UCF STIG Viewer Logo

The vRealize Operations server must use an enterprise user management system to uniquely identify and authenticate users (or processes acting on behalf of organizational users).


Overview

Finding ID Version Rule ID IA Controls Severity
V-88205 VROM-AP-000195 SV-98855r1_rule Medium
Description
To assure accountability and prevent unauthorized access, application server users must be uniquely identified and authenticated. This is typically accomplished via the use of a user store that is either local (OS-based) or centralized (LDAP) in nature. To ensure support to the enterprise, the authentication must utilize an enterprise solution.
STIG Date
VMware vRealize Operations Manager 6.x Application Security Technical Implementation Guide 2018-10-11

Details

Check Text ( C-87897r1_chk )
Obtain the site configuration control policy from the ISSO.

Review site procedures to determine if an enterprise management system is used to uniquely identify and authenticate users.

If an enterprise management solution is not used, this is a finding.
Fix Text (F-94947r1_fix)
Configure vROps to use an enterprise user management system and document this in the site configuration control policy.