[ Applies to ] StorageGuard / IBM Storage Protect / Data Protection (Backup)
This article lists the recommended baseline checks for IBM Storage Protect. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
IBM Storage Protect (formerly IBM Spectrum Protect and Tivoli Storage Manager) is an enterprise backup and recovery platform with centralized, policy-based data protection and deduplication.
Why hardening IBM Storage Protect matters
Storage Protect servers control the backups organizations rely on for recovery. Access controls, command approval, encryption and secure communications protect backup data from unauthorized access and tampering.
Recommended baseline checks
The baseline below contains 77 checks, listed alphabetically.
| ID | Configuration check |
|---|---|
| SG-C0393T169V01 | Account lockout threshold |
| SG-C0214T169V01 | Admin authority level (ro) |
| SG-C0214T169V02 | Admin authority level (rw) |
| SG-M2389T169V01 | Approved / Required LDAP servers (if AD used) |
| SG-M1133T169V01 | Approved admin users / groups |
| SG-C0435T169V01 | Approved LDAP servers |
| SG-C0096T169V01 | Archive retention protection |
| SG-C0331T169V01 | Audit log retention |
| SG-M3219T169V01 | Audit log retention period |
| SG-M9255T169V01 | Authentication is off |
| SG-M1193T169V01 | Authorized backup user |
| SG-C0550T169V01 | Backup initiation user |
| SG-F4313T169V01 | Certificate expiration warning |
| SG-C0166T169V01 | Command approval is disabled |
| SG-M8786T169V01 | Command approval is enabled |
| SG-M3805T169V01 | Command approver user is defined |
| SG-C0470T169V01 | Command approver user is not defined |
| SG-C0065T169V01 | Data at-rest encryption Storage pool |
| SG-C0073T169V01 | Data encryption strength |
| SG-C0080T169V01 | Data in-transit encryption - Admin session security level |
| SG-C0080T169V02 | Data in-transit encryption - Client session security level |
| SG-C0080T169V03 | Data in-transit encryption - Server session security level |
| SG-C0287T169V01 | Database backup protection status |
| SG-C0034T169V01 | Default authentication |
| SG-M6982T169V01 | Default passwords |
| SG-M1890T169V01 | Email alert status |
| SG-C0402T169V01 | Email notification status |
| SG-C0571T169V01 | Encryption password - backup protection |
| SG-M5410T169V01 | Event record retention period |
| SG-M5009T169V01 | FIPS for SSL (FIPS mode status) |
| SG-C0177T169V01 | FIPS mode status |
| SG-C0209T169V01 | Idle session timeout |
| SG-M9393T169V01 | Immutable backup |
| SG-C0039T169V01 | LDAP server configuration |
| SG-M4820T169V01 | LDAP server configuration (if AD used) |
| SG-C0025T169V01 | LDAP server redundancy |
| SG-M5639T169V01 | LDAP SSL (if AD used) |
| SG-C0427T169V01 | Login banner message |
| SG-C0426T169V01 | Login banner status |
| SG-M5939T169V01 | Master encryption key protection status |
| SG-M7721T169V01 | Max client session |
| SG-C0468T169V01 | Maximum concurrent sessions |
| SG-C0234T169V01 | Maximum password age |
| SG-C0270T169V01 | Minimum password digits |
| SG-C0264T169V01 | Minimum password length |
| SG-C0271T169V01 | Minimum password lowercase characters |
| SG-C0272T169V01 | Minimum password special characters |
| SG-C0273T169V01 | Minimum password uppercase characters |
| SG-C0239T169V01 | Multi-factor authentication |
| SG-C0230T169V01 | Non-default local admin |
| SG-M8928T169V01 | Not member of a Windows domain |
| SG-M2238T169V01 | Number of disallowed past passwords |
| SG-C0469T169V01 | Password authentication is required |
| SG-M1341T169V01 | Password file access restriction |
| SG-C0284T169V01 | Password history |
| SG-C0498T169V01 | Persistent checksum |
| SG-M8482T169V01 | Read-only commands authority level |
| SG-M5400T169V01 | Read-write commands authority level |
| SG-C0303T169V01 | Replication rule status |
| SG-C0439T169V01 | Required LDAP servers |
| SG-C0103T169V01 | Retention rule status |
| SG-M7345T169V01 | Secure client and server communication |
| SG-C0405T169V01 | Security notifications status |
| SG-C0379T169V01 | Server database backup |
| SG-C0012T169V01 | Server password set status |
| SG-M2734T169V01 | Server session security |
| SG-C0395T169V01 | SMTP server configuration |
| SG-C0058T169V01 | SNMP community default string |
| SG-C0365T169V01 | SSL authentication status |
| SG-M5569T169V01 | TLS level |
| SG-C0390T169V02 | TLS level - Admin TLS level |
| SG-C0390T169V03 | TLS level - Client TLS level |
| SG-C0390T169V01 | TLS level - Server TLS level |
| SG-C0116T169V01 | Unapproved admin users |
| SG-M9061T169V01 | Unique credentials |
| SG-M1554T169V01 | Use of local users (No AD) |
| SG-C0213T169V01 | Use of secure LDAP |
Related components
A complete baseline also covers the components that manage, connect to or protect IBM Storage Protect. Review the configuration of:
- Operations Center
- Backup-archive clients and data movers
- Tape libraries and container storage pools
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.