VCENTER-000012 - The vCenter Server administrative users must have the correct roles assigned

Information

Administrative users must only be assigned privileges they require. Least Privilege requires that these privileges must only be assigned if needed, to reduce risk of confidentiality, availability or integrity loss.

Solution

Create roles in vCenter with the required granularity of privilege for the organization's administrator types, and ensure that these roles are assigned to the correct, site-specific users. As a vCenter Server administrator, log into the vCenter Server with the vSphere Client. Go to 'Home>> Administration>> Roles' and create a role for each of the administrator privilege sets the organization requires and allows. Right click on each role name and select 'Edit'. Verify under 'All Privileges>> Virtual Machines' that only site-specific, required checkboxes are selected

See Also

http://iase.disa.mil/stigs/os/virtualization/Pages/index.aspx

Item Details

References: CAT|II, CCI|CCI-001499, Group-ID|V-39550, Rule-ID|SV-51408r1_rule, STIG-ID|VCENTER-000012

Plugin: VMware

Control ID: 7ac09b6995a5858c7a08fdd0c3449beccc99b97755391bd3f0071889fca33de5