Item Search

NameAudit NamePluginCategory
PHTN-67-000015 - The Photon operating system audit log must have correct permissions.DISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

AUDIT AND ACCOUNTABILITY

PHTN-67-000016 - The Photon operating system audit log must be owned by root.DISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

AUDIT AND ACCOUNTABILITY

PHTN-67-000034 - The Photon operating system must not have Duplicate User IDs (UIDs).DISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

IDENTIFICATION AND AUTHENTICATION

PHTN-67-000050 - The Photon operating system audit files and directories must have correct permissions - ausearchDISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

AUDIT AND ACCOUNTABILITY

PHTN-67-000050 - The Photon operating system audit files and directories must have correct permissions - autraceDISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

AUDIT AND ACCOUNTABILITY

PHTN-67-000073 - The Photon operating system must audit the insmod module.DISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

AUDIT AND ACCOUNTABILITY

PHTN-67-000076 - The Photon operating system must set the FAIL_DELAY parameter.DISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

CONFIGURATION MANAGEMENT

PHTN-67-000078 - The Photon operating system must ensure audit events are flushed to disk at proper intervals - flushDISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

CONFIGURATION MANAGEMENT

PHTN-67-000078 - The Photon operating system must ensure audit events are flushed to disk at proper intervals - freqDISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

CONFIGURATION MANAGEMENT

PHTN-67-000096 - The Photon operating system must be configured so that the /etc/skel default scripts are protected from unauthorized modification - bash_profileDISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

CONFIGURATION MANAGEMENT

PHTN-67-000102 - The Photon operating system must be configured so that all cron jobs are protected from unauthorized modification.DISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

CONFIGURATION MANAGEMENT

PHTN-67-000103 - The Photon operating system must be configured so that all cron paths are protected from unauthorized modification - cron.hourlyDISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

CONFIGURATION MANAGEMENT

PHTN-67-000106 - The Photon operating system must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted - net.ipv4.conf.default.accept_redirectsDISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

CONFIGURATION MANAGEMENT

PHTN-67-000106 - The Photon operating system must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted - net.ipv4.conf.eth0.accept_redirectsDISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

CONFIGURATION MANAGEMENT

PHTN-67-000109 - The Photon operating system must log IPv4 packets with impossible addresses - net.ipv4.conf.all.log_martiansDISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

CONFIGURATION MANAGEMENT

PHTN-67-000109 - The Photon operating system must log IPv4 packets with impossible addresses - net.ipv4.conf.default.log_martiansDISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

CONFIGURATION MANAGEMENT

PHTN-67-000110 - The Photon operating system must use a reverse-path filter for IPv4 network traffic - net.ipv4.conf.default.rp_filterDISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

CONFIGURATION MANAGEMENT

PHTN-67-000111 - The Photon operating system must not perform multicast packet forwarding - net.ipv6.conf.default.mc_forwardingDISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

CONFIGURATION MANAGEMENT

PHTN-67-000112 - The Photon operating system must not perform IPv4 packet forwarding.DISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

CONFIGURATION MANAGEMENT

SYMP-AG-000090 - Symantec ProxySG must immediately use updates made to policy enforcement mechanisms such as policies and rules - SSLDISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

ACCESS CONTROL

SYMP-AG-000200 - Symantec ProxySG must generate audit records containing information to establish the identity of any individual or process associated with the event.DISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

AUDIT AND ACCOUNTABILITY

SYMP-AG-000280 - Symantec ProxySG must not have unnecessary services and functions enabled.DISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

CONFIGURATION MANAGEMENT

SYMP-AG-000310 - Symantec ProxySG providing user authentication intermediary services must require users to reauthenticate every 900 seconds when organization-defined circumstances or situations require reauthentication - LDAPDISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

IDENTIFICATION AND AUTHENTICATION

SYMP-AG-000310 - Symantec ProxySG providing user authentication intermediary services must require users to reauthenticate every 900 seconds when organization-defined circumstances or situations require reauthentication - RADIUSDISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

IDENTIFICATION AND AUTHENTICATION

VCFL-67-000026 - vSphere Client must have the debug option turned off.DISA STIG VMware vSphere 6.7 Virgo Client v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

VCLD-67-000001 - VAMI must limit the number of simultaneous requests.DISA STIG VMware vSphere 6.7 VAMI-lighttpd v1r3Unix

ACCESS CONTROL

VCLD-67-000020 - VAMI must have resource mappings set to disable the serving of certain file types.DISA STIG VMware vSphere 6.7 VAMI-lighttpd v1r3Unix

CONFIGURATION MANAGEMENT

VCLD-67-000021 - VAMI must not have the Web Distributed Authoring (WebDAV) servlet installed.DISA STIG VMware vSphere 6.7 VAMI-lighttpd v1r3Unix

CONFIGURATION MANAGEMENT

VCLD-67-000022 - VAMI must prevent hosted applications from exhausting system resources.DISA STIG VMware vSphere 6.7 VAMI-lighttpd v1r3Unix

CONFIGURATION MANAGEMENT

VCLD-67-000023 - VAMI must not have any symbolic links in the web content directory tree.DISA STIG VMware vSphere 6.7 VAMI-lighttpd v1r3Unix

CONFIGURATION MANAGEMENT

VCLD-67-000026 - VAMI must restrict access to the web root.DISA STIG VMware vSphere 6.7 VAMI-lighttpd v1r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

VCLD-67-000033 - VAMI must be protected from being stopped by a non-privileged user.DISA STIG VMware vSphere 6.7 VAMI-lighttpd v1r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

VCPF-67-000031 - Performance Charts must be configured to limit access to internal packages.DISA STIG VMware vSphere 6.7 Perfcharts Tomcat v1r3Unix

CONFIGURATION MANAGEMENT

VCRP-67-000002 - The rhttpproxy must set a limit on established connections.DISA STIG VMware vSphere 6.7 RhttpProxy v1r3Unix

ACCESS CONTROL

VCST-67-000001 - The Security Token Service must limit the amount of time that each TCP connection is kept alive.DISA STIG VMware vSphere 6.7 STS Tomcat v1r3Unix

ACCESS CONTROL

VCST-67-000002 - The Security Token Service must limit the number of concurrent connections permitted.DISA STIG VMware vSphere 6.7 STS Tomcat v1r3Unix

ACCESS CONTROL

VCST-67-000006 - The Security Token Service must generate log records during Java startup and shutdown - bufferSizeDISA STIG VMware vSphere 6.7 STS Tomcat v1r3Unix

AUDIT AND ACCOUNTABILITY

VCST-67-000006 - The Security Token Service must generate log records during Java startup and shutdown - directoryDISA STIG VMware vSphere 6.7 STS Tomcat v1r3Unix

AUDIT AND ACCOUNTABILITY

VCST-67-000010 - The Security Token Service must not be configured with unused realms.DISA STIG VMware vSphere 6.7 STS Tomcat v1r3Unix

CONFIGURATION MANAGEMENT

VCST-67-000015 - The Security Token Service must be configured with memory leak protection.DISA STIG VMware vSphere 6.7 STS Tomcat v1r3Unix

CONFIGURATION MANAGEMENT

VCST-67-000026 - The Security Token Service must have the debug option disabled.DISA STIG VMware vSphere 6.7 STS Tomcat v1r3Unix

SYSTEM AND INFORMATION INTEGRITY

VCTR-67-000005 - The vCenter Server users must have the correct roles assigned.DISA STIG VMware vSphere 6.7 vCenter v1r4VMware

SYSTEM AND COMMUNICATIONS PROTECTION

VCTR-67-000015 - The vCenter Server must set the distributed port group Promiscuous Mode policy to reject.DISA STIG VMware vSphere 6.7 vCenter v1r4VMware

CONFIGURATION MANAGEMENT

VCUI-67-000015 - vSphere UI must not have any symbolic links in the web content directory tree.DISA STIG VMware vSphere 6.7 UI Tomcat v1r3Unix

CONFIGURATION MANAGEMENT

VCUI-67-000029 - vSphere UI must disable the shutdown port - server.xmlDISA STIG VMware vSphere 6.7 UI Tomcat v1r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

VMCH-67-000004 - Virtual disk shrinking must be disabled on the virtual machine.DISA STIG VMware vSphere 6.7 Virtual Machine v1r3VMware

CONFIGURATION MANAGEMENT

VMCH-67-000006 - Independent, non-persistent disks must be not be used on the virtual machine.DISA STIG VMware vSphere 6.7 Virtual Machine v1r3VMware

CONFIGURATION MANAGEMENT

VMCH-67-000011 - Unauthorized serial devices must be disconnected on the virtual machine.DISA STIG VMware vSphere 6.7 Virtual Machine v1r3VMware

CONFIGURATION MANAGEMENT

VMCH-67-000021 - Use of the virtual machine console must be minimized.DISA STIG VMware vSphere 6.7 Virtual Machine v1r3VMware

CONFIGURATION MANAGEMENT

VMCH-67-000024 - Encryption must be enabled for vMotion on the virtual machine.DISA STIG VMware vSphere 6.7 Virtual Machine v1r3VMware

CONFIGURATION MANAGEMENT