CIS Citrix Hypervisor Benchmark

Secure configuration guidelines for Citrix Hypervisor (XenServer)

v1.0.0 August 2024

Overview

▶

This CIS Benchmark provides prescriptive guidance for establishing a secure configuration posture for Citrix Hypervisor (formerly XenServer). Recommendations cover installation hardening, authentication, network configuration, storage security, virtual machine management, and logging and monitoring.

~90Recommendations
6Sections
2Profile Levels
SectionAreaFocus
1InstallationHost hardening, management
2AuthenticationAD, RBAC, access policies
3NetworkVirtual switches, firewall
4StorageRepos, data protection
5VM ManagementSecurity, guest tools
6LoggingSyslog, monitoring

Profile Definitions

▶
ProfileDescriptionIntended Use
L1Level 1 — StandardEssential security for all Citrix Hypervisor deployments; minimal performance impact.
L2Level 2 — HardenedAdvanced hardening for PCI-DSS, HIPAA, or high-security environments.

1 — Installation & Host Configuration

▶

1.1 Host Hardening

▶
1.1.1 Ensure Latest Hotfixes Are Applied (Manual)
L1 Manual
Description

This recommendation verifies that Latest Hotfixes Are Applied on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that Latest Hotfixes Are Applied. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Latest Hotfixes Are Applied. Apply the changes and verify.

1.1.2 Ensure Unnecessary Services Are Disabled (Automated)
L1 Auto
Description

This recommendation verifies that Unnecessary Services Are Disabled on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that Unnecessary Services Are Disabled. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Unnecessary Services Are Disabled. Apply the changes and verify.

1.1.3 Ensure NTP Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that NTP Is Configured on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that NTP Is Configured. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure NTP Is Configured. Apply the changes and verify.

1.1.4 Ensure Host File Permissions Are Restricted (Automated)
L1 Auto
Description

This setting ensures that Host File Permissions Are Restricted on the Citrix Hypervisor hypervisor. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Citrix Hypervisor hypervisor is essential for defense in depth.

Audit

In XenCenter or via xe CLI, verify that Host File Permissions Are Restricted. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Host File Permissions Are Restricted. Apply the changes and verify.

1.2 Management Configuration

▶
1.2.1 Ensure Management Interface Is on Dedicated Network (Automated)
L1 Auto
Description

This recommendation verifies that Management Interface Is on Dedicated Network on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that Management Interface Is on Dedicated Network. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Management Interface Is on Dedicated Network. Apply the changes and verify.

1.2.2 Ensure XAPI Listens Only on Management Interface (Automated)
L1 Auto
Description

This recommendation verifies that XAPI Listens Only on Management Interface on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that XAPI Listens Only on Management Interface. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure XAPI Listens Only on Management Interface. Apply the changes and verify.

1.2.3 Ensure SSH Access Is Restricted (Automated)
L1 Auto
Description

This setting ensures that SSH Access Is Restricted on the Citrix Hypervisor hypervisor. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Citrix Hypervisor hypervisor is essential for defense in depth.

Audit

In XenCenter or via xe CLI, verify that SSH Access Is Restricted. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure SSH Access Is Restricted. Apply the changes and verify.

1.2.4 Ensure TLS Is Enabled for Management Communication (Automated)
L1 Auto
Description

This recommendation verifies that TLS Is Enabled for Management Communication on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that TLS Is Enabled for Management Communication. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure TLS Is Enabled for Management Communication. Apply the changes and verify.

2 — Authentication & Access Control

▶

2.1 Authentication

▶
2.1.1 Ensure Default Root Password Is Changed (Manual)
L1 Manual
Description

This recommendation verifies that Default Root Password Is Changed on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that Default Root Password Is Changed. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Default Root Password Is Changed. Apply the changes and verify.

2.1.2 Ensure Active Directory Integration Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Active Directory Integration Is Configured on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that Active Directory Integration Is Configured. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Active Directory Integration Is Configured. Apply the changes and verify.

2.1.3 Ensure RBAC Is Configured with Least Privilege (Manual)
L1 Manual
Description

This recommendation verifies that RBAC Is Configured with Least Privilege on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that RBAC Is Configured with Least Privilege. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure RBAC Is Configured with Least Privilege. Apply the changes and verify.

2.1.4 Ensure Session Timeout Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Session Timeout Is Configured on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that Session Timeout Is Configured. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Session Timeout Is Configured. Apply the changes and verify.

2.2 Access Policies

▶
2.2.1 Ensure SSH Root Login Is Restricted (Automated)
L1 Auto
Description

This setting ensures that SSH Root Login Is Restricted on the Citrix Hypervisor hypervisor. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Citrix Hypervisor hypervisor is essential for defense in depth.

Audit

In XenCenter or via xe CLI, verify that SSH Root Login Is Restricted. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure SSH Root Login Is Restricted. Apply the changes and verify.

2.2.2 Ensure Password Complexity Is Enforced (Automated)
L1 Auto
Description

This recommendation ensures that Password Complexity Is Enforced on the Citrix Hypervisor hypervisor. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Citrix Hypervisor hypervisor may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

In XenCenter or via xe CLI, verify that Password Complexity Is Enforced. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Password Complexity Is Enforced. Apply the changes and verify.

2.2.3 Ensure Account Lockout Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Account Lockout Is Configured on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that Account Lockout Is Configured. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Account Lockout Is Configured. Apply the changes and verify.

3 — Network Configuration

▶

3.1 Virtual Networking

▶
3.1.1 Ensure Management Network Is Isolated from VM Traffic (Automated)
L1 Auto
Description

This recommendation verifies that Management Network Is Isolated from VM Traffic on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that Management Network Is Isolated from VM Traffic. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Management Network Is Isolated from VM Traffic. Apply the changes and verify.

3.1.2 Ensure VLAN Tagging Is Properly Configured (Automated)
L1 Auto
Description

This recommendation verifies that VLAN Tagging Is Properly Configured on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that VLAN Tagging Is Properly Configured. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure VLAN Tagging Is Properly Configured. Apply the changes and verify.

3.1.3 Ensure Promiscuous Mode Is Disabled on Virtual Switches (Automated)
L1 Auto
Description

This recommendation verifies that Promiscuous Mode Is Disabled on Virtual Switches on the Citrix Hypervisor hypervisor. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.

Rationale

Running unnecessary components on the Citrix Hypervisor hypervisor increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.

Audit

In XenCenter or via xe CLI, verify that Promiscuous Mode Is Disabled on Virtual Switches. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Promiscuous Mode Is Disabled on Virtual Switches. Apply the changes and verify.

3.1.4 Ensure MAC Address Spoofing Protection Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that MAC Address Spoofing Protection Is Enabled on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that MAC Address Spoofing Protection Is Enabled. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure MAC Address Spoofing Protection Is Enabled. Apply the changes and verify.

3.2 Firewall & Ports

▶
3.2.1 Ensure Host Firewall Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Host Firewall Is Enabled on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that Host Firewall Is Enabled. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Host Firewall Is Enabled. Apply the changes and verify.

3.2.2 Ensure Only Required Ports Are Open (Automated)
L1 Auto
Description

This recommendation ensures that Only Required Ports Are Open on the Citrix Hypervisor hypervisor. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Citrix Hypervisor hypervisor may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

In XenCenter or via xe CLI, verify that Only Required Ports Are Open. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Only Required Ports Are Open. Apply the changes and verify.

3.2.3 Ensure iSCSI Networks Are Isolated (Automated)
L2 Auto
Description

This recommendation verifies that iSCSI Networks Are Isolated on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that iSCSI Networks Are Isolated. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure iSCSI Networks Are Isolated. Apply the changes and verify.

4 — Storage Security

▶

4.1 Storage Configuration

▶
4.1.1 Ensure Storage Repositories Are on Dedicated Networks (Automated)
L1 Auto
Description

This recommendation verifies that Storage Repositories Are on Dedicated Networks on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that Storage Repositories Are on Dedicated Networks. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Storage Repositories Are on Dedicated Networks. Apply the changes and verify.

4.1.2 Ensure NFS Storage Uses Authenticated Connections (Automated)
L2 Auto
Description

This recommendation verifies that NFS Storage Uses Authenticated Connections on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that NFS Storage Uses Authenticated Connections. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure NFS Storage Uses Authenticated Connections. Apply the changes and verify.

4.1.3 Ensure iSCSI Storage Uses CHAP Authentication (Automated)
L2 Auto
Description

This recommendation verifies that iSCSI Storage Uses CHAP Authentication on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that iSCSI Storage Uses CHAP Authentication. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure iSCSI Storage Uses CHAP Authentication. Apply the changes and verify.

4.2 Data Protection

▶
4.2.1 Ensure VM Snapshots Are Not Used as Backups (Manual)
L1 Manual
Description

This recommendation verifies that VM Snapshots Are Not Used as Backups on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that VM Snapshots Are Not Used as Backups. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure VM Snapshots Are Not Used as Backups. Apply the changes and verify.

4.2.2 Ensure Backup Solution Is Configured and Tested (Manual)
L1 Manual
Description

This recommendation verifies that Backup Solution Is Configured and Tested on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that Backup Solution Is Configured and Tested. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Backup Solution Is Configured and Tested. Apply the changes and verify.

4.2.3 Ensure Thin Provisioning Is Monitored for Capacity (Automated)
L1 Auto
Description

This recommendation verifies that Thin Provisioning Is Monitored for Capacity on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that Thin Provisioning Is Monitored for Capacity. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Thin Provisioning Is Monitored for Capacity. Apply the changes and verify.

5 — Virtual Machine Management

▶

5.1 VM Security

▶
5.1.1 Ensure VM Templates Are Hardened Before Deployment (Manual)
L1 Manual
Description

This recommendation verifies that VM Templates Are Hardened Before Deployment on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that VM Templates Are Hardened Before Deployment. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure VM Templates Are Hardened Before Deployment. Apply the changes and verify.

5.1.2 Ensure Unused VMs Are Powered Off or Removed (Manual)
L1 Manual
Description

This recommendation verifies that Unused VMs Are Powered Off or Removed on the Citrix Hypervisor hypervisor. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.

Rationale

Running unnecessary components on the Citrix Hypervisor hypervisor increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.

Audit

In XenCenter or via xe CLI, verify that Unused VMs Are Powered Off or Removed. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Unused VMs Are Powered Off or Removed. Apply the changes and verify.

5.1.3 Ensure VM Resource Limits Are Configured (Automated)
L1 Auto
Description

This recommendation verifies that VM Resource Limits Are Configured on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that VM Resource Limits Are Configured. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure VM Resource Limits Are Configured. Apply the changes and verify.

5.1.4 Ensure Live Migration Uses Encrypted Transport (Automated)
L2 Auto
Description

This recommendation verifies that Live Migration Uses Encrypted Transport on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that Live Migration Uses Encrypted Transport. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Live Migration Uses Encrypted Transport. Apply the changes and verify.

5.2 Guest Tools

▶
5.2.1 Ensure Guest Tools Are Installed and Updated (Manual)
L1 Manual
Description

This recommendation verifies that Guest Tools Are Installed and Updated on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that Guest Tools Are Installed and Updated. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Guest Tools Are Installed and Updated. Apply the changes and verify.

5.2.2 Ensure CD/DVD Drives Are Disconnected When Not in Use (Manual)
L1 Manual
Description

This recommendation verifies that CD/DVD Drives Are Disconnected When Not in Use on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that CD/DVD Drives Are Disconnected When Not in Use. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure CD/DVD Drives Are Disconnected When Not in Use. Apply the changes and verify.

5.2.3 Ensure USB Passthrough Is Disabled When Not Required (Automated)
L2 Auto
Description

This recommendation verifies that USB Passthrough Is Disabled When Not Required on the Citrix Hypervisor hypervisor. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.

Rationale

Running unnecessary components on the Citrix Hypervisor hypervisor increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.

Audit

In XenCenter or via xe CLI, verify that USB Passthrough Is Disabled When Not Required. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure USB Passthrough Is Disabled When Not Required. Apply the changes and verify.

6 — Logging & Monitoring

▶

6.1 Logging

▶
6.1.1 Ensure Syslog Is Configured for Remote Logging (Automated)
L1 Auto
Description

This recommendation verifies that Syslog Is Configured for Remote Logging on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that Syslog Is Configured for Remote Logging. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Syslog Is Configured for Remote Logging. Apply the changes and verify.

6.1.2 Ensure Audit Logging Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Audit Logging Is Enabled on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that Audit Logging Is Enabled. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Audit Logging Is Enabled. Apply the changes and verify.

6.1.3 Ensure Log Rotation Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Log Rotation Is Configured on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that Log Rotation Is Configured. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Log Rotation Is Configured. Apply the changes and verify.

6.2 Monitoring

▶
6.2.1 Ensure SNMP Is Configured with SNMPv3 (Automated)
L2 Auto
Description

This recommendation verifies that SNMP Is Configured with SNMPv3 on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that SNMP Is Configured with SNMPv3. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure SNMP Is Configured with SNMPv3. Apply the changes and verify.

6.2.2 Ensure Host Performance Monitoring Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Host Performance Monitoring Is Configured on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that Host Performance Monitoring Is Configured. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Host Performance Monitoring Is Configured. Apply the changes and verify.

6.2.3 Ensure Alerts Are Configured for Critical Events (Automated)
L1 Auto
Description

This recommendation verifies that Alerts Are Configured for Critical Events on the Citrix Hypervisor hypervisor. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Citrix Hypervisor hypervisor vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In XenCenter or via xe CLI, verify that Alerts Are Configured for Critical Events. Review the host configuration for confirmation.

Remediation

In XenCenter or via xe CLI, configure Alerts Are Configured for Critical Events. Apply the changes and verify.