


For this example, we will be creating a Windows 2008 R2 scorecard. This tutorial assumes you already have vRealize Configuration Manager installed and configured and able to communicate with at least one managed system. This gem of a tool provides unified, cross-platform configuration and compliance management, and enforcement of over 80,000 distinct controls from a single interface, complete with fully customizable reports, dashboards, and a whole host of other fun features. This is where one of VMware vRealize Configuration Manager comes in. So, automating these processes became something of a necessity. Of course, this particular environment was fairly large, and the information assurance technical staff consisted basically of me. At the forefront of this list were a long list of DISA STIGs (Defense Information Systems Agency Security Technical Implementation Guides) – a daunting task in any size environment with any size staff. In my previous life as an InfoSec guy, I was responsible for assessing, enforcing, and ensuring continuous compliance with all the various baselines for which my organization was responsible.
