6.3

Table Of Contents
n
Risk Prole 2 enforces a medium level of security for your environment, and includes fewer symptoms
than Risk Prole 1. This prole is disabled by default.
n
Risk Prole 3 enforces a low level of security, and includes fewer symptoms than Risk Prole 2. This
prole is disabled by default.
All the compliance standards in vRealize Operations Manager, including any standards that you dene, are
based on alert denitions. The generated alerts and symptoms appear as violations to the compliance
standards on the Analysis > Compliance tab for a selected object.
You can nd the vSphere Hardening Guides at hp://www.vmware.com/security/hardening-guides.html.
vRealize Operations Manager Compliance for vSphere 6.0 Objects
To ensure compliance of your vSphere 6.0 and 5.5 objects, vRealize Operations Manager includes
compliance alerts for VMware vSphere Hardening Guide versions 6.0 and 5.5. These hardening guide alerts are
now based on object type.
When you customize a policy to enable the vSphere Hardening Guide alerts, you can enable vSphere 6.0 and
5.5 alerts for the following object types and versions:
n
ESXi host is violating vSphere Hardening Guide (5.5 and 6.0)
n
vCenter Server is violating vSphere Hardening Guide (6.0)
n
Virtual machine is violating Risk Prole 1 in vSphere Hardening Guide (5.5 and 6.0)
n
Virtual machine is violating Risk Prole 2 in vSphere Hardening Guide (5.5 and 6.0)
n
Virtual machine is violating Risk Prole 3 in vSphere Hardening Guide (5.5 and 6.0)
n
vSphere Distributed Port Group is violating vSphere Hardening Guide (6.0)
n
vSphere Distributed Virtual Switch is violating vSphere Hardening Guide (6.0)
By default, the alert named Virtual machine is violating Risk Profile 1 is the only active alert among
the risk proles. You can congure this prole later, and choose one of the other risk proles.
To determine whether an alert triggered against vSphere Hardening Guide 6.0 or 5.5, you must examine the
underlying symptoms. For example, for the alert named ESXi Host is violating vSphere Hardening Guide,
the following underlying symptoms for the alert include:
n
ESXi.set-account-lockout - The count failed login aempts before the account is locked out exceeded
maximum (vSphere Hardening Guide 6.0)
n
DCUI service is running (vSphere Hardening Guide 5.5)
You can nd the vSphere Hardening Guides at hp://www.vmware.com/security/hardening-guides.html.
Reset Default Content to Ensure Current Compliance Standards for vSphere 6.0
and 5.5 Objects
Alert denitions and symptom denitions now include the compliance standards for both vSphere 6.0 and
5.5. When you upgrade your current version of vRealize Operations Manager, you must select the option to
overwrite alert denitions and symptom denitions.
If you do not overwrite your alert denitions and symptom denitions with the new content provided with
this release, some compliance rules will include the new alert and symptom denitions, while other
compliance rules will continue to use outdated alert and symptom denitions.
Chapter 3 Customizing How vRealize Operations Manager Monitors Your Environment
VMware, Inc. 73