Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
SRG-OS-000005-ESXI5-PNF | SRG-OS-000005-ESXI5-PNF | SRG-OS-000005-ESXI5-PNF_rule | Medium |
Description |
---|
While user identities remain relatively constant over time, user privileges may change more frequently based on the ongoing mission/business requirements and operational needs of the organization. The operating system needs to be able to dynamically manage user privileges and access authorization decisions. Applicable, but permanent not-a-finding - There is only 1 local account on ESXi-v5 (root), which must never be disabled. All other accounts (excepting vpxuser which is automated by vCenter) are Active Directory. The root account login is locked in Lockdown Mode (a requirement). Dynamic privileges may be controlled via "roles". |
STIG | Date |
---|---|
VMware ESXi v5 Security Technical Implementation Guide | 2013-01-15 |
Check Text ( C-SRG-OS-000005-ESXI5-PNF_chk ) |
---|
ESXi supports this requirement and cannot be configured to be out of compliance. This is a permanent not a finding. |
Fix Text (F-SRG-OS-000005-ESXI5-PNF_fix) |
---|
This requirement is permanent not a finding. No fix is required. |