8.2.2 Ensure unnecessary CD/DVD devices are disconnected

Information

Ensure that no CD/DVD device is connected to a virtual machine unless required. For a
CD/DVD device to be disconnected, the ideX:Y.present parameter should either not be
present or have a value of FALSE.

*Rationale*

Removing unnecessary hardware devices can reduce the number of potential attack
channels and help prevent attacks.


NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

To implement the recommended configuration state, run the following PowerCLI
command-

# Remove all CD/DVD Drives attached to VMs
Get-VM | Get-CDDrive | Remove-CDDrive

See Also

https://workbench.cisecurity.org/files/2168

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: VMware

Control ID: c5660644139463ab7c661cb68c9f030e5f5fdb649a376ad88c4b9fc172b8e515