[ Applies to ] StorageGuard / Rubrik CDM / Data Protection (Backup)
This article lists the recommended baseline checks for Rubrik CDM. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
Rubrik Cloud Data Management (CDM) is a data management platform for backup, disaster recovery, archival, compliance and copy data management.
Why hardening Rubrik CDM matters
Rubrik clusters hold recovery copies that attackers try to destroy before deploying ransomware. Strong authentication, quorum authorization, secure protocols and network restrictions keep those copies safe.
Recommended baseline checks
The baseline below contains 142 checks, listed alphabetically.
| ID | Configuration check |
|---|---|
| SG-C0207T205V01 | Absolute session timeout - Web session |
| SG-C0393T205V01 | Account lockout threshold |
| SG-M1837T205V01 | API authentication method |
| SG-M9771T205V01 | Approved Admin user/group |
| SG-C0165T205V01 | Authorization policy status |
| SG-C0029T205V01 | Centralized log server |
| SG-C0233T205V01 | Centralized log server redundancy |
| SG-M8649T205V01 | Certificate algorithm |
| SG-M6441T205V01 | Certificate expiry dates |
| SG-M7266T205V01 | Client pattern for managed volumes |
| SG-C0369T205V01 | Cross origin resource sharing (CORS) status |
| SG-C0065T205V01 | Data at-rest encryption |
| SG-M1310T205V01 | Data in Transit encryption |
| SG-M8491T205V01 | Data retention mode |
| SG-M4474T205V01 | Disk encryption |
| SG-C0243T205V01 | DNS server configuration |
| SG-C0060T205V01 | DNS server redundancy |
| SG-M1826T205V01 | DNS service status |
| SG-M4709T205V01 | Email Alerts |
| SG-M3761T205V01 | Emergency account |
| SG-M5333T205V01 | Encryption cipher type |
| SG-C0074T205V01 | Encryption key rotation status |
| SG-M9862T205V01 | Encryption status |
| SG-C0600T205V01 | End of support |
| SG-C0175T205V01 | Event types enabled for audit logging |
| SG-M2725T205V01 | Exclude important file types from search results |
| SG-M3580T205V01 | Federated Login disabled |
| SG-M3129T205V01 | File share IP access list |
| SG-C0177T205V01 | FIPS mode status - data In-flight encryption |
| SG-M3604T205V01 | FTP access |
| SG-C0600T205V02 | Future end of support |
| SG-M6198T205V01 | Hardware encryption disabled |
| SG-M1737T205V01 | HTTP access |
| SG-M8341T205V01 | Identity Provider redundancy |
| SG-M3322T205V01 | Identity provider Status |
| SG-C0209T205V01 | Idle session timeout |
| SG-C0130T205V01 | Internet based cluster functions proxy status |
| SG-M4087T205V01 | IP access list |
| SG-M1329T205V01 | IPMI ADMIN disabled |
| SG-M7608T205V01 | IPMI default password |
| SG-C0360T205V01 | IPMI secure configuration |
| SG-M1129T205V01 | IPMI security |
| SG-M4154T205V01 | IPMI self-signed certificates |
| SG-M9140T205V01 | IPMI SMC RAKP enabled |
| SG-M5076T205V01 | IPMI status |
| SG-M5937T205V01 | IPMI virtual media port disabled |
| SG-M2154T205V01 | IPv6 status |
| SG-M6514T205V01 | KEK rotation |
| SG-M3099T205V01 | Key Recovery disabled |
| SG-M2699T205V01 | Key Rotation disabled |
| SG-M9649T205V01 | KMIP client authentication mode |
| SG-M6323T205V01 | KMIP server configuration |
| SG-M5831T205V01 | KMIP status |
| SG-M2429T205V01 | KMS Client Password |
| SG-C0049T205V01 | KMS server configuration |
| SG-C0052T205V01 | KMS server redundancy |
| SG-M6054T205V01 | LDAP server configuration |
| SG-C0025T205V01 | LDAP server redundancy |
| SG-M1335T205V01 | LDAP SSL |
| SG-M5870T205V01 | Local retention lock limit |
| SG-C0101T205V01 | Local SLA domain retention lock status |
| SG-M9404T205V01 | Log Frequency status |
| SG-C0427T205V01 | Login banner message |
| SG-C0426T205V01 | Login banner status |
| SG-M3547T205V01 | Management and Data network separation |
| SG-M4765T205V01 | Max retention lock |
| SG-M9595T205V01 | Max web sessions per user |
| SG-F8809T205V01 | MFA persistence setting |
| SG-C0392T205V01 | Minimum account lockout duration |
| SG-C0270T205V01 | Minimum password digits |
| SG-C0264T205V01 | Minimum password length |
| SG-M4673T205V01 | Minimum password lowercase |
| SG-C0271T205V01 | Minimum password lowercase characters |
| SG-C0272T205V01 | Minimum password special characters |
| SG-M8255T205V01 | Minimum password uppercase |
| SG-C0273T205V01 | Minimum password uppercase characters |
| SG-M3605T205V01 | Multi Factor Authentication/RSA server |
| SG-M6108T205V01 | Multi Factor Authentication/TOTP |
| SG-C0239T205V01 | Multi-factor authentication - Two Step verification |
| SG-M1555T205V01 | NFS authentication |
| SG-M9201T205V01 | NFS kerberos configuration |
| SG-M9707T205V01 | Node connection via Proxy status |
| SG-M1123T205V01 | Non-default local user accounts |
| SG-M3122T205V01 | Notification policies |
| SG-C0171T205V01 | NTP server configuration |
| SG-C0432T205V01 | NTP server redundancy |
| SG-M4099T205V01 | NTP server secure connection status |
| SG-M8938T205V01 | NTP service status |
| SG-M8378T205V01 | OS version check |
| SG-M1479T205V01 | Password based encryption at-REST disabled |
| SG-C0284T205V01 | Password history |
| SG-M1470T205V01 | Password rules status |
| SG-M5077T205V01 | Periodic checks |
| SG-M8493T205V01 | Quorum authorization |
| SG-F9522T205V01 | Quorum authorization (dual authorization) |
| SG-M5825T205V01 | Remote replication |
| SG-M7736T205V01 | Replication encryption |
| SG-M2332T205V01 | REST access |
| SG-M3268T205V01 | Retention lock enabled |
| SG-M3850T205V01 | Reuse of past passwords |
| SG-M1964T205V01 | SAP Hana SSL connection Trust store status |
| SG-C0008T205V01 | Secure NTP status |
| SG-M7180T205V01 | Secure SMB |
| SG-F2876T205V01 | Secure SMB enforcement |
| SG-M2936T205V01 | Session timeout |
| SG-M2182T205V01 | Shared accounts |
| SG-M9977T205V01 | SLA domain status |
| SG-C0134T205V01 | SMB domain authentication status |
| SG-C0364T205V01 | SMTP security |
| SG-C0395T205V01 | SMTP server configuration |
| SG-M1154T205V01 | SNMP Agent Status |
| SG-C0058T205V01 | SNMP community default string |
| SG-M6411T205V01 | SNMP message privacy |
| SG-C0155T205V01 | SNMP service disabled |
| SG-M8525T205V01 | SNMP status |
| SG-C0123T205V01 | SNMP versions enabled |
| SG-F1152T205V01 | SNMPv3 user configuration |
| SG-C0346T205V01 | SNMPv3 user security |
| SG-M8875T205V01 | Software Encryption |
| SG-M4320T205V01 | SSH access |
| SG-M8057T205V01 | SSH status |
| SG-M2947T205V01 | SSO Disabled |
| SG-C0279T205V01 | Strong passwords validation for local accounts |
| SG-M2007T205V01 | Support data movement status |
| SG-M6222T205V01 | Support tunnel absolute timeout |
| SG-M7367T205V01 | Support tunnel enabled on current node |
| SG-M9016T205V01 | Support tunnel inactivity timeout |
| SG-M2573T205V01 | Support tunnel service |
| SG-C0229T205V01 | Support tunnel status |
| SG-C0306T205V01 | Syslog communication protocol |
| SG-M4517T205V01 | Syslog protocol |
| SG-M8827T205V01 | Target BIOS version |
| SG-M5331T205V01 | Target BMC version |
| SG-M2006T205V01 | Target Rubrik CDM version |
| SG-M5165T205V01 | TCP SACK status |
| SG-M6396T205V01 | Telnet access |
| SG-M7333T205V01 | Time-based one-time password status |
| SG-M6032T205V01 | TLS level |
| SG-M7803T205V01 | Trusted Certificate Issuer |
| SG-M1363T205V01 | Unique user accounts |
| SG-M1295T205V01 | UTC time |
| SG-C0297T205V01 | WORM SLA domain status |
Related components
A complete baseline also covers the components that manage, connect to or protect Rubrik CDM. Review the configuration of:
- Rubrik Security Cloud (formerly Polaris)
- Rubrik Edge and Cloud Cluster
- Archival storage locations
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.