Compliance

Tenable One Vulnerability Management, Tenable Security Center, or Tenable Nessus can scan VMware environments for compliance. Compliance checks are targeted, credentialed checks of ESXi and/or vCenter servers based on the targets listed in the scan settings.

  • When scanning a vCenter host, Tenable reports on the vCenter server and on any ESXi servers that vCenter manages.

  • When scanning an ESXi host, the scan reports on that ESXi host.

  • You can scan both ESXi and vCenter hosts in a single scan.

  • The vCenter server must be listed as a scan target for vCenter compliance checks to run.

Required plugin: VMware vCenter/vSphere Compliance Checks (64455) must be enabled to execute compliance scanning. This plugin is automatically enabled when you add an audit file that requires it.

Required permissions: compliance scanning requires the Global → Settings privilege in vCenter, in addition to the read privileges needed for vulnerability scanning.

API behavior: compliance checks use the SOAP API regardless of vCenter version, unlike normal vulnerability checks, which use the REST API on VMware 7.0.3 and newer. This is because the SOAP API exposes configuration data at the level of detail compliance auditing requires.

Constraints:

  • Compliance scanning is unavailable with the Auto-Discovery feature enabled.

  • Some compliance audits — those with "Bare Metal" in the name — require an additional SSH credential configured with an administrator-level ESXi user. Adding these audits displays a notice that SSH credentials are required.

  • Audit/compliance is supported on vCenter 6.x, 7.x, and 8.x.