STIGQter STIGQter: STIG Summary: IBM Hardware Management Console (HMC) STIG Version: 1 Release: 5 Benchmark Date: 20 Jan 2015:

Product engineering access to the Hardware Management Console must be disabled.

DISA Rule

SV-31558r2_rule

Vulnerability Number

V-25388

Group Title

HMC0210

Rule Version

HMC0210

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

The System Administrator or System Programmer will set the
Product Engineering Access control for product engineering or remote product engineering to a disabled status.

This can be checked under the classic style user interface; this task is found under the Hardware Management Console Settings console action.
Open the Customize Product Engineering Access task. The Customize Product Engineering Access window is displayed.
Select the appropriate accesses for product engineering or remote product engineering. (Both should be disabled)
Click OK to save the changes and exit the task.

Check Contents

Have the System Administrator or System Programmer validate that IBM Product Engineering access to the Hardware Management Console is disabled.

This can be checked under the classic style user interface; this task is found under the Hardware Management Console Settings console action.
Open the Customize Product Engineering Access task. The Customize Product Engineering Access window is displayed.
Select the appropriate accesses for product engineering or remote product engineering. (Both should be disabled.)
Click OK to save the changes and exit the task.

If access to the Customize Product Engineering Access is not disabled, than this is a finding.

Vulnerability Number

V-25388

Documentable

False

Rule Version

HMC0210

Severity Override Guidance

Have the System Administrator or System Programmer validate that IBM Product Engineering access to the Hardware Management Console is disabled.

This can be checked under the classic style user interface; this task is found under the Hardware Management Console Settings console action.
Open the Customize Product Engineering Access task. The Customize Product Engineering Access window is displayed.
Select the appropriate accesses for product engineering or remote product engineering. (Both should be disabled.)
Click OK to save the changes and exit the task.

If access to the Customize Product Engineering Access is not disabled, than this is a finding.

Check Content Reference

M

Responsibility

Systems Programmer

Target Key

1891

Comments