DISA STIG VMware vSphere 7.0 Virtual Machine v1r3

Audit Details

Name: DISA STIG VMware vSphere 7.0 Virtual Machine v1r3

Updated: 6/17/2024

Authority: DISA STIG

Plugin: VMware

Revision: 1.1

Estimated Item Count: 28

File Details

Filename: DISA_STIG_VMware_vSphere_7.0_Virtual_Machine_v1r3.audit

Size: 124 kB

MD5: 2951c8eb0693ce44ff69eef224ea287a
SHA256: c7bd4c984f6df259bca4f78445a9fd7412d9b3c252c621baa405b3caed75a39d

Audit Items

DescriptionCategories
VMCH-70-000001 - Copy operations must be disabled on the virtual machine (VM).

CONFIGURATION MANAGEMENT

VMCH-70-000002 - Drag and drop operations must be disabled on the virtual machine (VM).

CONFIGURATION MANAGEMENT

VMCH-70-000003 - Paste operations must be disabled on the virtual machine (VM).

CONFIGURATION MANAGEMENT

VMCH-70-000004 - Virtual disk shrinking must be disabled on the virtual machine (VM).

CONFIGURATION MANAGEMENT

VMCH-70-000005 - Virtual disk wiping must be disabled on the virtual machine (VM).

CONFIGURATION MANAGEMENT

VMCH-70-000006 - Independent, nonpersistent disks must not be used on the virtual machine (VM).

CONFIGURATION MANAGEMENT

VMCH-70-000007 - Host Guest File System (HGFS) file transfers must be disabled on the virtual machine (VM).

CONFIGURATION MANAGEMENT

VMCH-70-000008 - Unauthorized floppy devices must be disconnected on the virtual machine (VM).

CONFIGURATION MANAGEMENT

VMCH-70-000009 - Unauthorized CD/DVD devices must be disconnected on the virtual machine (VM).

CONFIGURATION MANAGEMENT

VMCH-70-000010 - Unauthorized parallel devices must be disconnected on the virtual machine (VM).

CONFIGURATION MANAGEMENT

VMCH-70-000011 - Unauthorized serial devices must be disconnected on the virtual machine (VM).

CONFIGURATION MANAGEMENT

VMCH-70-000012 - Unauthorized USB devices must be disconnected on the virtual machine (VM).

CONFIGURATION MANAGEMENT

VMCH-70-000013 - Console connection sharing must be limited on the virtual machine (VM).

CONFIGURATION MANAGEMENT

VMCH-70-000015 - Informational messages from the virtual machine to the VMX file must be limited on the virtual machine (VM).

CONFIGURATION MANAGEMENT

VMCH-70-000016 - Unauthorized removal, connection, and modification of devices must be prevented on the virtual machine (VM).

CONFIGURATION MANAGEMENT

VMCH-70-000017 - The virtual machine (VM) must not be able to obtain host information from the hypervisor.

CONFIGURATION MANAGEMENT

VMCH-70-000018 - Shared salt values must be disabled on the virtual machine (VM).

CONFIGURATION MANAGEMENT

VMCH-70-000019 - Access to virtual machines (VMs) through the 'dvfilter' network Application Programming Interface (API) must be controlled.

CONFIGURATION MANAGEMENT

VMCH-70-000020 - System administrators must use templates to deploy virtual machines (VMs) whenever possible.

CONFIGURATION MANAGEMENT

VMCH-70-000021 - Use of the virtual machine (VM) console must be minimized.

CONFIGURATION MANAGEMENT

VMCH-70-000022 - The virtual machine (VM) guest operating system must be locked when the last console connection is closed.

CONFIGURATION MANAGEMENT

VMCH-70-000023 - All 3D features on the virtual machine (VM) must be disabled when not required.

CONFIGURATION MANAGEMENT

VMCH-70-000024 - Encryption must be enabled for vMotion on the virtual machine (VM).

CONFIGURATION MANAGEMENT

VMCH-70-000025 - Logging must be enabled on the virtual machine (VM).

CONFIGURATION MANAGEMENT

VMCH-70-000026 - Log size must be configured properly on the virtual machine (VM).

CONFIGURATION MANAGEMENT

VMCH-70-000027 - Log retention must be configured properly on the virtual machine (VM).

CONFIGURATION MANAGEMENT

VMCH-70-000028 - DirectPath I/O must be disabled on the virtual machine (VM) when not required.

CONFIGURATION MANAGEMENT

VMCH-70-000029 - Encryption must be enabled for Fault Tolerance on the virtual machine (VM).

CONFIGURATION MANAGEMENT