Lab O4: Compliance Benchmarking Against CIS / DISA STIG
VCF 9.0Intermediatevcp-foundation⏱ 75 min
Objectives
Run VCF Operations compliance checks against CIS vSphere benchmark and remediate drift.
Prerequisites
VCF lab environment deployed and operational
Lab Environment
Standard VCF lab environment for Cloud Operations 8.x Professional
Tasks
Task 1 Lab O4: Compliance Benchmarking Against CIS / DISA STIG
Run VCF Operations compliance checks against CIS vSphere benchmark and remediate drift.
Step 1
Enable CIS benchmark in VCF Operations compliance module.
Step 2
Run baseline scan across all ESXi hosts + vCenter.
Step 3
Export findings and categorize by severity.
Step 4
Remediate top 20 high-severity items via host profiles / DSC.
Step 5
Schedule recurring monthly scan with drift alerts.
Validation Gate
Check: Verify lab completion
Expected: Lab exercise completed successfully
Common Errors
Applying CIS/DISA STIG benchmarks without understanding their impact
Fix: CIS and DISA STIG benchmarks are prescriptive security hardening standards. Some controls may impact functionality: disabling certain ESXi services (required for VCF operations), changing SSH timeouts (affects support bundle collection), or restricting TLS versions (breaks legacy integrations). Review each control's impact before enabling.
Running compliance checks only on ESXi hosts, not management VMs
Fix: Compliance benchmarks apply to: ESXi hosts, vCenter appliance, NSX Manager VMs, SDDC Manager VM, and other management components. Checking only ESXi hosts misses vulnerabilities in management VMs. Configure compliance profiles for each component type.
Treating compliance score as a binary pass/fail
Fix: A 95% compliance score with the 5% gap in critical controls (e.g., encryption at rest disabled) is worse than 85% with all critical controls met. Prioritize remediation by control severity: critical/high first, then medium/low. Map each control to the organization's risk assessment.
Final Validation
Lab completed successfully
✓ All steps completed → No errors observed
Cleanup / Restore
• Revert to snapshot if needed
Design Reflection (VCDX)
Compliance benchmarking demonstrates security architecture awareness. VCDX designs for regulated industries should map to specific benchmarks (CIS, DISA STIG) with documented exceptions.
⚠ Known Pitfalls (from Community KB)
Blindly applying DISA STIG hardening without testing — some controls break VCF functionality.
Celebrating 95% compliance while ignoring that the missing 5% includes critical controls.
Was this page useful?Thanks — noted.
Type to search. ↑↓ to move,
Enter to open, Esc to close.