6.4 Ensure VMDK files are zeroed out prior to deletion

Information

The CLI command 'vmkfstools --writezeroes' can be used to write zeros to the entire contents of a virtual machine disk (VMDK) file prior to its deletion.

Rationale:

Zeroing out a VMDK file before deleting the file can help prevent users from reconstructing the original contents of the file from the physical storage media.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

When deleting a VMDK file with sensitive data:

Shut down or stop the virtual machine.

Issue the CLI command 'vmkfstools --writezeroes' on that file prior to deleting it from the datastore.

Impact:

When you use this command, you lose any existing data on the virtual disk.

References:

https://docs.vmware.com/en/VMware-vSphere/6.7/com.vmware.vsphere.storage.doc/GUID-050C0FEE-2C75-4356-B9E0-CC802333FF41.html

See Also

https://workbench.cisecurity.org/files/2816

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3

Plugin: VMware

Control ID: b52fcf2f39f0df187ea272fbd5055265fea65c5745604a52f61929478d8704f8