System administrators must use templates to deploy virtual machines (VMs) whenever possible.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
lowV-256468SRG-OS-000480-VMM-002000VMCH-70-000020SV-256468r959010_rule2024-12-161
Description
Capture a hardened base operating system image (with no applications installed) in a template to ensure all VMs are created with a known baseline level of security. Use this template to create other, application-specific templates, or use the application template to deploy VMs. Manual installation of the operating system and applications into a VM introduces the risk of misconfiguration due to human or process error.
ℹ️ Check
Ask the system administrator if hardened, patched templates are used for VM creation and properly configured operating system deployments, including applications dependent and nondependent on VM-specific configurations. If hardened, patched templates are not used for VM creation, this is a finding.
✔️ Fix
Create hardened VM templates to use for operating system deployments.