- DISA_STIG_VMware_vSphere_ESXi_6.5_v2r3.audit from DISA VMware vSphere 6.5 ESXi v2r3 STIG
- ESXI-65-000001 - The ESXi host must limit the number of concurrent sessions to ten for all accounts and/or account types by enabling lockdown mode.
- ESXI-65-000002 - The ESXi host must verify the DCUI.Access list.
- ESXI-65-000003 - The ESXi host must verify the exception users list for lockdown mode.
- ESXI-65-000004 - Remote logging for ESXi hosts must be configured.
- ESXI-65-000005 - The ESXi host must enforce the limit of three consecutive invalid logon attempts by a user.
- ESXI-65-000006 - The ESXi host must enforce the unlock timeout of 15 minutes after a user account is locked out.
- ESXI-65-000007 - The ESXi host must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the system.
- ESXI-65-000008 - The ESXi host must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the system.
- ESXI-65-000030 - The ESXi host must produce audit records containing information to establish what type of events occurred.
- ESXI-65-000031 - The ESXi host must enforce password complexity by requiring that at least one upper-case character be used.
- ESXI-65-000034 - The ESXi host must disable the Managed Object Browser (MOB).
- ESXI-65-000035 - The ESXi host must be configured to disable non-essential capabilities by disabling SSH.
- ESXI-65-000036 - The ESXi host must disable ESXi Shell unless needed for diagnostics or troubleshooting.
- ESXI-65-000037 - The ESXi host must use Active Directory for local user authentication.
- ESXI-65-000038 - The ESXi host must use the vSphere Authentication Proxy to protect passwords when adding ESXi hosts to Active Directory.
- ESXI-65-000039 - Active Directory ESX Admin group membership must not be used when adding ESXi hosts to Active Directory.
- ESXI-65-000040 - The ESXi host must use multifactor authentication for local access to privileged accounts.
- ESXI-65-000041 - The ESXi host must set a timeout to automatically disable idle sessions after 10 minutes.
- ESXI-65-000042 - The ESXi host must terminate shell services after 10 minutes.
- ESXI-65-000045 - The ESXi host must enable a persistent log location for all locally stored logs.
- ESXI-65-000046 - The ESXi host must configure NTP time synchronization.
- ESXI-65-000048 - The ESXi host must protect the confidentiality and integrity of transmitted information by isolating vMotion traffic.
- ESXI-65-000049 - The ESXi host must protect the confidentiality and integrity of transmitted information.
- ESXI-65-000050 - The ESXi host must protect the confidentiality and integrity of transmitted information by protecting IP based management traffic.
- ESXI-65-000052 - The ESXi host must protect the confidentiality and integrity of transmitted information by utilizing different TCP/IP stacks where possible.
- ESXI-65-000053 - SNMP must be configured properly on the ESXi host.
- ESXI-65-000054 - The ESXi host must enable bidirectional CHAP authentication for iSCSI traffic.
- ESXI-65-000055 - The ESXi host must disable Inter-VM transparent page sharing.
- ESXI-65-000057 - The ESXi host must configure the firewall to block network traffic by default - incoming