STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 5 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to IBM Hardware Management Console (HMC) STIG

V-25247

CAT II (Medium)

DCAF Console access must require a password to be entered by each user.

Rule ID

SV-31292r3_rule

STIG

IBM Hardware Management Console (HMC) STIG

Version

V1R5

CCIs

CCI-000764

Discussion

The DCAF Console enables an operator to access the ESCON Director Application remotely. Access to a DCAF Console by unauthorized personnel could result in varying of ESCON Directors online or offline and applying configuration changes. Unrestricted use by unauthorized personnel could lead to bypass of security, unlimited access to the system, and an altering of the environment. This would result in a loss of secure operations and will impact data operating integrity of the environment. NOTE: Many newer installations no longer support the ESCON Director Application. For installations not supporting the ESCON Director Application, this check is not applicable.

Check Content

If the ESCON Director Application is present, have the System Administrator attempt to sign on to the DCAF Console and validate that a password is required, otherwise, this check is not applicable.<br /><br />If sign-on access to the DCAF Console does not require a password this is a finding.<br />

Fix Text

Have the System Administrator review access authorization to DCAF Consoles. Ensure that all personnel are required to enter a password.<br /><br />Remote access to the LAN may be provided through DCAF via a LAN or modem connection.<br />DCAF passwords should be implemented to prevent unauthorized access.<br /><br />