[ Applies to ] StorageGuard / HPE StoreOnce / Data Protection (Backup)
This article lists the recommended baseline checks for HPE StoreOnce. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
HPE StoreOnce is a deduplication backup appliance that supports disk-based backup, Catalyst, VTL and NAS targets, replication and cloud tiering.
Why hardening HPE StoreOnce matters
StoreOnce holds sensitive backup data that must be protected from unauthorized access and tampering. Access controls, encryption, secure protocols and monitoring safeguard backup data and keep recovery operations dependable.
Recommended baseline checks
The baseline below contains 78 checks, listed alphabetically.
| ID | Configuration check |
|---|---|
| SG-F4034T157V01 | Account lockout attempts and interval |
| SG-C0168T157V01 | Account lockout is enforced |
| SG-C0393T157V01 | Account lockout threshold |
| SG-F9914T157V01 | Approved AD group mapping (StoreOnce Enterprise Manager) |
| SG-F2864T157V01 | Approved AD groups |
| SG-F6534T157V01 | Approved certificate issuer |
| SG-C0449T157V01 | Approved DNS servers |
| SG-C0435T157V01 | Approved LDAP servers |
| SG-C0013T157V01 | Approved NTP servers |
| SG-F1171T157V01 | Central authentication (StoreOnce Enterprise Manager) |
| SG-C0029T157V01 | Centralized log server |
| SG-C0233T157V01 | Centralized log server redundancy |
| SG-C0411T157V01 | CHAP authentication mode - initiator |
| SG-C0411T157V02 | CHAP authentication mode - target |
| SG-C0128T157V01 | CIFS SMB anonymous user access restriction |
| SG-C0344T157V01 | CIFS SMB server signing |
| SG-F5489T157V01 | Configured with a secure remote support Proxy Server Protocol |
| SG-F2414T157V01 | Configured with IPfilter/firewall/client ACL |
| SG-C0065T157V03 | Data at-rest encryption - NAS shares |
| SG-C0065T157V01 | Data at-rest encryption - Stores |
| SG-C0065T157V04 | Data at-rest encryption - VTL |
| SG-F6110T157V01 | Default password (StoreOnce Enterprise Manager) |
| SG-C0056T157V01 | Default passwords |
| SG-C0243T157V01 | DNS server configuration |
| SG-C0060T157V01 | DNS server redundancy |
| SG-F8589T157V01 | Enterprise Manager database backup (StoreOnce Enterprise Manager) |
| SG-F3773T157V01 | External key manager |
| SG-F6594T157V01 | FIPS mode is enabled |
| SG-C0209T157V01 | Idle session timeout |
| SG-F7640T157V01 | iSCSI CHAP authentication |
| SG-F6441T157V01 | iSCSI iSNS usage |
| SG-F2478T157V01 | LDAP Encryption Mechanism (StoreOnce Enterprise Manager) |
| SG-C0039T157V01 | LDAP server configuration |
| SG-C0025T157V01 | LDAP server redundancy |
| SG-F8227T157V01 | Least permission on key directories and files (StoreOnce Enterprise Manager) |
| SG-F7937T157V01 | Least permission on key StoreOnce directories and files |
| SG-F9723T157V01 | License status |
| SG-F4370T157V01 | Login banner is configured correctly |
| SG-F6797T157V01 | Management isolation from production domain |
| SG-C0234T157V01 | Maximum password age |
| SG-C0392T157V01 | Minimum account lockout duration |
| SG-C0262T157V01 | Minimum password age |
| SG-C0270T157V01 | Minimum password digits |
| SG-C0264T157V01 | Minimum password length |
| SG-C0271T157V01 | Minimum password lowercase characters |
| SG-C0272T157V01 | Minimum password special characters |
| SG-C0273T157V01 | Minimum password uppercase characters |
| SG-C0194T157V01 | NFS browsable exports |
| SG-F1933T157V01 | NFS root squash |
| SG-C0121T157V01 | NFS versions enabled |
| SG-C0231T157V01 | Non-default local users |
| SG-C0171T157V01 | NTP server configuration |
| SG-C0432T157V01 | NTP server redundancy |
| SG-C0284T157V01 | Password history |
| SG-C0138T157V01 | Remote support status |
| SG-C0450T157V01 | Required DNS servers |
| SG-C0439T157V01 | Required LDAP servers |
| SG-C0014T157V01 | Required NTP servers |
| SG-C0375T157V01 | Secure erase is disabled - shares |
| SG-C0375T157V02 | Secure erase is disabled - stores |
| SG-F3215T157V01 | Secure ports are enabled for StoreOnce NAS NFS shares |
| SG-F7824T157V01 | Secure protocol used (HTTPS) (StoreOnce Enterprise Manager) |
| SG-F4833T157V01 | SMTP configured for backup monitoring (StoreOnce Enterprise Manager) |
| SG-F3261T157V01 | SNMP authentication hash algorithm |
| SG-C0123T157V01 | SNMP versions enabled |
| SG-C0422T157V05 | SNMPv3 privacy encryption algorithm |
| SG-C0419T157V01 | SNMPv3 user authentication protocol |
| SG-F4673T157V01 | Store Job Log Retention |
| SG-F8600T157V01 | Stores configured for Secure Connection |
| SG-C0306T157V01 | Syslog communication protocol |
| SG-F8363T157V01 | Target Firmware version |
| SG-F5979T157V01 | Target OS version |
| SG-F2677T157V01 | TLS version |
| SG-C0119T157V01 | Unapproved user groups |
| SG-F1846T157V01 | Using FIPS-compliant encryption algorithm |
| SG-F3314T157V01 | VTL zoning restricted to backup infrastructure |
| SG-C0299T157V01 | Write protection is enabled for NAS shares |
| SG-F2431T157V01 | Write-protected StoreOnce network configuration |
Related components
A complete baseline also covers the components that manage, connect to or protect HPE StoreOnce. Review the configuration of:
- StoreOnce Enterprise Manager (SEM)
- Backup applications using Catalyst
- External key managers
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.