STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← Back to VMware vRealize Operations Manager 6.x Application Security Technical Implementation Guide

V-239840

CAT II (Medium)

The vRealize Operations server must use an enterprise user management system to uniquely identify and authenticate users (or processes acting on behalf of organizational users).

Rule ID

SV-239840r879589_rule

STIG

VMware vRealize Operations Manager 6.x Application Security Technical Implementation Guide

Version

V1R2

CCIs

CCI-000764

Discussion

To assure accountability and prevent unauthorized access, application server users must be uniquely identified and authenticated. This is typically accomplished via the use of a user store that is either local (OS-based) or centralized (LDAP) in nature. To ensure support to the enterprise, the authentication must utilize an enterprise solution.

Check Content

Obtain the site configuration control policy from the ISSO.

Review site procedures to determine if an enterprise management system is used to uniquely identify and authenticate users.

If an enterprise management solution is not used, this is a finding.

Fix Text

Configure vROps to use an enterprise user management system and document this in the site configuration control policy.