[ Applies to ] StorageGuard / Hitachi VSP (block) / Block & SAN Storage
This article lists the recommended baseline checks for Hitachi VSP (block). Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
Hitachi Virtual Storage Platform (VSP) is a high-end enterprise block storage platform built for performance, scalability and resiliency. It provides predictable SAN storage for databases, virtualization platforms and core business applications, with high availability and robust replication.
Why hardening Hitachi VSP (block) matters
VSP systems commonly store highly sensitive, business-critical data such as transactional databases and regulated information. Role-based access, encryption at rest and in transit, immutable snapshots and comprehensive auditing protect that data, because any breach or disruption directly affects the applications running on it.
Recommended baseline checks
The baseline below contains 69 checks, listed alphabetically.
| ID | Configuration check | Component |
|---|---|---|
| SG-C0393T139V02 | Account lockout threshold | Ops Center |
| SG-C0214T151V01 | Admin authority level | VSP |
| SG-C0163T139V01 | Approved AD domain | Ops Center |
| SG-C0437T139V01 | Approved identity provider servers - AD FS | Ops Center |
| SG-C0434T139V01 | Approved Kerberos realm | Ops Center |
| SG-C0435T139V01 | Approved LDAP servers | Ops Center |
| SG-F8393T151V01 | Approved NTP servers | VSP |
| SG-F2210T151V01 | Approved OS release | VSP |
| SG-C0015T151V02 | Approved Syslog servers | VSP |
| SG-C0182T151V01 | Array security status | VSP |
| SG-C0001T151V01 | Audit logging status | VSP |
| SG-C0031T139V01 | Authentication server configuration | Ops Center |
| SG-C0029T151V02 | Centralized log server | VSP |
| SG-C0233T151V02 | Centralized log server redundancy | VSP |
| SG-C0411T151V01 | CHAP authentication mode | VSP |
| SG-C0007T151V01 | Command device authentication | VSP |
| SG-C0217T151V01 | Command device restriction | VSP |
| SG-C0218T151V01 | Command device security | VSP |
| SG-C0909T151V01 | Encryption key without backup | VSP |
| SG-C0600T151V01 | End of support | VSP |
| SG-C0162T151V01 | Expired SSL certificate | VSP |
| SG-C0600T151V02 | Future end of support | VSP |
| SG-C0359T151V01 | Host communication | VSP |
| SG-C0037T139V01 | Identity provider configuration (AD FS) | Ops Center |
| SG-C0209T139V01 | Idle session timeout | Ops Center |
| SG-F8697T151V01 | IPv6 status | VSP |
| SG-C0120T139V01 | LDAP incorrect role mapping | Ops Center |
| SG-C0039T139V01 | LDAP server configuration | Ops Center |
| SG-C0025T139V01 | LDAP server redundancy | Ops Center |
| SG-C0069T151V01 | Logical device encryption | VSP |
| SG-C0185T151V02 | Logical unit port security | VSP |
| SG-C0701T151V01 | Master key status | VSP |
| SG-C0270T139V02 | Minimum password digits | Ops Center |
| SG-C0264T139V02 | Minimum password length | Ops Center |
| SG-C0271T139V01 | Minimum password lowercase characters | Ops Center |
| SG-C0272T139V01 | Minimum password special characters | Ops Center |
| SG-C0273T139V02 | Minimum password uppercase characters | Ops Center |
| SG-F8244T151V01 | Non-default local admin user accounts | VSP |
| SG-C0231T254V01 | Non-default local users | Ops Center Administrator |
| SG-C0231T151V01 | Non-default local users | VSP |
| SG-F8612T151V01 | NTP server configuration | VSP |
| SG-F4335T151V01 | NTP server redundancy | VSP |
| SG-C0908T151V01 | NVMe namespace security disabled | VSP |
| SG-C0730T151V01 | Parity group encryption | VSP |
| SG-C0488T151V01 | Product license | VSP |
| SG-C0293T151V01 | Protected recovery copies | VSP |
| SG-F5181T151V01 | Required authentication servers | VSP |
| SG-F2015T151V01 | Required NTP servers | VSP |
| SG-C0910T151V01 | Resource group isolation | VSP |
| SG-C0447T151V01 | Self-signed certificate | VSP |
| SG-C0011T151V01 | SMTP authentication | VSP |
| SG-C0395T151V01 | SMTP server configuration | VSP |
| SG-C0058T151V01 | SNMP community default string | VSP |
| SG-C0338T151V03 | SNMP encryption status | VSP |
| SG-C0154T254V01 | SNMP manager configuration | Ops Center Administrator |
| SG-C0345T151V01 | SNMP request access control list | VSP |
| SG-C0155T151V01 | SNMP service disabled | VSP |
| SG-C0123T151V01 | SNMP versions enabled | VSP |
| SG-C0422T151V03 | SNMPv3 privacy encryption algorithm | VSP |
| SG-C0419T151V01 | SNMPv3 user authentication protocol | VSP |
| SG-C0346T151V01 | SNMPv3 user security | VSP |
| SG-C0907T151V01 | Storage encryption disabled | VSP |
| SG-C0306T151V02 | Syslog communication protocol | VSP |
| SG-C0089T151V03 | T10 protection information - FC ports | VSP |
| SG-C0089T151V01 | T10 protection information - PI Status | VSP |
| SG-C0089T151V02 | T10 protection information - Storage volumes | VSP |
| SG-F6471T151V01 | Telnet disabled | VSP |
| SG-C0119T254V01 | Unapproved user groups | Ops Center Administrator |
| SG-C0213T139V01 | Use of secure LDAP | Ops Center |
Related components
A complete baseline also covers the components that manage, connect to or protect Hitachi VSP (block). Review the configuration of:
- Hitachi Ops Center (Administrator, Analyzer, Automator, Protector)
- Storage Navigator and SVP
- Replication peers
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.