HPE Nimble must be configured to disable HPE InfoSight.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-252902HPEN-NM-000221SV-252902r960966_ruleCCI-000382medium
Description
DoD requires that the Mission Owner uses only the cloud services offering listed in either the FedRAMP or DISA PA DoD Cloud Catalog to host Unclassified, public-releasable, DoD information. HPE InfoSight data collection is disabled by default in the HPE Nimble. Users must not enable it.
STIGDate
HPE Nimble Storage Array NDM Security Technical Implementation Guide2024-06-20

Details

Check Text (C-252902r960966_chk)

Navigate to Administration >> Alerts and Monitoring page of the storage array management interface. Verify the checkbox is not checked. If HPE InfoSight is enabled, this is a finding.

Fix Text (F-56307r822431_fix)

In HPE Nimble Storage arrays, data collection is disabled by default. Navigate to Administration >> Alerts and Monitoring page of the storage array management interface. Uncheck the checkbox.