STIGQter STIGQter: STIG Summary: IBM Hardware Management Console (HMC) Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

The password values must be set to meet the requirements in accordance with DODI 8500.2 for DoD information systems processing sensitive information and above, and CJCSI 6510.01E (INFORMATION ASSURANCE [IA] AND COMPUTER NETWORK DEFENSE [CND]).

DISA Rule

SV-256882r998335_rule

Vulnerability Number

V-256882

Group Title

SRG-OS-000069-GPOS-00037

Rule Version

HMC0140

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Have the system administrator (SA) validate that the settings in the Password Profiles Window meet the following specifications:

Passwords are a minimum of 14 characters in length.

Passwords are to be a mix of uppercase, lowercase alphabetic, numeric, and special characters, including at least one of each. Special characters include the national characters (i.e., @, #, and $) and other non-alphabetic and non-numeric characters typically found on a keyboard.

Each character of the password is to be unique, prohibiting the use of repeating characters.

Passwords are to contain no consecutive characters (e.g., 12, AB, etc.).

Check Contents

Have the system administrator (SA) display the Password Profile Task window on the Hardware Management Console and check that:

Passwords are to be a minimum of 14 characters in length.

Passwords are to be a mix of uppercase, lowercase alphabetic, numeric, and special characters, including at least one of each. Special characters include the national characters (i.e., @, #, and $) and other nonalphabetic and nonnumeric characters typically found on a keyboard.

Each character of the password is to be unique, prohibiting the use of repeating characters.

Passwords are to contain no consecutive characters (e.g., 12, AB, etc.).

If the Password Profile does not have the specifications for the above options then this is a finding.

Vulnerability Number

V-256882

Documentable

False

Rule Version

HMC0140

Severity Override Guidance

Have the system administrator (SA) display the Password Profile Task window on the Hardware Management Console and check that:

Passwords are to be a minimum of 14 characters in length.

Passwords are to be a mix of uppercase, lowercase alphabetic, numeric, and special characters, including at least one of each. Special characters include the national characters (i.e., @, #, and $) and other nonalphabetic and nonnumeric characters typically found on a keyboard.

Each character of the password is to be unique, prohibiting the use of repeating characters.

Passwords are to contain no consecutive characters (e.g., 12, AB, etc.).

If the Password Profile does not have the specifications for the above options then this is a finding.

Check Content Reference

M

Target Key

5533