STIGQter STIGQter: STIG Summary: HPE 3PAR StoreServ 3.2.x Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 28 Jul 2017:

The storage system must be operated at the latest maintenance update available from the vendor.

DISA Rule

SV-85079r1_rule

Vulnerability Number

V-70457

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

HP3P-32-001000

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The software update process must be performed by the vendor's support organization.

Contact the vendor's support organization to determine if an update is available.

Note: it is possible no update is currently available for the specific product model being evaluated. This is not an error.

If an update is available, the support organization will use this process to install the software.

Acquire the system update image on DVD media from the vendor's support organization.

Power on the Service Processor, and apply its software update first.

Perform an Attach operation between the Service Processor and the disk array. Then apply the software update to the 3PAR system.

Perform a Detach operation between the Service Processor and the disk array, and power off the Service Processor.

Check Contents

Determine when the last update occurred, by entering the following command:

cli% showpatch -hist

The output fields are
InstallTime Id Package Version

Examine the InstallTime of the last entry in the output.

If the last update occurred more than 3 months ago, verify on the vendor's website what the latest version is.

If the current installation is not at the latest release, this is a finding.

Vulnerability Number

V-70457

Documentable

False

Rule Version

HP3P-32-001000

Severity Override Guidance

Determine when the last update occurred, by entering the following command:

cli% showpatch -hist

The output fields are
InstallTime Id Package Version

Examine the InstallTime of the last entry in the output.

If the last update occurred more than 3 months ago, verify on the vendor's website what the latest version is.

If the current installation is not at the latest release, this is a finding.

Check Content Reference

M

Target Key

3013

Comments