Rule ID
SV-6792r1_rule
Version
V2R5
CCIs
The changing of passwords from the default value blocks malicious users with knowledge of the default passwords for the manufacturer's SAN Management software from creating a denial of service by disrupting the SAN or reconfigure the SAN topology leading to a compromise of sensitive data. The IAO/NSO will ensure that the manufacturer’s default passwords are changed for all SAN management software.
The reviewer will, with the assistance of the IAO/NSO, verify that the manufacturer’s default passwords have been changed for all SAN management software.
Develop a plan to change manufacturer’s default passwords for all SAN management software. Obtain CM approval of the plan and implement the plan.