[ Applies to ] StorageGuard / Dell ObjectScale / ECS / Object Storage
This article lists the recommended baseline checks for Dell ObjectScale / ECS. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
Dell ObjectScale and Elastic Cloud Storage (ECS) are software-defined object storage platforms for traditional and cloud-native workloads, supporting S3, Swift, CAS and NFS access.
Why hardening Dell ObjectScale / ECS matters
Object stores frequently hold backups, archives and application data exposed through APIs. Bucket policies, CORS settings, encryption, authentication and retention controls prevent unauthorized access and data loss.
Recommended baseline checks
The baseline below contains 208 checks, listed alphabetically.
| ID | Configuration check |
|---|---|
| SG-C0207T067V01 | Absolute session timeout |
| SG-M8467T067V01 | Access During Outage |
| SG-M6220T067V01 | Access-Control-Allow-Headers setting |
| SG-M7676T067V01 | Access-Control-Allow-Methods setting |
| SG-M9556T067V01 | Access-Control-Allow-Origin setting |
| SG-M9899T067V01 | Access-Control-Expose-Headers setting |
| SG-M4865T067V01 | Access-Control-Max-Age setting |
| SG-C0393T067V01 | Account lockout threshold |
| SG-M4447T067V01 | Alert policy configuration |
| SG-C0163T067V01 | Approved AD domain |
| SG-M8933T067V01 | Approved admin user/group |
| SG-F4763T067V01 | Approved DNS servers |
| SG-M4986T067V01 | Approved external syslog servers |
| SG-F8009T067V01 | Approved KMS server |
| SG-C0435T067V01 | Approved LDAP servers |
| SG-C0013T067V01 | Approved NTP servers |
| SG-C0015T067V01 | Approved Syslog servers |
| SG-M3331T067V01 | Authentication provider group whitelist |
| SG-F4867T067V01 | Authentication server configuration |
| SG-F4342T067V01 | Authentication server redundancy |
| SG-M9493T067V01 | Bucket ACL |
| SG-F7982T067V01 | Bucket ACL - full control for non-owners |
| SG-F1531T067V01 | Bucket ACL - public access |
| SG-M5523T067V01 | Bucket Audit Delete Expiration |
| SG-M8328T067V01 | Bucket auto-commit configuration |
| SG-M3850T067V01 | Bucket compliance status |
| SG-M4976T067V01 | Bucket default groups |
| SG-M6059T067V01 | Bucket permission |
| SG-M3752T067V01 | Bucket retention enforcemnt |
| SG-M7129T067V01 | Bucket retention settings |
| SG-M9611T067V01 | Call home state |
| SG-F4609T067V01 | CAS bucket IP restriction |
| SG-M7759T067V01 | CAS IP restrictions |
| SG-M4113T067V01 | Central Certificate Authority (CA) status |
| SG-C0029T067V01 | Centralized log server |
| SG-C0233T067V01 | Centralized log server redundancy |
| SG-M8750T067V01 | Certificate issuer |
| SG-C0065T067V01 | Data at-rest encryption |
| SG-C0065T067V02 | Data at-rest encryption - Namespace |
| SG-M9377T067V01 | Data encryption enforcement (namespace) |
| SG-M1914T067V01 | Default bucket retention |
| SG-M4678T067V01 | Default group directory exec permission |
| SG-M8191T067V01 | Default group file exec permission |
| SG-M7568T067V01 | Default group file write permission |
| SG-M2713T067V01 | Default object lock retention |
| SG-M5568T067V01 | Default passwords |
| SG-M3755T067V01 | Disable remote support if not used |
| SG-M9232T067V01 | Disable SNMP if not used |
| SG-M1490T067V01 | DNS server configuration |
| SG-M3390T067V01 | DNS server redundancy |
| SG-M5388T067V01 | DNS service status |
| SG-M7801T067V01 | ECS CLI client list |
| SG-M4308T067V01 | ECS CLI version |
| SG-M3603T067V01 | ECS node list |
| SG-M5302T067V01 | ECS streamer |
| SG-M8747T067V01 | ECS streamer version |
| SG-M3160T067V01 | ECS switch list |
| SG-M2584T067V01 | ECS system list |
| SG-M6026T067V01 | Email events status |
| SG-M8476T067V01 | Email SSL |
| SG-C0600T067V01 | End of support |
| SG-M3327T067V01 | ESRS configuration |
| SG-M5409T067V01 | ESRS status |
| SG-M9897T067V01 | Event encryption |
| SG-C0162T067V02 | Expired SSL certificate - data object |
| SG-M7277T067V01 | External key manager configuration |
| SG-M8871T067V01 | Fcli health |
| SG-M5210T067V01 | Filesystem access |
| SG-M9505T067V01 | Firewall status |
| SG-M6170T067V01 | Firmware version |
| SG-M7833T067V01 | Fixed retention configuration |
| SG-M8529T067V01 | Full replication |
| SG-C0600T067V02 | Future end of support |
| SG-M8939T067V01 | Hardening status |
| SG-M1245T067V01 | HTTP access |
| SG-C0209T067V03 | Idle session timeout |
| SG-M5532T067V01 | Inactive user time |
| SG-M5960T067V01 | IPMI access mode |
| SG-M7412T067V01 | IPMI alerting |
| SG-M3744T067V01 | IPMI anonymous user access |
| SG-M6671T067V01 | IPMI authentication type |
| SG-M2470T067V01 | IPMI default password |
| SG-M5570T067V01 | IPMI per message authentication |
| SG-M5717T067V01 | IPMI session type |
| SG-M7202T067V01 | IPMI status |
| SG-M5680T067V01 | IPMI user level authentication |
| SG-M9880T067V01 | IPMI user list |
| SG-M9113T067V01 | IPv6 status |
| SG-M4779T067V01 | Kerberos admin ACL (HDFS) |
| SG-M5478T067V01 | Kerberos configuration (HDFS) |
| SG-F4404T067V01 | Kerberos status |
| SG-M8609T067V01 | Kerberos status (HDFS) |
| SG-M1023T067V01 | KMS configuration |
| SG-C0049T067V01 | KMS server configuration |
| SG-F3692T067V01 | KMS server redundancy |
| SG-C0039T067V01 | LDAP server configuration |
| SG-C0025T067V01 | LDAP server redundancy |
| SG-C0040T067V01 | LDAP service status |
| SG-C0427T067V01 | Login banner message |
| SG-C0426T067V01 | Login banner status |
| SG-M9470T067V01 | Management, data and replication separation |
| SG-M1488T067V01 | Max number of sessions |
| SG-M1993T067V01 | Max session duration |
| SG-C0234T067V01 | Maximum password age |
| SG-M3065T067V01 | Min number of lowercase password chars |
| SG-M8682T067V01 | Min number of password numeric chars |
| SG-M5951T067V01 | Min number of password special chars |
| SG-M2934T067V01 | Min number of uppercase password chars |
| SG-M2848T067V01 | Min severity for syslog |
| SG-C0262T067V01 | Minimum password age |
| SG-C0270T067V01 | Minimum password digits |
| SG-C0264T067V01 | Minimum password length |
| SG-C0271T067V01 | Minimum password lowercase characters |
| SG-C0272T067V01 | Minimum password special characters |
| SG-C0282T067V01 | Minimum password string change |
| SG-C0273T067V01 | Minimum password uppercase characters |
| SG-C0087T067V01 | Namespace compliance status |
| SG-C0717T067V01 | Namespace group mapping |
| SG-M5664T067V01 | Namespace retention policy configuration |
| SG-M2381T067V01 | NFS anon user mapping |
| SG-M3691T067V01 | NFS authentication settings |
| SG-C0191T067V01 | NFS export ACL status |
| SG-M4618T067V01 | NFS exports |
| SG-M2702T067V01 | NFS root user mapping |
| SG-F3387T067V01 | NFS security protocol |
| SG-M7388T067V01 | NFS version |
| SG-M6209T067V01 | Node compliance mode |
| SG-M2459T067V01 | Node firewall health |
| SG-M7823T067V01 | Node firewall status |
| SG-M4278T067V01 | Node list (MACHINES) |
| SG-M2218T067V01 | Node lockdown |
| SG-F3693T067V01 | Node lockdown config |
| SG-C0230T067V01 | Non-default local admin |
| SG-C0231T067V01 | Non-default local users |
| SG-C0171T067V01 | NTP server configuration |
| SG-C0432T067V01 | NTP server redundancy |
| SG-M6801T067V01 | NTP service status |
| SG-M1050T067V01 | Openssl configuration |
| SG-F7872T067V01 | OS version check |
| SG-C0284T067V01 | Password history |
| SG-M6836T067V01 | Password length |
| SG-M2965T067V01 | Password reuse |
| SG-C0277T067V01 | Password rules status |
| SG-M1486T067V01 | Permission on sensitive directories/files |
| SG-M9520T067V01 | Rack switch SNMP community string |
| SG-M3928T067V01 | Readonly access during outage |
| SG-F9095T067V01 | Remote support availability |
| SG-M2076T067V01 | Remote support configuration |
| SG-C0138T067V01 | Remote support status |
| SG-M7051T067V01 | Replication configuration |
| SG-M5515T067V01 | Replication mode |
| SG-M2166T067V01 | Required external syslog servers |
| SG-C0439T067V01 | Required LDAP servers |
| SG-C0014T067V01 | Required NTP servers |
| SG-C0016T067V01 | Required Syslog servers |
| SG-M6244T067V01 | RPO alert |
| SG-M2472T067V01 | S3 bucket ACL |
| SG-M5926T067V01 | S3 Bucket lock configuration |
| SG-M8674T067V01 | S3 Bucket Versioning |
| SG-C0447T067V02 | Self-signed certificate - data object |
| SG-C0447T067V03 | Self-signed certificate - management |
| SG-M2237T067V01 | Server side encryption |
| SG-M6183T067V01 | Session timeout |
| SG-M8734T067V01 | SMTP TLS |
| SG-M1778T067V01 | SNMP authentication |
| SG-M7029T067V01 | SNMP authentication algorithm strength |
| SG-C0058T067V01 | SNMP community default string |
| SG-M4988T067V01 | SNMP community string |
| SG-M9378T067V01 | SNMP privacy |
| SG-M2665T067V01 | SNMP privacy algorithm strength |
| SG-M6802T067V01 | SNMP service status |
| SG-C0347T067V01 | SNMP trap host configuration |
| SG-M6533T067V01 | SNMP trap receiver |
| SG-C0123T067V01 | SNMP versions enabled |
| SG-C0422T067V01 | SNMPv3 privacy encryption algorithm |
| SG-C0419T067V01 | SNMPv3 user authentication protocol |
| SG-M1643T067V01 | SSL certificate status |
| SG-F4237T067V01 | STIG hardening rules configuration |
| SG-M5410T067V01 | Support data scrubbing |
| SG-C0306T067V01 | Syslog communication protocol |
| SG-M6269T067V01 | Syslog facility |
| SG-M5092T067V01 | Syslog protocol |
| SG-M8533T067V01 | Syslog status |
| SG-F4616T067V01 | Syslog transmit via TCP protocol |
| SG-C0019T067V01 | Target OS version |
| SG-C0385T067V01 | Telnet service status |
| SG-M3822T067V01 | TLS level |
| SG-C0448T067V02 | Trusted certificate-authority (CA) - data object |
| SG-C0448T067V03 | Trusted certificate-authority (CA) - management |
| SG-M1779T067V01 | Truststore accept_all_certificates |
| SG-F7393T067V01 | Unapproved admin users |
| SG-F6464T067V01 | Unapproved user groups |
| SG-M7919T067V01 | Unused ports |
| SG-M9052T067V01 | Unused services (atmos) |
| SG-M3247T067V01 | Unused services (cas) |
| SG-M1398T067V01 | Unused services (hdfs) |
| SG-M7030T067V01 | Unused services (NFS) |
| SG-M1073T067V01 | Unused services (S3) |
| SG-M2879T067V01 | Unused services (swift) |
| SG-C0213T067V01 | Use of secure LDAP |
| SG-M4257T067V01 | User Agreement Text |
| SG-M2476T067V01 | Variable retention configuration |
| SG-M9552T067V01 | Varray protection |
| SG-M6119T067V01 | VDC encryption |
| SG-M8662T067V01 | Vdc lockdown |
| SG-M3317T067V01 | XDoctor Auto update secure protocol |
| SG-M2351T067V01 | XDoctor Auto update status |
| SG-M4207T067V01 | XDoctor version |
Related components
A complete baseline also covers the components that manage, connect to or protect Dell ObjectScale / ECS. Review the configuration of:
- ObjectScale on Kubernetes
- Load balancers and S3 clients
- Replication groups
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.