STIGQter STIGQter: STIG Summary:

VMware vSphere 8.0 vCenter Security Technical Implementation Guide

Version: 2

Release: 4 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-258905r960840_ruleThe vCenter Server must enforce the limit of three consecutive invalid login attempts by a user.
SV-258906r960843_ruleThe vCenter Server must display the Standard Mandatory DOD Notice and Consent Banner before logon.
SV-258907r960891_ruleThe vCenter Server must produce audit records containing information to establish what type of events occurred.
SV-258908r960963_rulevCenter Server plugins must be verified.
SV-258909r1051115_ruleThe vCenter Server must uniquely identify and authenticate users or processes acting on behalf of users.
SV-258910r1210450_ruleThe vCenter Server must require multifactor authentication.
SV-258911r1015925_ruleThe vCenter Server passwords must be at least 15 characters in length.
SV-258912r1015267_ruleThe vCenter Server must prohibit password reuse for a minimum of five generations.
SV-258913r1015926_ruleThe vCenter Server passwords must contain at least one uppercase character.
SV-258914r1015927_ruleThe vCenter Server passwords must contain at least one lowercase character.
SV-258915r1015928_ruleThe vCenter Server passwords must contain at least one numeric character.
SV-258916r1015929_ruleThe vCenter Server passwords must contain at least one special character.
SV-258917r961029_ruleThe vCenter Server must enable FIPS-validated cryptography.
SV-258918r1043190_ruleThe vCenter Server must enforce a 90-day maximum password lifetime restriction.
SV-258919r1015931_ruleThe vCenter Server must enable revocation checking for certificate-based authentication.
SV-258920r1015932_ruleThe vCenter Server must terminate vSphere Client sessions after 15 minutes of inactivity.
SV-258921r1117171_ruleThe vCenter Server user roles must be verified.
SV-258922r961155_ruleThe vCenter Server must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial-of-service (DoS) attacks by enabling Network I/O Control (NIOC).
SV-258923r1015933_ruleThe vCenter Server must provide an immediate real-time alert to the system administrator (SA) and information system security officer (ISSO), at a minimum, on every Single Sign-On (SSO) account action.
SV-258924r961368_ruleThe vCenter Server must set the interval for counting failed login attempts to at least 15 minutes.
SV-258925r961395_ruleThe vCenter Server must be configured to send logs to a central log server.
SV-258926r961401_ruleThe vCenter server must provide an immediate real-time alert to the system administrator (SA) and information system security officer (ISSO), at a minimum, of all audit failure events requiring real-time alerts.
SV-258927r1015934_ruleThe vCenter Server must compare internal information system clocks at least every 24 hours with an authoritative time server.
SV-258928r961596_ruleThe vCenter Server Machine Secure Sockets Layer (SSL) certificate must be issued by a DOD certificate authority.
SV-258929r961599_ruleThe vCenter Server must enable data at rest encryption for vSAN.
SV-258930r961863_ruleThe vCenter Server must disable the Customer Experience Improvement Program (CEIP).
SV-258931r961878_ruleThe vCenter server must enforce SNMPv3 security features where SNMP is required.
SV-258932r961878_ruleThe vCenter server must disable SNMPv1/2 receivers.
SV-258933r961368_ruleThe vCenter Server must require an administrator to unlock an account locked due to excessive login failures.
SV-258934r961863_ruleThe vCenter Server must disable the distributed virtual switch health check.
SV-258935r961863_ruleThe vCenter Server must set the distributed port group Forged Transmits policy to "Reject".
SV-258936r961863_ruleThe vCenter Server must set the distributed port group Media Access Control (MAC) Address Change policy to "Reject".
SV-258937r961863_ruleThe vCenter Server must set the distributed port group Promiscuous Mode policy to "Reject".
SV-258938r961863_ruleThe vCenter Server must only send NetFlow traffic to authorized collectors.
SV-258939r961863_ruleThe vCenter Server must configure all port groups to a value other than that of the native virtual local area network (VLAN).
SV-258940r961863_ruleThe vCenter Server must not configure VLAN Trunking unless Virtual Guest Tagging (VGT) is required and authorized.
SV-258941r961863_ruleThe vCenter Server must not configure all port groups to virtual local area network (VLAN) values reserved by upstream physical switches.
SV-258942r961863_ruleThe vCenter Server must configure the "vpxuser" auto-password to be changed every 30 days.
SV-258943r961863_ruleThe vCenter Server must configure the "vpxuser" password to meet length policy.
SV-258944r961863_ruleThe vCenter Server must be isolated from the public internet but must still allow for patch notification and delivery.
SV-258945r961863_ruleThe vCenter Server must use unique service accounts when applications connect to vCenter.
SV-258946r961863_ruleThe vCenter Server must protect the confidentiality and integrity of transmitted information by isolating Internet Protocol (IP)-based storage traffic.
SV-258947r961395_ruleThe vCenter server must be configured to send events to a central log server.
SV-258948r961863_ruleThe vCenter Server must disable or restrict the connectivity between vSAN Health Check and public Hardware Compatibility List (HCL) by use of an external proxy server.
SV-258949r961863_ruleThe vCenter Server must configure the vSAN Datastore name to a unique name.
SV-258950r961863_ruleThe vCenter Server must disable Username/Password and Windows Integrated Authentication.
SV-258951r1003606_ruleThe vCenter Server must restrict access to the default roles with cryptographic permissions.
SV-258952r1003608_ruleThe vCenter Server must restrict access to cryptographic permissions.
SV-258953r961863_ruleThe vCenter Server must have Mutual Challenge Handshake Authentication Protocol (CHAP) configured for vSAN Internet Small Computer System Interface (iSCSI) targets.
SV-258954r1003610_ruleThe vCenter Server must have new Key Encryption Keys (KEKs) reissued at regular intervals for vSAN encrypted datastore(s).
SV-258955r961863_ruleThe vCenter Server must use secure Lightweight Directory Access Protocol (LDAPS) when adding an LDAP identity source.
SV-258956r961863_ruleThe vCenter Server must limit membership to the "SystemConfiguration.BashShellAdministrators" Single Sign-On (SSO) group.
SV-258957r961863_ruleThe vCenter Server must limit membership to the "TrustedAdmins" Single Sign-On (SSO) group.
SV-258958r961863_ruleThe vCenter server configuration must be backed up on a regular basis.
SV-258959r961863_ruleThe vCenter server must have task and event retention set to at least 30 days.
SV-258960r1051428_ruleThe vCenter server Native Key Provider must be backed up with a strong password.
SV-258961r1051430_ruleThe vCenter server must require authentication for published content libraries.
SV-258962r1051432_ruleThe vCenter server must enable the OVF security policy for content libraries.
SV-258963r961863_ruleThe vCenter Server must separate authentication and authorization for administrators.
SV-258964r961863_ruleThe vCenter Server must disable CDP/LLDP on distributed switches.
SV-258965r961863_ruleThe vCenter Server must remove unauthorized port mirroring sessions on distributed switches.
SV-258966r961863_ruleThe vCenter Server must not override port group settings at the port level on distributed switches.
SV-258967r961863_ruleThe vCenter Server must reset port configuration when virtual machines are disconnected.
SV-258968r1111830_ruleThe vCenter Server must disable Secure Shell (SSH) access.
SV-258969r961863_ruleThe vCenter Server must enable data in transit encryption for vSAN.
SV-265978r1003613_ruleThe vCenter Server must use DOD-approved encryption to protect the confidentiality of network sessions.
SV-265979r1003616_ruleThe vCenter Server must disable accounts used for Integrated Windows Authentication (IWA).