Skip to content

IBM Hardware Management Console (HMC) Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-OS-000077-GPOS-00045

    Group
  • The PASSWORD History Count value must be set to 10 or greater.

    History Count specifies the number of previous passwords saved for each USERID and compares it with an intended new password. If there is a match with one of the previous passwords, or with the cur...
    Rule Medium Severity
  • SRG-OS-000076-GPOS-00044

    Group
  • The PASSWORD expiration day(s) value must be set to equal or less then 60 days.

    Expiration Day(s) specifies the maximum number of days that each user's password is valid. When a user logs on to the Hardware Management Console it compares the system password interval value spec...
    Rule Medium Severity
  • SRG-OS-000021-GPOS-00005

    Group
  • A private web server must subscribe to certificates, issued from any DOD-authorized Certificate Authority (CA), as an access control mechanism for web users.

    If the Hardware Management Consoles (HMC) is network-connected, use SSL encryption techniques, through digital certificates to provide message privacy, message integrity and mutual authentication b...
    Rule Medium Severity
  • SRG-OS-000329-GPOS-00128

    Group
  • SRG-OS-000069-GPOS-00037

    Group
  • The password values must be set to meet the requirements in accordance with DODI 8500.2 for DoD information systems processing sensitive information and above, and CJCSI 6510.01E (INFORMATION ASSURANCE [IA] AND COMPUTER NETWORK DEFENSE [CND]).

    In accordance with DODI 8500.2 for DOD information systems processing sensitive information and above and CJCSI 6510.01E (INFORMATION ASSURANCE [IA] AND COMPUTER NETWORK DEFENSE [CND]). The followi...
    Rule Medium Severity
  • SRG-OS-000029-GPOS-00010

    Group
  • The terminal or workstation must lock out after a maximum of 15 minutes of inactivity, requiring the account password to resume.

    If the system, workstation, or terminal does not lock the session after more than15 minutes of inactivity, requiring a password to resume operations, the system or individual data could be compromi...
    Rule Medium Severity
  • SRG-OS-000023-GPOS-00006

    Group
  • The Department of Defense (DoD) logon banner must be displayed prior to any login attempt.

    Failure to display the required DoD logon banner prior to a login attempt may void legal proceedings resulting from unauthorized access to system resources and may leave the SA, IAO, IAM, and Insta...
    Rule Medium Severity
  • SRG-OS-000366-GPOS-00153

    Group
  • SRG-OS-000342-GPOS-00133

    Group
  • SRG-OS-000480-GPOS-00227

    Group
  • SRG-OS-000324-GPOS-00125

    Group
  • SRG-OS-000480-GPOS-00227

    Group
  • SRG-OS-000480-GPOS-00227

    Group
  • The manufacturer’s default passwords must be changed for all Hardware Management Console (HMC) Management software.

    The changing of passwords from the HMC default values, blocks malicious users with knowledge of these default passwords, from creating a denial of service or from reconfiguring the HMC topology le...
    Rule High Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules