UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The vCenter Server administrative users must have the correct roles assigned.


Overview

Finding ID Version Rule ID IA Controls Severity
VCENTER-000012 VCENTER-000012 VCENTER-000012_rule Medium
Description
Administrative users must only be assigned privileges they require. Least Privilege requires that these privileges must only be assigned if needed, to reduce risk of confidentiality, availability or integrity loss.
STIG Date
VMware vCenter Server Security Technical Implementation Guide 2013-01-15

Details

Check Text ( C-VCENTER-000012_chk )
Check that roles are created in vCenter with the required granularity of privilege for the organization's administrator types, and that these roles are assigned to the correct, site-specific users:
Log into the vCenter Server System using the vSphere Client as a vCenter Server System Administrator.
Go to "Home>> Administration>> Roles" and verify that a role exists for each of the administrator privilege sets the organization requires and allows.
Right click on each Role name and select "Edit". Verify under "All Privileges>> Virtual Machines" that only site-specific, required checkboxes are selected.

If the organization does not require roles for administrator privilege sets, this is a finding.

If a role does not exist for each of the organization-required, administrator privilege sets, this is a finding.
Fix Text (F-VCENTER-000012_fix)
Create roles in vCenter with the required granularity of privilege for the organization's administrator types, and ensure that these roles are assigned to the correct, site-specific users. As a vCenter Server administrator, log into the vCenter Server with the vSphere Client.
Go to "Home>> Administration>> Roles" and create a role for each of the administrator privilege sets the organization requires and allows.
Right click on each role name and select "Edit". Verify under "All Privileges>> Virtual Machines" that only site-specific, required checkboxes are selected.