STIGQter STIGQter: STIG Summary:

VMware vSphere 8.0 ESXi Security Technical Implementation Guide

Version: 2

Release: 4 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-258728r958388_ruleThe ESXi host must enforce the limit of three consecutive invalid logon attempts by a user.
SV-258729r958390_ruleThe ESXi host must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the system via the Direct Console User Interface (DCUI).
SV-258730r958398_ruleThe ESXi host must enable lockdown mode.
SV-258731r958402_ruleThe ESXi host client must be configured with an idle session timeout.
SV-258732r958408_ruleThe ESXi host Secure Shell (SSH) daemon must use FIPS 140-2 validated cryptographic modules to protect the confidentiality of remote access sessions.
SV-258733r958412_ruleThe ESXi must produce audit records containing information to establish what type of events occurred.
SV-258734r1015918_ruleThe ESXi host must enforce password complexity by configuring a password quality policy.
SV-258735r1003559_ruleThe ESXi host must prohibit password reuse for a minimum of five generations.
SV-258736r958478_ruleThe ESXi host must be configured to disable nonessential capabilities by disabling the Managed Object Browser (MOB).
SV-258737r1015919_ruleThe ESXi host must uniquely identify and must authenticate organizational users by using Active Directory.
SV-258738r1015920_ruleThe ESXi host Secure Shell (SSH) daemon must ignore .rhosts files.
SV-258739r1003562_ruleThe ESXi host must set a timeout to automatically end idle shell sessions after fifteen minutes.
SV-258740r1212384_ruleThe ESXi host must implement Secure Boot enforcement.
SV-258741r1003563_ruleThe ESXi host must enable Secure Boot.
SV-258742r1003564_ruleThe ESXi host must enforce an unlock timeout of 15 minutes after a user account is locked out.
SV-258743r958752_ruleThe ESXi host must allocate audit record storage capacity to store at least one week's worth of audit records.
SV-258744r1015921_ruleThe ESXi host must offload logs via syslog.
SV-258745r1038976_ruleThe ESXi host must synchronize internal information system clocks to an authoritative time source.
SV-258746r1015923_ruleThe ESXi Image Profile and vSphere Installation Bundle (VIB) acceptance level must be verified.
SV-258747r971545_ruleThe ESXi host must enable bidirectional Challenge-Handshake Authentication Protocol (CHAP) authentication for Internet Small Computer Systems Interface (iSCSI) traffic.
SV-258748r958908_ruleThe ESXi host must protect the confidentiality and integrity of transmitted information by isolating vMotion traffic.
SV-258750r1138009_ruleThe ESXi host Secure Shell (SSH) daemon must be configured to only use FIPS 140-2 validated ciphers.
SV-258751r959010_ruleThe ESXi host DCUI.Access list must be verified.
SV-258752r958390_ruleThe ESXi host must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the system via Secure Shell (SSH).
SV-258753r958390_ruleThe ESXi host Secure Shell (SSH) daemon must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the system.
SV-258754r958478_ruleThe ESXi host must be configured to disable nonessential capabilities by disabling Secure Shell (SSH).
SV-258755r958478_ruleThe ESXi host must be configured to disable nonessential capabilities by disabling the ESXi shell.
SV-258756r1003569_ruleThe ESXi host must automatically stop shell services after 10 minutes.
SV-258757r1003570_ruleThe ESXi host must set a timeout to automatically end idle DCUI sessions after 10 minutes.
SV-258758r958908_ruleThe ESXi host must protect the confidentiality and integrity of transmitted information by isolating ESXi management traffic.
SV-258759r958908_ruleThe ESXi host must protect the confidentiality and integrity of transmitted information by isolating IP-based storage traffic.
SV-258760r959010_ruleThe ESXi host lockdown mode exception users list must be verified.
SV-258761r959010_ruleThe ESXi host Secure Shell (SSH) daemon must not allow host-based authentication.
SV-258762r959010_ruleThe ESXi host Secure Shell (SSH) daemon must not permit user environment settings.
SV-258763r959010_ruleThe ESXi host Secure Shell (SSH) daemon must be configured to not allow gateway ports.
SV-258764r959010_ruleThe ESXi host Secure Shell (SSH) daemon must not permit tunnels.
SV-258765r959010_ruleThe ESXi host Secure Shell (SSH) daemon must set a timeout count on idle sessions.
SV-258766r959010_ruleThe ESXi host Secure Shell (SSH) daemon must set a timeout interval on idle sessions.
SV-258767r959010_ruleThe ESXi host must disable Simple Network Management Protocol (SNMP) v1 and v2c.
SV-258768r959010_ruleThe ESXi host must disable Inter-Virtual Machine (VM) Transparent Page Sharing.
SV-258769r1003571_ruleThe ESXi host must configure the firewall to block network traffic by default.
SV-258770r959010_ruleThe ESXi host must enable Bridge Protocol Data Units (BPDU) filter on the host to prevent being locked out of physical switch ports with Portfast and BPDU Guard enabled.
SV-258771r959010_ruleThe ESXi host must configure virtual switch security policies to reject forged transmits.
SV-258772r959010_ruleThe ESXi host must configure virtual switch security policies to reject Media Access Control (MAC) address changes.
SV-258773r959010_ruleThe ESXi host must configure virtual switch security policies to reject promiscuous mode requests.
SV-258774r959010_ruleThe ESXi host must restrict use of the dvFilter network application programming interface (API).
SV-258775r959010_ruleThe ESXi host must restrict the use of Virtual Guest Tagging (VGT) on standard switches.
SV-258776r959010_ruleThe ESXi host must have all security patches and updates installed.
SV-258777r959010_ruleThe ESXi host must not suppress warnings that the local or remote shell sessions are enabled.
SV-258778r959010_ruleThe ESXi host must not suppress warnings about unmitigated hyperthreading vulnerabilities.
SV-258779r1003572_ruleThe ESXi host must verify certificates for SSL syslog endpoints.
SV-258780r959010_ruleThe ESXi host must enable volatile key destruction.
SV-258781r959010_ruleThe ESXi host must configure a session timeout for the vSphere API.
SV-258782r959010_ruleThe ESXi host must be configured with an appropriate maximum password age.
SV-258783r959010_ruleThe ESXi Common Information Model (CIM) service must be disabled.
SV-258784r1212385_ruleThe ESXi host must use DOD-approved certificates.
SV-258785r959010_ruleThe ESXi host Secure Shell (SSH) daemon must disable port forwarding.
SV-258786r959010_ruleThe ESXi host OpenSLP service must be disabled.
SV-258787r1003573_ruleThe ESXi host must enable audit logging.
SV-258788r958754_ruleThe ESXi host must off-load audit records via syslog.
SV-258789r959010_ruleThe ESXi host must enable strict x509 verification for SSL syslog endpoints.
SV-258790r958412_ruleThe ESXi host must forward audit records containing information to establish what type of events occurred.
SV-258791r959010_ruleThe ESXi host must not be configured to override virtual machine (VM) configurations.
SV-258792r959010_ruleThe ESXi host must not be configured to override virtual machine (VM) logger settings.
SV-258793r959010_ruleThe ESXi host must require TPM-based configuration encryption.
SV-258794r1003574_ruleThe ESXi host must configure the firewall to restrict access to services running on the host.
SV-258795r959010_ruleThe ESXi host when using Host Profiles and/or Auto Deploy must use the vSphere Authentication Proxy to protect passwords when adding themselves to Active Directory.
SV-258796r959010_ruleThe ESXi host must not use the default Active Directory ESX Admin group.
SV-258797r1003575_ruleThe ESXi host must configure a persistent log location for all locally stored logs.
SV-258798r959010_ruleThe ESXi host must enforce the exclusive running of executables from approved VIBs.
SV-258799r959010_ruleThe ESXi host must use sufficient entropy for cryptographic operations.
SV-258800r959010_ruleThe ESXi host must not enable log filtering.
SV-265974r1003578_ruleThe ESXi host must use DOD-approved encryption to protect the confidentiality of network sessions.
SV-265975r1003581_ruleThe ESXi host must disable key persistence.
SV-265976r1003584_ruleThe ESXi host must deny shell access for the dcui account.
SV-265977r1003587_ruleThe ESXi host must disable virtual hardware management network interfaces.