VMware vSphere 8.0 STIG Implementation
18 items · Security · Hard difficulty · 1 day
Practical steps to apply the DISA vSphere 8.0 STIG across vCenter, ESXi and VMs.
-
Download the VMware vSphere 8.0 STIG from Cyber.mil
Get the latest XCCDF/STIG bundle from https://cyber.mil/ (or https://public.cyber.mil/ if no CAC).
-
Review STIG scope and component list
Identify which STIGs apply: vCenter, ESXi, Virtual Machine, and appliance services.
-
Inventory all vSphere assets and versions
List vCenter instances, ESXi hosts, appliances, and critical VMs with software versions.
-
Verify vSphere Update level or plan upgrade to Update 2
Ensure systems run vSphere 8.0 Update 2 or schedule an upgrade before applying STIGs.
-
Backup vCenter, ESXi configurations, and critical VMs
Take full backups and export configs before making STIG changes.
-
Apply vCenter STIG configuration settings
Implement recommended hardening, authentication, and logging per vCenter STIG.
-
Harden ESXi hosts according to ESXi STIG
Configure host lockdown, secure services, SSH access, and auditing settings.
-
Harden virtual machines per the VM STIG
Disable unnecessary virtual devices and apply guest OS STIG guidance.
-
Secure vCenter Appliance services
Apply STIG controls to vCenter appliance components and services.
-
Harden Photon OS on the vCenter Appliance
Apply OS-level hardening, patching, and secure defaults for Photon OS 4.0.
-
Secure PostgreSQL on the vCenter Appliance
Enforce DB authentication, remove default accounts, and enable encryption where required.
-
Verify and restrict appliance service accounts and permissions
Ensure least privilege for EAM, Envoy, Lookup, Perfcharts, UI, STS, and VAMI services.
-
Enable centralized logging and auditing for vCenter and ESXi
Forward logs to SIEM, enable audit trails, and configure retention per policy.
-
Run an automated STIG compliance scan (SCAP/XCCDF)
Use the provided XCCDF or DISA tooling to generate a compliance report.
-
Review scan results and remediate findings
Prioritize high-risk findings, apply fixes, and rerun scans until compliance met.
-
Document all configuration changes and maintain a change log
Record who made changes, approvals, and rollback steps for audits.
-
Subscribe for STIG updates and schedule periodic audits
Monitor Cyber.mil for updates and plan regular compliance reviews.
-
Submit comments or change requests to DISA if needed
Send proposed revisions to [email protected] per the STIG change process.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.