[ Applies to ] StorageGuard / HPE Alletra 5000/6000 / Unified Storage
This article lists the recommended baseline checks for HPE Alletra 5000/6000. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
HPE Alletra 5000 and 6000 (NimbleOS) are enterprise storage platforms managed through the Data Services Cloud Console, with predictive support from HPE InfoSight.
Why hardening HPE Alletra 5000/6000 matters
Alletra 5000/6000 systems store databases, application data and file repositories. Encryption, granular access controls, secure management and immutable snapshots protect this data and limit the blast radius of any incident.
Recommended baseline checks
The baseline below contains 60 checks, listed alphabetically.
| ID | Configuration check |
|---|---|
| SG-C0393T243V01 | Account lockout threshold |
| SG-C0700T243V01 | Approved CHAP users |
| SG-C0449T243V01 | Approved DNS servers |
| SG-C0044T243V01 | Approved KMS server |
| SG-C0013T243V01 | Approved NTP servers |
| SG-C0705T243V01 | Approved protection policies |
| SG-C0400T243V01 | Approved SMTP recipients |
| SG-C0406T243V01 | Approved SMTP server |
| SG-C0314T243V01 | Approved SMTP user |
| SG-C0348T243V01 | Approved SNMP trap hosts |
| SG-C0430T243V01 | Autosupport status |
| SG-C0032T243V01 | Central authentication |
| SG-C0029T243V01 | Centralized log server |
| SG-C0233T243V01 | Centralized log server redundancy |
| SG-C0702T243V01 | Common Criteria mode enabled |
| SG-C0065T243V01 | Data at-rest encryption |
| SG-C0065T243V02 | Data at-rest encryption - Space Domains |
| SG-C0073T243V01 | Data encryption strength |
| SG-C0243T243V01 | DNS server configuration |
| SG-C0060T243V01 | DNS server redundancy |
| SG-C0245T243V01 | Domain name configuration |
| SG-C0209T243V01 | Idle session timeout |
| SG-C0708T243V01 | iSCSI subnet restriction |
| SG-C0049T243V01 | KMS server configuration |
| SG-C0052T243V01 | KMS server redundancy |
| SG-C0509T243V01 | Log forwarding |
| SG-C0427T243V01 | Login banner message |
| SG-C0426T243V01 | Login banner status |
| SG-C0701T243V01 | Master key status |
| SG-C0468T243V01 | Maximum concurrent sessions |
| SG-C0269T243V01 | Maximum number of repeated password characters |
| SG-C0270T243V01 | Minimum password digits |
| SG-C0264T243V01 | Minimum password length |
| SG-C0271T243V01 | Minimum password lowercase characters |
| SG-C0272T243V01 | Minimum password special characters |
| SG-C0273T243V01 | Minimum password uppercase characters |
| SG-C0239T243V01 | Multi-factor authentication |
| SG-C0230T243V01 | Non-default local admin |
| SG-C0231T243V01 | Non-default local users |
| SG-C0171T243V01 | NTP server configuration |
| SG-C0432T243V01 | NTP server redundancy |
| SG-C0704T243V01 | Partner array configuration sync |
| SG-C0284T243V01 | Password history |
| SG-C0014T243V01 | Required NTP servers |
| SG-C0447T243V01 | Self-signed certificate |
| SG-C0011T243V01 | SMTP authentication |
| SG-C0364T243V01 | SMTP security |
| SG-C0395T243V01 | SMTP server configuration |
| SG-C0707T243V01 | Snapshots ACL status |
| SG-C0058T243V01 | SNMP community default string |
| SG-C0155T243V01 | SNMP service disabled |
| SG-C0347T243V01 | SNMP trap host configuration |
| SG-C0258T243V01 | SSH cipher strength |
| SG-C0547T243V01 | Storage and Management ethernet interfaces separation |
| SG-C0229T243V01 | Support tunnel status |
| SG-C0019T243V01 | Target OS version |
| SG-C0119T243V01 | Unapproved user groups |
| SG-C0710T243V01 | Unused users - disable |
| SG-C0710T243V02 | Unused users - remove |
| SG-F6773T243V01 | WORM / read-only snapshots |
Related components
A complete baseline also covers the components that manage, connect to or protect HPE Alletra 5000/6000. Review the configuration of:
- HPE InfoSight
- Data Services Cloud Console
- Replication partners
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.