6.3

Table Of Contents
User Scenario: Ensure Compliance of Your vSphere 6.0 Objects
As the virtual infrastructure administrator for your company, you must ensure that your vSphere 6.0 objects
comply with the compliance rules in the vSphere Hardening Guide. You use the compliance alerts in
vRealize Operations Manager to monitor your objects for violations to your compliance standards. When a
compliance alert triggers on your vCenter Server instance, hosts, virtual machines, distributed port groups,
or distributed switches, you investigate the compliance violation. You must and resolve the violation so that
the violated object continues to meet industry security standards.
You manage and monitor the security of your production, test, and development environments. Your objects
consist of multiple vCenter Server instances, with hosts, virtual machines, distributed port groups, and
distributed switches in each instance.
Your CIO requires that you run SSH on all vCenter Server instances and host machines in your production
and test environments. You monitor all hosts to ensure that they comply with the SSH requirement. You
produce a compliance report each week to prove to your manager and the compliance team that your
objects comply with the implemented security standards.
To enforce and report on the compliance of your vSphere 6.0 objects, you enable the compliance rules in the
vSphere Hardening Guide. Then, you enable the appropriate alerts, and apply a risk prole to your virtual
machines. After vRealize Operations Manager collects the compliance data from your objects, you resolve
any rule violations that occurred, and create a report of the compliance results for your manager and the
compliance team.
The Alert denitions provided with vRealize Operations Manager are based on object types instead of the
specic versions of the hardening guides. To use these alerts, you no longer must create a custom group and
apply the policy to that group.
Some alert denitions are common between vSphere 6.0 and vSphere 5.5 objects.
vRealize Operations Manager checks vSphere 6.0 symptoms against 6.0 objects, 5.5 symptoms against 5.5
objects, and a combination of 6.0 and 5.5 symptoms against both versions of the objects.
Prerequisites
Verify that the current version of vRealize Operations Manager is installed and running.
Procedure
1 In vRealize Operations Manager, enable the compliance rules.
a Click Administration, and click Solutions.
b Click the VMware vSphere solution, and click .
c In the Manage Solution dialog box, click  Monitoring Goals.
d Under Enable vSphere Hardening Guide Alerts, click Yes and click Save.
e When vRealize Operations Manager reports that the default policy is congured to collect
compliance data on your objects, click OK and click Close.
2 Enable the compliance alert denitions in the default policy.
a Click Policies > Policy Library.
b Click the Default Policy, and click Edit Selected Policy.
c In the Edit Monitoring Policy workspace on the left, click Alert / Symptom .
vRealize Operations Manager Customization and Administration Guide
74 VMware, Inc.