VM : prevent-device-interaction-edit

Information

Normal users and processes, that is users and processes without root or administrator privileges, within virtual machines have the capability to connect or disconnect devices, such as network adaptors and CD-ROM drives, as well as the ability to modify device settings. In general, you should use the virtual machine settings editor or configuration editor to remove any unneeded or unused hardware devices. However, you might want to use the device again, so removing it is not always a good solution. In that case, you can prevent a user or running process in the virtual machine from connecting or disconnecting a device from within the guest operating system, as well as modifying devices.

Solution

Set isolation.device.edit.disable to true in the virtual machine configuration file.

See Also

https://www.vmware.com/files/xls/hardeningguide-vsphere5-5-ga-released.xlsx

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(10)

Plugin: VMware

Control ID: 8fa6a90ac39498b55b923d9945b1654b68383a1c31b9453293498751fe38e682