Check: HMC0040
IBM Hardware Management Console (HMC) STIG:
HMC0040
(in version v1 r5)
Title
Access to the Hardware Management Console must be restricted to only authorized personnel. (Cat II impact)
Discussion
Access to the Hardware Management Console if not properly restricted to authorized personnel could lead to a bypass of security, access to the system, and an altering of the environment. This would result in a loss of secure operations and can cause an impact to data operating environment integrity.
Check Content
Verify that sign-on access to the Hardware Management Console is restricted to authorize personnel and that a DD2875 is on file for each user ID. Note: Sites must have a list of valid HMC users, indicating their USER IDs, Date of DD2875, and roles and responsibilities To display user roles chose User Profiles and then select the user for modification. View Task Roles and Manager Resources Roles. If each user displayed by the System Administrator does not have a DD2875, then this is a FINDING.
Fix Text
The System Administrator will see that sign-on access to the Hardware Management Console is restricted to authorized personnel and that a DD2875 is on file for each user ID. Note: Sites must have a list of valid HMC users, indicating their USER IDs, Date of DD2875, and roles and responsibilities. The System Administrator must see that the list and users defined to the Hardware Management Console match.
Additional Identifiers
Rule ID: SV-30008r2_rule
Vulnerability ID: V-24349
Group Title: HMC0040
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002227 |
The organization restricts privileged accounts on the information system to organization-defined personnel or roles. |
CCI-002235 |
The information system prevents non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures. |