<div dir="ltr"><p class="MsoNormal" style="margin:0in 0in 14pt;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Calibri,sans-serif"><b><span style="font-size:12pt;font-family:Arial,sans-serif">Product:</span></b><span style="font-size:12pt;font-family:Arial,sans-serif"><br>
BigFix Compliance</span></p>
<p class="MsoNormal" style="margin:14pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Calibri,sans-serif"><b><span style="font-size:12pt;font-family:Arial,sans-serif">Title:</span></b><span style="font-size:12pt;font-family:Arial,sans-serif"><br>
Updated </span><span style="font-size:12pt;font-family:Arial,sans-serif;color:black">CIS
Checklist for AIX 7.x to support a more recent version of the benchmark</span><b><span style="font-size:12pt;font-family:Arial,sans-serif"></span></b></p>
<p class="MsoNormal" style="margin:14pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Calibri,sans-serif"><b><span style="font-size:12pt;font-family:Arial,sans-serif">Security
Benchmark:</span></b><span style="font-size:12pt;font-family:Arial,sans-serif"><br>
CIS IBM AIX 7 Benchmark, v1.1.0</span></p>
<p class="MsoNormal" style="margin:14pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Calibri,sans-serif"><b><span style="font-size:12pt;font-family:Arial,sans-serif">Published
Sites:</span></b><span style="font-size:12pt;font-family:Arial,sans-serif"><br>
</span><span style="font-size:12pt;font-family:Arial,sans-serif;color:black">CIS Checklist for AIX 7.x</span><span style="font-size:12pt;font-family:Arial,sans-serif">, site version 6<br>
(The site version is provided for air-gap customers.)</span></p>
<p class="MsoNormal" style="margin:14pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Calibri,sans-serif"><b><span style="font-size:12pt;font-family:Arial,sans-serif">Details:</span></b><span style="font-size:12pt;font-family:Arial,sans-serif"> </span></p>
<ul style="margin-top:0in;margin-bottom:0in" type="disc">
<li class="MsoNormal" style="margin:14pt 0in 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:12pt;font-family:Arial,sans-serif;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial">Total <a name="_Hlk205997733">New
Fixlets</a>: 12</span></li>
<li class="MsoNormal" style="margin:0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:12pt;font-family:Arial,sans-serif;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial">Total <a name="_Hlk205997753">Updated Fixlets</a>:
9</span></li>
<li class="MsoNormal" style="margin:0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:12pt;font-family:Arial,sans-serif;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial">Total Fixlets in Site: 213</span></li>
</ul>
<p class="MsoNormal" style="margin:0in 0in 8pt 0.5in;line-height:107%;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial"><br>
<b>New Fixlets</b></span><b><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif">:</span></b><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif"><br>
</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif">cis-4.1.1.1 - Ensure access on root
user smit.log is configured<br>
cis-1.3.3.2 - Ensure SSH client and server packages are installed on AIX 7.2<br>
cis-3.5 - Ensure there are no group staff writable files</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif"><br>
</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif">cis-4.2.8 - Ensure snmpd is not
installed</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif"><br>
</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif">cis-4.3.1.6 - Ensure snapp is not
installed</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif"><br>
</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif">cis-4.3.1.7 - Ensure NIM master is
not installed</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif"><br>
</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif">cis-4.3.2.2 - Ensure dhcp client
services are not in use</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif"><br>
</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif">cis-4.4.1.6 - Ensure access by root
over nfs is disabled or blocked</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif"><br>
</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif">cis-4.7.6 - Ensure TMOUT is
configured</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif"><br>
</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif">cis-4.7.7 - Unattended terminal
session timeout is 900 seconds (or less) – readonly</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif"><br>
</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif">cis-5.2.6 - Ensure password
expiration is configured</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif"><br>
</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif">cis-5.2.10 - Ensure number of
characters changed in new password is configured</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif"><br>
<br>
</span><b><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif">Updated Fixlets:</span></b><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif"><br>
</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif">cis-2.5 - Ensure Unauthorized
Applications are reported</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif"><br>
</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif">cis-4.1.2.5 - Ensure access to
/etc/security is configured</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif"><br>
</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif">cis-4.4.1.7 - Ensure secure RPC
authentication is enabled</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif"><br>
</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif">cis-4.6.1.7 - Ensure CDE
screensaver lock is enabled</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif"><br>
</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif">cis-4.6.1.8 - Ensure CDE login
screen hostname is masked</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif"><br>
</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif">cis-4.7.1 - Ensure herald is
configured</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif"><br>
</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif">cis-5.1.6 - Ensure all local user
accounts have valid stanzas in /etc/security/passwd</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif"><br>
</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif">cis-4.6.1.11 - Ensure access to
Xresources is configured</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif"><br>
</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif">cis-4.2.7 - Ensure legacy remote
daemon support is not available</span><span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif"></span></p>
<p class="gmail-MsoListParagraphCxSpFirst" style="margin:0in 0in 0in 0.5in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:12pt;font-family:Symbol">·<span style="font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;font-size-adjust:none;font-kerning:auto;font-feature-settings:normal;font-stretch:normal;font-size:7pt;line-height:normal;font-family:"Times New Roman""> </span></span><span style="font-size:12pt;font-family:Arial,sans-serif">Introduced continuous compliance for 40% of checks using
BigFix relevance</span></p>
<p class="gmail-MsoListParagraphCxSpLast" style="margin:0in 0in 0in 0.5in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:12pt;font-family:Symbol">·<span style="font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;font-size-adjust:none;font-kerning:auto;font-feature-settings:normal;font-stretch:normal;font-size:7pt;line-height:normal;font-family:"Times New Roman""> </span></span><span style="font-size:12pt;font-family:Arial,sans-serif">Both analysis and remediation checks are included</span></p>
<ul style="margin-top:0in;margin-bottom:0in" type="disc">
<li class="MsoNormal" style="margin:0in 0in 12pt;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:12pt;font-family:Arial,sans-serif">Some
of the checks allow you to use the parameterized setting to enable
customization for compliance evaluation. Note that parameterization and
remediation actions require the creation of a custom site.</span></li>
</ul>
<p class="MsoNormal" style="margin:14pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Calibri,sans-serif"><b><span style="font-size:12pt;font-family:Arial,sans-serif">Actions to
take:</span></b><span style="font-size:12pt;font-family:Arial,sans-serif"></span></p>
<p class="MsoNormal" style="margin:14pt 0in 0in 0.5in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:10pt;font-family:"Noto Sans Symbols"">●<span style="font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;font-size-adjust:none;font-kerning:auto;font-feature-settings:normal;font-stretch:normal;font-size:7pt;line-height:normal;font-family:"Times New Roman"">
</span></span><span style="font-size:12pt;font-family:Arial,sans-serif">To subscribe to the above site,
you can use the License Overview Dashboard to enable and gather the site. Note
that you must be entitled to the BigFix Compliance product, and you must be
using BigFix version 10 and later.</span></p>
<p class="MsoNormal" style="margin:0in 0in 14pt 0.5in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:10pt;font-family:"Noto Sans Symbols"">●<span style="font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;font-size-adjust:none;font-kerning:auto;font-feature-settings:normal;font-stretch:normal;font-size:7pt;line-height:normal;font-family:"Times New Roman"">
</span></span><span style="font-size:12pt;font-family:Arial,sans-serif">If you use custom sites, update
your custom sites accordingly to use the latest content. You can synchronize
your content by using the Synchronize Custom Checks wizard. For more
information, see<br>
</span><span style="color:black"><a href="https://help.hcl-software.com/bigfix/11.0/compliance/Compliance/SCM_Users_Guide/c_using_synchronize_custom_checks_wiz.html"><span style="font-size:12pt;font-family:Arial,sans-serif">https://help.hcl-software.com/bigfix/11.0/compliance/Compliance/SCM_Users_Guide/c_using_synchronize_custom_checks_wiz.html</span></a></span><span style="font-size:12pt;font-family:Arial,sans-serif"></span></p>
<p class="MsoNormal" style="margin:14pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Calibri,sans-serif"><b><span style="font-size:12pt;font-family:Arial,sans-serif">More
information:</span></b><span style="font-size:12pt;font-family:Arial,sans-serif"><br>
To know more about the BigFix Compliance SCM checklists, please see the
following resources:</span></p>
<p class="MsoNormal" style="margin:14pt 0in 0in 0.5in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:10pt;font-family:"Noto Sans Symbols"">●<span style="font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;font-size-adjust:none;font-kerning:auto;font-feature-settings:normal;font-stretch:normal;font-size:7pt;line-height:normal;font-family:"Times New Roman"">
</span></span><span style="font-size:12pt;font-family:Arial,sans-serif">BigFix Forum:<br>
</span><span style="color:black"><a href="https://forum.bigfix.com/c/release-announcements/compliance"><span style="font-size:12pt;font-family:Arial,sans-serif;color:rgb(0,136,204)">https://forum.bigfix.com/c/release-announcements/compliance</span></a></span><span style="font-size:12pt;font-family:Arial,sans-serif"></span></p>
<p class="MsoNormal" style="margin:0in 0in 14pt 0.5in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:10pt;font-family:"Noto Sans Symbols"">●<span style="font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;font-size-adjust:none;font-kerning:auto;font-feature-settings:normal;font-stretch:normal;font-size:7pt;line-height:normal;font-family:"Times New Roman"">
</span></span><span style="font-size:12pt;font-family:Arial,sans-serif">BigFix Compliance SCM Checklists:<br>
</span><span style="color:black"><a href="https://bigfix-wiki.hcltechsw.com/wikis/home?lang=en-us#!/wiki/BigFix%20Wiki/page/SCM%20Checklists"><span style="font-size:12pt;font-family:Arial,sans-serif;color:rgb(0,136,204)">https://bigfix-wiki.hcltechsw.com/wikis/home?lang=en-us#!/wiki/BigFix%20Wiki/page/SCM%20Checklists</span></a></span><span style="font-size:12pt;font-family:Arial,sans-serif"></span></p>
<span style="font-size:12pt;line-height:107%;font-family:Arial,sans-serif">We hope you find this latest release of SCM
content useful and effective. Thank you!<br>
<i>– The BigFix Compliance team</i></span></div>