UCF STIG Viewer Logo

The operating system must dynamically manage user privileges and associated access authorizations.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-OS-000005-ESXI5-PNF SRG-OS-000005-ESXI5-PNF SRG-OS-000005-ESXI5-PNF_rule Medium
Description
While user identities remain relatively constant over time, user privileges may change more frequently based on the ongoing mission/business requirements and operational needs of the organization. The operating system needs to be able to dynamically manage user privileges and access authorization decisions. Applicable, but permanent not-a-finding - There is only 1 local account on ESXi-v5 (root), which must never be disabled. All other accounts (excepting vpxuser which is automated by vCenter) are Active Directory. The root account login is locked in Lockdown Mode (a requirement). Dynamic privileges may be controlled via "roles".
STIG Date
VMware ESXi v5 Security Technical Implementation Guide 2013-01-15

Details

Check Text ( C-SRG-OS-000005-ESXI5-PNF_chk )
ESXi supports this requirement and cannot be configured to be out of compliance. This is a permanent not a finding.
Fix Text (F-SRG-OS-000005-ESXI5-PNF_fix)
This requirement is permanent not a finding. No fix is required.