DISA STIG VMware vSphere Virtual Machine 6.x v1r1

Audit Details

Name: DISA STIG VMware vSphere Virtual Machine 6.x v1r1

Updated: 6/17/2024

Authority: DISA STIG

Plugin: VMware

Revision: 1.17

Estimated Item Count: 43

File Details

Filename: DISA_STIG_VMware_vSphere_Virtual_Machine_6_v1r1.audit

Size: 195 kB

MD5: 7d9b9d6680373bf2364c725536768348
SHA256: a77779a45406fb81102c6f3657f4f4a852ca0ffd23169dd82bd9ab95c0ed8a88

Audit Items

DescriptionCategories
VMCH-06-000001 - The system must explicitly disable copy operations.

CONFIGURATION MANAGEMENT

VMCH-06-000002 - The system must explicitly disable drag and drop operations.

CONFIGURATION MANAGEMENT

VMCH-06-000003 - The system must explicitly disable any GUI functionality for copy/paste operations.

CONFIGURATION MANAGEMENT

VMCH-06-000004 - The system must explicitly disable paste operations.

CONFIGURATION MANAGEMENT

VMCH-06-000005 - The system must disable virtual disk shrinking.

CONFIGURATION MANAGEMENT

VMCH-06-000006 - The system must disable virtual disk erasure.

CONFIGURATION MANAGEMENT

VMCH-06-000007 - The system must not use independent, non-persistent disks.

CONFIGURATION MANAGEMENT

VMCH-06-000008 - The system must disable HGFS file transfers.

CONFIGURATION MANAGEMENT

VMCH-06-000009 - The unexposed feature keyword isolation.tools.ghi.autologon.disable must be set.

CONFIGURATION MANAGEMENT

VMCH-06-000010 - The unexposed feature keyword isolation.bios.bbs.disable must be set.

CONFIGURATION MANAGEMENT

VMCH-06-000011 - The unexposed feature keyword isolation.tools.getCreds.disable must be set.

CONFIGURATION MANAGEMENT

VMCH-06-000012 - The unexposed feature keyword isolation.tools.ghi.launchmenu.change must be set.

CONFIGURATION MANAGEMENT

VMCH-06-000013 - The unexposed feature keyword isolation.tools.memSchedFakeSampleStats.disable must be set.

CONFIGURATION MANAGEMENT

VMCH-06-000014 - The unexposed feature keyword isolation.tools.ghi.protocolhandler.info.disable must be set.

CONFIGURATION MANAGEMENT

VMCH-06-000015 - The unexposed feature keyword isolation.ghi.host.shellAction.disable must be set.

CONFIGURATION MANAGEMENT

VMCH-06-000016 - The unexposed feature keyword isolation.tools.dispTopoRequest.disable must be set.

CONFIGURATION MANAGEMENT

VMCH-06-000017 - The unexposed feature keyword isolation.tools.trashFolderState.disable must be set.

CONFIGURATION MANAGEMENT

VMCH-06-000018 - The unexposed feature keyword isolation.tools.ghi.trayicon.disable must be set.

CONFIGURATION MANAGEMENT

VMCH-06-000019 - The unexposed feature keyword isolation.tools.unity.disable must be set.

CONFIGURATION MANAGEMENT

VMCH-06-000020 - The unexposed feature keyword isolation.tools.unityInterlockOperation.disable must be set.

CONFIGURATION MANAGEMENT

VMCH-06-000021 - The unexposed feature keyword isolation.tools.unity.push.update.disable must be set.

CONFIGURATION MANAGEMENT

VMCH-06-000022 - The unexposed feature keyword isolation.tools.unity.taskbar.disable must be set.

CONFIGURATION MANAGEMENT

VMCH-06-000023 - The unexposed feature keyword isolation.tools.unityActive.disable must be set.

CONFIGURATION MANAGEMENT

VMCH-06-000024 - The unexposed feature keyword isolation.tools.unity.windowContents.disable must be set.

CONFIGURATION MANAGEMENT

VMCH-06-000025 - The unexposed feature keyword isolation.tools.vmxDnDVersionGet.disable must be set.

CONFIGURATION MANAGEMENT

VMCH-06-000026 - The unexposed feature keyword isolation.tools.guestDnDVersionSet.disable must be set.

CONFIGURATION MANAGEMENT

VMCH-06-000027 - The system must disable VIX messages from the VM.

CONFIGURATION MANAGEMENT

VMCH-06-000028 - The system must disconnect unauthorized floppy devices.

CONFIGURATION MANAGEMENT

VMCH-06-000029 - The system must disconnect unauthorized CD/DVD devices.

CONFIGURATION MANAGEMENT

VMCH-06-000030 - The system must disconnect unauthorized parallel devices.

CONFIGURATION MANAGEMENT

VMCH-06-000031 - The system must disconnect unauthorized serial devices.

CONFIGURATION MANAGEMENT

VMCH-06-000032 - The system must disconnect unauthorized USB devices.

CONFIGURATION MANAGEMENT

VMCH-06-000033 - The system must limit sharing of console connections.

CONFIGURATION MANAGEMENT

VMCH-06-000034 - The system must disable console access through the VNC protocol.

CONFIGURATION MANAGEMENT

VMCH-06-000035 - The system must disable tools auto install.

CONFIGURATION MANAGEMENT

VMCH-06-000036 - The system must limit informational messages from the VM to the VMX file.

CONFIGURATION MANAGEMENT

VMCH-06-000037 - The system must prevent unauthorized removal, connection and modification of devices.

CONFIGURATION MANAGEMENT

VMCH-06-000038 - The system must prevent unauthorized removal, connection and modification of devices.

CONFIGURATION MANAGEMENT

VMCH-06-000039 - The system must not send host information to guests.

CONFIGURATION MANAGEMENT

VMCH-06-000040 - The system must disable shared salt values.

CONFIGURATION MANAGEMENT

VMCH-06-000041 - The system must control access to VMs through the dvfilter network APIs.

CONFIGURATION MANAGEMENT

VMCH-06-000043 - The system must use templates to deploy VMs whenever possible.

CONFIGURATION MANAGEMENT

VMCH-06-000044 - The system must minimize use of the VM console.

CONFIGURATION MANAGEMENT