UCF STIG Viewer Logo

The operating system must enforce information flow control using protected processing domains (e.g., domain type-enforcement) as a basis for flow control decisions.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-OS-000010-ESXI5-PF SRG-OS-000010-ESXI5-PF SRG-OS-000010-ESXI5-PF_rule Medium
Description
Protected processing domains can be used to separate different data types. The operating system must enforce information flow control to ensure information does not pass into domains that are not authorized to process it. Applicable, but permanent finding - The hypervisor does not support domain separation, only VM isolation.
STIG Date
VMware ESXi v5 Security Technical Implementation Guide 2013-01-15

Details

Check Text ( C-SRG-OS-000010-ESXI5-PF_chk )
ESXi does not support this requirement. This is a permanent finding.
Fix Text (F-SRG-OS-000010-ESXI5-PF_fix)
This requirement is a permanent finding and cannot be fixed. An appropriate mitigation for the system must be implemented but this finding cannot be considered fixed.