CIS VMware ESXi 6.7 v1.1.0 Level 2

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS VMware ESXi 6.7 v1.1.0 Level 2

Updated: 7/7/2022

Authority: CIS

Plugin: VMware

Revision: 1.4

Estimated Item Count: 32

Audit Items

DescriptionCategories
5.2 Ensure DCUI is disabled

CONFIGURATION MANAGEMENT

5.11 Ensure contents of exposed configuration files have not been modified
6.4 Ensure VMDK files are zeroed out prior to deletion

ACCESS CONTROL

8.1.2 Ensure only one remote console connection is permitted to a VM at any time

ACCESS CONTROL

8.2.2 Ensure unnecessary CD/DVD devices are disconnected

CONFIGURATION MANAGEMENT

8.4.5 Ensure Autologon is disabled

ACCESS CONTROL

8.4.6 Ensure BIOS BBS is disabled

CONFIGURATION MANAGEMENT

8.4.7 Ensure Guest Host Interaction Protocol Handler is set to disabled

CONFIGURATION MANAGEMENT

8.4.8 Ensure Unity Taskbar is disabled

CONFIGURATION MANAGEMENT

8.4.9 Ensure Unity Active is disabled

CONFIGURATION MANAGEMENT

8.4.10 Ensure Unity Window Contents is disabled

CONFIGURATION MANAGEMENT

8.4.11 Ensure Unity Push Update is disabled

CONFIGURATION MANAGEMENT

8.4.12 Ensure Drag and Drop Version Get is disabled

CONFIGURATION MANAGEMENT

8.4.13 Ensure Drag and Drop Version Set is disabled

CONFIGURATION MANAGEMENT

8.4.14 Ensure Shell Action is disabled

CONFIGURATION MANAGEMENT

8.4.15 Ensure Request Disk Topology is disabled

CONFIGURATION MANAGEMENT

8.4.16 Ensure Trash Folder State is disabled

CONFIGURATION MANAGEMENT

8.4.17 Ensure Guest Host Interaction Tray Icon is disabled

CONFIGURATION MANAGEMENT

8.4.18 Ensure Unity is disabled

CONFIGURATION MANAGEMENT

8.4.19 Ensure Unity Interlock is disabled

CONFIGURATION MANAGEMENT

8.4.20 Ensure GetCreds is disabled

CONFIGURATION MANAGEMENT

8.4.21 Ensure Host Guest File System Server is disabled

CONFIGURATION MANAGEMENT

8.4.22 Ensure Guest Host Interaction Launch Menu is disabled

CONFIGURATION MANAGEMENT

8.4.23 Ensure memSchedFakeSampleStats is disabled

CONFIGURATION MANAGEMENT

8.4.29 Ensure all but VGA mode on virtual machines is disabled

SYSTEM AND COMMUNICATIONS PROTECTION

8.5.1 Ensure VM limits are configured correctly - CPU Share Level

SYSTEM AND COMMUNICATIONS PROTECTION

8.5.1 Ensure VM limits are configured correctly - Mem Share Level

SYSTEM AND COMMUNICATIONS PROTECTION

8.5.1 Ensure VM limits are configured correctly - Num Mem Shares

SYSTEM AND COMMUNICATIONS PROTECTION

8.5.2 Ensure hardware-based 3D acceleration is disabled

CONFIGURATION MANAGEMENT

8.6.1 Ensure nonpersistent disks are limited

AUDIT AND ACCOUNTABILITY

8.7.1 Ensure VIX messages from the VM are disabled

CONFIGURATION MANAGEMENT

8.7.3 Ensure host information is not sent to guests

SYSTEM AND COMMUNICATIONS PROTECTION