[ Applies to ] StorageGuard / Hitachi Content Platform / Object Storage
This article lists the recommended baseline checks for Hitachi Content Platform. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
Hitachi Content Platform (HCP) is an object storage platform deployed as physical or virtual appliances. HCP for Cloud Scale extends it with a scale-out S3 architecture.
Why hardening Hitachi Content Platform matters
HCP often stores archives, backups and compliance data that must remain intact. Tenant and namespace access controls, encryption, retention and authentication settings protect that data from unauthorized access and tampering.
Recommended baseline checks
The baseline below contains 228 checks, listed alphabetically.
| ID | Configuration check | Component |
|---|---|---|
| SG-M2738T133V01 | 3DES Ciphers status | HCP |
| SG-C0288T133V01 | A-time synchronization | HCP |
| SG-C0196T133V01 | Access control list status | HCP |
| SG-C0393T133V01 | Account lockout threshold | HCP |
| SG-M1124T133V01 | ACL for Search Console for the default tenant | HCP |
| SG-M5187T133V01 | Active Directory status | HCP |
| SG-M2894T133V01 | Active Directory with SSL | HCP |
| SG-M3626T133V01 | Anonymous user access enabled | HCP |
| SG-C0127T133V01 | Anonymous users required permissions | HCP |
| SG-M9292T133V01 | Approved admin user/group | HCP |
| SG-M2257T133V01 | Approved KMIP servers | HCP |
| SG-F4629T133V01 | Approved role mapping (user groups) | HCP |
| SG-F2855T133V01 | Approved/Required External KMIP Server | HCP |
| SG-F5618T133V01 | Approved/Required Instance DNS Server | HCP |
| SG-F8605T133V01 | Approved/Required Instance NTP server | HCP |
| SG-F5041T133V01 | Approved/Required SMTP server | HCP |
| SG-F9154T133V01 | Approved/Required Syslog server | HCP |
| SG-C0215T133V01 | Authenticated users min permission properties | HCP |
| SG-C0216T133V01 | Authenticated users required permissions | HCP |
| SG-M6084T133V01 | Automatically fail over | HCP |
| SG-F9831T133V01 | Bucket level encryption | HCP |
| SG-C0029T238V01 | Centralized log server | HCP for Cloud Scale |
| SG-C0029T133V01 | Centralized log server - Tenant | HCP |
| SG-F8359T133V01 | Certificate expiration (client) | HCP |
| SG-M9043T133V01 | Certificate expiry | HCP |
| SG-M4672T133V01 | CIFS Authentication | HCP |
| SG-M1943T133V01 | CIFS Enabled | HCP |
| SG-M6507T133V01 | CIFS required allow list | HCP |
| SG-M8288T133V01 | CIFS required deny list | HCP |
| SG-C0187T133V01 | CIFS SMB allowed access list | HCP |
| SG-C0128T133V01 | CIFS SMB anonymous user access restriction | HCP |
| SG-C0188T133V01 | CIFS SMB configured ACL | HCP |
| SG-C0189T133V01 | CIFS SMB denied access list | HCP |
| SG-C0150T133V01 | CIFS SMB enabled (Namespace) | HCP |
| SG-M8335T133V01 | CLI tool conf file | HCP |
| SG-M4825T133V01 | CLI tool installations list | HCP |
| SG-M6048T133V01 | Compress objects criteria | HCP |
| SG-M4179T133V01 | Compress objects Exclusion criteria | HCP |
| SG-C0198T133V01 | Console security allowed access list | HCP |
| SG-C0199T133V01 | Console security configured access list | HCP |
| SG-C0200T133V01 | Console security denied access list | HCP |
| SG-M7412T133V01 | Console Security required allow list | HCP |
| SG-M5915T133V01 | Console Security required deny list | HCP |
| SG-M4414T133V01 | Content Verification service | HCP |
| SG-M6665T133V01 | CORS Allowed Origins configuration | HCP |
| SG-C0369T238V01 | Cross origin resource sharing (CORS) status | HCP for Cloud Scale |
| SG-F5119T133V01 | Data at REST encryption license (DARE) | HCP |
| SG-C0065T238V01 | Data at-rest encryption | HCP for Cloud Scale |
| SG-F9895T133V01 | Data in-flight encryption (application) | HCP |
| SG-F6129T133V01 | Data in-flight encryption (External Key Server) | HCP |
| SG-F7019T133V01 | Data in-flight encryption (IdP server) - LDAP SSL /AD SSL | HCP |
| SG-F7576T133V01 | Data in-flight encryption (managed storage component) | HCP |
| SG-F8370T133V01 | Data in-flight encryption (Management API) | HCP |
| SG-F5461T133V01 | Data in-flight encryption (Object Management GUI) | HCP |
| SG-F1750T133V01 | Data in-flight encryption (S3) | HCP |
| SG-F2911T133V01 | Data in-flight encryption (SMTP server) | HCP |
| SG-F8502T133V01 | Data in-flight encryption (System GUI) | HCP |
| SG-C0080T238V01 | Data in-transit encryption | HCP for Cloud Scale |
| SG-C0097T133V02 | Data retention mode | HCP |
| SG-C0097T133V01 | Data retention mode - Namespace | HCP |
| SG-C0098T133V01 | Data retention period | HCP |
| SG-M7167T133V01 | Default data retention mode | HCP |
| SG-C0086T133V01 | Default namespace hashing algorithm | HCP |
| SG-C0301T133V01 | Default namespace replication status | HCP |
| SG-C0250T133V01 | Default namespace versioning settings | HCP |
| SG-C0099T133V01 | Default retention | HCP |
| SG-C0371T133V01 | Default shredding setting | HCP |
| SG-C0376T133V01 | Default UID GID (NFS) | HCP |
| SG-C0174T133V01 | Delete operations logging | HCP |
| SG-C0137T133V01 | Disable inactive users | HCP |
| SG-M2814T133V01 | DNS configuration | HCP |
| SG-M1008T133V01 | DNS TSIG | HCP |
| SG-F5880T133V01 | Email notification recipients | HCP |
| SG-F7350T133V01 | Email notification rules | HCP |
| SG-M8095T133V01 | Email recipients | HCP |
| SG-M9251T133V01 | Enable scheduled updates to HDvM | HCP |
| SG-C0602T133V01 | End of extended support | HCP |
| SG-C0602T238V01 | End of extended support | HCP for Cloud Scale |
| SG-C0600T133V01 | End of support | HCP |
| SG-C0600T238V01 | End of support | HCP for Cloud Scale |
| SG-M1725T133V01 | Enterprise mode | HCP |
| SG-M7162T133V01 | Erasure coding | HCP |
| SG-M9581T133V01 | Exclusive support access credentials | HCP |
| SG-C0162T238V01 | Expired SSL certificate | HCP for Cloud Scale |
| SG-F1605T133V01 | External KMIP Server | HCP |
| SG-C0602T133V02 | Future end of extended support | HCP |
| SG-C0602T238V02 | Future end of extended support | HCP for Cloud Scale |
| SG-C0600T133V02 | Future end of support | HCP |
| SG-C0600T238V02 | Future end of support | HCP for Cloud Scale |
| SG-M9693T133V01 | HCP Anywhere console ACL | HCP |
| SG-M1388T133V01 | HCP Anywhere default password | HCP |
| SG-M1726T133V01 | HCP Anywhere HTTP SSL | HCP |
| SG-M5780T133V01 | HCP Anywhere idle session timeout | HCP |
| SG-M6281T133V01 | HCP Anywhere login message | HCP |
| SG-M4951T133V01 | HCP Anywhere max password age | HCP |
| SG-M5844T133V01 | HCP Anywhere minimum password length | HCP |
| SG-M6285T133V01 | HCP default password | HCP |
| SG-M1239T133V01 | HCP edge awservice.conf | HCP |
| SG-M4953T133V01 | HCP FTP check | HCP |
| SG-M9738T133V01 | HCP Gateway Console Admin default password | HCP |
| SG-M1268T133V01 | HCP Gateway default password | HCP |
| SG-M4854T133V01 | HCP Gateway Linux OS default password | HCP |
| SG-M2849T133V01 | HCP Gateway sam.properties | HCP |
| SG-M9057T133V01 | HCP telnet check | HCP |
| SG-M3212T133V01 | HDvM port | HCP |
| SG-M8779T133V01 | HS3 status | HCP |
| SG-C0129T133V01 | HSwift authentication | HCP |
| SG-C0152T133V01 | HSwift status | HCP |
| SG-C0036T133V01 | HTTP AD SSO enabled | HCP |
| SG-C0202T133V01 | HTTP allowed access list | HCP |
| SG-C0203T133V01 | HTTP configured access list | HCP |
| SG-C0204T133V01 | HTTP denied access list | HCP |
| SG-M3797T133V01 | HTTP required allow list | HCP |
| SG-M4876T133V01 | HTTP required deny list | HCP |
| SG-C0381T133V02 | HTTP service status | HCP |
| SG-M5040T133V01 | HTTP status | HCP |
| SG-C0209T133V01 | Idle session timeout | HCP |
| SG-C0209T238V01 | Idle session timeout | HCP for Cloud Scale |
| SG-F2542T133V01 | IdP server configuration | HCP |
| SG-M8300T133V01 | Inactivity timeout | HCP |
| SG-F3339T133V01 | Instance DNS Server | HCP |
| SG-F6205T133V01 | Instance DNS Server Redundancy | HCP |
| SG-F6537T133V01 | Instance NTP server configuration | HCP |
| SG-F5442T133V01 | Instance NTP server redundancy | HCP |
| SG-F4800T133V01 | Instance redundancy | HCP |
| SG-F5223T133V01 | Instance-side disk encryption | HCP |
| SG-M5475T133V01 | KMIP Server configuration | HCP |
| SG-C0047T238V01 | KMIP status | HCP for Cloud Scale |
| SG-C0427T133V01 | Login banner message | HCP |
| SG-C0427T238V01 | Login banner message | HCP for Cloud Scale |
| SG-C0427T238V02 | Login banner message - Admin | HCP for Cloud Scale |
| SG-C0427T238V03 | Login banner message - Monitor | HCP for Cloud Scale |
| SG-C0427T238V04 | Login banner message - Search | HCP for Cloud Scale |
| SG-C0426T133V01 | Login banner status | HCP |
| SG-C0426T238V01 | Login banner status | HCP for Cloud Scale |
| SG-C0426T238V02 | Login banner status - Admin | HCP for Cloud Scale |
| SG-C0426T238V03 | Login banner status - Monitor | HCP for Cloud Scale |
| SG-C0426T238V04 | Login banner status - Search | HCP for Cloud Scale |
| SG-M3848T133V01 | Login warning banner | HCP |
| SG-M7010T133V01 | Management and data network separation (VLAN tagging) | HCP |
| SG-M1957T133V01 | Management API ACL | HCP |
| SG-C0234T133V01 | Maximum password age | HCP |
| SG-C0264T133V01 | Minimum password length | HCP |
| SG-C0088T133V01 | Namespace hashing algorithm | HCP |
| SG-M1864T133V01 | NFS ACL configured | HCP |
| SG-C0153T133V01 | NFS enabled | HCP |
| SG-C0191T133V01 | NFS export ACL status | HCP |
| SG-M5004T133V01 | NFS required allow list | HCP |
| SG-M2460T133V01 | Node list | HCP |
| SG-M3274T133V01 | NTLMv2 authentication | HCP |
| SG-M6197T133V01 | NTP configuration | HCP |
| SG-M9062T133V01 | NTP server redundancy | HCP |
| SG-C0291T133V01 | Object custom metadata changes | HCP |
| SG-C0292T133V01 | Object permission hardening | HCP |
| SG-C0251T133V01 | Object versioning protection | HCP |
| SG-M3723T133V01 | Permissions for anonymous users | HCP |
| SG-M5760T133V01 | Permissions for authenticated users | HCP |
| SG-M2770T133V01 | Ping status | HCP |
| SG-M1168T133V01 | Protection service status | HCP |
| SG-M7079T133V01 | Public Link endpoints | HCP |
| SG-M5268T133V01 | PVLAN status | HCP |
| SG-M4052T133V01 | RADIUS server configuration | HCP |
| SG-M2997T133V01 | Replication link configuration | HCP |
| SG-C0091T133V01 | Replication link encryption | HCP |
| SG-M3847T133V01 | Replication mode | HCP |
| SG-M4046T133V01 | Required KMIP servers | HCP |
| SG-M6778T133V01 | Required RADIUS Server | HCP |
| SG-C0132T133V01 | REST API authentication | HCP |
| SG-C0144T133V01 | REST API is enabled - Namespace | HCP |
| SG-M9351T133V01 | REST authentication | HCP |
| SG-M9034T133V01 | REST status | HCP |
| SG-M6379T133V01 | REST token timeout limit | HCP |
| SG-M8839T133V01 | Retain period for deletion records | HCP |
| SG-C0133T133V01 | S3 API authentication | HCP |
| SG-C0151T133V01 | S3 API status | HCP |
| SG-C0404T133V01 | Security email notification | HCP |
| SG-C0447T238V01 | Self-signed certificate | HCP for Cloud Scale |
| SG-M7420T133V01 | Server BIOS configuration | HCP |
| SG-M4742T133V01 | Shredding algorithm | HCP |
| SG-M7769T133V01 | SMBv1 status | HCP |
| SG-C0408T133V01 | SMTP allowed access list | HCP |
| SG-M4851T133V01 | SMTP authentication | HCP |
| SG-C0409T133V01 | SMTP configured access list | HCP |
| SG-C0410T133V01 | SMTP denied access list | HCP |
| SG-C0146T133V01 | SMTP enabled | HCP |
| SG-M3808T133V01 | SMTP required allow list | HCP |
| SG-M9047T133V01 | SMTP required deny list | HCP |
| SG-M2504T133V01 | SMTP security protocol | HCP |
| SG-F2364T133V01 | SMTP server configuration | HCP |
| SG-M4091T133V01 | SNMP - send security events | HCP |
| SG-M1819T133V01 | SNMP ACL | HCP |
| SG-M5053T133V01 | SNMP community string | HCP |
| SG-M7534T133V01 | SNMP manager | HCP |
| SG-M4755T133V01 | SNMP min level | HCP |
| SG-M6751T133V01 | SNMP Send compliance events | HCP |
| SG-M8952T133V01 | SNMP version | HCP |
| SG-M9011T133V01 | SNMP write/update status | HCP |
| SG-M1259T133V01 | SSH status | HCP |
| SG-M2271T133V01 | SSL renegotiation | HCP |
| SG-M9649T133V01 | Syslog - send security events | HCP |
| SG-M9247T133V01 | Syslog - shredded object messages | HCP |
| SG-M2655T133V01 | Syslog min level | HCP |
| SG-M4936T133V01 | Syslog Send compliance events | HCP |
| SG-M5771T133V01 | Syslog Send log messages for HTTP-based data access requests. | HCP |
| SG-M9375T133V01 | Syslog Send log messages for management API requests | HCP |
| SG-M9631T133V01 | Syslog server list | HCP |
| SG-M2175T133V01 | Systemwide permission mask | HCP |
| SG-M4342T133V01 | Target BMC firmware | HCP |
| SG-M6448T133V01 | Target HBA firmware | HCP |
| SG-M6724T133V01 | Target HCP Anywhere Edge release | HCP |
| SG-M8123T133V01 | Target HCP Gateway release | HCP |
| SG-M9592T133V01 | Target HCP version | HCP |
| SG-M4601T133V01 | Target RAID controller firmware | HCP |
| SG-C0227T133V01 | Tenant administration allowed | HCP |
| SG-C0043T133V01 | Tenant authentication services | HCP |
| SG-C0232T133V01 | Tenant local user authentication | HCP |
| SG-C0249T133V01 | Tenant management network separation | HCP |
| SG-C0305T133V01 | Tenant replication allowed | HCP |
| SG-C0107T133V01 | Tenant retention mode administration | HCP |
| SG-C0157T133V01 | Tenant SNMP status | HCP |
| SG-M3441T133V01 | Tenant syslog enabled | HCP |
| SG-M6049T133V01 | Tenant user authentication mode | HCP |
| SG-C0253T133V01 | Tenant versioning configuration enabled | HCP |
| SG-M5756T133V01 | TLS Level | HCP |
| SG-M4530T133V01 | Trusted certificate issuer | HCP |
| SG-C0448T238V01 | Trusted certificate-authority (CA) | HCP for Cloud Scale |
| SG-C0136T133V01 | WebDAV authentication | HCP |
| SG-C0158T133V01 | WebDAV status | HCP |
Related components
A complete baseline also covers the components that manage, connect to or protect Hitachi Content Platform. Review the configuration of:
- HCP nodes
- Hitachi Data Ingestor (HDI) and HCP Gateway
- HCP Anywhere and HCP Anywhere Edge
- HCP Data Migrator (HCP-DM) and HCP CLI tool
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.