UCF STIG Viewer Logo

The HPE 3PAR OS must be configured to disable nonessential Remote Copy services.


Overview

Finding ID Version Rule ID IA Controls Severity
V-255298 HP3P-33-131001 SV-255298r870284_rule Medium
Description
It is detrimental for operating systems to provide, or install by default, functionality exceeding requirements or mission objectives. These unnecessary capabilities or services are often overlooked and therefore may remain unsecured. They increase the risk to the platform by providing additional attack vectors. The HPE 3PAR OS does not, by default, operate nonessential services. The Remote Copy services component must be configured for it to start. If it is not required by the mission, then it must be disabled.
STIG Date
HPE 3PAR StoreServ 3.3.x Security Technical Implementation Guide 2023-11-30

Details

Check Text ( C-58971r870284_chk )
Verify with the Information Owner that the mission objectives exclude Remote Copy functionality.

If Remote Copy is required by the mission, this requirement is not applicable.

If Remote Copy is not required by the mission, verify the state of RC functionality:

cli% showrcopy

If the output is an error and indicates the system is not licensed for Remote Copy, this is not a finding.

If the output indicates "Remote Copy is not configured for this system", this is not a finding.

If the output indicates any other status, this is a finding.
Fix Text (F-58915r870212_fix)
Verify with the Information Owner that the mission objectives do not require remote copy.

If Remote Copy is not required by the mission, forcibly stop the functionality, and clear the configuration:

cli% stoprcopy -f -clear