STIGhubSTIGhub
STIGsSearchCompareAbout

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • VPAT
  • DISA STIG Library
STIGs updated 2 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to STIGs

VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 Security Technical Implementation Guide

Version

V1R1

Release Date

Oct 29, 2023

SCAP Benchmark ID

VMW_vSphere_8-0_VCSA_Photon_OS_4-0_STIG

Total Checks

104

Tags

vmware
CAT I: 13CAT II: 88CAT III: 3

This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DOD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.

Export CKLExport CSVExport JSONDownload STIG ZIP

Checks (104)

V-258801MEDIUMThe Photon operating system must audit all account creations.V-258802MEDIUMThe Photon operating system must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.V-258803MEDIUMThe Photon operating system must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system.V-258804LOWThe Photon operating system must limit the number of concurrent sessions to ten for all accounts and/or account types.V-258805MEDIUMThe Photon operating system must monitor remote access logins.V-258806HIGHThe Photon operating system must have the OpenSSL FIPS provider installed to protect the confidentiality of remote access sessions.V-258807MEDIUMThe Photon operating system must configure auditd to log to disk.V-258808MEDIUMThe Photon operating system must enable the auditd service.V-258809MEDIUMThe Photon operating system must be configured to audit the execution of privileged functions.V-258810MEDIUMThe Photon operating system must alert the ISSO and SA in the event of an audit processing failure.V-258811MEDIUMThe Photon operating system must protect audit logs from unauthorized access.V-258812MEDIUMThe Photon operating system must allow only authorized users to configure the auditd service.V-258813MEDIUMThe Photon operating system must generate audit records when successful/unsuccessful attempts to access privileges occur.V-258814MEDIUMThe Photon operating system must enforce password complexity by requiring that at least one uppercase character be used.V-258815MEDIUMThe Photon operating system must enforce password complexity by requiring that at least one lowercase character be used.V-258816MEDIUMThe Photon operating system must enforce password complexity by requiring that at least one numeric character be used.V-258817MEDIUMThe Photon operating system must require the change of at least eight characters when passwords are changed.V-258818HIGHThe operating system must store only encrypted representations of passwords.V-258819HIGHThe Photon operating system must not have the telnet package installed.V-258820MEDIUMThe Photon operating system must enforce one day as the minimum password lifetime.V-258821MEDIUMThe Photon operating systems must enforce a 90-day maximum password lifetime restriction.V-258822MEDIUMThe Photon operating system must prohibit password reuse for a minimum of five generations.V-258823MEDIUMThe Photon operating system must enforce a minimum 15-character password length.V-258824MEDIUMThe Photon operating system must require authentication upon booting into single-user and maintenance modes.V-258825MEDIUMThe Photon operating system must disable unnecessary kernel modules.V-258826MEDIUMThe Photon operating system must not have duplicate User IDs (UIDs).V-258827MEDIUMThe Photon operating system must use mechanisms meeting the requirements of applicable federal laws, Executive orders, directives, policies, regulations, standards, and guidance for authentication to a cryptographic module.V-258828MEDIUMThe Photon operating system must restrict access to the kernel message buffer.V-258829MEDIUMThe Photon operating system must be configured to use TCP syncookies.V-258830MEDIUMThe Photon operating system must terminate idle Secure Shell (SSH) sessions after 15 minutes.V-258831MEDIUMThe Photon operating system /var/log directory must be restricted.V-258832MEDIUMThe Photon operating system must reveal error messages only to authorized users.V-258833MEDIUMThe Photon operating system must audit all account modifications.V-258834MEDIUMThe Photon operating system must audit all account removal actions.V-258835HIGHThe Photon operating system must implement only approved ciphers to protect the integrity of remote access sessions.V-258836MEDIUMThe Photon operating system must initiate session audits at system startup.V-258837MEDIUMThe Photon operating system must protect audit tools from unauthorized access.V-258838MEDIUMThe Photon operating system must enforce password complexity by requiring that at least one special character be used.V-258839HIGHThe Photon operating system must use cryptographic mechanisms to protect the integrity of audit tools.V-258840MEDIUMThe operating system must automatically terminate a user session after inactivity time-outs have expired.V-258841HIGHThe Photon operating system must enable symlink access control protection in the kernel.V-258842MEDIUMThe Photon operating system must audit the execution of privileged functions.V-258843MEDIUMThe Photon operating system must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts in 15 minutes occur.V-258844LOWThe Photon operating system must allocate audit record storage capacity to store audit records when audit records are not immediately sent to a central audit record storage facility.V-258845LOWThe Photon operating system must immediately notify the SA and ISSO when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity.V-258846HIGHThe Photon operating system TDNF package management tool must cryptographically verify the authenticity of all software packages during installation.V-258847MEDIUMThe Photon operating system must require users to reauthenticate for privilege escalation.V-258848MEDIUMThe Photon operating system must implement address space layout randomization to protect its memory from unauthorized code execution.V-258849MEDIUMThe Photon operating system must remove all software components after updated versions have been installed.V-258850MEDIUMThe Photon operating system must generate audit records when successful/unsuccessful logon attempts occur.V-258851MEDIUMThe Photon operating system must be configured to audit the loading and unloading of dynamic kernel modules.V-258852HIGHThe Photon operating system must implement NIST FIPS-validated cryptography for the following: to provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.V-258853MEDIUMThe Photon operating system must prevent the use of dictionary words for passwords.V-258854MEDIUMThe Photon operating system must enforce a delay of at least four seconds between logon prompts following a failed logon attempt in login.defs.V-258855MEDIUMThe Photon operating system must ensure audit events are flushed to disk at proper intervals.V-258856MEDIUMThe Photon operating system must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.V-258857HIGHThe Photon operating system must configure Secure Shell (SSH) to disallow HostbasedAuthentication.V-258858MEDIUMThe Photon operating system must be configured to use the pam_faillock.so module.V-258859MEDIUMThe Photon operating system must prevent leaking information of the existence of a user account.V-258860MEDIUMThe Photon operating system must audit logon attempts for unknown users.V-258861MEDIUMThe Photon operating system must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.V-258862MEDIUMThe Photon operating system must persist lockouts between system reboots.V-258863MEDIUMThe Photon operating system must be configured to use the pam_pwquality.so module.V-258864HIGHThe Photon operating system TDNF package management tool must cryptographically verify the authenticity of all software packages during installation for all repos.V-258865MEDIUMThe Photon operating system must configure the Secure Shell (SSH) SyslogFacility.V-258866MEDIUMThe Photon operating system must enable Secure Shell (SSH) authentication logging.V-258867MEDIUMThe Photon operating system must terminate idle Secure Shell (SSH) sessions.V-258868MEDIUMThe Photon operating system must audit all account modifications.V-258869MEDIUMThe Photon operating system must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.V-258870HIGHThe Photon operating system must configure Secure Shell (SSH) to disallow authentication with an empty password.V-258871HIGHThe Photon operating system must configure Secure Shell (SSH) to disable user environment processing.V-258872MEDIUMThe Photon operating system must create a home directory for all new local interactive user accounts.V-258873MEDIUMThe Photon operating system must disable the debug-shell service.V-258874MEDIUMThe Photon operating system must configure Secure Shell (SSH) to disallow Generic Security Service Application Program Interface (GSSAPI) authentication.V-258875MEDIUMThe Photon operating system must configure Secure Shell (SSH) to disable X11 forwarding.V-258876MEDIUMThe Photon operating system must configure Secure Shell (SSH) to perform strict mode checking of home directory configuration files.V-258877MEDIUMThe Photon operating system must configure Secure Shell (SSH) to disallow Kerberos authentication.V-258878MEDIUMThe Photon operating system must configure Secure Shell (SSH) to disallow compression of the encrypted session stream.V-258879MEDIUMThe Photon operating system must configure Secure Shell (SSH) to display the last login immediately after authentication.V-258880MEDIUMThe Photon operating system must configure Secure Shell (SSH) to ignore user-specific trusted hosts lists.V-258881MEDIUMThe Photon operating system must configure Secure Shell (SSH) to ignore user-specific known_host files.V-258882MEDIUMThe Photon operating system must configure Secure Shell (SSH) to limit the number of allowed login attempts per connection.V-258883MEDIUMThe Photon operating system must configure Secure Shell (SSH) to restrict AllowTcpForwarding.V-258884MEDIUMThe Photon operating system must configure Secure Shell (SSH) to restrict LoginGraceTime.V-258885MEDIUMThe Photon operating system must be configured so that the x86 Ctrl-Alt-Delete key sequence is disabled on the command line.V-258886MEDIUMThe Photon operating system must not forward IPv4 or IPv6 source-routed packets.V-258887MEDIUMThe Photon operating system must not respond to IPv4 Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.V-258888MEDIUMThe Photon operating system must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted.V-258889MEDIUMThe Photon operating system must prevent IPv4 Internet Control Message Protocol (ICMP) secure redirect messages from being accepted.V-258890MEDIUMThe Photon operating system must not send IPv4 Internet Control Message Protocol (ICMP) redirects.V-258891MEDIUMThe Photon operating system must log IPv4 packets with impossible addresses.V-258892MEDIUMThe Photon operating system must use a reverse-path filter for IPv4 network traffic.V-258893MEDIUMThe Photon operating system must not perform IPv4 packet forwarding.V-258894MEDIUMThe Photon operating system must send TCP timestamps.V-258895MEDIUMThe Photon operating system must be configured to protect the Secure Shell (SSH) public host key from unauthorized modification.V-258896MEDIUMThe Photon operating system must be configured to protect the Secure Shell (SSH) private host key from unauthorized access.V-258897MEDIUMThe Photon operating system must enforce password complexity on the root account.V-258898MEDIUMThe Photon operating system must disable systemd fallback DNS.V-258899MEDIUMThe Photon operating system must generate audit records for all access and modifications to the opasswd file.V-258900HIGHThe Photon operating system must implement only approved Message Authentication Codes (MACs) to protect the integrity of remote access sessions.V-258901MEDIUMThe Photon operating system must enable the rsyslog service.V-258902MEDIUMThe Photon operating system must be configured to use the pam_pwhistory.so module.V-258903MEDIUMThe Photon operating system must enable hardlink access control protection in the kernel.V-258904MEDIUMThe Photon operating system must restrict core dumps.