| Checked | Name | Title |
|---|
| ☐ | SV-258728r958388_rule | The ESXi host must enforce the limit of three consecutive invalid logon attempts by a user. |
| ☐ | SV-258729r958390_rule | The ESXi host must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the system via the Direct Console User Interface (DCUI). |
| ☐ | SV-258730r958398_rule | The ESXi host must enable lockdown mode. |
| ☐ | SV-258731r958402_rule | The ESXi host client must be configured with an idle session timeout. |
| ☐ | SV-258732r958408_rule | The ESXi host Secure Shell (SSH) daemon must use FIPS 140-2 validated cryptographic modules to protect the confidentiality of remote access sessions. |
| ☐ | SV-258733r958412_rule | The ESXi must produce audit records containing information to establish what type of events occurred. |
| ☐ | SV-258734r1015918_rule | The ESXi host must enforce password complexity by configuring a password quality policy. |
| ☐ | SV-258735r1003559_rule | The ESXi host must prohibit password reuse for a minimum of five generations. |
| ☐ | SV-258736r958478_rule | The ESXi host must be configured to disable nonessential capabilities by disabling the Managed Object Browser (MOB). |
| ☐ | SV-258737r1015919_rule | The ESXi host must uniquely identify and must authenticate organizational users by using Active Directory. |
| ☐ | SV-258738r1015920_rule | The ESXi host Secure Shell (SSH) daemon must ignore .rhosts files. |
| ☐ | SV-258739r1003562_rule | The ESXi host must set a timeout to automatically end idle shell sessions after fifteen minutes. |
| ☐ | SV-258740r1212384_rule | The ESXi host must implement Secure Boot enforcement. |
| ☐ | SV-258741r1003563_rule | The ESXi host must enable Secure Boot. |
| ☐ | SV-258742r1003564_rule | The ESXi host must enforce an unlock timeout of 15 minutes after a user account is locked out. |
| ☐ | SV-258743r958752_rule | The ESXi host must allocate audit record storage capacity to store at least one week's worth of audit records. |
| ☐ | SV-258744r1015921_rule | The ESXi host must offload logs via syslog. |
| ☐ | SV-258745r1038976_rule | The ESXi host must synchronize internal information system clocks to an authoritative time source. |
| ☐ | SV-258746r1015923_rule | The ESXi Image Profile and vSphere Installation Bundle (VIB) acceptance level must be verified. |
| ☐ | SV-258747r971545_rule | The ESXi host must enable bidirectional Challenge-Handshake Authentication Protocol (CHAP) authentication for Internet Small Computer Systems Interface (iSCSI) traffic. |
| ☐ | SV-258748r958908_rule | The ESXi host must protect the confidentiality and integrity of transmitted information by isolating vMotion traffic. |
| ☐ | SV-258750r1138009_rule | The ESXi host Secure Shell (SSH) daemon must be configured to only use FIPS 140-2 validated ciphers. |
| ☐ | SV-258751r959010_rule | The ESXi host DCUI.Access list must be verified. |
| ☐ | SV-258752r958390_rule | The ESXi host must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the system via Secure Shell (SSH). |
| ☐ | SV-258753r958390_rule | The ESXi host Secure Shell (SSH) daemon must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the system. |
| ☐ | SV-258754r958478_rule | The ESXi host must be configured to disable nonessential capabilities by disabling Secure Shell (SSH). |
| ☐ | SV-258755r958478_rule | The ESXi host must be configured to disable nonessential capabilities by disabling the ESXi shell. |
| ☐ | SV-258756r1003569_rule | The ESXi host must automatically stop shell services after 10 minutes. |
| ☐ | SV-258757r1003570_rule | The ESXi host must set a timeout to automatically end idle DCUI sessions after 10 minutes. |
| ☐ | SV-258758r958908_rule | The ESXi host must protect the confidentiality and integrity of transmitted information by isolating ESXi management traffic. |
| ☐ | SV-258759r958908_rule | The ESXi host must protect the confidentiality and integrity of transmitted information by isolating IP-based storage traffic. |
| ☐ | SV-258760r959010_rule | The ESXi host lockdown mode exception users list must be verified. |
| ☐ | SV-258761r959010_rule | The ESXi host Secure Shell (SSH) daemon must not allow host-based authentication. |
| ☐ | SV-258762r959010_rule | The ESXi host Secure Shell (SSH) daemon must not permit user environment settings. |
| ☐ | SV-258763r959010_rule | The ESXi host Secure Shell (SSH) daemon must be configured to not allow gateway ports. |
| ☐ | SV-258764r959010_rule | The ESXi host Secure Shell (SSH) daemon must not permit tunnels. |
| ☐ | SV-258765r959010_rule | The ESXi host Secure Shell (SSH) daemon must set a timeout count on idle sessions. |
| ☐ | SV-258766r959010_rule | The ESXi host Secure Shell (SSH) daemon must set a timeout interval on idle sessions. |
| ☐ | SV-258767r959010_rule | The ESXi host must disable Simple Network Management Protocol (SNMP) v1 and v2c. |
| ☐ | SV-258768r959010_rule | The ESXi host must disable Inter-Virtual Machine (VM) Transparent Page Sharing. |
| ☐ | SV-258769r1003571_rule | The ESXi host must configure the firewall to block network traffic by default. |
| ☐ | SV-258770r959010_rule | The ESXi host must enable Bridge Protocol Data Units (BPDU) filter on the host to prevent being locked out of physical switch ports with Portfast and BPDU Guard enabled. |
| ☐ | SV-258771r959010_rule | The ESXi host must configure virtual switch security policies to reject forged transmits. |
| ☐ | SV-258772r959010_rule | The ESXi host must configure virtual switch security policies to reject Media Access Control (MAC) address changes. |
| ☐ | SV-258773r959010_rule | The ESXi host must configure virtual switch security policies to reject promiscuous mode requests. |
| ☐ | SV-258774r959010_rule | The ESXi host must restrict use of the dvFilter network application programming interface (API). |
| ☐ | SV-258775r959010_rule | The ESXi host must restrict the use of Virtual Guest Tagging (VGT) on standard switches. |
| ☐ | SV-258776r959010_rule | The ESXi host must have all security patches and updates installed. |
| ☐ | SV-258777r959010_rule | The ESXi host must not suppress warnings that the local or remote shell sessions are enabled. |
| ☐ | SV-258778r959010_rule | The ESXi host must not suppress warnings about unmitigated hyperthreading vulnerabilities. |
| ☐ | SV-258779r1003572_rule | The ESXi host must verify certificates for SSL syslog endpoints. |
| ☐ | SV-258780r959010_rule | The ESXi host must enable volatile key destruction. |
| ☐ | SV-258781r959010_rule | The ESXi host must configure a session timeout for the vSphere API. |
| ☐ | SV-258782r959010_rule | The ESXi host must be configured with an appropriate maximum password age. |
| ☐ | SV-258783r959010_rule | The ESXi Common Information Model (CIM) service must be disabled. |
| ☐ | SV-258784r1212385_rule | The ESXi host must use DOD-approved certificates. |
| ☐ | SV-258785r959010_rule | The ESXi host Secure Shell (SSH) daemon must disable port forwarding. |
| ☐ | SV-258786r959010_rule | The ESXi host OpenSLP service must be disabled. |
| ☐ | SV-258787r1003573_rule | The ESXi host must enable audit logging. |
| ☐ | SV-258788r958754_rule | The ESXi host must off-load audit records via syslog. |
| ☐ | SV-258789r959010_rule | The ESXi host must enable strict x509 verification for SSL syslog endpoints. |
| ☐ | SV-258790r958412_rule | The ESXi host must forward audit records containing information to establish what type of events occurred. |
| ☐ | SV-258791r959010_rule | The ESXi host must not be configured to override virtual machine (VM) configurations. |
| ☐ | SV-258792r959010_rule | The ESXi host must not be configured to override virtual machine (VM) logger settings. |
| ☐ | SV-258793r959010_rule | The ESXi host must require TPM-based configuration encryption. |
| ☐ | SV-258794r1003574_rule | The ESXi host must configure the firewall to restrict access to services running on the host. |
| ☐ | SV-258795r959010_rule | The ESXi host when using Host Profiles and/or Auto Deploy must use the vSphere Authentication Proxy to protect passwords when adding themselves to Active Directory. |
| ☐ | SV-258796r959010_rule | The ESXi host must not use the default Active Directory ESX Admin group. |
| ☐ | SV-258797r1003575_rule | The ESXi host must configure a persistent log location for all locally stored logs. |
| ☐ | SV-258798r959010_rule | The ESXi host must enforce the exclusive running of executables from approved VIBs. |
| ☐ | SV-258799r959010_rule | The ESXi host must use sufficient entropy for cryptographic operations. |
| ☐ | SV-258800r959010_rule | The ESXi host must not enable log filtering. |
| ☐ | SV-265974r1003578_rule | The ESXi host must use DOD-approved encryption to protect the confidentiality of network sessions. |
| ☐ | SV-265975r1003581_rule | The ESXi host must disable key persistence. |
| ☐ | SV-265976r1003584_rule | The ESXi host must deny shell access for the dcui account. |
| ☐ | SV-265977r1003587_rule | The ESXi host must disable virtual hardware management network interfaces. |