1.3 (L1) Host hardware must enable Intel TXT, if available

Information

Intel Xeon Scalable Processor platforms have Trusted Execution Technology, or TXT, that help harden systems against malware, rootkits, BIOS & firmware attacks, and more. When enabled, ESXi will take advantage of security benefits offered by this technology.

Enabling Intel TXT (Trusted Execution Technology) on host hardware, when available, provides a hardware-based foundation for security.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Impact:

In early implementations, operations such as firmware updates and abrupt system shutdowns may activate attestation alarms in vCenter Server or cause boot failures. Typically, a cold system restart offers a temporary fix, while a system firmware update provides a permanent solution. Refer to KB 78243.

See Also

https://workbench.cisecurity.org/benchmarks/19200

Item Details

Category: CONFIGURATION MANAGEMENT, MAINTENANCE

References: 800-53|CM-7, 800-53|MA-4, CSCv7|5.1

Plugin: VMware

Control ID: 65c3d875bf0552cfc1d46fc3efb31c5a8f9923fe690ebb1f14f0555c400c4acc