interface (iSCSI) targets.
SV-256367r885712_ruleThe vCenter Server must have new Key Encryption Keys (KEKs) reissued at regular intervals for vSAN encrypted datastore(s).
SV-256368r885715_ruleThe vCenter Server must use secure Lightweight Directory Access Protocol (LDAPS) when adding an LDAP identity source.
SV-256369r885718_ruleThe vCenter Server must use a limited privilege account when adding a Lightweight Directory Access Protocol (LDAP) identity source.
SV-256370r885721_ruleThe vCenter Server must limit membership to the "SystemConfiguration.BashShellAdministrators" Single Sign-On (SSO) group.
SV-256371r885724_ruleThe vCenter Server must limit membership to the "TrustedAdmins" Single Sign-On (SSO) group.
SV-256372r885727_ruleThe vCenter server configuration must be backed up on a regular basis.
SV-256373r885730_rulevCenter task and event retention must be set to at least 30 days.
SV-256374r919046_rulevCenter Native Key Providers must be backed up with a strong password.