8.4.24 Disable VM Monitor Control

Information

Disable VM Monitor Control.

*Rationale*

When Virtual Machines are running on a hypervisor they are 'aware' that they are running
in a virtual environment and this and this information is available to tools inside the guest
OS. This can give attackers information about the platform that they are running on that
they may not get from a normal physical server. This option completely disables all hooks
for a virtual machine and the guest OS will not be aware that it is running in a virtual
environment at all.

Solution

To implement the recommended configuration state, run the following PowerCLI
command-# Add the setting to all VMs
Get-VM | New-AdvancedSetting -Name 'isolation.monitor.control.disable' -value $true

Impact-This configuration option may cause unexpected results, the virtual machine will be
completely unaware that it is running in a virtualized setting. VMware tools will not install
or function.

Default Value-The prescribed state is not the default state.

See Also

https://workbench.cisecurity.org/files/902

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: VMware

Control ID: 540918be2ddc73914480f70502fcb8853120cd498b97c2c31690701d8c991f87