Skip to content

III - Administrative Sensitive

Rules and Groups employed by this XCCDF Profile

  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • The Hardware Management Console must be located in a secure location.

    &lt;VulnDiscussion&gt;The Hardware Management Console is used to perform Initial Program Load (IPLs) and control the Processor Resource/System Mana...
    Rule High Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • Dial-out access from the Hardware Management Console Remote Support Facility (RSF) must be restricted to an authorized vendor site.

    &lt;VulnDiscussion&gt;Dial-out access from the Hardware Management Console could impact the integrity of the environment, by enabling the possible ...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • Dial-out access from the Hardware Management Console Remote Support Facility (RSF) must be disabled for all classified systems.

    &lt;VulnDiscussion&gt;This feature will not be activated for any classified systems. Allowing dial-out access from the Hardware Management Console ...
    Rule High Severity
  • SRG-OS-000324-GPOS-00125

    <GroupDescription></GroupDescription>
    Group
  • Access to the Hardware Management Console must be restricted to only authorized personnel.

    &lt;VulnDiscussion&gt;Access to the Hardware Management Console if not properly restricted to authorized personnel could lead to a bypass of securi...
    Rule Medium Severity
  • SRG-OS-000080-GPOS-00048

    <GroupDescription></GroupDescription>
    Group
  • Access to the Hardware Management Console (HMC) must be restricted by assigning users proper roles and responsibilities.

    &lt;VulnDiscussion&gt;Access to the HMC if not properly controlled and restricted by assigning users proper roles and responsibilities, could allow...
    Rule Medium Severity
  • SRG-OS-000324-GPOS-00125

    <GroupDescription></GroupDescription>
    Group
  • Automatic Call Answering to the Hardware Management Console must be disabled.

    &lt;VulnDiscussion&gt;Automatic Call Answering to the Hardware Management Console allows unrestricted access by unauthorized personnel and could le...
    Rule Medium Severity
  • SRG-OS-000062-GPOS-00031

    <GroupDescription></GroupDescription>
    Group
  • The Hardware Management Console Event log must be active.

    &lt;VulnDiscussion&gt;The Hardware Management Console controls the operation and availability of the Central Processor Complex (CPC). Failure to cr...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • The manufacturer’s default passwords must be changed for all Hardware Management Console (HMC) Management software.

    &lt;VulnDiscussion&gt;The changing of passwords from the HMC default values, blocks malicious users with knowledge of these default passwords, from...
    Rule High Severity
  • SRG-OS-000080-GPOS-00048

    <GroupDescription></GroupDescription>
    Group
  • Predefined task roles to the Hardware Management Console (HMC) must be specified to limit capabilities of individual users.

    &lt;VulnDiscussion&gt;Individual task roles with access to specific resources if not created and restricted, will allow unrestricted access to syst...
    Rule Medium Severity
  • SRG-OS-000104-GPOS-00051

    <GroupDescription></GroupDescription>
    Group
  • Individual user accounts with passwords must be maintained for the Hardware Management Console operating system and application.

    &lt;VulnDiscussion&gt;Without identification and authentication, unauthorized users could reconfigure the Hardware Management Console or disrupt it...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules