ESXI5-VM-000050 - The system must use templates to deploy VMs whenever possible.

Information

By capturing a hardened base operating system image (with no applications installed) in a template, ensure all virtual machines are created with a known baseline level of security. Then use this template to create other, application-specific templates, or use the application template to deploy virtual machines. Manual installation of the OS and applications into a VM introduces the risk of misconfiguration due to human or process error.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Hardened, patched templates must be used for VM creation, properly configured OS deployments and applications. Applications dependent on VM-specific information must also use hardened, patched templates.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_ESXi5_Virtual_Machine_V2R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Group-ID|V-39504, Rule-ID|SV-250721r799639_rule, STIG-ID|ESXI5-VM-000050, STIG-Legacy|SV-51362, STIG-Legacy|V-39504, Vuln-ID|V-250721

Plugin: VMware

Control ID: c5387ce11e0369aeef806b1888e0ed099b13e5817b11615659081d5289adf7fe