[ Applies to ] StorageGuard / Commvault / Data Protection (Backup)
This article lists the recommended baseline checks for Commvault. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
Commvault is an enterprise backup and recovery platform that protects applications, databases, virtual machines, endpoints and cloud workloads through a CommServe server, MediaAgents and Command Center.
Why hardening Commvault matters
Attackers increasingly target backup servers before launching ransomware. Hardening authentication, role-based access, encryption, WORM storage and network controls prevents backup data from being deleted, encrypted or exfiltrated.
Recommended baseline checks
The baseline below contains 178 checks, listed alphabetically.
| ID | Configuration check |
|---|---|
| SG-M7271T049V01 | Backup rule |
| SG-C0393T049V01 | Account lockout threshold |
| SG-M8482T049V01 | Active backup policy |
| SG-F3523T049V01 | Approved AD domain |
| SG-M7951T049V01 | Approved AD servers |
| SG-M5159T049V01 | Approved Admin users/groups |
| SG-M3400T049V01 | Approved DNS servers |
| SG-C0437T049V01 | Approved identity provider servers |
| SG-F2279T049V01 | Approved KMS server |
| SG-F9354T049V01 | Approved LDAP servers |
| SG-M9411T049V01 | Approved MediaAgent OS |
| SG-M2695T049V01 | Approved NTP servers |
| SG-C0406T049V01 | Approved SMTP server |
| SG-M2741T049V01 | Approved SNMP trap destination |
| SG-M7451T049V01 | Approved Syslog servers |
| SG-C0208T049V01 | Archive recovery idle periods |
| SG-C0331T049V01 | Audit log retention |
| SG-M9978T049V01 | Authenticated user permissions |
| SG-M5618T049V01 | Authentication code for new user |
| SG-C0031T049V01 | Authentication server configuration |
| SG-C0024T049V01 | Authentication server redundancy |
| SG-F5642T049V01 | Authorization policy status |
| SG-M1865T049V01 | Authorization workflow |
| SG-M6788T049V01 | Authorized Certificate issuer |
| SG-M9076T049V01 | AWS S3 Encryption |
| SG-M9399T049V01 | Backup security status |
| SG-C0029T049V01 | Centralized log server |
| SG-F5562T049V01 | Centralized log server redundancy |
| SG-M1896T049V01 | Change default SQL server instance name |
| SG-M2277T049V01 | Change the default MS-SQL service ports |
| SG-M5569T049V01 | Cleartext HTTP access |
| SG-C0536T049V01 | Client backup status |
| SG-C0412T049V01 | Client certificate encryption algorithm |
| SG-M6531T049V01 | Client certificate encryption status |
| SG-M2348T049V01 | Client encryption |
| SG-M2913T049V01 | Client encryption cipher type |
| SG-M6815T049V01 | Client encryption flag |
| SG-C0568T049V01 | Client encryption key length |
| SG-C0568T049V03 | Client encryption key length - Disk Pool |
| SG-C0568T049V02 | Client encryption key length - HyperScale Storage |
| SG-C0413T049V01 | Client private key encryption strength |
| SG-C0166T049V01 | Command approval is disabled |
| SG-M9574T049V01 | Commcell console / web console relocated |
| SG-M9998T049V01 | Commvault Air Gap |
| SG-M7416T049V01 | Commvault Retention Lock |
| SG-C0354T049V01 | Commvault SSL session status |
| SG-M5619T049V01 | Critical anomalous event reporting |
| SG-M1920T049V01 | Data at-REST encryption |
| SG-C0065T049V01 | Data at-rest encryption - Disk Pool |
| SG-C0065T049V02 | Data at-rest encryption - HyperScale Storage |
| SG-C0073T049V01 | Data encryption strength - Disk Pool |
| SG-C0073T049V02 | Data encryption strength - HyperScale Storage |
| SG-M1244T049V01 | Data in-transit encryption |
| SG-C0080T049V01 | Data in-transit encryption - Mandate encryption |
| SG-C0463T049V01 | Data loss prevention disabled |
| SG-F3530T049V01 | Data retention period |
| SG-M2492T049V01 | Data-Cube Configurations |
| SG-F9779T049V01 | Default passwords |
| SG-C0137T049V01 | Disable inactive users |
| SG-M7975T049V01 | Disable NETBIOS |
| SG-F3617T049V01 | DNS server configuration |
| SG-F9826T049V01 | DNS server redundancy |
| SG-M4873T049V01 | DR backup configuration |
| SG-C0600T049V01 | End of support |
| SG-C0416T049V01 | Enforce SHA256 digest for certificates |
| SG-C0388T049V01 | Enforce TLSv1.2 |
| SG-M6756T049V01 | Event types enabled for audit logging |
| SG-M9686T049V01 | Everyone group removed |
| SG-F6888T049V01 | Expired SSL certificate |
| SG-M9370T049V01 | External syslog server redundancy |
| SG-M1086T049V01 | File activity anomaly Alert |
| SG-C0600T049V02 | Future end of support |
| SG-M4101T049V01 | Hide the SQL instance |
| SG-M4979T049V01 | HTTP Proxy Authentication enabled |
| SG-F5522T049V01 | HTTP service status |
| SG-M5179T049V01 | Identity Provider redundancy |
| SG-C0209T049V01 | Idle session timeout |
| SG-C0237T049V01 | Idle session timeout - GUI |
| SG-C0455T049V01 | Infected file versions restore status |
| SG-M6602T049V01 | KMS encryption key length |
| SG-M6399T049V01 | KMS encryption type |
| SG-C0049T049V01 | KMS server configuration |
| SG-C0052T049V01 | KMS server redundancy |
| SG-C0039T049V01 | LDAP server configuration |
| SG-C0025T049V01 | LDAP server redundancy |
| SG-C0040T049V01 | LDAP service status |
| SG-M3146T049V01 | LDAP SSL status |
| SG-F2959T049V01 | Login banner status |
| SG-C0234T049V01 | Maximum password age |
| SG-M8619T049V01 | MediaAgent ports restricted |
| SG-C0392T049V01 | Minimum account lockout duration |
| SG-F1807T049V01 | Minimum password digits |
| SG-C0264T049V01 | Minimum password length |
| SG-F3339T049V01 | Minimum password lowercase characters |
| SG-F4156T049V01 | Minimum password special characters |
| SG-F4469T049V01 | Minimum password uppercase characters |
| SG-M6621T049V01 | Multi factor authentication disabled |
| SG-C0239T049V01 | Multi-factor authentication |
| SG-M6956T049V01 | Multi-Person Authorization feature |
| SG-C0377T049V01 | NFS root squash status |
| SG-C0230T049V01 | Non-default local admin |
| SG-C0231T049V01 | Non-default local users |
| SG-F7897T049V01 | NTP server configuration |
| SG-F1350T049V01 | NTP server redundancy |
| SG-F7365T049V01 | NTP service status |
| SG-M6401T049V01 | Null sessions disallowed |
| SG-M5446T049V01 | Number of disallowed past passwords |
| SG-M8511T049V01 | Offline / separated data copies |
| SG-C0274T049V01 | Password complexity |
| SG-C0284T049V01 | Password history |
| SG-M4903T049V01 | Password vault used |
| SG-M8632T049V01 | Private key encryption disabled |
| SG-M8562T049V01 | RADIUS server disabled |
| SG-M6960T049V01 | Ransomware monitoring policy |
| SG-M4852T049V01 | Ransomware Protection |
| SG-C0457T049V01 | Ransomware protection (Windows Media Agents) |
| SG-M7567T049V01 | Ransomware Protection feature disabled |
| SG-M6766T049V01 | Ransomware Protection for a Disk Library on an NFS Share |
| SG-M4188T049V01 | Rate of change alert |
| SG-M9227T049V01 | Rename SQL Server default sa account |
| SG-M4822T049V01 | Replication groups status |
| SG-F1788T049V01 | Replication link encryption |
| SG-C0441T049V01 | Required identity provider servers |
| SG-M2945T049V01 | Required Syslog servers |
| SG-M9218T049V01 | Restore SAP backup without ID enabled |
| SG-M4176T049V01 | Root Squash disabled |
| SG-M5633T049V01 | Secondary backup data encryption |
| SG-M6654T049V01 | Secure Communication between console and ComServe |
| SG-C0375T049V01 | Secure erase is disabled |
| SG-C0367T049V01 | Secure internal communication (Additional Setting) |
| SG-M7443T049V01 | Secure SSL Connection to Cassandra |
| SG-M2190T049V01 | Secure SSL Connection to MySQL |
| SG-M7310T049V01 | Secure syslog messaging (TLS) |
| SG-M7547T049V01 | Secure transport mode for VMware |
| SG-F4872T049V01 | Security officer account |
| SG-F7088T049V01 | Self-signed certificate |
| SG-M4901T049V01 | Self-signed certificate not used |
| SG-M8823T049V01 | SELinux enabled |
| SG-M8677T049V01 | Session grace attempts |
| SG-C0395T049V01 | SMTP server configuration |
| SG-C0295T049V01 | Snapshots status |
| SG-M8956T049V01 | SNMP authentication protocol |
| SG-C0420T049V01 | SNMP message privacy enforcement |
| SG-C0155T049V01 | SNMP service disabled |
| SG-M6540T049V01 | SNMP status |
| SG-M4484T049V01 | SNMP user authentication |
| SG-F7331T049V01 | SNMP versions enabled |
| SG-C0422T049V01 | SNMPv3 privacy encryption algorithm |
| SG-C0419T049V01 | SNMPv3 user authentication protocol |
| SG-C0346T049V01 | SNMPv3 user security |
| SG-M6740T049V01 | SSO for third-party applications status |
| SG-M6470T049V01 | SSO status |
| SG-M7952T049V01 | Standby CommServe Host |
| SG-C0306T049V01 | Syslog communication protocol |
| SG-M7723T049V01 | Syslog protocol |
| SG-M7052T049V01 | Syslog status |
| SG-M2035T049V01 | Target Commvault version |
| SG-C0019T049V01 | Target OS version |
| SG-C0005T049V01 | TLS audit logging |
| SG-M7050T049V01 | TLS level |
| SG-C0390T049V03 | TLS level - Azure |
| SG-C0390T049V02 | TLS level - SDK |
| SG-F1520T049V01 | Trusted certificate-authority (CA) |
| SG-F9370T049V01 | Unapproved admin users |
| SG-F9618T049V01 | Unapproved user groups |
| SG-C0119T049V01 | Unapproved user groups - Disk Pool |
| SG-C0119T049V02 | Unapproved user groups - HyperScale Storage |
| SG-M5771T049V01 | UNC shares have a dedicated user name and password |
| SG-M3190T049V01 | Unprotected VM's discovered |
| SG-C0213T049V01 | Use of secure LDAP |
| SG-M2835T049V01 | Use Passphrase for zipped log files |
| SG-F2491T049V01 | User role configuration |
| SG-M3658T049V01 | Virtual Server iDA TLS |
| SG-M1837T049V01 | Weak SNMP privacy algorithm used |
| SG-M5391T049V01 | Workflow SSL certificate validation |
| SG-C0298T049V01 | WORM storage mode is disabled |
| SG-M2691T049V01 | WORM Storage Mode not in use |
| SG-M9819T049V01 | Write-protecting mount paths |
Related components
A complete baseline also covers the components that manage, connect to or protect Commvault. Review the configuration of:
- Commvault Command Center
- HyperScale X and Commvault Distributed Storage
- Metallic (Commvault Cloud)
- Windows SNMP service on Commvault servers
- Target storage systems
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.