[ Applies to ] StorageGuard / Dell PowerProtect DD / Data Protection (Backup)
This article lists the recommended baseline checks for Dell PowerProtect DD. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
Dell PowerProtect DD (formerly Data Domain) appliances provide deduplicated protection storage for backup and archive data, running the DD Operating System (DDOS).
Why hardening Dell PowerProtect DD matters
PowerProtect DD systems hold the backup copies organizations rely on for ransomware recovery. Retention Lock, secure authentication, encryption, restricted management access and audit logging prevent those copies from being deleted or altered.
Recommended baseline checks
The baseline below contains 251 checks, listed alphabetically.
| ID | Configuration check |
|---|---|
| SG-M5974T061V01 | 2FA configuration (cert/pass) |
| SG-M8319T061V01 | 2FA configuration (SecurID) |
| SG-C0393T061V01 | Account lockout threshold |
| SG-C0832T061V01 | Alert notification recipients |
| SG-M9968T061V01 | Align backup retention period policy with retention lock time |
| SG-C0163T061V01 | Approved AD domain |
| SG-M1522T061V01 | Approved Admin user/group |
| SG-M3411T061V01 | Approved CIFS admin users / groups |
| SG-C0816T061V01 | Approved CIFS organizational unit |
| SG-C0449T061V01 | Approved DNS servers |
| SG-C0504T061V01 | Approved HTTPS port |
| SG-C0434T061V01 | Approved Kerberos realm |
| SG-C0044T061V01 | Approved KMS server |
| SG-C0435T061V01 | Approved LDAP servers |
| SG-M9110T061V01 | Approved NFS versions |
| SG-C0013T061V01 | Approved NTP servers |
| SG-C0015T061V01 | Approved Syslog servers |
| SG-M7594T061V01 | Approved target Data Domain |
| SG-M9943T061V01 | Authentication server configuration (if used) |
| SG-C0024T061V02 | Authentication server redundancy - Kerberos |
| SG-C0024T061V01 | Authentication server redundancy - NIS |
| SG-C0165T061V01 | Authorization policy status |
| SG-M6928T061V01 | Automatic lock delay |
| SG-C0467T061V01 | Automatic retention lock status |
| SG-M2690T061V01 | Automatic retention period |
| SG-C0824T061V02 | Autosupport and alert destinations - Alert destinations |
| SG-C0824T061V01 | Autosupport and alert destinations - Autosupport destinations |
| SG-M5707T061V01 | Backup application commits files for retention locking |
| SG-M8741T061V01 | BIOS password set |
| SG-M1661T061V01 | Central Certificate Authority (CA) status |
| SG-C0029T061V01 | Centralized log server |
| SG-C0233T061V01 | Centralized log server redundancy |
| SG-M4453T061V01 | Certificate expiry |
| SG-M1514T061V01 | Certificate Issuer |
| SG-M1861T061V01 | Certificate key size |
| SG-C0834T061V01 | CIFS authentication mode |
| SG-C0836T061V01 | CIFS role groups |
| SG-C0128T061V01 | CIFS SMB anonymous user access restriction |
| SG-C0344T061V01 | CIFS SMB server signing |
| SG-C0122T061V01 | CIFS SMB version enabled |
| SG-M5673T061V01 | CIFS SMBv1 status |
| SG-C0830T061V01 | CIFS Status |
| SG-M2507T061V01 | Client authentication enforcement |
| SG-C0197T061V01 | Client IP ACL |
| SG-M6255T061V01 | Client session encryption is disabled |
| SG-C0149T061V01 | Cloud status |
| SG-M8710T061V01 | CloudIQ settings |
| SG-C0396T061V01 | CloudIQ status |
| SG-M9449T061V01 | CRL configuration |
| SG-C0065T061V01 | Data at-rest encryption |
| SG-M2260T061V01 | Data at-REST encryption algorithm |
| SG-C0073T061V01 | Data encryption strength |
| SG-F4807T061V01 | Date change frequency |
| SG-F9820T061V01 | Date change restriction |
| SG-M8992T061V01 | DD boost user assignment to single unit |
| SG-M2287T061V01 | DD Boost user role |
| SG-M6397T061V01 | DDBoost client ACL |
| SG-M8531T061V01 | DDBoost encryption enforcement |
| SG-C0090T061V01 | DDboost file replication encryption |
| SG-C0009T061V01 | DDboost global authentication mode |
| SG-M2247T061V01 | DDNS status |
| SG-M8731T061V01 | Default local user accounts |
| SG-C0056T061V01 | Default passwords |
| SG-F3633T061V01 | Default passwords - iDRAC/IPMI |
| SG-M3710T061V01 | Disable default root account |
| SG-C0137T061V01 | Disable inactive users - Expired users |
| SG-M2853T061V01 | Disable of expired users |
| SG-C0243T061V01 | DNS server configuration |
| SG-C0060T061V01 | DNS server redundancy |
| SG-M3014T061V01 | DNS service status |
| SG-C0245T061V01 | Domain name configuration |
| SG-M1990T061V01 | Email alerts |
| SG-C0823T061V01 | Encryption key rotation configured |
| SG-C0600T061V01 | End of support |
| SG-M4651T061V01 | ESRS secure connection |
| SG-M1685T061V01 | ESRS settings and state |
| SG-F9535T061V01 | Event types enabled for audit logging |
| SG-C0162T061V01 | Expired SSL certificate |
| SG-C0510T061V01 | External key manager status |
| SG-M4400T061V01 | External log host status |
| SG-M2299T061V01 | External syslog server redundancy |
| SG-M1008T061V01 | File share export options |
| SG-M1716T061V01 | File share max connections |
| SG-C0819T061V01 | Filesystem clean schedule configured |
| SG-C0820T061V01 | Filesystem clean throttle configured |
| SG-C0821T061V01 | Filesystem marker-type |
| SG-C0815T061V01 | Filesystem operational status |
| SG-C0177T061V01 | FIPS mode status |
| SG-M2729T061V01 | FTP ACL |
| SG-C0380T061V01 | FTP service status |
| SG-C0826T061V01 | FTPS Status |
| SG-C0600T061V02 | Future end of support |
| SG-C0814T061V01 | HA operational status |
| SG-M9567T061V01 | Host-based access lists |
| SG-C0381T061V01 | HTTP service status |
| SG-C0461T061V01 | HTTP/HTTPS default port used |
| SG-C0466T061V01 | HTTPS allowed access list |
| SG-M7612T061V01 | HTTPS allowed hosts list |
| SG-C0827T061V01 | HTTPS Status |
| SG-C0209T061V01 | Idle session timeout - SSH |
| SG-C0209T061V02 | Idle session timeout - Web |
| SG-M8655T061V01 | iDRAC Retention Lock Compliance |
| SG-C0825T061V01 | iDRAC users |
| SG-M5803T061V01 | In-flight data encryption enforcement |
| SG-C0261T061V01 | Initial password change |
| SG-M6756T061V01 | IPFilter status |
| SG-M9706T061V01 | IPMI configuration |
| SG-C0309T061V01 | IPMI root user status |
| SG-C0831T061V01 | IPMI Status |
| SG-M8030T061V01 | IPv6 configuration |
| SG-F6988T061V01 | IPv6 status |
| SG-C0031T061V01 | Kerberos configuration |
| SG-M3547T061V01 | Kerberos for BoostFS |
| SG-M9747T061V01 | KMIP configuration |
| SG-C0049T061V01 | KMS server configuration |
| SG-C0052T061V01 | KMS server redundancy |
| SG-C0039T061V01 | LDAP server configuration |
| SG-C0025T061V01 | LDAP server redundancy |
| SG-C0040T061V01 | LDAP service status |
| SG-M6985T061V01 | Limit access to iDRAC Virtual Console |
| SG-C0427T061V01 | Login banner message |
| SG-C0426T061V01 | Login banner status |
| SG-M7306T061V01 | MAC algorithm strength |
| SG-F8707T061V01 | Management interfaces restriction |
| SG-C0269T061V01 | Maximum number of repeated password characters |
| SG-C0234T061V01 | Maximum password age |
| SG-M3410T061V01 | Maximum retention period |
| SG-C0392T061V01 | Minimum account lockout duration |
| SG-C0263T061V01 | Minimum passphrase length |
| SG-C0262T061V01 | Minimum password age |
| SG-C0270T061V01 | Minimum password digits |
| SG-C0264T061V01 | Minimum password length |
| SG-C0271T061V01 | Minimum password lowercase characters |
| SG-C0812T061V01 | Minimum password position changes |
| SG-C0272T061V01 | Minimum password special characters |
| SG-C0273T061V01 | Minimum password uppercase characters |
| SG-M6427T061V01 | Minimum retention period |
| SG-M9478T061V01 | Mtree replication encryption |
| SG-C0573T061V01 | Mtree retention lock level |
| SG-F2214T061V01 | MTree retention-lock automatic lock delay |
| SG-F2919T061V01 | MTree retention-lock automatic retention period |
| SG-M8945T061V01 | Mtree with retention lock |
| SG-C0239T061V02 | Multi-factor authentication |
| SG-C0239T061V01 | Multi-factor authentication - RSA SecureID |
| SG-M2164T061V01 | NDMP authentication type |
| SG-M7222T061V01 | NDMP configuration |
| SG-F7639T061V01 | NDMP status |
| SG-M6518T061V01 | NFS export client ACL |
| SG-M4345T061V01 | NFS port |
| SG-M4529T061V01 | NFS privacy (krb) |
| SG-C0377T061V01 | NFS root squash status |
| SG-C0829T061V01 | NFS Status |
| SG-F6901T061V01 | NFS versions enabled |
| SG-M7418T061V01 | NFS/CIFS share ACL |
| SG-C0230T061V01 | Non-default local admin |
| SG-C0231T061V01 | Non-default local users |
| SG-M4624T061V01 | NTP configuration |
| SG-C0171T061V01 | NTP server configuration |
| SG-C0432T061V01 | NTP server redundancy |
| SG-C0172T061V01 | NTP service status |
| SG-M3459T061V01 | NTP status |
| SG-M8854T061V01 | Number of concurrent sessions is limited |
| SG-M6446T061V01 | Number of disallowed past passwords |
| SG-C0813T061V01 | Password dictionary check |
| SG-C0417T061V01 | Password hash strength |
| SG-C0284T061V01 | Password history |
| SG-M9785T061V01 | Permission on sensitive directories/files |
| SG-M5943T061V01 | Portmapper status |
| SG-M8399T061V01 | Remote replication |
| SG-C0397T061V01 | Remote support configuration |
| SG-M2538T061V01 | Replication encryption over wire |
| SG-C0117T061V01 | Replication interface access |
| SG-M2140T061V01 | Replication pair status |
| SG-M7573T061V01 | Replication peer authentication |
| SG-F8011T061V01 | Replication port status |
| SG-M2249T061V01 | Replication topology |
| SG-C0946T061V01 | Required alert notification recipients |
| SG-C0164T061V01 | Required domain name |
| SG-C0723T061V01 | Required Kerberos realm |
| SG-M7629T061V01 | Required Mtree lock |
| SG-C0014T061V01 | Required NTP servers |
| SG-C0246T061V01 | Required search domains |
| SG-C0349T061V01 | Required SNMP trap hosts |
| SG-C0016T061V01 | Required Syslog servers |
| SG-M1562T061V01 | Retention Lock configuration |
| SG-M8563T061V01 | Retention Lock mode status |
| SG-M8051T061V01 | Retention Lock use (manual vs automatic) |
| SG-C0294T061V01 | Retention-Lock compliance license |
| SG-C0265T061V01 | Retention-lock compliance mode |
| SG-M8826T061V01 | Root squash is enforced |
| SG-C0811T061V01 | SCP service status |
| SG-C0008T061V01 | Secure NTP status |
| SG-C0167T061V01 | Security officer account |
| SG-M3168T061V01 | Security Officer authorization enabled |
| SG-M5616T061V01 | Security officer configuration |
| SG-C0447T061V01 | Self-signed certificate |
| SG-M8072T061V01 | Session timeout |
| SG-M6172T061V01 | SMB digital signing |
| SG-C0395T061V01 | SMTP server configuration |
| SG-C0058T061V01 | SNMP community default string |
| SG-M2448T061V01 | SNMP message privacy |
| SG-M1232T061V01 | SNMP message privacy algorithm strength |
| SG-C0155T061V01 | SNMP service disabled |
| SG-C0156T061V01 | SNMP service enabled |
| SG-F1830T061V01 | SNMP status |
| SG-C0818T061V01 | SNMP System Contact |
| SG-C0817T061V01 | SNMP System Location |
| SG-C0347T061V01 | SNMP trap host configuration |
| SG-M3135T061V01 | SNMP user authentication |
| SG-C0123T061V01 | SNMP versions enabled |
| SG-M6088T061V01 | SNMPv1 / SNMPv2 version |
| SG-C0422T061V01 | SNMPv3 privacy encryption algorithm |
| SG-C0351T061V01 | SNMPv3 read-only user |
| SG-F2495T061V01 | SSH access to the replication interface is enabled |
| SG-C0465T061V01 | SSH allowed access list |
| SG-M4140T061V01 | SSH allowed hosts list |
| SG-M3238T061V01 | SSH cipher strength |
| SG-C0833T061V01 | SSH key-exchange algorithm strength |
| SG-C0255T061V01 | SSH MAC strength |
| SG-C0462T061V01 | SSH non-default port |
| SG-M1796T061V01 | SSH session timeout |
| SG-C0822T061V01 | SSH Status |
| SG-M8196T061V01 | SSL certificate status |
| SG-M2934T061V01 | SSO configuration |
| SG-C0835T061V01 | Support notification method |
| SG-C0259T061V01 | System cipher strength |
| SG-C0493T061V01 | System timezone |
| SG-M9342T061V01 | Target Data Domain OS version |
| SG-M6932T061V01 | Target Mtree Replication propagate retention lock |
| SG-C0385T061V01 | Telnet service status |
| SG-C0386T061V01 | Telnet uninstalled |
| SG-M4668T061V01 | Time change limits |
| SG-C0005T061V01 | TLS audit logging |
| SG-M9159T061V01 | TLS for FTP |
| SG-C0390T061V01 | TLS level |
| SG-C0448T061V01 | Trusted certificate-authority (CA) |
| SG-F1815T061V01 | Two-factor authentication (certificate and password) |
| SG-F5452T061V01 | Two-factor authentication for critical operations (RSA SecurID) |
| SG-M4585T061V01 | Two-factor authentication for iDRAC |
| SG-C0119T061V01 | Unapproved user groups |
| SG-M1104T061V01 | Unique credentials |
| SG-M5879T061V01 | Unused ports |
| SG-M2229T061V01 | USB ports disabled |
| SG-M9783T061V01 | Use of limited-admin |
| SG-M9531T061V01 | Use of local users (No AD) |
| SG-C0213T061V01 | Use of secure LDAP |
| SG-C0341T061V01 | User role configuration |
| SG-F1529T061V01 | Vault NTP server |
| SG-M1383T061V01 | VTL service |
| SG-C0828T061V01 | Web Service Status |
| SG-M6725T061V01 | Web session timeout |
Related components
A complete baseline also covers the components that manage, connect to or protect Dell PowerProtect DD. Review the configuration of:
- Data Protection Central (DPC)
- PowerProtect Data Manager
- DD Management Center
- iDRAC and IPMI
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.