HPE Nimble must be configured to disable HPE InfoSight.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-252902 | HPEN-NM-000221 | SV-252902r960966_rule | CCI-000382 | medium |
| Description | ||||
| DoD requires that the Mission Owner uses only the cloud services offering listed in either the FedRAMP or DISA PA DoD Cloud Catalog to host Unclassified, public-releasable, DoD information. HPE InfoSight data collection is disabled by default in the HPE Nimble. Users must not enable it. | ||||
| STIG | Date | |||
| HPE Nimble Storage Array NDM Security Technical Implementation Guide | 2024-06-20 | |||
Details
Check Text (C-252902r960966_chk)
Navigate to Administration >> Alerts and Monitoring page of the storage array management interface. Verify the checkbox is not checked.
If HPE InfoSight is enabled, this is a finding.
Fix Text (F-56307r822431_fix)
In HPE Nimble Storage arrays, data collection is disabled by default.
Navigate to Administration >> Alerts and Monitoring page of the storage array management interface.
Uncheck the checkbox.