Hi,
Thanks for raising this topic again Peter!
Totally agree on your thoughts & concerns; I raised this idea:
AIX Security reporting tool
about a year ago, last update seems to be August/2024, so hoping to hear news regarding this from PowerSC team soon as well,
Br,
tommi
------------------------------
Tommi Sihvo, Lead Service Architect
Tietoevry Tech Services
email
tommi.sihvo@tietoevry.com mobile +358 (0)40 5180 Finland
------------------------------
Original Message:
Sent: Wed February 26, 2025 04:09 AM
From: Peter Furtado
Subject: AIX 7.3 CIS benchmark & Tools + PowerSC (again :)
Hello Anoop,
We're looking into how well our AIX systems are keeping up with security best practices, especially the CIS IBM AIX benchmarks. We saw that the newest benchmark for AIX 7.2 (version 1.1.0) came out on September 30, 2023.
We're wondering:
Are the CISv2_Lev1 and CISv2_Lev2 profiles in PowerSC2.2 based on that latest AIX 7.2 CIS version?
How well does PowerSC match up with that CIS benchmark for AIX 7.3?
Just trying to make sure we're on the right track with security.
Best regards,
------------------------------
Peter Furtado
Original Message:
Sent: Fri February 02, 2024 03:23 AM
From: Anoop Mourya
Subject: AIX 7.3 CIS benchmark & Tools + PowerSC (again :)
Estimated date for AIX benchmark 7.x(7.3) is May 2024
Regards
Anoop
------------------------------
Anoop Mourya
Original Message:
Sent: Tue January 30, 2024 12:44 AM
From: Tommi Sihvo
Subject: AIX 7.3 CIS benchmark & Tools + PowerSC (again :)
Hi
Thanks for the replies Debbie!
Any timetable estimate when AIX7.3 benchmark would be available?
Br,
t
------------------------------
Tommi Sihvo, Lead Service Architect
Tietoevry, Compute Services
email tommi.sihvo@tietoevry.com mobile +358 (0)40 5180 Finland
Original Message:
Sent: Mon January 29, 2024 09:58 AM
From: Debbie Quick
Subject: AIX 7.3 CIS benchmark & Tools + PowerSC (again :)
Hi @Tommi Sihvo,
- The CIS benchmark document is not yet available for IBM AIX 7.3. Once the document is available, the Rocket team will work on updating the compliance profile in IBM PowerSC.
- Security reports for AIX can be generated from IBM PowerSC. I'm not sure if we have any additional tools for doing so. Perhaps @Madan Chukka might have additional information for you.
- @Madan Chukka, can you also help with this question?
Thanks, Debbie
------------------------------
Debbie Quick
Original Message:
Sent: Fri January 19, 2024 03:30 AM
From: Tommi Sihvo
Subject: AIX 7.3 CIS benchmark & Tools + PowerSC (again :)
Hello!
Any updates on possibilities to get proper AIX 7.3 CIS benchmark / baseline / Reporting Tool ?
Since latest CIS-CAT does not have AIX benchmark at all , so currently we are forced to use the old CIS-CAT Pro Assessor, v3 (which is unsupported), to be able to create security reports out of AIX :(
And I assume PowerSC as well contains CIS template for AIX 7.2 only?
Or are there some new tools which I am not aware of ?
And does anyone know whether there would be any possibility to have AIX support for Openscap Tool?
So the main questions would be :
- Is there (or will there be) CIS baseline/benchmark or PowerSC template for AIX 7.3
- What is the best Tool to create security reports from AIX systems?
- Who / What org needs to be contacted for RFE on AIX support for Openscap Tool ?
------------------------------
Tommi Sihvo, Lead Service Architect
Tietoevry, Compute Services
email tommi.sihvo@tietoevry.com mobile +358 (0)40 5180 Finland
------------------------------