[ Applies to ] StorageGuard / IBM FlashSystem / Block & SAN Storage
This article lists the recommended baseline checks for IBM FlashSystem. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
IBM FlashSystem is a family of all-flash and hybrid storage systems built on IBM Storage Virtualize software and IBM FlashCore Module technology. It delivers low-latency block storage, data reduction and replication, and can virtualize external storage.
The same Storage Virtualize checks apply to IBM SAN Volume Controller (SVC).
Why hardening IBM FlashSystem matters
FlashSystem arrays often store critical and sensitive data. Encryption, strict access controls, secure management interfaces and regular configuration reviews protect that data from unauthorized access or manipulation and help meet compliance requirements.
Recommended baseline checks
The baseline below contains 104 checks, listed alphabetically.
| ID | Configuration check |
|---|---|
| SG-C0393T175V01 | Account lockout threshold |
| SG-C0214T175V01 | Admin authority level |
| SG-C0453T175V01 | Antivirus server redundancy |
| SG-C0449T175V01 | Approved DNS servers |
| SG-C0435T175V01 | Approved LDAP servers |
| SG-C0013T175V01 | Approved NTP servers |
| SG-C0400T175V01 | Approved SMTP recipients |
| SG-C0348T175V01 | Approved SNMP trap hosts |
| SG-C0015T175V01 | Approved Syslog servers |
| SG-C0031T175V01 | Authentication server configuration |
| SG-C0165T175V01 | Authorization policy status |
| SG-C0895T175V01 | Call Home connection |
| SG-C0894T175V01 | Call Home status |
| SG-C0029T175V01 | Centralized log server |
| SG-C0233T175V01 | Centralized log server redundancy |
| SG-C0235T175V01 | Certificate key size |
| SG-C0415T175V01 | Certificate signature algorithm |
| SG-C0411T175V01 | CHAP authentication mode - Status |
| SG-C0411T175V02 | CHAP authentication mode - Users |
| SG-C0065T175V01 | Data at-rest encryption |
| SG-C0065T175V05 | Data at-rest encryption - MDisk group |
| SG-C0904T175V01 | Data encryption license |
| SG-C0098T175V01 | Data retention period |
| SG-C0056T175V01 | Default passwords |
| SG-C0060T175V01 | DNS server redundancy |
| SG-C0244T175V01 | DNS service status |
| SG-C0602T175V01 | End of extended support |
| SG-C0600T175V01 | End of support |
| SG-C0112T175V01 | Enhanced data in the call home report |
| SG-C0372T175V01 | Eradication delay (secure data erasure) |
| SG-C0372T175V02 | Eradication delay (secure data erasure) - Volume protection time |
| SG-C0602T175V02 | Future end of extended support |
| SG-C0600T175V02 | Future end of support |
| SG-C0209T175V03 | Idle session timeout - CLI |
| SG-C0237T175V02 | Idle session timeout - GUI |
| SG-C0209T175V01 | Idle session timeout - remote support |
| SG-C0209T175V04 | Idle session timeout - REST |
| SG-C0038T175V01 | Kerberos status |
| SG-C0049T175V01 | KMS server configuration |
| SG-C0049T175V02 | KMS server configuration - Servers |
| SG-C0052T175V01 | KMS server redundancy |
| SG-C0059T175V01 | LDAP authentication cache |
| SG-C0039T175V01 | LDAP server configuration |
| SG-C0040T175V01 | LDAP service status |
| SG-C0169T175V01 | Lockout enforcement for admin |
| SG-C0234T175V01 | Maximum password age |
| SG-C0392T175V01 | Minimum account lockout duration |
| SG-C0262T175V01 | Minimum password age |
| SG-C0270T175V01 | Minimum password digits |
| SG-C0264T175V01 | Minimum password length |
| SG-C0271T175V01 | Minimum password lowercase characters |
| SG-C0272T175V01 | Minimum password special characters |
| SG-C0273T175V01 | Minimum password uppercase characters |
| SG-C0239T175V01 | Multi-factor authentication |
| SG-C0239T175V02 | Multi-factor authentication - Superuser |
| SG-C0231T175V01 | Non-default local users |
| SG-C0171T175V01 | NTP server configuration |
| SG-C0281T175V01 | Password expiration warning message |
| SG-C0284T175V01 | Password history |
| SG-C0293T175V01 | Protected recovery copies - DiskGroup |
| SG-C0293T175V02 | Protected recovery copies - Volume |
| SG-C0293T175V03 | Protected recovery copies - VolumeGroup |
| SG-C0414T175V01 | Public key algorithm |
| SG-C0010T175V01 | Remote copy authentication status |
| SG-C0138T175V01 | Remote support status |
| SG-C0398T175V01 | Remote support via proxy |
| SG-C0450T175V01 | Required DNS servers |
| SG-C0051T175V01 | Required KMS server |
| SG-C0439T175V01 | Required LDAP servers |
| SG-C0014T175V01 | Required NTP servers |
| SG-C0349T175V01 | Required SNMP trap hosts |
| SG-C0016T175V01 | Required Syslog servers |
| SG-C0505T175V01 | Retention policy |
| SG-C0447T175V01 | Self-signed certificate |
| SG-C0114T175V01 | Sensitive data removal - call home |
| SG-C0442T175V01 | Single Sign-On (SSO) status |
| SG-C0011T175V01 | SMTP authentication |
| SG-C0395T175V01 | SMTP server configuration |
| SG-C0058T175V01 | SNMP community default string |
| SG-C0403T175V01 | SNMP minimum storage alerts level |
| SG-C0155T175V01 | SNMP service disabled |
| SG-C0347T175V01 | SNMP trap host configuration |
| SG-C0258T175V01 | SSH cipher strength - Security level |
| SG-C0905T175V01 | SSH login grace time |
| SG-C0255T175V01 | SSH MAC strength - Hardening |
| SG-C0906T175V01 | SSH maximum authentication attempts |
| SG-C0547T175V01 | Storage and Management ethernet interfaces separation |
| SG-C0902T175V01 | Support contact alternate phone |
| SG-C0899T175V01 | Support contact email |
| SG-C0903T175V01 | Support contact location |
| SG-C0900T175V01 | Support contact name |
| SG-C0901T175V01 | Support contact phone |
| SG-C0898T175V01 | Support proxy URL |
| SG-C0897T175V01 | Support statistics frequency |
| SG-C0896T175V01 | Support statistics status |
| SG-C0306T175V01 | Syslog communication protocol |
| SG-C0493T175V01 | System timezone |
| SG-C0019T175V01 | Target OS version |
| SG-C0390T175V01 | TLS level |
| SG-C0116T175V01 | Unapproved admin users |
| SG-C0119T175V01 | Unapproved user groups |
| SG-C0140T175V01 | Unused ports - Fiber |
| SG-C0140T175V02 | Unused ports - USB |
| SG-C0213T175V01 | Use of secure LDAP |
Related components
A complete baseline also covers the components that manage, connect to or protect IBM FlashSystem. Review the configuration of:
- IBM Storage Insights
- IBM Copy Services Manager
- External key managers
- Virtualized back-end storage
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.