3.19 (L1) Host must have an accurate Exception Users list

Information

Establishing an accurate Exception Users list is essential for managing user privileges during lockdown mode. Users on this list retain their privileges, making it imperative to include only those necessary for direct host access like service accounts for third-party solutions. Ensuring a well-maintained list mitigates the risk associated with unauthorized actions, especially during host isolation scenarios in lockdown mode.

The Exception Users list is crucial for preserving necessary operational capabilities while maintaining a secure environment. By carefully managing this list, organizations can balance between security and functionality, ensuring that critical operations continue unhindered during lockdown mode.

Solution

To correct the membership of the Exception Users list, perform the following in the vSphere Web Client:

- Select the host.
- Click on Configure then expand System and select Security Profile
- Select Edit next to Lockdown Mode
- Click on Exception Users
- Add or delete users as appropriate.
- Click OK

Impact:

An improperly managed Exception Users list could potentially undermine the security posture by allowing unauthorized access, increasing the risk of malicious actions. It's vital to review and update this list regularly to align with the current operational and security requirements.

See Also

https://workbench.cisecurity.org/benchmarks/15784

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-2, 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6, CSCv7|16.6

Plugin: VMware

Control ID: 19dce474788ef3bbee4b107dbd42fd86cb7b3d781c211a9f42ef24dbcacee243