AIX

AIX

Connect with fellow AIX users and experts to gain knowledge, share insights, and solve problems.

 View Only
  • 1.  Where is the CIS security benchmark scripts for AIX ?

    Posted Wed August 21, 2024 04:40 AM
    Edited by YUKARI KOBAYASHI Wed August 21, 2024 05:55 AM

    Could anyone tell me about CIS security benchmark check scripts?

    My customer wants to get the CIS security check benchmark scripts for AIX, but I don' t know it much...

    Is it available for customer? 

    Where can be it download?



    ------------------------------
    YUKARI KOBAYASHI
    ------------------------------



  • 2.  RE: Where is the CIS security benchmark scripts for AIX ?

    Posted Wed August 21, 2024 05:35 AM

    I found the very older zip files for AIX 7.1 on CIS Workbench site (registration of this site is required.)

    Does anyone know the latest one for AIX 7.2 or AIX 7.3?



    ------------------------------
    YUKARI KOBAYASHI
    ------------------------------



  • 3.  RE: Where is the CIS security benchmark scripts for AIX ?

    Posted Wed August 21, 2024 02:07 PM

    CIS Downloads (cisecurity.org)

    "https://downloads.cisecurity.org/#/"

    7.2 is available.

    7.3 will be available in first week of Oct 2024.



    ------------------------------
    Anoop Mourya
    ------------------------------



  • 4.  RE: Where is the CIS security benchmark scripts for AIX ?

    Posted Thu August 22, 2024 06:08 AM

    Hi Anoop,

    Thank you very much for your information.

    I could understand that the current latest version is for AIX 7.2 and downloaded the  "CIS_IBM_AIX_7.2_Benchmark_v1.1.0.pdf".

    I hope the one for AIX 7.3 will be released month after next.

    Best Regards,



    ------------------------------
    YUKARI KOBAYASHI
    ------------------------------



  • 5.  RE: Where is the CIS security benchmark scripts for AIX ?

    Posted Wed October 09, 2024 02:27 AM

    Hello Anoop,

    >7.3 will be available in first week of Oct 2024.

    How is the AIX 7.3 version of CIS security benchmark ?



    ------------------------------
    YUKARI KOBAYASHI
    ------------------------------



  • 6.  RE: Where is the CIS security benchmark scripts for AIX ?

    Posted Thu August 22, 2024 02:54 AM

    Hi Yukari,

    Pls take a look if you are Entitled to download PowerSC product for AIX (and Linux on Power)

    https://www.ibm.com/products/powersc

    https://www.ibm.com/docs/en/powersc-standard/2.2?topic=concepts

    Once you install PowerSC client on AIX, you will get CIS scripts / XML files in your AIX systems /etc/security/aixpert/custom folder; and you can implement / view rules with pscxpert cmd :

    https://www.ibm.com/docs/en/powersc-standard/2.2?topic=automation-configuring-compliance-from-cli

    More info on the CIS settings:

    https://www.ibm.com/docs/en/powersc-standard/2.2?topic=scac-center-internet-security-cis-benchmarks-compliance-aix-72

    AIX7.2 scripts are the latest ones like Snoop said; 7.3 coming soon (I hope) 

    In the next? PowerSC release there might be also enhancements on the Security reporting on AIX :

    https://ibm-power-systems.ideas.ibm.com/ideas/PSC-I-39

    Hope this helps,

    Br,

    tommi



    ------------------------------
    Tommi Sihvo, Lead Service Architect
    Tietoevry Tech Services
    email tommi.sihvo@tietoevry.com mobile +358 (0)40 5180 Finland
    ------------------------------



  • 7.  RE: Where is the CIS security benchmark scripts for AIX ?

    Posted Thu August 22, 2024 06:56 AM

    Hi Tommi,

    Thank you for detailed information. 

    I would like to get more information on this topic, if you could?

    My customer is looking for scripts to check whether or not complies with CIS security.

    1. I found there were some checking scripts on CIS Workbench site. For example, these following zip files is still downloadable, though it's 7 or  10 years old. I think that these are scripts for checking. Do you know if the latest versions of there are provided somewhere?

    • CIS_IBM_AIX_7.1_Benchmark_v1.1.0_AIXPERT_7.1.tar
    • CIS_IBM_AIX_7.1_Benchmark_v1.1.0_Remediation_Kit.zip

    2. Can the scripts included in PowerSC only do checking of CIS security compliance?  You said "implement / view rules"...



    ------------------------------
    YUKARI KOBAYASHI
    ------------------------------



  • 8.  RE: Where is the CIS security benchmark scripts for AIX ?

    Posted Thu August 22, 2024 07:26 AM

    Hi,

    There is an own forum for PowerSC :

    PowerSC

    I know that the PowerSC developers are reading / contributing there as well, so best way to have 100% accurate answers is to put a post there & get contact with them. 

    We have always implemented the CIS rules before verifying the environment, but I think one can

    verify existing system (against CIS rules without actually implementing them), by pscxpert -c parameter:

    pscxpert for linux command

    Example: 

    pscxpert -c -P /etc/security/aixpert/custom/CISv2_Lev1.xml

    Like stated, verify if your company is Entitled to use / download PowerSC already, or otherwise you need to for example request a 90 days trial :

    PowerSC 2.2 Trial

    Ibm remove preview
    PowerSC 2.2 Trial
    View this on Ibm >

    Ibm remove preview
    pscxpert for linux command
    View this on Ibm >

    Ibm remove preview
    PowerSC
    View this on Ibm >



    ------------------------------
    Tommi Sihvo, Lead Service Architect
    Tietoevry Tech Services
    email tommi.sihvo@tietoevry.com mobile +358 (0)40 5180 Finland
    ------------------------------



  • 9.  RE: Where is the CIS security benchmark scripts for AIX ?

    Posted Thu August 22, 2024 08:50 AM

    Hi Tommi,

    Thank you very much for the useful information.

    I will put my questions to the forum for PowerSC within a few days and also consider requesting the 90 days trial of PowerSC.

    Thank you again.



    ------------------------------
    YUKARI KOBAYASHI
    ------------------------------