STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 4 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to IBM Hardware Management Console (HMC) STIG

V-24378

CAT II (Medium)

Unauthorized partitions must not exist on the system complex.

Rule ID

SV-30052r2_rule

STIG

IBM Hardware Management Console (HMC) STIG

Version

V1R5

CCIs

CCI-002101

Discussion

The running of unauthorized Logical Partitions (LPARs) could allow a “Trojan horse” version of the operating environment to be introduced into the system complex. This could impact the integrity of the system complex and the confidentiality of the data that resides in it.

Check Content

Using the Hardware Management Console, do the following:<br /><br />Access the Change LPAR Control Panel. (This will list the LPARs.)<br /><br />Compare the partition names listed on the Partition Page to the names entered on the Central Processor Complex Domain/LPAR Names table.  <br />Note: Each site should maintain a list of valid LPARS that are configured on thier system , what operating system, and the purpose of each LPAR.<br />If unauthorized partitions exist on the system complex and the deviation is not documented, this is a FINDING. 

Fix Text

Review the LPARs on the system and remove any unauthorized LPARs. If a deviation exists, the system administrator will provide written justification for the deviation.<br /><br />This will be displayed by using the Change LPAR Control Panel.