STIGhubSTIGhub
STIGsSearchCompareAbout

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • VPAT
  • DISA STIG Library
STIGs updated 2 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to STIGs

VMware vSphere 7.0 vCenter Appliance Photon OS Security Technical Implementation Guide

Version

V1R4

Release Date

Dec 16, 2024

SCAP Benchmark ID

VMW_vSphere_7-0_vCA_Photon_OS_STIG

Total Checks

113

Tags

vmware
CAT I: 1CAT II: 110CAT III: 2

This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DOD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.

Export CKLExport CSVExport JSONDownload STIG ZIP

Checks (113)

V-256478MEDIUMThe Photon operating system must audit all account creations.V-256479MEDIUMThe Photon operating system must automatically lock an account when three unsuccessful logon attempts occur.V-256480MEDIUMThe Photon operating system must display the Standard Mandatory DOD Notice and Consent Banner before granting Secure Shell (SSH) access.V-256481MEDIUMThe Photon operating system must limit the number of concurrent sessions to 10 for all accounts and/or account types.V-256482MEDIUMThe Photon operating system must set a session inactivity timeout of 15 minutes or less.V-256483MEDIUMThe Photon operating system must have the sshd SyslogFacility set to "authpriv".V-256484MEDIUMThe Photon operating system must have sshd authentication logging enabled.V-256485MEDIUMThe Photon operating system must have the sshd LogLevel set to "INFO".V-256486LOWThe Photon operating system must configure sshd to use approved encryption algorithms.V-256487MEDIUMThe Photon operating system must configure auditd to log to disk.V-256488MEDIUMThe Photon operating system must configure auditd to use the correct log format.V-256489MEDIUMThe Photon operating system must be configured to audit the execution of privileged functions.V-256490MEDIUMThe Photon operating system must have the auditd service running.V-256491MEDIUMThe Photon operating system audit log must log space limit problems to syslog.V-256492MEDIUMThe Photon operating system audit log must attempt to log audit failures to syslog.V-256493MEDIUMThe Photon operating system audit log must have correct permissions.V-256494MEDIUMThe Photon operating system audit log must be owned by root.V-256495MEDIUMThe Photon operating system audit log must be group-owned by root.V-256496MEDIUMThe Photon operating system must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.V-256497MEDIUMThe Photon operating system must generate audit records when successful/unsuccessful attempts to access privileges occur.V-256498MEDIUMThe Photon operating system must enforce password complexity by requiring that at least one uppercase character be used.V-256499MEDIUMThe Photon operating system must enforce password complexity by requiring that at least one lowercase character be used.V-256500MEDIUMThe Photon operating system must enforce password complexity by requiring that at least one numeric character be used.V-256501MEDIUMThe Photon operating system must require that new passwords are at least four characters different from the old password.V-256502MEDIUMThe Photon operating system must store only encrypted representations of passwords.V-256503MEDIUMThe Photon operating system must use an OpenSSH server version that does not support protocol 1.V-256504MEDIUMThe Photon operating system must be configured so that passwords for new users are restricted to a 24-hour minimum lifetime.V-256505MEDIUMThe Photon operating system must be configured so that passwords for new users are restricted to a 90-day maximum lifetime.V-256506MEDIUMThe Photon operating system must prohibit password reuse for a minimum of five generations.V-256507MEDIUMThe Photon operating system must enforce a minimum eight-character password length.V-256508HIGHThe Photon operating system must require authentication upon booting into single-user and maintenance modes.V-256509MEDIUMThe Photon operating system must disable the loading of unnecessary kernel modules.V-256510MEDIUMThe Photon operating system must not have duplicate User IDs (UIDs).V-256511MEDIUMThe Photon operating system must disable new accounts immediately upon password expiration.V-256512MEDIUMThe Photon operating system must use Transmission Control Protocol (TCP) syncookies.V-256513MEDIUMThe Photon operating system must configure sshd to disconnect idle Secure Shell (SSH) sessions.V-256514MEDIUMThe Photon operating system must configure sshd to disconnect idle Secure Shell (SSH) sessions.V-256515MEDIUMThe Photon operating system "/var/log" directory must be owned by root.V-256516MEDIUMThe Photon operating system messages file must have the correct ownership and file permissions.V-256517MEDIUMThe Photon operating system must audit all account modifications.V-256518MEDIUMThe Photon operating system must audit all account modifications.V-256519MEDIUMThe Photon operating system must audit all account disabling actions.V-256520MEDIUMThe Photon operating system must audit all account removal actions.V-256521MEDIUMThe Photon operating system must initiate auditing as part of the boot process.V-256522MEDIUMThe Photon operating system audit files and directories must have correct permissions.V-256523MEDIUMThe Photon operating system must protect audit tools from unauthorized modification and deletion.V-256524MEDIUMThe Photon operating system must enforce password complexity by requiring that at least one special character be used.V-256525MEDIUMThe Photon operating system package files must not be modified.V-256526MEDIUMThe Photon operating system must audit the execution of privileged functions.V-256527MEDIUMThe Photon operating system must configure auditd to keep five rotated log files.V-256528MEDIUMThe Photon operating system must configure auditd to keep logging in the event max log file size is reached.V-256529MEDIUMThe Photon operating system must configure auditd to log space limit problems to syslog.V-256530MEDIUMThe Photon operating system RPM package management tool must cryptographically verify the authenticity of all software packages during installation.V-256531MEDIUMThe Photon operating system RPM package management tool must cryptographically verify the authenticity of all software packages during installation.V-256532MEDIUMThe  Photon operating system YUM repository must cryptographically verify the authenticity of all software packages during installation.V-256533MEDIUMThe Photon operating system must require users to reauthenticate for privilege escalation.V-256534LOWThe Photon operating system must configure sshd to use FIPS 140-2 ciphers.V-256535MEDIUMThe Photon operating system must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution.V-256536MEDIUMThe Photon operating system must remove all software components after updated versions have been installed.V-256537MEDIUMThe Photon operating system must generate audit records when the sudo command is used.V-256538MEDIUMThe Photon operating system must generate audit records when successful/unsuccessful logon attempts occur.V-256539MEDIUMThe Photon operating system must audit the "insmod" module.V-256540MEDIUMThe Photon operating system auditd service must generate audit records for all account creations, modifications, disabling, and termination events.V-256541MEDIUMThe Photon operating system must use the "pam_cracklib" module.V-256542MEDIUMThe Photon operating system must set the "FAIL_DELAY" parameter.V-256543MEDIUMThe Photon operating system must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.V-256544MEDIUMThe Photon operating system must ensure audit events are flushed to disk at proper intervals.V-256545MEDIUMThe Photon operating system must create a home directory for all new local interactive user accounts.V-256546MEDIUMThe Photon operating system must disable the debug-shell service.V-256547MEDIUMThe Photon operating system must configure sshd to disallow Generic Security Service Application Program Interface (GSSAPI) authentication.V-256548MEDIUMThe Photon operating system must configure sshd to disable environment processing.V-256549MEDIUMThe Photon operating system must configure sshd to disable X11 forwarding.V-256550MEDIUMThe Photon operating system must configure sshd to perform strict mode checking of home directory configuration files.V-256551MEDIUMThe Photon operating system must configure sshd to disallow Kerberos authentication.V-256552MEDIUMThe Photon operating system must configure sshd to disallow authentication with an empty password.V-256553MEDIUMThe Photon operating system must configure sshd to disallow compression of the encrypted session stream.V-256554MEDIUMThe Photon operating system must configure sshd to display the last login immediately after authentication.V-256555MEDIUMThe Photon operating system must configure sshd to ignore user-specific trusted hosts lists.V-256556MEDIUMThe Photon operating system must configure sshd to ignore user-specific "known_host" files.V-256557MEDIUMThe Photon operating system must configure sshd to limit the number of allowed login attempts per connection.V-256558MEDIUMThe Photon operating system must be configured so the x86 Ctrl-Alt-Delete key sequence is disabled on the command line.V-256559MEDIUMThe Photon operating system must be configured so the "/etc/skel" default scripts are protected from unauthorized modification.V-256560MEDIUMThe Photon operating system must be configured so the "/root" path is protected from unauthorized access.V-256561MEDIUMThe Photon operating system must be configured so that all global initialization scripts are protected from unauthorized modification.V-256562MEDIUMThe Photon operating system must be configured so that all system startup scripts are protected from unauthorized modification.V-256563MEDIUMThe Photon operating system must be configured so that all files have a valid owner and group owner.V-256564MEDIUMThe Photon operating system must be configured so the "/etc/cron.allow" file is protected from unauthorized modification.V-256565MEDIUMThe Photon operating system must be configured so that all cron jobs are protected from unauthorized modification.V-256566MEDIUMThe Photon operating system must be configured so that all cron paths are protected from unauthorized modification.V-256567MEDIUMThe Photon operating system must not forward IPv4 or IPv6 source-routed packets.V-256568MEDIUMThe Photon operating system must not respond to IPv4 Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.V-256569MEDIUMThe Photon operating system must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted.V-256570MEDIUMThe Photon operating system must prevent IPv4 Internet Control Message Protocol (ICMP) secure redirect messages from being accepted.V-256571MEDIUMThe Photon operating system must not send IPv4 Internet Control Message Protocol (ICMP) redirects.V-256572MEDIUMThe Photon operating system must log IPv4 packets with impossible addresses.V-256573MEDIUMThe Photon operating system must use a reverse-path filter for IPv4 network traffic.V-256574MEDIUMThe Photon operating system must not perform multicast packet forwarding.V-256575MEDIUMThe Photon operating system must not perform IPv4 packet forwarding.V-256576MEDIUMThe Photon operating system must send Transmission Control Protocol (TCP) timestamps.V-256577MEDIUMThe Photon operating system must be configured to protect the Secure Shell (SSH) public host key from unauthorized modification.V-256578MEDIUMThe Photon operating system must be configured to protect the Secure Shell ( SSH) private host key from unauthorized access.V-256579MEDIUMThe Photon operating system must enforce password complexity on the root account.V-256580MEDIUMThe Photon operating system must protect all boot configuration files from unauthorized modification.V-256581MEDIUMThe Photon operating system must protect sshd configuration from unauthorized access.V-256582MEDIUMThe Photon operating system must protect all "sysctl" configuration files from unauthorized access.V-256583MEDIUMThe Photon operating system must set the "umask" parameter correctly.V-256584MEDIUMThe Photon operating system must configure sshd to disallow HostbasedAuthentication.V-256585MEDIUMThe Photon operating system must store only encrypted representations of passwords.V-256586MEDIUMThe Photon operating system must ensure the old passwords are being stored.V-256587MEDIUMThe Photon operating system must configure sshd to restrict AllowTcpForwarding.V-256588MEDIUMThe Photon operating system must configure sshd to restrict LoginGraceTime.V-256589MEDIUMThe Photon operating system must implement NIST FIPS-validated cryptography for the following: to provision digital signatures, generate cryptographic hashes, and protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.V-256590MEDIUMThe Photon operating system must disable systemd fallback Domain Name System (DNS).