Check: VMCH-67-000020
VMware vSphere 6.7 Virtual Machine STIG:
VMCH-67-000020
(in versions v1 r3 through v1 r1)
Title
System administrators must use templates to deploy virtual machines whenever possible. (Cat III impact)
Discussion
By capturing a hardened base operating system image (with no applications installed) in a template, ensure all virtual machines are created with a known baseline level of security. Then use this template to create other, application-specific templates, or use the application template to deploy virtual machines. Manual installation of the OS and applications into a VM introduces the risk of misconfiguration due to human or process error.
Check Content
Ask the SA if hardened, patched templates are used for VM creation, properly configured OS deployments, including applications both dependent and non-dependent on VM-specific configurations. If hardened, patched templates are not used for VM creation, this is a finding.
Fix Text
Create hardened virtual machine templates to use for OS deployments.
Additional Identifiers
Rule ID: SV-239351r679602_rule
Vulnerability ID: V-239351
Group Title: SRG-OS-000480-VMM-002000
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |