VMware Cloud Community
nsousaarlington
Enthusiast
Enthusiast
Jump to solution

VMware Security Configuration & Hardening Guide 8

https://core.vmware.com/security-configuration-guide

Is there anything available for the VMware Security Configuration Guide? I was hoping there was a compliance management pack but I don't see one.

Labels (3)
0 Kudos
1 Solution

Accepted Solutions
nsousaarlington
Enthusiast
Enthusiast
Jump to solution

I think this might be everything that I needed:

Configure > Alerts > Alert Definitions > search for “security configuration guide” > Edit each alert definition and assign it to the default policy.

After doing this, the Optimize > Compliance pane displayed two new compliance sections:

nsousaarlington_0-1685567153139.png

"vSphere Security Configuration Guide" and "vSAN Security Configuration Guide".

The alert definitions are categorized as "version 7 and above", but I'm assuming the Security Configuration Guide settings for vSphere 8 may be included:

nsousaarlington_1-1685567370778.png

View solution in original post

0 Kudos
7 Replies
Shen88
Hot Shot
Hot Shot
Jump to solution

@nsousaarlington,

Sorry, could you elaborate.. Compliance management pack for?

If you think your queries have been answered, Mark this response as "Correct" or "Helpful" and consider giving kudos to appreciate!

Regards,
Shen
0 Kudos
nsousaarlington
Enthusiast
Enthusiast
Jump to solution

A compliance pack that includes the latest hardening and security settings straight from VMware. The link I provided goes to the guide in question.

0 Kudos
Shen88
Hot Shot
Hot Shot
Jump to solution

We have it for the VCF environment, are you looking in specific for the vSphere alone?

VMware Cloud Foundation 4.2 Compliance Kit | VMware

If you think your queries have been answered, Mark this response as "Correct" or "Helpful" and consider giving kudos to appreciate!

Regards,
Shen
0 Kudos
nsousaarlington
Enthusiast
Enthusiast
Jump to solution

The link you provided looks similar to the vSphere security/hardening guide. I was looking for a management pack that could be installed within Aria Ops.

0 Kudos
Shen88
Hot Shot
Hot Shot
Jump to solution

@nsousaarlington,

There you go VMware Marketplace - View Solution

For other compliance packs checkout - VMware Marketplace - View Solutions

If you think your queries have been answered, Mark this response as "Correct" or "Helpful" and consider giving kudos to appreciate!

Regards,
Shen
0 Kudos
nsousaarlington
Enthusiast
Enthusiast
Jump to solution

I installed the CIS and ISO compliance packs, but they don't match up with the VMware Security Configuration Guide.

I did however find one alert definition that has some of the settings that I was looking for:

nsousaarlington_0-1685473588420.png

Do you or anyone else know where these alerts came from? They appear to be defined in the vCenter object and its descendants. I don't want to try to piece together all of the alert definitions, so I'm hoping there is some information on where these came from.

0 Kudos
nsousaarlington
Enthusiast
Enthusiast
Jump to solution

I think this might be everything that I needed:

Configure > Alerts > Alert Definitions > search for “security configuration guide” > Edit each alert definition and assign it to the default policy.

After doing this, the Optimize > Compliance pane displayed two new compliance sections:

nsousaarlington_0-1685567153139.png

"vSphere Security Configuration Guide" and "vSAN Security Configuration Guide".

The alert definitions are categorized as "version 7 and above", but I'm assuming the Security Configuration Guide settings for vSphere 8 may be included:

nsousaarlington_1-1685567370778.png

0 Kudos