The SAN fabric zoning lists are not based on a policy of Deny-by-Default with blocks on all services and protocols not required on the given port or by the site.
An XCCDF Rule
Description
By using the Deny-by-Default based policy, any service or protocol not required by a port and overlooked in the zoning list will be denied access. If Deny-by-Default based policy was not used any overlooked service or protocol not required by a port could have access to sensitive data compromising that data. The IAO/NSO will ensure that SAN fabric zoning lists are based on a policy of Deny-by-Default with blocks on all services and protocols not required on the given port or by the site.
Property | Value |
---|---|
Responsibility | Information Assurance Officer |
IA Controls | DCBP-1 |
Potential Impact | Changing to a policy based on Deny-by-Default can cause overlooked services or protocols required by a port to be denied access to data they need. |
- ID
- SV-6793r1_rule
- Version
- SAN04.019.00
- Severity
- High
- Updated
Remediation Templates
A Manual Procedure
Develop a plan to identify all services and protocols needed by each port in the SAN, modify the routing lists to enforce a Deny-by-Default policy and allow only the identified services and protocols on each port that requires them. Obtain CM approval for the plan and implement the plan.