[ Applies to ] StorageGuard / Cohesity DataPlatform / Data Protection (Backup)
This article lists the recommended baseline checks for Cohesity DataPlatform. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
Cohesity DataPlatform is a hyperconverged, scale-out data management platform that consolidates backup, recovery, file services and archival across on-premises and cloud locations.
Why hardening Cohesity DataPlatform matters
Because DataPlatform holds an organization's recovery copies, it must be protected against deletion and tampering. Strong authentication, DataLock immutability, quorum approval, network allow lists and audit logging keep backups trustworthy.
Recommended baseline checks
The baseline below contains 163 checks, listed alphabetically.
| ID | Configuration check |
|---|---|
| SG-C0207T043V01 | Absolute session timeout |
| SG-F5203T043V01 | Access control list status (file shares) |
| SG-M2558T043V01 | Account lockout duration |
| SG-C0393T043V01 | Account lockout threshold |
| SG-M7691T043V01 | AD domain configuration (if used) |
| SG-M3064T043V01 | AD group mapping to role (if used) |
| SG-M3106T043V01 | Alert notification by email |
| SG-M7131T043V01 | Alerting status |
| SG-M7921T043V01 | All_squash settings |
| SG-M5725T043V01 | Allowed access protocols |
| SG-C0126T043V01 | Anonymous user access |
| SG-M2683T043V01 | Anonymous user access configuration |
| SG-M9075T043V01 | Antivirus scan enabled |
| SG-C0453T043V01 | Antivirus server redundancy |
| SG-C0454T043V01 | Antivirus status |
| SG-C0163T043V01 | Approved AD domain |
| SG-M5563T043V01 | Approved administrative users / group |
| SG-C0449T043V01 | Approved DNS servers |
| SG-C0044T043V01 | Approved KMS server |
| SG-C0435T043V01 | Approved LDAP servers |
| SG-C0013T043V01 | Approved NTP servers |
| SG-C0348T043V01 | Approved SNMP trap hosts |
| SG-C0015T043V01 | Approved Syslog servers |
| SG-M8138T043V01 | Approved/Required syslog servers |
| SG-C0331T043V01 | Audit log retention |
| SG-C0001T043V01 | Audit logging status |
| SG-C0031T043V01 | Authentication server configuration |
| SG-C0024T043V01 | Authentication server redundancy |
| SG-M1143T043V01 | Auto patch download |
| SG-M4426T043V01 | Backup alerts |
| SG-M8623T043V01 | Backup interval |
| SG-M3302T043V01 | Backup retention |
| SG-M5075T043V01 | Banner settings |
| SG-C0193T043V01 | Browsable file shares (NFS SMB) |
| SG-M2270T043V01 | Browsable shares |
| SG-F2712T043V01 | Central authentication for CIFS SMB file share access |
| SG-C0029T043V01 | Centralized log server |
| SG-C0233T043V01 | Centralized log server redundancy |
| SG-M8245T043V01 | Certificate-based authentication |
| SG-C0188T043V01 | CIFS SMB configured ACL - view permissions |
| SG-M2750T043V01 | Client NFS access |
| SG-M1547T043V01 | Client NFS All squash configuration |
| SG-M1064T043V01 | Client NFS root squash configuration |
| SG-M9928T043V01 | Cluster level encryption |
| SG-M1863T043V01 | Cohesity default administrative password |
| SG-M2461T043V01 | Cohesity default console password |
| SG-M7506T043V01 | Cohesity default support password |
| SG-M8421T043V01 | Cohesity version |
| SG-M8210T043V01 | Data lock policy |
| SG-C0097T043V01 | Data retention mode |
| SG-C0098T043V01 | Data retention period |
| SG-M4092T043V01 | DB log backup settings |
| SG-M2331T043V01 | Default local groups |
| SG-C0243T043V01 | DNS server configuration |
| SG-C0060T043V01 | DNS server redundancy |
| SG-M8463T043V01 | DNS service status |
| SG-C0245T043V01 | Domain name configuration |
| SG-M5082T043V01 | Dual authorization for system changes |
| SG-M4306T043V01 | Email notification rules |
| SG-M5248T043V01 | Email server configuration |
| SG-M4707T043V01 | Enable ACL Backups |
| SG-C0600T043V01 | End of support |
| SG-M9385T043V01 | Event types enabled for audit logging |
| SG-M2754T043V01 | External Application enabled |
| SG-M4577T043V01 | File share access rights |
| SG-C0325T043V01 | File share access rights - view permissions |
| SG-M4733T043V01 | File share client IP ACL |
| SG-C0326T043V01 | File share client IP ACL (view permissions) |
| SG-C0600T043V02 | Future end of support |
| SG-M5924T043V01 | Global allowlist |
| SG-M4896T043V01 | Hardening status |
| SG-C0068T043V01 | Hardware-based encryption status |
| SG-C0228T043V01 | Helios access level |
| SG-M8962T043V01 | Helios status |
| SG-M4414T043V01 | HTTP service status |
| SG-C0209T043V01 | Idle session timeout |
| SG-M7541T043V01 | IdP configuration (if used) |
| SG-M1660T043V01 | IPMI default password |
| SG-M4196T043V01 | KMIP status |
| SG-C0049T043V01 | KMS server configuration |
| SG-C0052T043V01 | KMS server redundancy |
| SG-C0039T043V01 | LDAP server configuration |
| SG-C0025T043V01 | LDAP server redundancy |
| SG-C0040T043V01 | LDAP service status |
| SG-M9989T043V01 | Linux default password |
| SG-F3339T043V01 | Local account sudo privileges |
| SG-C0427T043V01 | Login banner message |
| SG-C0426T043V01 | Login banner status |
| SG-C0468T043V01 | Maximum concurrent sessions |
| SG-C0234T043V01 | Maximum password age |
| SG-M6690T043V01 | MFA type |
| SG-C0392T043V01 | Minimum account lockout duration |
| SG-C0264T043V01 | Minimum password length |
| SG-C0282T043V01 | Minimum password string change |
| SG-C0239T043V01 | Multi-factor authentication |
| SG-C0191T043V01 | NFS export ACL status - view permissions |
| SG-C0377T043V01 | NFS root squash status - Client |
| SG-M5265T043V01 | NFS view permissions |
| SG-C0230T043V01 | Non-default local admin |
| SG-C0231T043V01 | Non-default local users |
| SG-M4137T043V01 | Non-vulnerable Cohesity version |
| SG-C0171T043V01 | NTP server configuration |
| SG-C0432T043V01 | NTP server redundancy |
| SG-M3030T043V01 | NTP service status |
| SG-C0274T043V01 | Password complexity |
| SG-C0284T043V01 | Password history |
| SG-M6564T043V01 | Password reuse policy |
| SG-M7248T043V01 | Ransomware (anomaly) alerts |
| SG-M9349T043V01 | Ransomware File Filtration |
| SG-C0456T043V01 | Ransomware protection policy |
| SG-M7756T043V01 | Remote access configuration |
| SG-C0138T043V01 | Remote support status |
| SG-C0091T043V01 | Replication link encryption |
| SG-C0450T043V01 | Required DNS servers |
| SG-C0164T043V01 | Required domain name |
| SG-C0349T043V01 | Required SNMP trap hosts |
| SG-C0016T043V01 | Required Syslog servers |
| SG-M2895T043V01 | Retention lock |
| SG-M6572T043V01 | Secure communication between Cohesity Clusters |
| SG-M3843T043V01 | Session limits |
| SG-M6633T043V01 | Share allowlist |
| SG-C0328T043V01 | SMB access based enumeration |
| SG-M9938T043V01 | SMB view permissions |
| SG-C0011T043V01 | SMTP authentication |
| SG-M3174T043V01 | SMTP encryption |
| SG-M3780T043V01 | SMTP recipients |
| SG-F9856T043V01 | SMTP recipients configured |
| SG-C0364T043V01 | SMTP security |
| SG-C0395T043V01 | SMTP server configuration |
| SG-M6056T043V01 | SNMP Agent Status |
| SG-M1456T043V01 | SNMP alerts level |
| SG-M1495T043V01 | SNMP authentication protocol |
| SG-C0058T043V01 | SNMP community default string |
| SG-M1182T043V01 | SNMP message privacy |
| SG-M5026T043V01 | SNMP privacy algorithm |
| SG-C0155T043V01 | SNMP service disabled |
| SG-C0347T043V01 | SNMP trap host configuration |
| SG-M5306T043V01 | SNMP user authentication |
| SG-C0123T043V01 | SNMP versions enabled |
| SG-C0422T043V01 | SNMPv3 privacy encryption algorithm |
| SG-C0351T043V01 | SNMPv3 read-only user |
| SG-C0419T043V01 | SNMPv3 user authentication protocol |
| SG-C0346T043V01 | SNMPv3 user security |
| SG-M8330T043V01 | SSH ciphers and hash algorithm strength |
| SG-C0180T043V01 | STIG mode |
| SG-M1267T043V01 | Storage domain encryption |
| SG-M5316T043V01 | Strong authentication method |
| SG-C0042T043V01 | Strong authentication type used |
| SG-M6903T043V01 | Support Channel settings |
| SG-M2716T043V01 | SYSLOG protocol |
| SG-C0019T043V01 | Target OS version |
| SG-M2045T043V01 | TLS level |
| SG-M8860T043V01 | Trusted certificate issuer |
| SG-C0116T043V01 | Unapproved admin users |
| SG-C0119T043V01 | Unapproved user groups |
| SG-C0213T043V01 | Use of secure LDAP |
| SG-M3261T043V01 | Use of self-signed certificates |
| SG-C0341T043V01 | User role configuration |
| SG-M7634T043V01 | Valid certificates used |
| SG-M9853T043V01 | View allow list |
| SG-C0460T043V01 | Vulnerability scanning |
| SG-C0260T043V01 | Weak cipher suites |
| SG-M4458T043V01 | Web SSL certificate |
Related components
A complete baseline also covers the components that manage, connect to or protect Cohesity DataPlatform. Review the configuration of:
- Cohesity SmartFiles
- Cohesity DataProtect and Helios
- Cisco UCS and other hardware platforms
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.