STIGhubSTIGhub
STIGsSearchCompareAbout

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • VPAT
  • DISA STIG Library
STIGs updated 1 hour ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to STIGs

VMware vRealize Operations Manager 6.x tc Server Security Technical Implementation Guide

Version

V1R2

Release Date

Sep 12, 2023

SCAP Benchmark ID

VMW_vRealize_Operations_Manager_6-x_tcServer_STIG

Total Checks

173

Tags

vmware
CAT I: 15CAT II: 158CAT III: 0

This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DOD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.

Export CKLExport CSVExport JSONDownload STIG ZIP

Checks (173)

V-241573MEDIUMtc Server UI must limit the number of maximum concurrent connections permitted.V-241574MEDIUMtc Server CaSa must limit the number of maximum concurrent connections permitted.V-241575MEDIUMtc Server API must limit the number of maximum concurrent connections permitted.V-241576MEDIUMtc Server UI must limit the amount of time that each TCP connection is kept alive.V-241577MEDIUMtc Server CaSa must limit the amount of time that each TCP connection is kept alive.V-241578MEDIUMtc Server API must limit the amount of time that each TCP connection is kept alive.V-241579MEDIUMtc Server UI must limit the number of times that each TCP connection is kept alive.V-241580MEDIUMtc Server CaSa must limit the number of times that each TCP connection is kept alive.V-241581MEDIUMtc Server API must limit the number of times that each TCP connection is kept alive.V-241582MEDIUMtc Server UI must perform server-side session management.V-241583MEDIUMtc Server CaSa must perform server-side session management.V-241584MEDIUMtc Server API must perform server-side session management.V-241585MEDIUMtc Server UI must be configured with FIPS 140-2 compliant ciphers for HTTPS connections.V-241586MEDIUMtc Server CaSa must be configured with FIPS 140-2 compliant ciphers for HTTPS connections.V-241587MEDIUMtc Server API must be configured with FIPS 140-2 compliant ciphers for HTTPS connections.V-241588MEDIUMtc Server UI must use cryptography to protect the integrity of remote sessions.V-241589MEDIUMtc Server CaSa must use cryptography to protect the integrity of remote sessions.V-241590MEDIUMtc Server API must use cryptography to protect the integrity of remote sessions.V-241591MEDIUMtc Server UI must record user access in a format that enables monitoring of remote access.V-241592MEDIUMtc Server CaSa must record user access in a format that enables monitoring of remote access.V-241593MEDIUMtc Server API must record user access in a format that enables monitoring of remote access.V-241594MEDIUMtc Server ALL must generate log records for system startup and shutdown.V-241595MEDIUMtc Server UI must generate log records for user access and authentication events.V-241596MEDIUMtc Server CaSa must generate log records for user access and authentication events.V-241597MEDIUMtc Server API must generate log records for user access and authentication events.V-241598MEDIUMtc Server ALL must initiate logging during service start-up.V-241599MEDIUMtc Server UI must produce log records containing sufficient information to establish what type of events occurred.V-241600MEDIUMtc Server CaSa must produce log records containing sufficient information to establish what type of events occurred.V-241601MEDIUMtc Server API must produce log records containing sufficient information to establish what type of events occurred.V-241602MEDIUMtc Server UI must produce log records containing sufficient information to establish when (date and time) events occurred.V-241603MEDIUMtc Server CaSa must produce log records containing sufficient information to establish when (date and time) events occurred.V-241604MEDIUMtc Server API must produce log records containing sufficient information to establish when (date and time) events occurred.V-241605MEDIUMtc Server UI must produce log records containing sufficient information to establish where within the web server the events occurred.V-241606MEDIUMtc Server CaSa must produce log records containing sufficient information to establish where within the web server the events occurred.V-241607MEDIUMtc Server API must produce log records containing sufficient information to establish where within the web server the events occurred.V-241608MEDIUMtc Server UI must produce log records containing sufficient information to establish the source of events.V-241609MEDIUMtc Server CaSa must produce log records containing sufficient information to establish the source of events.V-241610MEDIUMtc Server API must produce log records containing sufficient information to establish the source of events.V-241611MEDIUMtc Server UI must be configured with the RemoteIpValve in order to produce log records containing the client IP information as the source and destination and not the load balancer or proxy IP information with each event.V-241612MEDIUMtc Server CaSa must be configured with the RemoteIpValve in order to produce log records containing the client IP information as the source and destination and not the load balancer or proxy IP information with each event.V-241613MEDIUMtc Server API must be configured with the RemoteIpValve in order to produce log records containing the client IP information as the source and destination and not the load balancer or proxy IP information with each event.V-241614MEDIUMtc Server UI must produce log records that contain sufficient information to establish the outcome (success or failure) of events.V-241615MEDIUMtc Server CaSa must produce log records that contain sufficient information to establish the outcome (success or failure) of events.V-241616MEDIUMtc Server API must produce log records that contain sufficient information to establish the outcome (success or failure) of events.V-241617MEDIUMtc Server UI must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event.V-241618MEDIUMtc Server CaSa must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event.V-241619MEDIUMtc Server API must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event.V-241620MEDIUMtc Server ALL must use a logging mechanism that is configured to alert the ISSO and SA in the event of a processing failure.V-241621MEDIUMtc Server UI log files must only be accessible by privileged users.V-241622MEDIUMtc Server CaSa log files must only be accessible by privileged users.V-241623MEDIUMtc Server API log files must only be accessible by privileged users.V-241624MEDIUMtc Server UI log files must be protected from unauthorized modification.V-241625MEDIUMtc Server CaSa log files must be protected from unauthorized modification.V-241626MEDIUMtc Server API log files must be protected from unauthorized modification.V-241627MEDIUMtc Server UI log files must be protected from unauthorized deletion.V-241628MEDIUMtc Server CaSa log files must be protected from unauthorized deletion.V-241629MEDIUMtc Server API log files must be protected from unauthorized deletion.V-241630MEDIUMtc Server ALL log data and records must be backed up onto a different system or media.V-241631MEDIUMtc Server ALL server files must be verified for their integrity (e.g., checksums and hashes) before becoming part of the production web server.V-241632MEDIUMtc Server ALL expansion modules must be fully reviewed, tested, and signed before they can exist on a production web server.V-241633MEDIUMtc Server UI must not use the tomcat-users XML database for user management.V-241634MEDIUMtc Server CaSa must not use the tomcat-users XML database for user management.V-241635MEDIUMtc Server API must not use the tomcat-users XML database for user management.V-241636MEDIUMtc Server ALL must only contain services and functions necessary for operation.V-241637HIGHtc Server ALL must exclude documentation, sample code, example applications, and tutorials.V-241638MEDIUMtc Server ALL must exclude installation of utility programs, services, plug-ins, and modules not necessary for operation.V-241639MEDIUMtc Server ALL must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled.V-241640MEDIUMtc Server ALL must have all mappings to unused and vulnerable scripts to be removed.V-241641MEDIUMtc Server UI must have mappings set for Java Servlet Pages.V-241642MEDIUMtc Server CaSa must have mappings set for Java Servlet Pages.V-241643MEDIUMtc Server API must have mappings set for Java Servlet Pages.V-241644MEDIUMtc Server ALL must not have the Web Distributed Authoring (WebDAV) servlet installed.V-241645MEDIUMtc Server UI must be configured with memory leak protection.V-241646MEDIUMtc Server CaSa must be configured with memory leak protection.V-241647MEDIUMtc Server API must be configured with memory leak protection.V-241648HIGHtc Server UI must not have any symbolic links in the web content directory tree.V-241649HIGHtc Server CaSa must not have any symbolic links in the web content directory tree.V-241650HIGHtc Server API must not have any symbolic links in the web content directory tree.V-241651MEDIUMtc Server UI must be configured to use a specified IP address and port.V-241652MEDIUMtc Server CaSa must be configured to use a specified IP address and port.V-241653MEDIUMtc Server API must be configured to use a specified IP address and port.V-241654MEDIUMtc Server UI must encrypt passwords during transmission.V-241655MEDIUMtc Server CaSa must encrypt passwords during transmission.V-241656MEDIUMtc Server API must encrypt passwords during transmission.V-241657MEDIUMtc Server ALL must validate client certificates, to include all intermediary CAs, to ensure the client-presented certificates are valid and that the entire trust chain is valid. If PKI is not being used, this check is Not Applicable.V-241658MEDIUMtc Server ALL must only allow authenticated system administrators to have access to the keystore.V-241659MEDIUMtc Server ALL must only allow authenticated system administrators to have access to the truststore.V-241660MEDIUMtc Server UI must use cryptographic modules that meet the requirements of applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance when authenticating users and processes.V-241661MEDIUMtc Server CaSa must use cryptographic modules that meet the requirements of applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance when authenticating users and processes.V-241662MEDIUMtc Server API must use cryptographic modules that meet the requirements of applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance when authenticating users and processes.V-241663HIGHtc Server UI accounts accessing the directory tree, the shell, or other operating system functions and utilities must be administrative accounts.V-241664HIGHtc Server CaSa accounts accessing the directory tree, the shell, or other operating system functions and utilities must be administrative accounts.V-241665HIGHtc Server API accounts accessing the directory tree, the shell, or other operating system functions and utilities must be administrative accounts.V-241666HIGHtc Server UI web server application directories must not be accessible to anonymous user.V-241667HIGHtc Server CaSa web server application directories must not be accessible to anonymous user.V-241668HIGHtc Server API web server application directories must not be accessible to anonymous user.V-241669MEDIUMtc Server ALL baseline must be documented and maintained.V-241670MEDIUMtc Server UI must be built to fail to a known safe state if system initialization fails, shutdown fails, or aborts fail.V-241671MEDIUMtc Server CaSa must be built to fail to a known safe state if system initialization fails, shutdown fails, or aborts fail.V-241672MEDIUMtc Server API must be built to fail to a known safe state if system initialization fails, shutdown fails, or aborts fail.V-241673MEDIUMtc Server UI document directory must be in a separate partition from the web servers system files.V-241674MEDIUMtc Server CaSa document directory must be in a separate partition from the web servers system files.V-241675MEDIUMtc Server API document directory must be in a separate partition from the web servers system files.V-241676MEDIUMtc Server UI must be configured with a cross-site scripting (XSS) filter.V-241677MEDIUMtc Server CaSa must be configured with a cross-site scripting (XSS) filter.V-241678MEDIUMtc Server API must be configured with a cross-site scripting (XSS) filter.V-241679MEDIUMtc Server UI must set URIEncoding to UTF-8.V-241680MEDIUMtc Server CaSa must set URIEncoding to UTF-8.V-241681MEDIUMtc Server API must set URIEncoding to UTF-8.V-241682MEDIUMtc Server UI must use the setCharacterEncodingFilter filter.V-241683MEDIUMtc Server CaSa must use the setCharacterEncodingFilter filter.V-241684MEDIUMtc Server API must use the setCharacterEncodingFilter filter.V-241685MEDIUMtc Server UI must set the welcome-file node to a default web page.V-241686MEDIUMtc Server CaSa must set the welcome-file node to a default web page.V-241687MEDIUMtc Server API must set the welcome-file node to a default web page.V-241688MEDIUMtc Server UI must have the allowTrace parameter set to false.V-241689MEDIUMtc Server CaSa must have the allowTrace parameter set to false.V-241690MEDIUMtc Server API must have the allowTrace parameter set to false.V-241691MEDIUMtc Server UI must have the debug option turned off.V-241692MEDIUMtc Server CaSa must have the debug option turned off.V-241693MEDIUMtc Server API must have the debug option turned off.V-241694MEDIUMtc Server UI must set an inactive timeout for sessions.V-241695MEDIUMtc Server CaSa must set an inactive timeout for sessions.V-241696MEDIUMtc Server API must set an inactive timeout for sessions.V-241697HIGHtc Server ALL must be configured to the correct user authentication source.V-241698MEDIUMtc Server UI must be configured to use the https scheme.V-241699MEDIUMtc Server CaSa must be configured to use the https scheme.V-241700MEDIUMtc Server API must be configured to use the https scheme.V-241701MEDIUMtc Server ALL must use a logging mechanism that is configured to allocate log record storage capacity large enough to accommodate the logging requirements of the web server.V-241702MEDIUMtc Server ALL log files must be moved to a permanent repository in accordance with site policy.V-241703MEDIUMtc Server ALL must use a logging mechanism that is configured to provide a warning to the ISSO and SA when allocated record storage volume reaches 75% of maximum log record storage capacity.V-241704MEDIUMtc Server UI must generate log records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).V-241705MEDIUMtc Server CaSa must generate log records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).V-241706MEDIUMtc Server API must generate log records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).V-241707MEDIUMtc Server UI must record time stamps for log records to a minimum granularity of one second.V-241708MEDIUMtc Server CaSa must record time stamps for log records to a minimum granularity of one second.V-241709MEDIUMtc Server API must record time stamps for log records to a minimum granularity of one second.V-241710MEDIUMtc Server UI application, libraries, and configuration files must only be accessible to privileged users.V-241711MEDIUMtc Server CaSa application, libraries, and configuration files must only be accessible to privileged users.V-241712MEDIUMtc Server API application, libraries, and configuration files must only be accessible to privileged users.V-241713MEDIUMtc Server UI must be configured with the appropriate ports.V-241714MEDIUMtc Server CaSa must be configured with the appropriate ports.V-241715MEDIUMtc Server API must be configured with the appropriate ports.V-241716MEDIUMtc Server UI must use NSA Suite A cryptography when encrypting data that must be compartmentalized.V-241717MEDIUMtc Server CaSa must use NSA Suite A cryptography when encrypting data that must be compartmentalized.V-241718MEDIUMtc Server API must use NSA Suite A cryptography when encrypting data that must be compartmentalized.V-241719MEDIUMtc Server UI must disable the shutdown port.V-241720MEDIUMtc Server CaSa must disable the shutdown port.V-241721MEDIUMtc Server API must disable the shutdown port.V-241722MEDIUMtc Server UI must employ cryptographic mechanisms (TLS/DTLS/SSL) preventing the unauthorized disclosure of information during transmission.V-241723MEDIUMtc Server CaSa must employ cryptographic mechanisms (TLS/DTLS/SSL) preventing the unauthorized disclosure of information during transmission.V-241724MEDIUMtc Server API must employ cryptographic mechanisms (TLS/DTLS/SSL) preventing the unauthorized disclosure of information during transmission.V-241725MEDIUMtc Server UI session IDs must be sent to the client using SSL/TLS.V-241726MEDIUMtc Server CaSa session IDs must be sent to the client using SSL/TLS.V-241727MEDIUMtc Server API session IDs must be sent to the client using SSL/TLS.V-241728MEDIUMtc Server UI must set the useHttpOnly parameter.V-241729MEDIUMtc Server CaSa must set the useHttpOnly parameter.V-241730MEDIUMtc Server API must set the useHttpOnly parameter.V-241731MEDIUMtc Server UI must set the secure flag for cookies.V-241732MEDIUMtc Server CaSa must set the secure flag for cookies.V-241733MEDIUMtc Server API must set the secure flag for cookies.V-241734HIGHtc Server UI must set sslEnabledProtocols to an approved Transport Layer Security (TLS) version.V-241735HIGHtc Server CaSa must set sslEnabledProtocols to an approved Transport Layer Security (TLS) version.V-241736HIGHtc Server API must set sslEnabledProtocols to an approved Transport Layer Security (TLS) version.V-241737MEDIUMtc Server UI must remove all export ciphers to protect the confidentiality and integrity of transmitted information.V-241738MEDIUMtc Server CaSa must remove all export ciphers to protect the confidentiality and integrity of transmitted information.V-241739MEDIUMtc Server API must remove all export ciphers to protect the confidentiality and integrity of transmitted information.V-241740MEDIUMtc Server UI must use approved Transport Layer Security (TLS) versions to maintain the confidentiality and integrity of information during reception.V-241741MEDIUMtc Server CaSa must use approved Transport Layer Security (TLS) versions to maintain the confidentiality and integrity of information during reception.V-241742MEDIUMtc Server API must use approved Transport Layer Security (TLS) versions to maintain the confidentiality and integrity of information during reception.V-241743MEDIUMtc Server ALL must have all security-relevant software updates installed within the configured time period directed by an authoritative source.V-241744MEDIUMtc Server ALL must be configured in accordance with the security configuration settings based on DoD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs.V-258459HIGHThe version of vRealize Operations Manager 6.x tc Server running on the system must be a supported version.