<div class="socmaildefaultfont" dir="ltr" style="font-family:"Helvetica Neue", Helvetica, Arial, sans-serif;font-size:10.5pt" ><div dir="ltr" style="font-family:"Helvetica Neue", Helvetica, Arial, sans-serif;font-size:10.5pt" ><div dir="ltr" style="font-family:"Helvetica Neue", Helvetica, Arial, sans-serif;font-size:10.5pt" ><div dir="ltr" ><div style="background:white;" ><strong><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >Product:</span></span></span></strong></div>
<div style="background:white;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >IBM BigFix Compliance</span></span></span></div>
<div style="background:white;" > </div>
<div style="background:white;" ><strong><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >Title:</span></span></span></strong></div>
<div style="background:white;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >Updated Security Configuration Management (SCM) DISA STIG Checklist for Solaris 11</span></span></span></div>
<div style="background:white;" > </div>
<div style="background:white;" ><strong><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >Security Benchmark:</span></span></span></strong></div>
<div style="background:white;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >Solaris 11 SPARC Manual STIG, V1, R8</span></span></span></div>
<div style="background:white;" > </div>
<div style="background:white;" ><strong><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >Details:</span></span></span></strong></div>
<ul>        <li style="background:white;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >IBM is pleased to announce the availability of an updated Security Configuration Management (SCM) checklist for IBM BigFix Compliance.  The checklist is based on DISA STIG Solaris 11, V1, R8</span></span></span></li>        <li style="background:white;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >This checklist contains a number of checks to evaluate the security configurations of your Solaris 11 endpoints based on the STIG.  Both analysis and and remediation checks are included<em>.</em></span></span></span></li>        <li style="background:white;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >Some of the checks allow you to use the parameterized setting to enable customization for compliance evaluation. Note that parameterization and remediation actions require the creation of a custom site.  </span></span></span></li></ul>
<div style="background:white;" > </div>
<div style="background:white;" ><strong><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >Published Site:</span></span></span></strong></div>
<div style="background:white;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >DISA STIG Checklist for </span></span></span><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >Solaris 11, site version 3</span></span></span></div>
<div style="background:white;" ><em><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >*The site version is provided for air-gap customers.</span></span></span></em></div>
<div style="background:white;" > </div>
<div style="background:white;" ><strong><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >Release Notes:</span></span></span></strong></div>
<div style="text-autospace:none;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >Changed checks:</span></span></span></div>
<ul>        <li style="text-autospace:none;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >SOL-11.1-010400 Check that p_minfree is not equal to 2 or greater.</span></span></span></li>        <li style="text-autospace:none;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >SOL-11.1-020140 Check for service /service/network/tftp.</span></span></span></li>        <li style="text-autospace:none;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >SOL-11.1-020160 Check for service /service/network/uucp.</span></span></span></li>        <li style="text-autospace:none;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >SOL-11.1-040030 Check for minimum days less than 1.</span></span></span></li>        <li style="text-autospace:none;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >SOL-11.1-040170 Allow for less than or equal time intervals.</span></span></span></li>        <li style="text-autospace:none;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >SOL-11.1-050090 The check is slightly different if OS level is > 5.11.1.</span></span></span></li>        <li style="text-autospace:none;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >SOL-11.1-050470 This check now does more detailed analysis of the </span></span></span></li>        <li style="text-autospace:none;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >settings, please see the documentation for details.</span></span></span></li>        <li style="text-autospace:none;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >SOL-11.1-070080 Users gdm and upnp only excluded if no gui installed.</span></span></span></li>        <li style="text-autospace:none;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >SOL-11.1-070090 No longer excludes the following users: nobody, </span></span></span></li>        <li style="text-autospace:none;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >noaccess, aiuser, nobody4.  Remediation has been removed since by </span></span></span></li>        <li style="text-autospace:none;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >default the home directory for these users is / and you would end up </span></span></span></li>        <li style="text-autospace:none;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >with one of them owning it unless you give those users their own home </span></span></span></li>        <li style="text-autospace:none;" > </li>        <li style="text-autospace:none;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >SOL-11.1-070130 Added ikeuser to SYSTEM_ACCOUNTS in params file.</span></span></span></li>        <li style="text-autospace:none;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >SOL-11.1-080040 Coreadm may now allow logging to be enabled.</span></span></span></li>        <li style="text-autospace:none;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >SOL-11.1-100020 If the output of zonecfg has a setting for limitpriv and </span></span></span></li>        <li style="background:white;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >it is not "default" then that is a finding.</span></span></span></li></ul>
<div style="background:white;" > </div>
<div style="background:white;" ><strong><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >Actions to Take:</span></span></span></strong></div>
<div style="background:white;" ><span style="color:#353535;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >If you have not subscribed to the site above, you can use the License Overview dashboard to enable and gather the site. Note that you must be entitled to the new content and you are using IBM BigFix version 9.2 and later.</span></span></span></div>
<div style="background:white;" > </div>
<div style="background:white;" ><strong><span style="background:white;" ><span style="color:black;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >More information: </span></span></span></span></strong></div>
<div style="background:white;" ><span style="background:white;" ><span style="color:black;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >To know more about IBM BigFix Compliance SCM checklists, please see</span></span></span></span></div>
<ul>        <li style="color:#121212;background:white;" ><span style="color:black;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >IBM Developer Works: </span></span></span><span style="color:windowtext;" ><a href="https://www.ibm.com/developerworks/community/wikis/home?lang=en%22%20%5Cl%20%22!/wiki/Tivoli%20Endpoint%20Manager/page/SCM%20Checklists%22%20%5Ct%20%22_blank" target="_blank" ><span style="color:black;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >https://www.ibm.com/developerworks/community/wikis/home?lang=en#!/wiki/Tivoli%20Endpoint%20Manager/page/SCM%20Checklists</span></span></span></a></span></li></ul>
<ul>        <li style="color:#121212;background:white;" ><span style="color:black;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >SCM Checklist Deployment: </span></span></span><span style="color:windowtext;" ><a href="https://www.ibm.com/developerworks/community/wikis/home?lang=en%22%20%5Cl%20%22!/wiki/Tivoli%20Endpoint%20Manager/page/SCM%20Checklist%20Deployment%20Best%20Practices" target="_blank" ><span style="color:black;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >https://www.ibm.com/developerworks/community/wikis/home?lang=en#!/wiki/Tivoli%20Endpoint%20Manager/page/SCM%20Checklist%20Deployment%20Best%20Practices</span></span></span></a></span></li></ul>
<ul>        <li style="color:#121212;background:white;" ><span style="color:black;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >IBM Blog for Checklist Release Announcement: </span></span></span><span style="color:windowtext;" ><a href="https://www.ibm.com/developerworks/community/groups/service/html/community/updates?communityUuid=a1a33778-88b7-452a-9133-c955812f8910&filter=all" target="_blank" ><span style="color:black;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >https://www.ibm.com/developerworks/community/groups/service/html/community/updates?communityUuid=a1a33778-88b7-452a-9133-c955812f8910&filter=all</span></span></span></a></span></li></ul>
<ul>        <li style="color:#121212;background:white;" ><span style="color:black;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >Bigfix forums: </span></span></span><span style="color:windowtext;" ><a href="https://forum.bigfix.com/" target="_blank" ><span style="color:black;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >https://forum.bigfix.com/</span></span></span></a></span></li></ul>
<div style="color:#121212;background:white;" > </div>
<div><br><span style="background:white;" ><span style="color:black;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" >We hope you find this latest release of SCM content useful and effective. Thank you!</span></span></span></span><br><em><span style="background:white;" ><span style="color:black;" ><span style="font-family:helvetica;" ><span style="font-size:10.5pt;" > -- The IBM BigFix Compliance team</span></span></span></span></em></div>
<div> </div></div></div></div></div><BR>