STIGQter STIGQter: STIG Summary:

IBM Hardware Management Console (HMC) Security Technical Implementation Guide

Version: 2

Release: 1 Benchmark Date: 24 Jul 2024

CheckedNameTitle
SV-256857r991589_ruleThe Enterprise System Connection (ESCON) Director (ESCD) Application Console must be located in a secure location
SV-256858r958726_ruleSign-on to the ESCD Application Console must be restricted to only authorized personnel.
SV-256859r958442_ruleThe ESCON Director Application Console Event log must be enabled.
SV-256860r958726_ruleThe Distributed Console Access Facility (DCAF) Console must be restricted to only authorized personnel.
SV-256861r958482_ruleDCAF Console access must require a password to be entered by each user.
SV-256862r991589_ruleUnauthorized partitions must not exist on the system complex.
SV-256863r958472_ruleOn Classified Systems, Logical Partition must be restricted with read/write access to only its own IOCDS.
SV-256864r958472_ruleProcessor Resource/Systems Manager (PR/SM) must not allow unrestricted issuing of control program commands.
SV-256865r958472_ruleClassified Logical Partition (LPAR) channel paths must be restricted.
SV-256866r958472_ruleOn Classified Systems the Processor Resource/Systems Manager (PR/SM) must not allow access to system complex data.
SV-256867r958472_ruleCentral processors must be restricted for classified/restricted Logical Partitions (LPARs).
SV-256868r991589_ruleThe Hardware Management Console must be located in a secure location.
SV-256869r1001084_ruleDial-out access from the Hardware Management Console Remote Support Facility (RSF) must be restricted to an authorized vendor site.
SV-256870r1001085_ruleDial-out access from the Hardware Management Console Remote Support Facility (RSF) must be disabled for all classified systems.
SV-256871r958726_ruleAccess to the Hardware Management Console must be restricted to only authorized personnel.
SV-256872r958472_ruleAccess to the Hardware Management Console (HMC) must be restricted by assigning users proper roles and responsibilities.
SV-256873r958726_ruleAutomatic Call Answering to the Hardware Management Console must be disabled.
SV-256874r958442_ruleThe Hardware Management Console Event log must be active.
SV-256875r1001086_ruleThe manufacturer’s default passwords must be changed for all Hardware Management Console (HMC) Management software.
SV-256876r958472_rulePredefined task roles to the Hardware Management Console (HMC) must be specified to limit capabilities of individual users.
SV-256877r958482_ruleIndividual user accounts with passwords must be maintained for the Hardware Management Console operating system and application.
SV-256878r998329_ruleThe PASSWORD History Count value must be set to 10 or greater.
SV-256879r998332_ruleThe PASSWORD expiration day(s) value must be set to equal or less then 60 days.
SV-256880r958388_ruleMaximum failed password attempts before disable delay must be set to 3 or less.
SV-256881r958736_ruleA maximum of 60-minute delay must be specified for the password retry after 3 failed attempts to enter your password
SV-256882r998335_ruleThe password values must be set to meet the requirements in accordance with DODI 8500.2 for DoD information systems processing sensitive information and above, and CJCSI 6510.01E (INFORMATION ASSURANCE [IA] AND COMPUTER NETWORK DEFENSE [CND]).
SV-256883r958402_ruleThe terminal or workstation must lock out after a maximum of 15 minutes of inactivity, requiring the account password to resume.
SV-256884r958390_ruleThe Department of Defense (DoD) logon banner must be displayed prior to any login attempt.
SV-256885r998338_ruleA private web server must subscribe to certificates, issued from any DOD-authorized Certificate Authority (CA), as an access control mechanism for web users.
SV-256886r958754_ruleHardware Management Console audit record content data must be backed up.
SV-256887r958412_ruleAudit records content must contain valid information to allow for proper incident reporting.
SV-256888r991589_ruleHardware Management Console management must be accomplished by using the out-of-band or direct connection method.
SV-256889r958726_ruleProduct engineering access to the Hardware Management Console must be disabled.
SV-256890r991589_ruleConnection to the Internet for IBM remote support must be in compliance with the Remote Access STIGs.
SV-256891r991589_ruleConnection to the Internet for IBM remote support must be in compliance with mitigations specified in the Ports and Protocols and Services Management (PPSM) requirements.