UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Automatic Call Answering to the Hardware Management Console must be disabled.


Overview

Finding ID Version Rule ID IA Controls Severity
V-24350 HMC0050 SV-30013r1_rule EBRP-1 EBRU-1 Medium
Description
Automatic Call Answering to the Hardware Management Console allows unrestricted access by unauthorized personnel and could lead to a bypass of security, access to the system, and an altering of the environment. This would result in a loss of secure operations and impact the integrity of the operating environment, files, and programs. Note: Dial-in access to the Hardware Management Console is prohibited.
STIG Date
IBM Hardware Management Console (HMC) STIG 2013-06-26

Details

Check Text ( C-29847r1_chk )
Have the System Administrator verify if either the Enable Remote Operations parameter or the Automatic Call Answering parameter are active on the Enable Hardware Management Console Services panel.

The Enable Remote Operations is found under Customize Remote Services and Automatic Call Answering is found under Customize Auto Answer Settings.

If either of the above options are active, then this is a FINDING.
Fix Text (F-26737r1_fix)
The System Administrator will set dial-in facility to off. Do this by ensuring that both the Enable Remote Operations parameter and the Automatic Call Answering parameter are turned off.

In Check Content: Enable Remote Operations is found under Customize Remote Services and Automatic Call Answering is found under Customize Auto Answer Settings.