IBM Hardware Management Console (HMC) Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
SRG-OS-000077-GPOS-00045
Group -
The PASSWORD History Count value must be set to 10 or greater.
History Count specifies the number of previous passwords saved for each USERID and compares it with an intended new password. If there is a match with one of the previous passwords, or with the cur...Rule Medium Severity -
SRG-OS-000076-GPOS-00044
Group -
The PASSWORD expiration day(s) value must be set to equal or less then 60 days.
Expiration Day(s) specifies the maximum number of days that each user's password is valid. When a user logs on to the Hardware Management Console it compares the system password interval value spec...Rule Medium Severity -
SRG-OS-000021-GPOS-00005
Group -
A private web server must subscribe to certificates, issued from any DOD-authorized Certificate Authority (CA), as an access control mechanism for web users.
If the Hardware Management Consoles (HMC) is network-connected, use SSL encryption techniques, through digital certificates to provide message privacy, message integrity and mutual authentication b...Rule Medium Severity -
SRG-OS-000329-GPOS-00128
Group -
SRG-OS-000069-GPOS-00037
Group -
The password values must be set to meet the requirements in accordance with DODI 8500.2 for DoD information systems processing sensitive information and above, and CJCSI 6510.01E (INFORMATION ASSURANCE [IA] AND COMPUTER NETWORK DEFENSE [CND]).
In accordance with DODI 8500.2 for DOD information systems processing sensitive information and above and CJCSI 6510.01E (INFORMATION ASSURANCE [IA] AND COMPUTER NETWORK DEFENSE [CND]). The followi...Rule Medium Severity -
SRG-OS-000029-GPOS-00010
Group -
The terminal or workstation must lock out after a maximum of 15 minutes of inactivity, requiring the account password to resume.
If the system, workstation, or terminal does not lock the session after more than15 minutes of inactivity, requiring a password to resume operations, the system or individual data could be compromi...Rule Medium Severity -
SRG-OS-000023-GPOS-00006
Group -
The Department of Defense (DoD) logon banner must be displayed prior to any login attempt.
Failure to display the required DoD logon banner prior to a login attempt may void legal proceedings resulting from unauthorized access to system resources and may leave the SA, IAO, IAM, and Insta...Rule Medium Severity -
SRG-OS-000366-GPOS-00153
Group -
SRG-OS-000342-GPOS-00133
Group -
SRG-OS-000480-GPOS-00227
Group -
SRG-OS-000324-GPOS-00125
Group -
SRG-OS-000480-GPOS-00227
Group -
SRG-OS-000480-GPOS-00227
Group -
The manufacturer’s default passwords must be changed for all Hardware Management Console (HMC) Management software.
The changing of passwords from the HMC default values, blocks malicious users with knowledge of these default passwords, from creating a denial of service or from reconfiguring the HMC topology le...Rule High Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.