3.2 Configure Host Profiles to monitor and alert on configuration changes

Information

The Host Profiles feature monitors host configurations against an established profile and
provides notification when unauthorized configurations take place.

*Rationale*

Monitoring for configuration drift and unauthorized changes is critical to ensuring the
security of an ESXi hosts. Host Profiles provide an automated method for monitoring host
configurations against an established template and for providing notification in the event
deviations are detected.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Perform the following-1. Configure a reference ESXi host with the desired configuration and use the host to
create a Host Profile.
2. Attach the host profile to other hosts with identical hardware configurations.
3. Monitor hosts compliance to the host profile from the vSphere Client.

See Also

https://workbench.cisecurity.org/files/902