| Checked | Name | Title |
|---|
| ☐ | SV-258905r934373_rule | The vCenter Server must enforce the limit of three consecutive invalid login attempts by a user. |
| ☐ | SV-258906r934376_rule | The vCenter Server must display the Standard Mandatory DOD Notice and Consent Banner before logon. |
| ☐ | SV-258907r934379_rule | The vCenter Server must produce audit records containing information to establish what type of events occurred. |
| ☐ | SV-258908r934382_rule | vCenter Server plugins must be verified. |
| ☐ | SV-258909r934385_rule | The vCenter Server must uniquely identify and authenticate users or processes acting on behalf of users. |
| ☐ | SV-258910r934388_rule | The vCenter Server must require multifactor authentication. |
| ☐ | SV-258911r934391_rule | The vCenter Server passwords must be at least 15 characters in length. |
| ☐ | SV-258912r934394_rule | The vCenter Server must prohibit password reuse for a minimum of five generations. |
| ☐ | SV-258913r934397_rule | The vCenter Server passwords must contain at least one uppercase character. |
| ☐ | SV-258914r934400_rule | The vCenter Server passwords must contain at least one lowercase character. |
| ☐ | SV-258915r934403_rule | The vCenter Server passwords must contain at least one numeric character. |
| ☐ | SV-258916r934406_rule | The vCenter Server passwords must contain at least one special character. |
| ☐ | SV-258917r934409_rule | The vCenter Server must enable FIPS-validated cryptography. |
| ☐ | SV-258918r934412_rule | The vCenter Server must enforce a 90-day maximum password lifetime restriction. |
| ☐ | SV-258919r934415_rule | The vCenter Server must enable revocation checking for certificate-based authentication. |
| ☐ | SV-258920r934418_rule | The vCenter Server must terminate vSphere Client sessions after 15 minutes of inactivity. |
| ☐ | SV-258921r934421_rule | The vCenter Server user roles must be verified. |
| ☐ | SV-258922r934424_rule | The vCenter Server must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial-of-service (DoS) attacks by enabling Network I/O Control (NIOC). |
| ☐ | SV-258923r934427_rule | The vCenter Server must provide an immediate real-time alert to the system administrator (SA) and information system security officer (ISSO), at a minimum, on every Single Sign-On (SSO) account action. |
| ☐ | SV-258924r934430_rule | The vCenter Server must set the interval for counting failed login attempts to at least 15 minutes. |
| ☐ | SV-258925r934433_rule | The vCenter Server must be configured to send logs to a central log server. |
| ☐ | SV-258926r934436_rule | The vCenter server must provide an immediate real-time alert to the system administrator (SA) and information system security officer (ISSO), at a minimum, of all audit failure events requiring real-time alerts. |
| ☐ | SV-258927r934439_rule | The vCenter Server must compare internal information system clocks at least every 24 hours with an authoritative time server. |
| ☐ | SV-258928r934442_rule | The vCenter Server Machine Secure Sockets Layer (SSL) certificate must be issued by a DOD certificate authority. |
| ☐ | SV-258929r934445_rule | The vCenter Server must enable data at rest encryption for vSAN. |
| ☐ | SV-258930r934448_rule | The vCenter Server must disable the Customer Experience Improvement Program (CEIP). |
| ☐ | SV-258931r934451_rule | The vCenter server must enforce SNMPv3 security features where SNMP is required. |
| ☐ | SV-258932r934454_rule | The vCenter server must disable SNMPv1/2 receivers. |
| ☐ | SV-258933r934457_rule | The vCenter Server must require an administrator to unlock an account locked due to excessive login failures. |
| ☐ | SV-258934r934460_rule | The vCenter Server must disable the distributed virtual switch health check. |
| ☐ | SV-258935r934463_rule | The vCenter Server must set the distributed port group Forged Transmits policy to "Reject". |
| ☐ | SV-258936r934466_rule | The vCenter Server must set the distributed port group Media Access Control (MAC) Address Change policy to "Reject". |
| ☐ | SV-258937r934469_rule | The vCenter Server must set the distributed port group Promiscuous Mode policy to "Reject". |
| ☐ | SV-258938r934472_rule | The vCenter Server must only send NetFlow traffic to authorized collectors. |
| ☐ | SV-258939r934475_rule | The vCenter Server must configure all port groups to a value other than that of the native virtual local area network (VLAN). |
| ☐ | SV-258940r934478_rule | The vCenter Server must not configure VLAN Trunking unless Virtual Guest Tagging (VGT) is required and authorized. |
| ☐ | SV-258941r934481_rule | The vCenter Server must not configure all port groups to virtual local area network (VLAN) values reserved by upstream physical switches. |
| ☐ | SV-258942r934484_rule | The vCenter Server must configure the "vpxuser" auto-password to be changed every 30 days. |
| ☐ | SV-258943r934487_rule | The vCenter Server must configure the "vpxuser" password to meet length policy. |
| ☐ | SV-258944r934490_rule | The vCenter Server must be isolated from the public internet but must still allow for patch notification and delivery. |
| ☐ | SV-258945r934493_rule | The vCenter Server must use unique service accounts when applications connect to vCenter. |
| ☐ | SV-258946r934496_rule | The vCenter Server must protect the confidentiality and integrity of transmitted information by isolating Internet Protocol (IP)-based storage traffic. |
| ☐ | SV-258947r934499_rule | The vCenter server must be configured to send events to a central log server. |
| ☐ | SV-258948r934502_rule | The vCenter Server must disable or restrict the connectivity between vSAN Health Check and public Hardware Compatibility List (HCL) by use of an external proxy server. |
| ☐ | SV-258949r934505_rule | The vCenter Server must configure the vSAN Datastore name to a unique name. |
| ☐ | SV-258950r934508_rule | The vCenter Server must disable Username/Password and Windows Integrated Authentication. |
| ☐ | SV-258951r934511_rule | The vCenter Server must restrict access to the default roles with cryptographic permissions. |
| ☐ | SV-258952r934514_rule | The vCenter Server must restrict access to cryptographic permissions. |
| ☐ | SV-258953r934517_rule | The vCenter Server must have Mutual Challenge Handshake Authentication Protocol (CHAP) configured for vSAN Internet Small Computer System Interface (iSCSI) targets. |
| ☐ | SV-258954r934520_rule | The vCenter Server must have new Key Encryption Keys (KEKs) reissued at regular intervals for vSAN encrypted datastore(s). |
| ☐ | SV-258955r934523_rule | The vCenter Server must use secure Lightweight Directory Access Protocol (LDAPS) when adding an LDAP identity source. |
| ☐ | SV-258956r934526_rule | The vCenter Server must limit membership to the "SystemConfiguration.BashShellAdministrators" Single Sign-On (SSO) group. |
| ☐ | SV-258957r934529_rule | The vCenter Server must limit membership to the "TrustedAdmins" Single Sign-On (SSO) group. |
| ☐ | SV-258958r934532_rule | The vCenter server configuration must be backed up on a regular basis. |
| ☐ | SV-258959r934535_rule | The vCenter server must have task and event retention set to at least 30 days. |
| ☐ | SV-258960r934538_rule | The vCenter server Native Key Provider must be backed up with a strong password. |
| ☐ | SV-258961r934541_rule | The vCenter server must require authentication for published content libraries. |
| ☐ | SV-258962r934544_rule | The vCenter server must enable the OVF security policy for content libraries. |
| ☐ | SV-258963r934547_rule | The vCenter Server must separate authentication and authorization for administrators. |
| ☐ | SV-258964r934550_rule | The vCenter Server must disable CDP/LLDP on distributed switches. |
| ☐ | SV-258965r934553_rule | The vCenter Server must remove unauthorized port mirroring sessions on distributed switches. |
| ☐ | SV-258966r934556_rule | The vCenter Server must not override port group settings at the port level on distributed switches. |
| ☐ | SV-258967r934559_rule | The vCenter Server must reset port configuration when virtual machines are disconnected. |
| ☐ | SV-258968r934562_rule | The vCenter Server must disable Secure Shell (SSH) access. |
| ☐ | SV-258969r934565_rule | The vCenter Server must enable data in transit encryption for vSAN. |