VCENTER-000012 - The vCenter Server administrative users must have the correct roles assigned.

Information

Administrative users must only be assigned privileges they require. Least Privilege requires that these privileges must only be assigned if needed, to reduce risk of confidentiality, availability or integrity loss.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Create roles in vCenter with the required granularity of privilege for the organization's administrator types, and ensure that these roles are assigned to the correct, site-specific users. As a vCenter Server administrator, log into the vCenter Server with the vSphere Client.
Go to 'Home>> Administration>> Roles' and create a role for each of the administrator privilege sets the organization requires and allows.
Right click on each role name and select 'Edit'. Verify under 'All Privileges>> Virtual Machines' that only site-specific, required checkboxes are selected.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_ESXi5_vCenter_Server_V2R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-5(6), CAT|II, CCI|CCI-001499, Group-ID|V-39550, Rule-ID|SV-250732r799886_rule, STIG-ID|VCENTER-000012, STIG-Legacy|SV-51408, STIG-Legacy|V-39550, Vuln-ID|V-250732

Plugin: VMware

Control ID: 37ea1224b4a5bc1884d06498b284e972ca3d0c0482c379901b3c0fd4b5a85ffa