vSAN: vsan-8.data-at-rest

Information

vSAN must protect data at rest. vSAN Data-at-Rest encryption helps maintain the confidentiality of sensitive data while it resides on storage devices and reduce the risk of unauthorized access or exposure in the event of physical theft or loss. This configuration parameter can be altered while the cluster is operational. Enabling data-at-rest protections will reformat disk groups (for vSAN OSA) and rewrite stored objects (for vSAN ESA), which may take considerable time, but it will be done in the background. Workloads do not need to be powered off. vSAN ESA 8.0.2 introduced the ability to enable data-at-rest protections on an existing vSAN ESA datastore; vSAN ESA 8.0.3 introduced the ability to disable it again. It is recommended that you run the latest version of vSAN if using ESA.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

N/A

See Also

https://github.com/vmware/vcf-security-and-compliance-guidelines/raw/refs/heads/main/security-configuration-hardening-guide/vsphere/8.0/