<?xml version='1.0' encoding='iso-8859-1' ?><rss version="2.0"><channel><title>VMware</title><link>http://www.checklist20.com/bestpractices.html</link><description>Database Checklist</description><item><title>Restrict Owner and Group File Ownership to Root for .vmdk Files </title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=367&amp;tn=Restrict Owner and Group File Ownership to Root for .vmdk Files </link><description>Restricting file ownership for virtual machine disk files helps prevent accidental or malicious changes to application data.Set file ownership for all .vmdk disk files to:Restrict owner and group file ownership to root ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=367&amp;tn=Restrict Owner and Group File Ownership to Root for .vmdk Files '>View More</a>]]></description></item><item><title>Restrict Owner and Group file ownership to Root for .vmx Files</title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=366&amp;tn=Restrict Owner and Group file ownership to Root for .vmx Files</link><description>Restricting file ownership for configuration files helps prevent accidental or malicious changes to the system.Set file ownership for all .vmx files to:Restrict owner and group file ownership to root ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=366&amp;tn=Restrict Owner and Group file ownership to Root for .vmx Files'>View More</a>]]></description></item><item><title>Disable Group and Other Read, Write and Execute File Permissions for .vmdk Files</title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=365&amp;tn=Disable Group and Other Read, Write and Execute File Permissions for .vmdk Files</link><description>Disabling file permissions for virtual machine disk files helps prevent accidental or malicious changes to application data.Set file permissions for all .vmdk disk files to:Deny group read, write and execute accessDeny other read, write and execut ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=365&amp;tn=Disable Group and Other Read, Write and Execute File Permissions for .vmdk Files'>View More</a>]]></description></item><item><title>Disable Group and Other Write File Permissions for .vmx Files</title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=364&amp;tn=Disable Group and Other Write File Permissions for .vmx Files</link><description>Disabling file permissions for configuration files helps prevent accidental or malicious changes to the system.Set file permissions for all .vmx configuration files to:Deny group write accessDeny other write access ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=364&amp;tn=Disable Group and Other Write File Permissions for .vmx Files'>View More</a>]]></description></item><item><title>Implement logon warning banners</title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=363&amp;tn=Implement logon warning banners</link><description>There are no default warning banners since your organization&#8217;s exact wording is unknown at installation.Presenting some sort of statutory warning message prior to the normal user logon may assist the prosecution of trespassers on the computer syst ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=363&amp;tn=Implement logon warning banners'>View More</a>]]></description></item><item><title>Use CHAP protocol to connect to iSCSI devices</title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=362&amp;tn=Use CHAP protocol to connect to iSCSI devices</link><description>Use of the CHAP protocol ensures ESX hosts and storage devices are communicating with known endpoints. Configure connections to iSCSI storage devices to use the CHAP protocol for authentication. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=362&amp;tn=Use CHAP protocol to connect to iSCSI devices'>View More</a>]]></description></item><item><title>Harden firewall settings to allow only authorized traffic</title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=361&amp;tn=Harden firewall settings to allow only authorized traffic</link><description>If unauthorized ports are opened to the ESX host by a firewall change, traffic containing disruptive or malicious payloads may negatively impact the host&amp;#65533;s performance or securityConfigure the built-in firewall to ensure only authorized por ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=361&amp;tn=Harden firewall settings to allow only authorized traffic'>View More</a>]]></description></item><item><title>Protect against MAC address spoofing, forged transmits, and promiscuous mode</title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=360&amp;tn=Protect against MAC address spoofing, forged transmits, and promiscuous mode</link><description>Change the flags to reject for the settings MAC Address Changes and Forged Transmits for a &amp;lt;vSwitch&amp;gt; or a &amp;lt;PortGroup&amp;gt;.The default setting is accept in virtual switches and in portgroups.These settings provide the ability to drop incomi ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=360&amp;tn=Protect against MAC address spoofing, forged transmits, and promiscuous mode'>View More</a>]]></description></item><item><title>Enable BIOS passwords</title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=345&amp;tn=Enable BIOS passwords</link><description>Disable the server's ability to boot off all non-hard disk devices, including floppy, CD-ROM, and USB. Configure any required BIOS passwords in conformance with the organization's policy. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=345&amp;tn=Enable BIOS passwords'>View More</a>]]></description></item><item><title>Isolate service console management traffic</title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=342&amp;tn=Isolate service console management traffic</link><description>During the installation, un-select the default option to create a default network for virtual machines.This default installation option will combine the virtual machine network with the virtual infrastructure service console management network. Th ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=342&amp;tn=Isolate service console management traffic'>View More</a>]]></description></item><item><title>Configure syslogd to send logs to a remote LogHost</title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=357&amp;tn=Configure syslogd to send logs to a remote LogHost</link><description>Remote logging is essential in detecting intrusion and monitoring multiple servers simultaneously. If an intruder is able to obtain root on a host, they may be able to edit the system logs to remove all traces of the attack. If a copy of the logs  ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=357&amp;tn=Configure syslogd to send logs to a remote LogHost'>View More</a>]]></description></item><item><title>Review logs periodically</title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=356&amp;tn=Review logs periodically</link><description>Reviewing logs in a timely manner may detect a performance or security issue in its early stages enabling the organization to take countermeasures to reduce the event&#8217;s impact.Establish procedures defining the timing of and the staff responsibilit ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=356&amp;tn=Review logs periodically'>View More</a>]]></description></item><item><title>Enable compression and rotation for log files</title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=355&amp;tn=Enable compression and rotation for log files</link><description>The larger the log file the more events will be captured to help research system performance or security issues. Compression will allow more events to be captured in the file space provided. Increase the file size 2096K and enable compression for  ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=355&amp;tn=Enable compression and rotation for log files'>View More</a>]]></description></item><item><title>Minimum password length</title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=354&amp;tn=Minimum password length</link><description>The longer the total character length of a password, the more difficult it is to guess by unauthorized users.Set the minimum required number of characters a password must contain to:Greater than or equal to 8 characters. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=354&amp;tn=Minimum password length'>View More</a>]]></description></item><item><title>Enable password minimum days parameter</title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=353&amp;tn=Enable password minimum days parameter</link><description>Combined with the history setting (see section 1.3.4), the minimum days setting will cause multiple days to transpire before a user can return to a favorite password, discouraging password reuse.Set the minimum number of days a password must exist ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=353&amp;tn=Enable password minimum days parameter'>View More</a>]]></description></item><item><title>Enable maximum password life parameter</title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=352&amp;tn=Enable maximum password life parameter</link><description>Minimizing the life of a credential reduces the likelihood that the password will become compromised.Set the maximum number of days before a password is required to be changed toLess than or equal to 90 days. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=352&amp;tn=Enable maximum password life parameter'>View More</a>]]></description></item><item><title>Failed login attempts</title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=351&amp;tn=Failed login attempts</link><description>For user accounts, setting the failed attempt number at a low level discourages repetitive tries, which may be automated, to guess a user&#8217;s password.Set the number of login attempts allowed before the account is locked / disabled to:Less than or e ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=351&amp;tn=Failed login attempts'>View More</a>]]></description></item><item><title>Implement strong password complexity</title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=350&amp;tn=Implement strong password complexity</link><description>The user should create a password that consists of a mix of character classes from the four choices; upper case, lower case, numeric, or special to reduce the use of common words as passwords and increase the difficulty of an unauthorized user gue ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=350&amp;tn=Implement strong password complexity'>View More</a>]]></description></item><item><title>Implement strong password controls</title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=349&amp;tn=Implement strong password controls</link><description>Retain a history of previous passwords used and configure the authentication controls to validate new passwords against greater than or equal to 10 recently used credentials.Maintaining a history file containing previously used credentials for eac ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=349&amp;tn=Implement strong password controls'>View More</a>]]></description></item><item><title>Restrict SSH Access</title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=348&amp;tn=Restrict SSH Access</link><description>Securing administrator login and communication sessions reduces the chance of unauthorized interception of credentials or sensitive configuration information.Remote shell access to the console operating system should protect both the authenticatio ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=348&amp;tn=Restrict SSH Access'>View More</a>]]></description></item><item><title>Configure system clock synchornization with NTP</title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=347&amp;tn=Configure system clock synchornization with NTP</link><description>Add configuration settings to enable system clock synchronization with Network Time Protocol (NTP) server(s). Keeping systems synchronized to a local or remote NTP server ensures log entries are date and time stamped consistently across systems al ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=347&amp;tn=Configure system clock synchornization with NTP'>View More</a>]]></description></item><item><title>Disable unnecessary services</title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=346&amp;tn=Disable unnecessary services</link><description>Services enabled at ESX host startup should be limited to the vendor&amp;#65533;s default services and any authorized exceptions. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=346&amp;tn=Disable unnecessary services'>View More</a>]]></description></item><item><title>Apply critical security patches</title><link>http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=344&amp;tn=Apply critical security patches</link><description>It is critical that an organization develop a formal process for keeping up-to-date with applicable VMware patches. VMware uses three categories for patches: Security, Critical, and General. The patch # refers to KB (knowledge base) article number ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=168&amp;cn=VMware&amp;tid=344&amp;tn=Apply critical security patches'>View More</a>]]></description></item></channel></rss>
