Skip to content

III - Administrative Sensitive

Rules and Groups employed by this XCCDF Profile

  • The manufacturer’s default passwords have not been changed for all SAN management software.

    <VulnDiscussion>The changing of passwords from the default value blocks malicious users with knowledge of the default passwords for the manuf...
    Rule High Severity
  • SAN Fabric Zoning List Deny-By-Default

    <GroupDescription></GroupDescription>
    Group
  • The SAN fabric zoning lists are not based on a policy of Deny-by-Default with blocks on all services and protocols not required on the given port or by the site.

    &lt;VulnDiscussion&gt;By using the Deny-by-Default based policy, any service or protocol not required by a port and overlooked in the zoning list w...
    Rule High Severity
  • Logging Failed Access to Port, Protocols, Services

    <GroupDescription></GroupDescription>
    Group
  • Attempts to access ports, protocols, or services that are denied are not logged..

    &lt;VulnDiscussion&gt;Logging or auditing of failed access attempts is a necessary component for the forensic investigation of security incidents. ...
    Rule Low Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules