| Checked | Name | Title |
|---|
| ☐ | SV-259137r935315_rule | The vCenter VAMI service must limit the number of allowed simultaneous session requests. |
| ☐ | SV-259138r935318_rule | The vCenter VAMI service must use cryptography to protect the integrity of remote sessions. |
| ☐ | SV-259139r935321_rule | The vCenter VAMI service must generate information to monitor remote access. |
| ☐ | SV-259140r935324_rule | The vCenter VAMI service must produce log records containing sufficient information to establish what type of events occurred. |
| ☐ | SV-259141r935327_rule | The vCenter VAMI service log files must only be accessible by privileged users. |
| ☐ | SV-259142r935330_rule | The vCenter VAMI service must off-load log records onto a different system or media from the system being logged. |
| ☐ | SV-259143r935333_rule | The vCenter VAMI service must explicitly disable Multipurpose Internet Mail Extensions (MIME) mime mappings based on "Content-Type". |
| ☐ | SV-259144r935336_rule | The vCenter VAMI service must have resource mappings set to disable the serving of certain file types. |
| ☐ | SV-259145r935339_rule | The vCenter VAMI service must have Web Distributed Authoring (WebDAV) disabled. |
| ☐ | SV-259146r935342_rule | The vCenter VAMI service must protect system resources and privileged operations from hosted applications. |
| ☐ | SV-259147r935345_rule | The vCenter VAMI service must restrict access to the web server's private key. |
| ☐ | SV-259148r935348_rule | The vCenter VAMI service must enable FIPS mode. |
| ☐ | SV-259149r935351_rule | The vCenter VAMI service must restrict the ability of users to launch Denial of Service (DoS) attacks against other information systems or networks. |
| ☐ | SV-259150r935354_rule | The vCenter VAMI service must set the encoding for all text mime types to UTF-8. |
| ☐ | SV-259151r935357_rule | The vCenter VAMI service must disable directory listing. |
| ☐ | SV-259152r935360_rule | The vCenter VAMI service must not be configured to use the "mod_status" module. |
| ☐ | SV-259153r935363_rule | The vCenter VAMI service must have debug logging disabled. |
| ☐ | SV-259154r935366_rule | The vCenter VAMI service must enable honoring the SSL cipher order. |
| ☐ | SV-259155r935369_rule | The vCenter VAMI service must disable client initiated TLS renegotiation. |
| ☐ | SV-259156r935372_rule | The vCenter VAMI service must be configured to hide the server type and version in client responses. |
| ☐ | SV-259157r935375_rule | The vCenter VAMI service must implement HTTP Strict Transport Security (HSTS). |
| ☐ | SV-259158r935378_rule | The vCenter VAMI service must implement prevent rendering inside a frame or iframe on another site. |
| ☐ | SV-259159r935381_rule | The vCenter VAMI service must protect against MIME sniffing. |
| ☐ | SV-259160r935384_rule | The vCenter VAMI service must enable Content Security Policy. |