STIGQter STIGQter: STIG Summary: IBM Hardware Management Console (HMC) Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

Unauthorized partitions must not exist on the system complex.

DISA Rule

SV-256862r991589_rule

Vulnerability Number

V-256862

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

HLP0010

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Review the LPARs on the system and remove any unauthorized LPARs. If a deviation exists, the system administrator will provide written justification for the deviation.

This will be displayed by using the Change LPAR Control Panel.

Check Contents

Using the Hardware Management Console, do the following:

Access the Change LPAR Control Panel. (This will list the LPARs.)

Compare the partition names listed on the Partition Page to the names entered on the Central Processor Complex Domain/LPAR Names table.
Note: Each site should maintain a list of valid LPARS that are configured on thier system , what operating system, and the purpose of each LPAR.
If unauthorized partitions exist on the system complex and the deviation is not documented, this is a FINDING.

Vulnerability Number

V-256862

Documentable

False

Rule Version

HLP0010

Severity Override Guidance

Using the Hardware Management Console, do the following:

Access the Change LPAR Control Panel. (This will list the LPARs.)

Compare the partition names listed on the Partition Page to the names entered on the Central Processor Complex Domain/LPAR Names table.
Note: Each site should maintain a list of valid LPARS that are configured on thier system , what operating system, and the purpose of each LPAR.
If unauthorized partitions exist on the system complex and the deviation is not documented, this is a FINDING.

Check Content Reference

M

Target Key

5533