HP StorageWorks XP Command View Advanced Edition Common Component Security Guide Description and Operator's Guide (T1780-96308, July 2009)

Overview of Security Setup and Operation
10
An account administrator and a storage administrator are responsible for operations they must
perform for their related tasks during system operation. Therefore, persons selected as the account
administrator and storage administrator must be reliable persons who will not commit any malicious
acts.
The selected account administrator and storage administrator must prepare as follows before
operation starts.
Read the HP StorageWorks XP Command View Advanced Edition software manuals and fully
understand their contents.
Read this guide and fully understand the HP StorageWorks XP Command View Advanced
Edition Common Component security functions.
When operating the system, the administrators must perform the procedures described in this guide.
1-3-2
1-3-3
Hardware Management
The hardware required for the system to be created or operated is managed in a center. A center is
a physical area equivalent to, for example, the computer center of a company. The center must be
managed according to the following rules:
Control of entry to and exit from the computer room must be strict to prevent anyone other than
an administrator from entering the center.
A network in the center is called an internal network. A network outside the center is called an
external network. Install a firewall on the boundary between an internal network and an
external network.
Never bring any device other than hardware required for creating or operating the system into
the center. The required hardware is described in section 2-1 , and is the hardware required for
operating the software described in section 2-2 . Required hardware also includes the
application servers, storage devices, and peripherals required for system operation.
Software Management
The software required for the system to be created or operated must be managed according to the
following rules.
The software required for the system must be installed and set up as described in this guide.
To specify OS settings not covered in this guide, follow the documentation for the operating
system.
Security patches must be applied to required software, such as operating systems and
browsers.
Only the following specified HP StorageWorks XP Command View Advanced Edition products
use security functions that have been evaluated based on ISO/IEC15408.
Table 1-2 Specified XP Command View AE products
No. HP StorageWorks XP Command View Advanced
Edition software name
Version
1 XP Command View AE Device Manager 6.0.0
2 XP Command View AE Provisioning Manager 6.0.0
A client terminal must be managed in a way that prevents malicious software from being
installed when the client terminal connects to the management server. This can be
accomplished in several ways, including setting up a password on the client terminal, using the
locking function on the client terminal, or using antivirus software.