vSphere Security
vSphere 5.0 has achieved Common Criteria certification at Evaluation Assurance Level 4 (EAL4+) under the Common Criteria Evaluation and Certification Scheme (CCS) and vSphere 5.1 is currently undergoing CCS at EAL2+. vSphere 5.5 Hardening Guide recommends 3 levels of security hardening for following vSphere components:
Virtual machines
ESXi hosts
Virtual network
vCenter Server
VMware Update Manager
vCenter Single Sign-On
vSphere Web Client
vCenter Server Virtual Appliance
The 3 recommended security levels (profiles) have following characteristic:
Profile 3: guidelines that should be implemented in all environments
Profile 2: guidelines that should be implemented for more sensitive environments, e.g. those handling more sensitive data, those subject to stricter compliance rules, etc.
Profile 1: guidelines that only be implemented in the highest security environments, e.g. top-secret government or military, extremely sensitive data, etc.