[ Applies to ] StorageGuard / IBM SAN Volume Controller / Storage Virtualization
This article lists the recommended baseline checks for IBM SAN Volume Controller. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
IBM SAN Volume Controller (SVC) virtualizes heterogeneous storage into a single pool, running the same IBM Storage Virtualize software as IBM FlashSystem, with non-disruptive migration and replication.
Because SVC and FlashSystem share Storage Virtualize, the same checks apply; see also IBM FlashSystem.
Why hardening IBM SAN Volume Controller matters
Because SVC sits between servers and every virtualized array, a compromise affects the entire storage estate. Access controls, encryption and secure management settings protect data integrity and availability and help meet regulatory requirements.
Recommended baseline checks
The baseline below contains 104 checks, listed alphabetically.
| ID | Configuration check |
|---|---|
| SG-C0393T175V01 | Account lockout threshold |
| SG-C0214T175V01 | Admin authority level |
| SG-C0453T175V01 | Antivirus server redundancy |
| SG-C0449T175V01 | Approved DNS servers |
| SG-C0435T175V01 | Approved LDAP servers |
| SG-C0013T175V01 | Approved NTP servers |
| SG-C0400T175V01 | Approved SMTP recipients |
| SG-C0348T175V01 | Approved SNMP trap hosts |
| SG-C0015T175V01 | Approved Syslog servers |
| SG-C0031T175V01 | Authentication server configuration |
| SG-C0165T175V01 | Authorization policy status |
| SG-C0895T175V01 | Call Home connection |
| SG-C0894T175V01 | Call Home status |
| SG-C0029T175V01 | Centralized log server |
| SG-C0233T175V01 | Centralized log server redundancy |
| SG-C0235T175V01 | Certificate key size |
| SG-C0415T175V01 | Certificate signature algorithm |
| SG-C0411T175V01 | CHAP authentication mode - Status |
| SG-C0411T175V02 | CHAP authentication mode - Users |
| SG-C0065T175V01 | Data at-rest encryption |
| SG-C0065T175V05 | Data at-rest encryption - MDisk group |
| SG-C0904T175V01 | Data encryption license |
| SG-C0098T175V01 | Data retention period |
| SG-C0056T175V01 | Default passwords |
| SG-C0060T175V01 | DNS server redundancy |
| SG-C0244T175V01 | DNS service status |
| SG-C0602T175V01 | End of extended support |
| SG-C0600T175V01 | End of support |
| SG-C0112T175V01 | Enhanced data in the call home report |
| SG-C0372T175V01 | Eradication delay (secure data erasure) |
| SG-C0372T175V02 | Eradication delay (secure data erasure) - Volume protection time |
| SG-C0602T175V02 | Future end of extended support |
| SG-C0600T175V02 | Future end of support |
| SG-C0209T175V03 | Idle session timeout - CLI |
| SG-C0237T175V02 | Idle session timeout - GUI |
| SG-C0209T175V01 | Idle session timeout - remote support |
| SG-C0209T175V04 | Idle session timeout - REST |
| SG-C0038T175V01 | Kerberos status |
| SG-C0049T175V01 | KMS server configuration |
| SG-C0049T175V02 | KMS server configuration - Servers |
| SG-C0052T175V01 | KMS server redundancy |
| SG-C0059T175V01 | LDAP authentication cache |
| SG-C0039T175V01 | LDAP server configuration |
| SG-C0040T175V01 | LDAP service status |
| SG-C0169T175V01 | Lockout enforcement for admin |
| SG-C0234T175V01 | Maximum password age |
| SG-C0392T175V01 | Minimum account lockout duration |
| SG-C0262T175V01 | Minimum password age |
| SG-C0270T175V01 | Minimum password digits |
| SG-C0264T175V01 | Minimum password length |
| SG-C0271T175V01 | Minimum password lowercase characters |
| SG-C0272T175V01 | Minimum password special characters |
| SG-C0273T175V01 | Minimum password uppercase characters |
| SG-C0239T175V01 | Multi-factor authentication |
| SG-C0239T175V02 | Multi-factor authentication - Superuser |
| SG-C0231T175V01 | Non-default local users |
| SG-C0171T175V01 | NTP server configuration |
| SG-C0281T175V01 | Password expiration warning message |
| SG-C0284T175V01 | Password history |
| SG-C0293T175V01 | Protected recovery copies - DiskGroup |
| SG-C0293T175V02 | Protected recovery copies - Volume |
| SG-C0293T175V03 | Protected recovery copies - VolumeGroup |
| SG-C0414T175V01 | Public key algorithm |
| SG-C0010T175V01 | Remote copy authentication status |
| SG-C0138T175V01 | Remote support status |
| SG-C0398T175V01 | Remote support via proxy |
| SG-C0450T175V01 | Required DNS servers |
| SG-C0051T175V01 | Required KMS server |
| SG-C0439T175V01 | Required LDAP servers |
| SG-C0014T175V01 | Required NTP servers |
| SG-C0349T175V01 | Required SNMP trap hosts |
| SG-C0016T175V01 | Required Syslog servers |
| SG-C0505T175V01 | Retention policy |
| SG-C0447T175V01 | Self-signed certificate |
| SG-C0114T175V01 | Sensitive data removal - call home |
| SG-C0442T175V01 | Single Sign-On (SSO) status |
| SG-C0011T175V01 | SMTP authentication |
| SG-C0395T175V01 | SMTP server configuration |
| SG-C0058T175V01 | SNMP community default string |
| SG-C0403T175V01 | SNMP minimum storage alerts level |
| SG-C0155T175V01 | SNMP service disabled |
| SG-C0347T175V01 | SNMP trap host configuration |
| SG-C0258T175V01 | SSH cipher strength - Security level |
| SG-C0905T175V01 | SSH login grace time |
| SG-C0255T175V01 | SSH MAC strength - Hardening |
| SG-C0906T175V01 | SSH maximum authentication attempts |
| SG-C0547T175V01 | Storage and Management ethernet interfaces separation |
| SG-C0902T175V01 | Support contact alternate phone |
| SG-C0899T175V01 | Support contact email |
| SG-C0903T175V01 | Support contact location |
| SG-C0900T175V01 | Support contact name |
| SG-C0901T175V01 | Support contact phone |
| SG-C0898T175V01 | Support proxy URL |
| SG-C0897T175V01 | Support statistics frequency |
| SG-C0896T175V01 | Support statistics status |
| SG-C0306T175V01 | Syslog communication protocol |
| SG-C0493T175V01 | System timezone |
| SG-C0019T175V01 | Target OS version |
| SG-C0390T175V01 | TLS level |
| SG-C0116T175V01 | Unapproved admin users |
| SG-C0119T175V01 | Unapproved user groups |
| SG-C0140T175V01 | Unused ports - Fiber |
| SG-C0140T175V02 | Unused ports - USB |
| SG-C0213T175V01 | Use of secure LDAP |
Related components
A complete baseline also covers the components that manage, connect to or protect IBM SAN Volume Controller. Review the configuration of:
- IBM Storage Insights
- Virtualized back-end storage
- External key managers
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.