STIGQter STIGQter: STIG Summary:

HPE Nimble Storage Array NDM Security Technical Implementation Guide

Version: 2

Release: 1 Benchmark Date: 24 Jul 2024

CheckedNameTitle
SV-252186r960741_ruleThe HPE Nimble must initiate a session lock after a 15-minute period of inactivity.
SV-252187r960840_ruleThe HPE Nimble must be configured to enforce the limit of three consecutive invalid logon attempts, after which time it must block any login attempt for 15 minutes.
SV-252188r960843_ruleThe HPE Nimble must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the device.
SV-252190r997770_ruleThe HPE Nimble must enforce a minimum 15-character password length.
SV-252191r997772_ruleThe HPE Nimble must enforce password complexity by requiring that at least one uppercase character be used.
SV-252192r997774_ruleThe HPE Nimble must enforce password complexity by requiring that at least one lowercase character be used.
SV-252193r997775_ruleThe HPE Nimble must enforce password complexity by requiring that at least one numeric character be used.
SV-252194r997777_ruleThe HPE Nimble must enforce password complexity by requiring that at least one special character be used.
SV-252195r997779_ruleThe HPE Nimble must require that when a password is changed, the characters are changed in at least eight of the positions within the password.
SV-252196r961068_ruleThe HPE Nimble must terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after 10 minutes of inactivity.
SV-252197r997780_ruleThe HPE Nimble must be configured to use an authentication server for the purpose of authenticating users prior to granting administrative access.
SV-252198r1001013_ruleThe HPE Nimble must obtain its public key certificates from an appropriate certificate policy through an approved service provider.
SV-252199r961863_ruleThe HPE Nimble must forward critical alerts (at a minimum) to the system administrators and the ISSO.
SV-252200r961863_ruleThe HPE Nimble must be running an operating system release that is currently supported by the vendor.
SV-252201r960735_ruleThe HPE Nimble must limit the number of concurrent sessions to an organization-defined number for each administrator account.
SV-252202r1001011_ruleThe HPE Nimble must be configured to synchronize internal information system clocks using an authoritative time source.
SV-252203r961860_ruleThe HPE Nimble must configure a syslog server onto a different system or media than the system being audited.
SV-252902r960966_ruleHPE Nimble must be configured to disable HPE InfoSight.
SV-259800r960966_ruleHPE Nimble must not be configured to use "HPE Greenlake: Data Services Cloud Console".
SV-259801r960966_ruleHPE Alletra 5000/6000 must be configured to disable management by "HPE Greenlake: Data Services Cloud Console".