1.10 (L2) Host hardware must enable Intel SGX, if available

Information

Intel Xeon Scalable Processor platforms have Software Guard Extensions, or SGX, a technology that helps applications protect data in system memory. When configured properly, vSphere supports the use of SGX inside guest virtual machines. Enabling SGX in system firmware eases future enablement inside virtual machines and guest OSes.

Intel SGX (Software Guard Extensions) provides hardware-based memory encryption that protects sensitive data from unauthorized access or modification by malicious software running at higher privilege levels, enhancing server security.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Impact:

Use of SGX requires guest OS support, and will limit some operational features inside vSphere, such as vMotion, snapshots, fault tolerance, and suspend/resume.

See Also

https://workbench.cisecurity.org/benchmarks/15784

Item Details

Category: CONFIGURATION MANAGEMENT, MAINTENANCE

References: 800-53|CM-7, 800-53|MA-4, CSCv7|5.1

Plugin: VMware

Control ID: 153f78cc5a5784e63515f2d1d73277b0a651c22fa3c89cf937da729fb1f10e63