Today I had an interesting question posed to me by a customer.
“What’s a way we can verify file integrity compliance of our VMware View gold image, at regular intervals, WITHOUT powering it on? Because powering it on would force us to recompose all VMs once it’s powered down again”
In order to verity file integrity of a VM, there will need to be a file integrity check at some point in time. [PCI DSS 11.5] This is not a point in doubt. The question arose regarding regular scheduled checks on file integrity, at a pre-set interval. That’s the key. They need to ensure it weekly or monthly.