STIGQter STIGQter: STIG Summary:

VMware vSphere 8.0 ESXi Security Technical Implementation Guide

Version: 1

Release: 1 Benchmark Date: 31 Oct 2023

CheckedNameTitle
SV-258728r933245_ruleThe ESXi host must enforce the limit of three consecutive invalid logon attempts by a user.
SV-258729r933248_ruleThe ESXi host must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the system via the Direct Console User Interface (DCUI).
SV-258730r933251_ruleThe ESXi host must enable lockdown mode.
SV-258731r933254_ruleThe ESXi host client must be configured with an idle session timeout.
SV-258732r933257_ruleThe ESXi host Secure Shell (SSH) daemon must use FIPS 140-2 validated cryptographic modules to protect the confidentiality of remote access sessions.
SV-258733r933260_ruleThe ESXi must produce audit records containing information to establish what type of events occurred.
SV-258734r933263_ruleThe ESXi host must enforce password complexity by configuring a password quality policy.
SV-258735r933266_ruleThe ESXi host must prohibit password reuse for a minimum of five generations.
SV-258736r933269_ruleThe ESXi host must be configured to disable nonessential capabilities by disabling the Managed Object Browser (MOB).
SV-258737r933272_ruleThe ESXi host must uniquely identify and must authenticate organizational users by using Active Directory.
SV-258738r933275_ruleThe ESXi host Secure Shell (SSH) daemon must ignore .rhosts files.
SV-258739r933278_ruleThe ESXi host must set a timeout to automatically end idle shell sessions after fifteen minutes.
SV-258740r933281_ruleThe ESXi host must implement Secure Boot enforcement.
SV-258741r933284_ruleThe ESXi host must enable Secure Boot.
SV-258742r933287_ruleThe ESXi host must enforce an unlock timeout of 15 minutes after a user account is locked out.
SV-258743r933290_ruleThe ESXi host must allocate audit record storage capacity to store at least one week's worth of audit records.
SV-258744r933293_ruleThe ESXi host must off-load logs via syslog.
SV-258745r933296_ruleThe ESXi host must synchronize internal information system clocks to an authoritative time source.
SV-258746r933299_ruleThe ESXi Image Profile and vSphere Installation Bundle (VIB) acceptance level must be verified.
SV-258747r933302_ruleThe ESXi host must enable bidirectional Challenge-Handshake Authentication Protocol (CHAP) authentication for Internet Small Computer Systems Interface (iSCSI) traffic.
SV-258748r933305_ruleThe ESXi host must protect the confidentiality and integrity of transmitted information by isolating vMotion traffic.
SV-258749r933308_ruleThe ESXi host must maintain the confidentiality and integrity of information during transmission by exclusively enabling Transport Layer Security (TLS) 1.2.
SV-258750r933311_ruleThe ESXi host Secure Shell (SSH) daemon must be configured to only use FIPS 140-2 validated ciphers.
SV-258751r933314_ruleThe ESXi host DCUI.Access list must be verified.
SV-258752r933317_ruleThe ESXi host must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the system via Secure Shell (SSH).
SV-258753r933320_ruleThe ESXi host Secure Shell (SSH) daemon must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the system.
SV-258754r933323_ruleThe ESXi host must be configured to disable nonessential capabilities by disabling Secure Shell (SSH).
SV-258755r933326_ruleThe ESXi host must be configured to disable nonessential capabilities by disabling the ESXi shell.
SV-258756r933329_ruleThe ESXi host must automatically stop shell services after 10 minutes.
SV-258757r933332_ruleThe ESXi host must set a timeout to automatically end idle DCUI sessions after 10 minutes.
SV-258758r933335_ruleThe ESXi host must protect the confidentiality and integrity of transmitted information by isolating ESXi management traffic.
SV-258759r933338_ruleThe ESXi host must protect the confidentiality and integrity of transmitted information by isolating IP-based storage traffic.
SV-258760r933341_ruleThe ESXi host lockdown mode exception users list must be verified.
SV-258761r933344_ruleThe ESXi host Secure Shell (SSH) daemon must not allow host-based authentication.
SV-258762r933347_ruleThe ESXi host Secure Shell (SSH) daemon must not permit user environment settings.
SV-258763r933350_ruleThe ESXi host Secure Shell (SSH) daemon must be configured to not allow gateway ports.
SV-258764r933353_ruleThe ESXi host Secure Shell (SSH) daemon must not permit tunnels.
SV-258765r933356_ruleThe ESXi host Secure Shell (SSH) daemon must set a timeout count on idle sessions.
SV-258766r933359_ruleThe ESXi host Secure Shell (SSH) daemon must set a timeout interval on idle sessions.
SV-258767r933362_ruleThe ESXi host must disable Simple Network Management Protocol (SNMP) v1 and v2c.
SV-258768r933365_ruleThe ESXi host must disable Inter-Virtual Machine (VM) Transparent Page Sharing.
SV-258769r933368_ruleThe ESXi host must configure the firewall to block network traffic by default.
SV-258770r933371_ruleThe ESXi host must enable Bridge Protocol Data Units (BPDU) filter on the host to prevent being locked out of physical switch ports with Portfast and BPDU Guard enabled.
SV-258771r933374_ruleThe ESXi host must configure virtual switch security policies to reject forged transmits.
SV-258772r933377_ruleThe ESXi host must configure virtual switch security policies to reject Media Access Control (MAC) address changes.
SV-258773r933380_ruleThe ESXi host must configure virtual switch security policies to reject promiscuous mode requests.
SV-258774r933383_ruleThe ESXi host must restrict use of the dvFilter network application programming interface (API).
SV-258775r933386_ruleThe ESXi host must restrict the use of Virtual Guest Tagging (VGT) on standard switches.
SV-258776r933389_ruleThe ESXi host must have all security patches and updates installed.
SV-258777r933392_ruleThe ESXi host must not suppress warnings that the local or remote shell sessions are enabled.
SV-258778r933395_ruleThe ESXi host must not suppress warnings about unmitigated hyperthreading vulnerabilities.
SV-258779r933398_ruleThe ESXi host must verify certificates for SSL syslog endpoints.
SV-258780r933401_ruleThe ESXi host must enable volatile key destruction.
SV-258781r933404_ruleThe ESXi host must configure a session timeout for the vSphere API.
SV-258782r933407_ruleThe ESXi host must be configured with an appropriate maximum password age.
SV-258783r933410_ruleThe ESXi Common Information Model (CIM) service must be disabled.
SV-258784r933413_ruleThe ESXi host must use DOD-approved certificates.
SV-258785r933416_ruleThe ESXi host Secure Shell (SSH) daemon must disable port forwarding.
SV-258786r933419_ruleThe ESXi host OpenSLP service must be disabled.
SV-258787r933422_ruleThe ESXi host must enable audit logging.
SV-258788r933425_ruleThe ESXi host must off-load audit records via syslog.
SV-258789r933428_ruleThe ESXi host must enable strict x509 verification for SSL syslog endpoints.
SV-258790r933431_ruleThe ESXi host must forward audit records containing information to establish what type of events occurred.
SV-258791r933434_ruleThe ESXi host must not be configured to override virtual machine (VM) configurations.
SV-258792r933437_ruleThe ESXi host must not be configured to override virtual machine (VM) logger settings.
SV-258793r933440_ruleThe ESXi host must require TPM-based configuration encryption.
SV-258794r933443_ruleThe ESXi host must configure the firewall to restrict access to services running on the host.
SV-258795r933446_ruleThe ESXi host when using Host Profiles and/or Auto Deploy must use the vSphere Authentication Proxy to protect passwords when adding themselves to Active Directory.
SV-258796r933449_ruleThe ESXi host must not use the default Active Directory ESX Admin group.
SV-258797r933452_ruleThe ESXi host must configure a persistent log location for all locally stored logs.
SV-258798r933455_ruleThe ESXi host must enforce the exclusive running of executables from approved VIBs.
SV-258799r933458_ruleThe ESXi host must use sufficient entropy for cryptographic operations.
SV-258800r933461_ruleThe ESXi host must not enable log filtering.