Skip to content

IBM Hardware Management Console (HMC) Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-OS-000104-GPOS-00051

    <GroupDescription></GroupDescription>
    Group
  • DCAF Console access must require a password to be entered by each user.

    &lt;VulnDiscussion&gt;The DCAF Console enables an operator to access the ESCON Director Application remotely. Access to a DCAF Console by unauthori...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • Unauthorized partitions must not exist on the system complex.

    &lt;VulnDiscussion&gt;The running of unauthorized Logical Partitions (LPARs) could allow a “Trojan horse” version of the operating environment to b...
    Rule Medium Severity
  • SRG-OS-000080-GPOS-00048

    <GroupDescription></GroupDescription>
    Group
  • Dial-out access from the Hardware Management Console Remote Support Facility (RSF) must be restricted to an authorized vendor site.

    &lt;VulnDiscussion&gt;Dial-out access from the Hardware Management Console could impact the integrity of the environment, by enabling the possible ...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • Dial-out access from the Hardware Management Console Remote Support Facility (RSF) must be disabled for all classified systems.

    &lt;VulnDiscussion&gt;This feature will not be activated for any classified systems. Allowing dial-out access from the Hardware Management Console ...
    Rule High Severity
  • SRG-OS-000324-GPOS-00125

    <GroupDescription></GroupDescription>
    Group
  • Access to the Hardware Management Console must be restricted to only authorized personnel.

    &lt;VulnDiscussion&gt;Access to the Hardware Management Console if not properly restricted to authorized personnel could lead to a bypass of securi...
    Rule Medium Severity
  • SRG-OS-000080-GPOS-00048

    <GroupDescription></GroupDescription>
    Group
  • Access to the Hardware Management Console (HMC) must be restricted by assigning users proper roles and responsibilities.

    &lt;VulnDiscussion&gt;Access to the HMC if not properly controlled and restricted by assigning users proper roles and responsibilities, could allow...
    Rule Medium Severity
  • SRG-OS-000324-GPOS-00125

    <GroupDescription></GroupDescription>
    Group
  • Automatic Call Answering to the Hardware Management Console must be disabled.

    &lt;VulnDiscussion&gt;Automatic Call Answering to the Hardware Management Console allows unrestricted access by unauthorized personnel and could le...
    Rule Medium Severity
  • SRG-OS-000062-GPOS-00031

    <GroupDescription></GroupDescription>
    Group
  • The Hardware Management Console Event log must be active.

    &lt;VulnDiscussion&gt;The Hardware Management Console controls the operation and availability of the Central Processor Complex (CPC). Failure to cr...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • SRG-OS-000080-GPOS-00048

    <GroupDescription></GroupDescription>
    Group
  • Predefined task roles to the Hardware Management Console (HMC) must be specified to limit capabilities of individual users.

    &lt;VulnDiscussion&gt;Individual task roles with access to specific resources if not created and restricted, will allow unrestricted access to syst...
    Rule Medium Severity
  • SRG-OS-000104-GPOS-00051

    <GroupDescription></GroupDescription>
    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules