Dial-out access from the Hardware Management Console Remote Support Facility (RSF) must be disabled for all classified systems.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-256870HMC0035SV-256870r1001085_ruleCCI-001762high
Description
This feature will not be activated for any classified systems. Allowing dial-out access from the Hardware Management Console could impact the integrity of the environment by enabling the possible introduction of spyware or other malicious code.
STIGDate
IBM Hardware Management Console (HMC) Security Technical Implementation Guide2024-06-24

Related Frameworks

3 paths across 3 frameworks
NIST 800-531 mapping
  • DISA · V2R1 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
NIST 800-1711 mapping
3.4.7
1.00
  • DISA · V2R1 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
CCI-001762
1.00
  • DISA · V2R1 · disa_xccdf · related

Details

Check Text (C-256870r1001085_chk)

Have the Systems Administrator or Systems Programmer validate that dial-out access from the Hardware Management Console is not activated for any classified systems. Note: This can be accomplished by going to the Customize Remote Service Panel on the Hardware Management Console and verifying that enable remote service is not enabled. If this is a classified system and enable remote service is enabled, then this is a FINDING.

Fix Text (F-60488r890955_fix)

Have the Systems Administrator or Systems Programmer validate that dial-out access from the Hardware Management Console is not activated for any classified systems. Note: This can be accomplished by going to the Customize Remote Service Panel on the Hardware Management Console and verifying that enable remote service is not enabled.