STIGQter STIGQter: STIG Summary: IBM Hardware Management Console (HMC) Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

Individual user accounts with passwords must be maintained for the Hardware Management Console operating system and application.

DISA Rule

SV-256877r958482_rule

Vulnerability Number

V-256877

Group Title

SRG-OS-000104-GPOS-00051

Rule Version

HMC0100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Have the System Administrator verify that all users of the Hardware Management Console are individually defined with USER IDs and passwords and that their roles and responsibilities are documented. Verify that a DD2875 exists for each USER ID.

Check Contents

Have the System Administrator prove that individual USER IDs are specified for each user and DD2875 are on file for each user.

If USERIDs are shared among multiple users and crresponding DD2875 forms do not exist for each user, then this is a FINDING.

Vulnerability Number

V-256877

Documentable

False

Rule Version

HMC0100

Severity Override Guidance

Have the System Administrator prove that individual USER IDs are specified for each user and DD2875 are on file for each user.

If USERIDs are shared among multiple users and crresponding DD2875 forms do not exist for each user, then this is a FINDING.

Check Content Reference

M

Target Key

5533