UCF STIG Viewer Logo

VMware vSphere 6.5 Virtual Machine Security Technical Implementation Guide


Overview

Date Finding Count (39)
2019-10-01 CAT I (High): 0 CAT II (Med): 15 CAT III (Low): 24
STIG Description
This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DoD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via e-mail to the following address: disa.stig_spt@mail.mil.

Available Profiles



Findings (MAC III - Administrative Sensitive)

Finding ID Severity Title
V-94617 Medium Unauthorized parallel devices must be disconnected on the virtual machine.
V-94613 Medium Unauthorized floppy devices must be disconnected on the virtual machine.
V-94651 Medium Encryption must be enabled for vMotion on the virtual machine.
V-94619 Medium Unauthorized serial devices must be disconnected on the virtual machine.
V-94639 Medium Use of the virtual machine console must be minimized.
V-94631 Medium The virtual machine must not be able to obtain host information from the hypervisor.
V-94577 Medium HGFS file transfers must be disabled on the virtual machine.
V-94575 Medium Independent, non-persistent disks must be not be used on the virtual machine.
V-94573 Medium Virtual disk erasure must be disabled on the virtual machine.
V-94571 Medium Virtual disk shrinking must be disabled on the virtual machine.
V-94647 Medium The virtual machine guest operating system must be locked when the last console connection is closed.
V-94629 Medium Unauthorized removal, connection and modification of devices must be prevented on the virtual machine.
V-94625 Medium Console access through the VNC protocol must be disabled on the virtual machine.
V-94623 Medium Console connection sharing must be limited on the virtual machine.
V-94621 Medium Unauthorized USB devices must be disconnected on the virtual machine.
V-94565 Low Drag and drop operations must be disabled on the virtual machine.
V-94567 Low GUI functionality for copy/paste operations must be disabled on the virtual machine.
V-94563 Low Copy operations must be disabled on the virtual machine.
V-94569 Low Paste operations must be disabled on the virtual machine.
V-94605 Low The unexposed feature keyword isolation.tools.unityActive.disable must be set on the virtual machine.
V-94615 Low Unauthorized CD/DVD devices must be disconnected on the virtual machine.
V-94599 Low The unexposed feature keyword isolation.tools.unityInterlockOperation.disable must be set on the virtual machine.
V-94611 Low The unexposed feature keyword isolation.tools.guestDnDVersionSet.disable must be set on the virtual machine.
V-94595 Low The unexposed feature keyword isolation.tools.ghi.trayicon.disable must be set on the virtual machine.
V-94597 Low The unexposed feature keyword isolation.tools.unity.disable must be set on the virtual machine.
V-94593 Low The unexposed feature keyword isolation.ghi.host.shellAction.disable must be set on the virtual machine.
V-94635 Low Access to virtual machines through the dvfilter network APIs must be controlled.
V-94637 Low System administrators must use templates to deploy virtual machines whenever possible.
V-94633 Low Shared salt values must be disabled on the virtual machine.
V-94579 Low The unexposed feature keyword isolation.tools.ghi.autologon.disable must be set on the virtual machine.
V-94601 Low The unexposed feature keyword isolation.tools.unity.push.update.disable must be set on the virtual machine.
V-94603 Low The unexposed feature keyword isolation.tools.unity.taskbar.disable must be set on the virtual machine.
V-94649 Low 3D features on the virtual machine must be disabled when not required.
V-94583 Low The unexposed feature keyword isolation.tools.memSchedFakeSampleStats.disable must be set on the virtual machine.
V-94581 Low The unexposed feature keyword isolation.tools.ghi.launchmenu.change must be set on the virtual machine.
V-94585 Low The unexposed feature keyword isolation.tools.ghi.protocolhandler.info.disable must be set on the virtual machine.
V-94609 Low The unexposed feature keyword isolation.tools.vmxDnDVersionGet.disable must be set on the virtual machine.
V-94607 Low The unexposed feature keyword isolation.tools.unity.windowContents.disable must be set on the virtual machine.
V-94627 Low Informational messages from the virtual machine to the VMX file must be limited on the virtual machine.