STIGQter STIGQter: STIG Summary: IBM Hardware Management Console (HMC) Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

On Classified Systems, Logical Partition must be restricted with read/write access to only its own IOCDS.

DISA Rule

SV-256863r958472_rule

Vulnerability Number

V-256863

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

HLP0020

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Review the Security Definition parameters specified under Processor Resource/Systems Manager (PR/SM).
Verify and implement the correct settings.

Check Contents

Using the Hardware Management Console, verify that a logical partition cannot read or write to any IOCDS. Use the Security Definitions Page panel to do this by checking to see if the Input/Output (I/O) Configuration Control option has been turned on.

NOTE: The default is applicable to only classified systems.

Confirm whether or not the I/O Configuration Control option is checked.

If the Logical Partition is not restricted with read/write access to only its own IOCDS, this is a FINDING.

Vulnerability Number

V-256863

Documentable

False

Rule Version

HLP0020

Severity Override Guidance

Using the Hardware Management Console, verify that a logical partition cannot read or write to any IOCDS. Use the Security Definitions Page panel to do this by checking to see if the Input/Output (I/O) Configuration Control option has been turned on.

NOTE: The default is applicable to only classified systems.

Confirm whether or not the I/O Configuration Control option is checked.

If the Logical Partition is not restricted with read/write access to only its own IOCDS, this is a FINDING.

Check Content Reference

M

Target Key

5533