Lab: Apply Security Compliance Benchmark and Configure Chargeback
Objectives
- Enable and apply CIS ESXi security benchmark in VCF Operations
- Analyze compliance findings and execute remediation workflows
- Create custom compliance benchmarks for VCF-specific requirements
- Configure costing rate cards for chargeback/showback reporting
- Generate cost allocation reports per workload domain and business unit
- Design a unified compliance + cost governance strategy for VCDX defense
Prerequisites
VCF Operations deployed with vCenter adapter collecting data (Lab 11 prerequisite)
Prior labs: vcp-admin-11
Required skills:
- VCF Operations UI navigation
- ESXi security hardening concepts
- CIS benchmark framework understanding
- Basic cost management principles
Lab Environment
Holodeck VCF pod with VCF Operations monitoring management domain. ESXi hosts in default (non-hardened) state for compliance testing.
Credentials
| System | Username | Password |
|---|---|---|
| VCF Operations | admin | |
| vCenter | administrator@vsphere.local |
Tasks
Task 1 Enable CIS Compliance Benchmark and Analyze Findings
securitySecurity compliance is a key exam topic (Obj 4.3). CIS benchmarks provide industry-standard hardening checks for ESXi hosts. Understanding how VCF Operations automates compliance scanning is critical for both admin operations and VCDX defense.
Navigate to VCF Operations → Compliance → Overview. Observe the current state — no benchmarks enabled means no compliance data.
Install CIS benchmark: Administration → Solutions → Repository → search 'CIS' → locate 'CIS ESXi 8 Benchmark' → Install.
Enable benchmark: Compliance → Manage → select 'CIS ESXi 8 Benchmark' → Enable → apply to management cluster hosts.
Wait for initial compliance scan (runs within 15 minutes). Navigate to Compliance → Overview → review per-host compliance status: green (compliant), yellow (partially), red (non-compliant).
Click a host with low compliance score. Expand findings list. For each finding, review: CIS control ID, description, current value, expected value, remediation command (esxcli or PowerCLI), severity level.
Export compliance report: Compliance → Reports → Generate → select 'CIS ESXi 8 Benchmark' → scope=management cluster → format=PDF. Review the report structure: executive summary, per-host details, remediation recommendations.
Validation Gate
Check: Compliance dashboard shows per-host compliance percentage with detailed findings
Expected: CIS ESXi 8 benchmark results visible for all management cluster hosts with specific control findings
Task 2 Execute Compliance Remediation Workflows
securityKnowing what's non-compliant is only half the story — remediation demonstrates operational competence. This task covers both manual and automated remediation approaches.
Select a non-compliant finding with clear remediation: 'SSH service enabled' (CIS 1.2). Review the remediation command: esxcli system settings advanced set -o /UserVars/ESXiShellInteractiveTimeOut -i 900. Note the risk: disabling SSH breaks Holodeck lab access.
Remediate a safe finding: Set shell timeout. SSH to an ESXi host → run: esxcli system settings advanced set -o /UserVars/ESXiShellInteractiveTimeOut -i 900. This sets 15-minute shell timeout without breaking lab functionality.
Trigger compliance re-scan: Compliance → select host → Rescan. Wait for scan to complete. Verify the remediated finding now shows 'Compliant'.
Document remediation exceptions: For findings that cannot be remediated (e.g., SSH must remain enabled for SDDC Manager), create a compliance exception record. In VCF Operations: Compliance → Manage → select finding → Suppress → add justification: 'Required for VCF lifecycle management per KB 123456'.
Review Host Profiles approach: vCenter → Host Profiles → create profile from a hardened host. This captures security settings (firewall rules, service states, NTP, lockdown mode) as a baseline that can be applied to all hosts in a cluster for consistent compliance.
Validation Gate
Check: At least one finding remediated and re-scan shows improved compliance score
Expected: Compliance percentage increased after remediation. Exception documented for unremediated findings.
Task 3 Create Custom Compliance Benchmark for VCF
securityCIS benchmarks are generic ESXi hardening. VCF environments have specific requirements (SDDC Manager connectivity, NSX VTEP MTU, vSAN network settings) that need custom compliance checks.
Navigate to Compliance → Manage → Custom Benchmarks → Create New. Name='VCF 9.0 Operational Baseline'. Description='Custom compliance checks specific to VMware Cloud Foundation operational requirements'.
Add custom compliance checks (symptoms and alert definitions that map to compliance controls):
- vSAN Network MTU Check: Verify VMkernel adapter MTU >= 9000 for vSAN traffic
- SDDC Manager Connectivity: Verify ESXi host can reach SDDC Manager on port 443
- NTP Synchronization: Verify time drift < 5 seconds across all hosts
- vSAN Disk Health: Verify no disks in 'Degraded' or 'Absent' state
Enable custom benchmark alongside CIS: Compliance → Manage → enable 'VCF 9.0 Operational Baseline' → apply to management cluster.
Compare compliance views: Compliance → Overview → filter by benchmark. Review CIS score vs custom VCF score separately. Note which areas each benchmark catches that the other misses.
Validation Gate
Check: Custom VCF compliance benchmark created, enabled, and producing compliance data alongside CIS
Expected: Two benchmarks active with separate compliance scores per host
Task 4 Configure Costing Rate Cards and Generate Business Unit Reports
manageabilityChargeback/showback is exam-relevant under Obj 4.3. Rate cards translate infrastructure consumption into business costs, enabling IT-as-a-service financial transparency.
Navigate to VCF Operations → Administration → Cost Settings → Rate Card Editor. Review the default rate card structure: compute (CPU $/GHz/day, Memory $/GB/day), storage ($/GB/day), network ($/Mbps/day).
Create tiered rate cards for different service levels:
- 'Standard Tier': CPU=$0.03/GHz/day, Memory=$0.008/GB/day, Storage=$0.003/GB/day
- 'Performance Tier': CPU=$0.06/GHz/day, Memory=$0.015/GB/day, Storage=$0.008/GB/day (vSAN all-flash)
- 'Mission Critical': CPU=$0.10/GHz/day, Memory=$0.025/GB/day, Storage=$0.015/GB/day (stretched cluster + HA)
Assign rate cards to clusters: Cost Settings → Assign. Map 'Standard Tier' to management cluster. In production, 'Performance Tier' would map to VI workload domain compute clusters, 'Mission Critical' to stretched clusters.
Generate cost reports: Cost → Overview → review per-VM cost breakdown. Drill into a VM to see: daily compute cost, daily storage cost, total monthly projection. Navigate to Cost → Reports → Create → 'Monthly Cost by VM' → PDF.
Configure cost allocation by business unit: Create custom groups in VCF Operations (Environment → Custom Groups) → group VMs by business unit using naming convention or tags. Generate cost report filtered by custom group to show per-department costs.
Compare showback vs chargeback modes: Review the difference — showback displays costs for transparency without billing action; chargeback integrates with finance/ERP systems (ServiceNow, SAP) for actual cross-charging. In VCF Operations, configure: Cost → Settings → Mode = Showback (lab default).
Validation Gate
Check: Tiered rate cards created, assigned to clusters, per-VM cost reports generated with business unit allocation
Expected: Cost dashboard shows per-VM costs with rate card pricing. Business unit cost allocation visible via custom groups.
Task 5 Unified Compliance + Cost Governance Strategy and VCDX Defense
manageabilityCompliance and costing are two sides of governance. This task ties them together into a holistic operational model that demonstrates architect-level thinking for VCDX defense.
Build a governance dashboard in VCF Operations: Create a custom dashboard (Dashboards → New) with widgets showing:
- Compliance Score by Cluster (scoreboard widget)
- Non-Compliant Findings Trend (line chart, 30 days)
- Monthly Cost by Workload Domain (bar chart)
- Cost per VM Trend (line chart, 90 days)
- Top 10 Most Expensive VMs (top-N widget)
Create compliance-cost correlation: Using Super Metrics (from Lab 11), create a metric that calculates 'Cost of Non-Compliance' = (number of non-compliant findings) x (estimated remediation hours) x (engineer hourly rate). This quantifies the business impact of security debt.
Configure automated alerts for governance thresholds:
- Alert if compliance score drops below 80% on any cluster
- Alert if monthly cost exceeds budget threshold per business unit
- Alert if a VM runs without compliance scan for > 48 hours
Set notification channel to email (configured in Lab 11).
VCDX Defense Preparation — document and rehearse responses to these panelist questions:
- 'How do you balance security hardening (CIS) with operational needs (SSH access for troubleshooting)?'
Answer: Exception-based model. SSH disabled by default, enabled via change request during maintenance windows with audited access. SDDC Manager uses its own management path that doesn't require persistent SSH.
- 'What costing model justifies VCF investment to leadership?'
Answer: TCO comparison. VCF per-core licensing vs traditional vSphere + separate NSX + separate vSAN licensing. Show consolidated management reduces ops cost by 30-40%. Tiered rate cards demonstrate value-based pricing.
- 'A CIS finding says disable NTP client but VCF requires NTP. How do you handle this?'
Answer: This is a false positive — CIS checks generic NTP, but VCF requires chrony/NTP for vSAN CMMDS quorum. Document as exception with KB reference, suppress finding with justification.
- 'How do you handle shared infrastructure costs (management domain, NSX edges) in chargeback?'
Answer: Shared infrastructure costs allocated proportionally based on workload domain resource consumption. Management domain cost treated as platform overhead — either absorbed centrally or distributed evenly across business units.
Validation Gate
Check: Governance dashboard created, compliance-cost correlation configured, alerts set, VCDX defense responses prepared
Expected: Unified governance view operational with proactive monitoring and documented defense strategy
Final Validation
CIS compliance benchmark applied and remediated, custom VCF benchmark created, tiered costing configured with business unit allocation, unified governance dashboard operational.
✓ CIS ESXi 8 benchmark enabled and producing compliance data → Per-host compliance status visible with detailed findings
✓ At least one finding remediated with improved compliance score → Post-remediation re-scan shows improvement
✓ Custom VCF operational benchmark active → VCF-specific compliance checks producing results
✓ Tiered rate cards assigned to clusters → Per-VM cost calculations with tiered pricing
✓ Cost allocation by business unit configured → Custom groups showing per-department costs
✓ Governance dashboard with compliance + cost widgets → Unified view of security posture and cost efficiency
Cleanup / Restore
• Take snapshot 'post-compliance-costing'
• Note: Leave compliance benchmarks enabled for ongoing monitoring
Design Reflection (VCDX)
Panelist: How do you balance security hardening (CIS) with operational needs (SSH access for troubleshooting)? What costing model justifies VCF investment to leadership? How do you quantify security debt in business terms?
Requirements
- Regulatory compliance reporting (CIS, DISA STIG, industry-specific)
- Cost transparency per business unit with tiered service levels
- Automated compliance monitoring with drift detection
- Exception management with audit trail
Constraints
- CIS benchmarks may flag VCF-required configurations as violations
- Rate card accuracy depends on current hardware and licensing costs
- Compliance remediation may require maintenance windows
- Custom benchmarks need ongoing maintenance as VCF versions change
Assumptions
- Compliance benchmarks updated with each VCF upgrade
- Rate cards reviewed quarterly to reflect actual infrastructure costs
- Business units accept showback model before chargeback transition
- Host Profiles used to enforce consistent hardening across clusters
Risks
- Over-hardening can break VCF operational workflows (SSH, NTP, firewall rules)
- Inaccurate rate cards lead to billing disputes and loss of IT credibility
- Compliance exceptions without proper documentation create audit exposure
- Cost allocation model disputes between shared infrastructure consumers
Self-Assessment Discussion Prompts
- How would you handle a CIS finding that directly conflicts with VCF operational requirements?
- What's the difference between chargeback and showback, and when should each be used?
- How do you quantify the business impact of compliance debt to executive stakeholders?
- What's your approach to shared infrastructure cost allocation in a multi-tenant VCF environment?
- How would you design a compliance remediation workflow that minimizes operational disruption?
References
- CIS ESXi BenchmarkTier 1 — Official
- VCF Operations Compliance ManagementTier 1 — Official
- VCF Operations Cost ManagementTier 2 — VMware Press
- VMware Security Hardening GuideTier 2 — VMware Press