{"id":3957,"date":"2019-06-12T16:29:26","date_gmt":"2019-06-12T21:29:26","guid":{"rendered":"http:\/\/www.jasemccarty.com\/blog\/?p=3957"},"modified":"2020-02-16T16:29:46","modified_gmt":"2020-02-16T22:29:46","slug":"vmware-hci-disa-stig","status":"publish","type":"post","link":"https:\/\/www.jasemccarty.com\/blog\/vmware-hci-disa-stig\/","title":{"rendered":"VMware HCI, Still the Only HCI Solution That is Part of a DISA STIG"},"content":{"rendered":"<p>When vSAN was added to the vSphere 6.0 STIG Framework, it was the <a href=\"http:\/\/blogs.vmware.com\/virtualblocks\/2017\/04\/17\/vmware-1st-hci-solution-disa-stig\/\" target=\"_blank\" rel=\"noopener noreferrer\">1st and only HCI solution that was included in a publicly available DISA STIG<\/a>.<\/p>\n<p>As of 12 JUN 2019, the <a href=\"https:\/\/public.cyber.mil\/stigs\/downloads\/?_dl_facet_stigs=operating-systems%2Cvirtualization\" target=\"_blank\" rel=\"noopener noreferrer\">vSphere 6.5 STIG Framework was released.<\/a><\/p>\n<p>More than 2 years later, vSphere and vSAN are still the only HCI solution that is part of a DISA STIG.<\/p>\n<p>Customers running vSAN 6.2 who have been waiting for the release of the vSphere 6.5 STIG Framework can now plan to deploy the latest version of vSAN 6.6, part of the latest release of vSphere 6.5. We&#8217;ve made some significant updates in vSAN 6.6, many of which can be found on <a href=\"https:\/\/storagehub.vmware.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">StorageHub<\/a> and in our <a href=\"https:\/\/storagehub.vmware.com\/t\/vmware-vsan\/archive\/vsan-6-6-technical-overview\/\" target=\"_blank\" rel=\"noopener noreferrer\">vSAN 6.6 Technical Overview<\/a>.<\/p>\n<p>The Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) are published by DISA through a rigorous formal process. If the proposed changes, updates, or additions are not approved by the Risk Management Executive, a proposed STIG is not approved. Approval of an updated STIG validates that the product in the STIG meets the risk acceptance level for use in the DoD.<\/p>\n<p>Misleading terms like &#8220;STIG Compliant&#8221; are often used to imply adherence to a DISA STIG. These statements do not indicate being part of a formally approved or certified, officially released publication from DISA.<\/p>\n<p>The vSphere 6.5 STIG can be found on the updated <a href=\"https:\/\/public.cyber.mil\/\" target=\"_blank\" rel=\"noopener noreferrer\">DoD Cyber Exchange<\/a> website.<\/p>\n<p><a href=\"https:\/\/public.cyber.mil\/stigs\/downloads\/?_dl_facet_stigs=operating-systems%2Cvirtualization\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-17082 size-large\" title=\"DISA STIG\" src=\"http:\/\/blogs.vmware.com\/virtualblocks\/files\/2019\/06\/STIGJUNE2019-1024x839.png\" alt=\"DISA STIG\" width=\"580\" height=\"475\" srcset=\"https:\/\/blogs.vmware.com\/virtualblocks\/files\/2019\/06\/STIGJUNE2019-1024x839.png 1024w, https:\/\/blogs.vmware.com\/virtualblocks\/files\/2019\/06\/STIGJUNE2019-208x170.png 208w, https:\/\/blogs.vmware.com\/virtualblocks\/files\/2019\/06\/STIGJUNE2019-768x629.png 768w, https:\/\/blogs.vmware.com\/virtualblocks\/files\/2019\/06\/STIGJUNE2019-232x190.png 232w, https:\/\/blogs.vmware.com\/virtualblocks\/files\/2019\/06\/STIGJUNE2019.png 1662w\" sizes=\"auto, (max-width: 580px) 100vw, 580px\" \/><\/a><\/p>\n<p>VMware is the only vendor with virtualization operating system DISA STIGs.<\/p>\n<p>&nbsp;<\/p>\n<p>This was originally posted on the VMware Virtual Blocks site: https:\/\/blogs.vmware.com\/virtualblocks\/2019\/06\/12\/vmware-hci-disa-stig\/<\/p>\n","protected":false},"excerpt":{"rendered":"<p>When vSAN was added to the vSphere 6.0 STIG Framework, it was the 1st and only HCI solution that was included in a publicly available &hellip; <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3957","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/www.jasemccarty.com\/blog\/wp-json\/wp\/v2\/posts\/3957","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.jasemccarty.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.jasemccarty.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.jasemccarty.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.jasemccarty.com\/blog\/wp-json\/wp\/v2\/comments?post=3957"}],"version-history":[{"count":2,"href":"https:\/\/www.jasemccarty.com\/blog\/wp-json\/wp\/v2\/posts\/3957\/revisions"}],"predecessor-version":[{"id":3959,"href":"https:\/\/www.jasemccarty.com\/blog\/wp-json\/wp\/v2\/posts\/3957\/revisions\/3959"}],"wp:attachment":[{"href":"https:\/\/www.jasemccarty.com\/blog\/wp-json\/wp\/v2\/media?parent=3957"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.jasemccarty.com\/blog\/wp-json\/wp\/v2\/categories?post=3957"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.jasemccarty.com\/blog\/wp-json\/wp\/v2\/tags?post=3957"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}