STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 4 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to IBM Hardware Management Console (HMC) STIG

V-25386

CAT II (Medium)

Access to the Hardware Management Console (HMC) must be restricted by assigning users proper roles and responsibilities.

Rule ID

SV-31555r2_rule

STIG

IBM Hardware Management Console (HMC) STIG

Version

V1R5

CCIs

CCI-000225

Discussion

Access to the HMC if not properly controlled and restricted by assigning users proper roles and responsibilities, could allow modification to areas outside the need-to-know and abilities of the individual resulting in a bypass of security and an altering of the environment. This would result in a loss of secure operations and can cause an impact to data operating environment integrity.

Check Content

Have the System Administrator verify to the reviewer that the Roles and Responsibilities assigned are assigned to the proper individuals by their areas of responsibility.<br /><br />Note: Sites must have a list of valid HMC users, indicating their USERID, Date of DD2875, and roles and responsibilities.<br /><br />Have the System Administrator verify to the reviewer that the Roles and Responsibilities assigned are assigned to the proper individuals by their areas of responsibility.<br /><br />To display user roles chose User Profiles and then select the user for modification. View Task Roles and Manager Resources Roles.<br /><br />If the HMC user-IDs displayed by the System Administrator are not properly assigned by Roles and Responsibilities, then this is a FINDING.<br />

Fix Text

Have the System Administrator using the list user IDs and responsibilities, validate that each user is properly specified in the HMC based on his/her roles and responsibilities.<br /> <br />Note: Sites must have a list of valid HMC users, indicating their USERID, Date of DD2785, roles and responsibilities<br /><br />To display user roles choose User Profiles and then select the user for modification. View Task Roles and Manager Roles.<br />