| Checked | Name | Title |
|---|
| ☐ | SV-258728r933245_rule | The ESXi host must enforce the limit of three consecutive invalid logon attempts by a user. |
| ☐ | SV-258729r933248_rule | The ESXi host must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the system via the Direct Console User Interface (DCUI). |
| ☐ | SV-258730r933251_rule | The ESXi host must enable lockdown mode. |
| ☐ | SV-258731r933254_rule | The ESXi host client must be configured with an idle session timeout. |
| ☐ | SV-258732r933257_rule | The ESXi host Secure Shell (SSH) daemon must use FIPS 140-2 validated cryptographic modules to protect the confidentiality of remote access sessions. |
| ☐ | SV-258733r933260_rule | The ESXi must produce audit records containing information to establish what type of events occurred. |
| ☐ | SV-258734r933263_rule | The ESXi host must enforce password complexity by configuring a password quality policy. |
| ☐ | SV-258735r933266_rule | The ESXi host must prohibit password reuse for a minimum of five generations. |
| ☐ | SV-258736r933269_rule | The ESXi host must be configured to disable nonessential capabilities by disabling the Managed Object Browser (MOB). |
| ☐ | SV-258737r933272_rule | The ESXi host must uniquely identify and must authenticate organizational users by using Active Directory. |
| ☐ | SV-258738r933275_rule | The ESXi host Secure Shell (SSH) daemon must ignore .rhosts files. |
| ☐ | SV-258739r933278_rule | The ESXi host must set a timeout to automatically end idle shell sessions after fifteen minutes. |
| ☐ | SV-258740r933281_rule | The ESXi host must implement Secure Boot enforcement. |
| ☐ | SV-258741r933284_rule | The ESXi host must enable Secure Boot. |
| ☐ | SV-258742r933287_rule | The ESXi host must enforce an unlock timeout of 15 minutes after a user account is locked out. |
| ☐ | SV-258743r933290_rule | The ESXi host must allocate audit record storage capacity to store at least one week's worth of audit records. |
| ☐ | SV-258744r933293_rule | The ESXi host must off-load logs via syslog. |
| ☐ | SV-258745r933296_rule | The ESXi host must synchronize internal information system clocks to an authoritative time source. |
| ☐ | SV-258746r933299_rule | The ESXi Image Profile and vSphere Installation Bundle (VIB) acceptance level must be verified. |
| ☐ | SV-258747r933302_rule | The ESXi host must enable bidirectional Challenge-Handshake Authentication Protocol (CHAP) authentication for Internet Small Computer Systems Interface (iSCSI) traffic. |
| ☐ | SV-258748r933305_rule | The ESXi host must protect the confidentiality and integrity of transmitted information by isolating vMotion traffic. |
| ☐ | SV-258749r933308_rule | The ESXi host must maintain the confidentiality and integrity of information during transmission by exclusively enabling Transport Layer Security (TLS) 1.2. |
| ☐ | SV-258750r933311_rule | The ESXi host Secure Shell (SSH) daemon must be configured to only use FIPS 140-2 validated ciphers. |
| ☐ | SV-258751r933314_rule | The ESXi host DCUI.Access list must be verified. |
| ☐ | SV-258752r933317_rule | The ESXi host must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the system via Secure Shell (SSH). |
| ☐ | SV-258753r933320_rule | The ESXi host Secure Shell (SSH) daemon must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the system. |
| ☐ | SV-258754r933323_rule | The ESXi host must be configured to disable nonessential capabilities by disabling Secure Shell (SSH). |
| ☐ | SV-258755r933326_rule | The ESXi host must be configured to disable nonessential capabilities by disabling the ESXi shell. |
| ☐ | SV-258756r933329_rule | The ESXi host must automatically stop shell services after 10 minutes. |
| ☐ | SV-258757r933332_rule | The ESXi host must set a timeout to automatically end idle DCUI sessions after 10 minutes. |
| ☐ | SV-258758r933335_rule | The ESXi host must protect the confidentiality and integrity of transmitted information by isolating ESXi management traffic. |
| ☐ | SV-258759r933338_rule | The ESXi host must protect the confidentiality and integrity of transmitted information by isolating IP-based storage traffic. |
| ☐ | SV-258760r933341_rule | The ESXi host lockdown mode exception users list must be verified. |
| ☐ | SV-258761r933344_rule | The ESXi host Secure Shell (SSH) daemon must not allow host-based authentication. |
| ☐ | SV-258762r933347_rule | The ESXi host Secure Shell (SSH) daemon must not permit user environment settings. |
| ☐ | SV-258763r933350_rule | The ESXi host Secure Shell (SSH) daemon must be configured to not allow gateway ports. |
| ☐ | SV-258764r933353_rule | The ESXi host Secure Shell (SSH) daemon must not permit tunnels. |
| ☐ | SV-258765r933356_rule | The ESXi host Secure Shell (SSH) daemon must set a timeout count on idle sessions. |
| ☐ | SV-258766r933359_rule | The ESXi host Secure Shell (SSH) daemon must set a timeout interval on idle sessions. |
| ☐ | SV-258767r933362_rule | The ESXi host must disable Simple Network Management Protocol (SNMP) v1 and v2c. |
| ☐ | SV-258768r933365_rule | The ESXi host must disable Inter-Virtual Machine (VM) Transparent Page Sharing. |
| ☐ | SV-258769r933368_rule | The ESXi host must configure the firewall to block network traffic by default. |
| ☐ | SV-258770r933371_rule | The ESXi host must enable Bridge Protocol Data Units (BPDU) filter on the host to prevent being locked out of physical switch ports with Portfast and BPDU Guard enabled. |
| ☐ | SV-258771r933374_rule | The ESXi host must configure virtual switch security policies to reject forged transmits. |
| ☐ | SV-258772r933377_rule | The ESXi host must configure virtual switch security policies to reject Media Access Control (MAC) address changes. |
| ☐ | SV-258773r933380_rule | The ESXi host must configure virtual switch security policies to reject promiscuous mode requests. |
| ☐ | SV-258774r933383_rule | The ESXi host must restrict use of the dvFilter network application programming interface (API). |
| ☐ | SV-258775r933386_rule | The ESXi host must restrict the use of Virtual Guest Tagging (VGT) on standard switches. |
| ☐ | SV-258776r933389_rule | The ESXi host must have all security patches and updates installed. |
| ☐ | SV-258777r933392_rule | The ESXi host must not suppress warnings that the local or remote shell sessions are enabled. |
| ☐ | SV-258778r933395_rule | The ESXi host must not suppress warnings about unmitigated hyperthreading vulnerabilities. |
| ☐ | SV-258779r933398_rule | The ESXi host must verify certificates for SSL syslog endpoints. |
| ☐ | SV-258780r933401_rule | The ESXi host must enable volatile key destruction. |
| ☐ | SV-258781r933404_rule | The ESXi host must configure a session timeout for the vSphere API. |
| ☐ | SV-258782r933407_rule | The ESXi host must be configured with an appropriate maximum password age. |
| ☐ | SV-258783r933410_rule | The ESXi Common Information Model (CIM) service must be disabled. |
| ☐ | SV-258784r933413_rule | The ESXi host must use DOD-approved certificates. |
| ☐ | SV-258785r933416_rule | The ESXi host Secure Shell (SSH) daemon must disable port forwarding. |
| ☐ | SV-258786r933419_rule | The ESXi host OpenSLP service must be disabled. |
| ☐ | SV-258787r933422_rule | The ESXi host must enable audit logging. |
| ☐ | SV-258788r933425_rule | The ESXi host must off-load audit records via syslog. |
| ☐ | SV-258789r933428_rule | The ESXi host must enable strict x509 verification for SSL syslog endpoints. |
| ☐ | SV-258790r933431_rule | The ESXi host must forward audit records containing information to establish what type of events occurred. |
| ☐ | SV-258791r933434_rule | The ESXi host must not be configured to override virtual machine (VM) configurations. |
| ☐ | SV-258792r933437_rule | The ESXi host must not be configured to override virtual machine (VM) logger settings. |
| ☐ | SV-258793r933440_rule | The ESXi host must require TPM-based configuration encryption. |
| ☐ | SV-258794r933443_rule | The ESXi host must configure the firewall to restrict access to services running on the host. |
| ☐ | SV-258795r933446_rule | The ESXi host when using Host Profiles and/or Auto Deploy must use the vSphere Authentication Proxy to protect passwords when adding themselves to Active Directory. |
| ☐ | SV-258796r933449_rule | The ESXi host must not use the default Active Directory ESX Admin group. |
| ☐ | SV-258797r933452_rule | The ESXi host must configure a persistent log location for all locally stored logs. |
| ☐ | SV-258798r933455_rule | The ESXi host must enforce the exclusive running of executables from approved VIBs. |
| ☐ | SV-258799r933458_rule | The ESXi host must use sufficient entropy for cryptographic operations. |
| ☐ | SV-258800r933461_rule | The ESXi host must not enable log filtering. |