HP StorageWorks P9000 Command View Advanced Edition Software Common Component Security Guide

Preparations before system operation
33
5 Preparations before system operation
This chapter describes the preparations required for operating a system in the configuration
evaluated based on Common Criteria for Common Component.
Notification from the System Integrator (see section 5-1 )
Determining and Updating Rules Related to Security Functions (see section 5-2 )
Notifying Users (see section 5-3 )
5-1 Notification from the system integrator
The account administrator must obtain information necessary for system operation from the system
integrator in a secure and safe way. The following information is necessary information.
Information required for using the system
Method for using client terminals for access and notes on use (for example, not installing
unnecessary software)
Authentication information (user ID and password) that the account administrator must enter in
the User Login window to initiate access
Information required for performing operations
Operation rules required for determining and updating security parameters
Rules necessary for managing accounts (for example, quickly deleting accounts that are no
longer needed)
The account administrator must also manage his or her own authentication information properly (for
example, promptly changing the password) according to the instructions provided in subsection 1-3-
5 .
Notes on use
The system integrator must notify the account administrator about the management of passwords
according to the instructions provided in subsection 1-3-5 .
The system integrator must notify the account administrator that unnecessary software is not to be
installed on a client terminal.
5-2 Determining and updating rules related to
security functions
Obtain and examine the information required for correctly operating the Common Component
security functions, and decide which information to use. If existing rules must be changed, consider
the changes that need to be made. The information determined here will be set during system
operation.
The following items need to be examined:
Storage administrator information
Determine the storage administrator information that the account administrator will register during
system operation. The storage administrator must be selected based on subsection 1-3-1 .
Updating the security parameter settings