<div dir="ltr"><p class="MsoNormal" style="margin:12pt 0in;line-height:115%;font-size:11pt;font-family:Arial,sans-serif"><b><span lang="EN">Product:</span></b><span lang="EN">
BigFix Compliance</span></p>

<p class="MsoNormal" style="margin:12pt 0in;line-height:115%;font-size:11pt;font-family:Arial,sans-serif"><b><span lang="EN">Title:</span></b><span lang="EN"> BigFix
Compliance: SCM Checklist Updates for Scan Exclusions, DISA IDs, and
Environment Setup Task</span></p>

<p class="MsoNormal" style="margin:12pt 0in;line-height:115%;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN">We have released three updates to BigFix
Compliance SCM checklists, covering scan exclusion, task reliability, and
reporting accuracy. This post gives a brief overview of each, with
documentation links where available.</span></p>

<p class="MsoNormal" style="margin:12pt 0in;line-height:115%;font-size:11pt;font-family:Arial,sans-serif"><b><i><span lang="EN">Note:</span></i></b><i><span lang="EN"> These changes will be applied to checklists published going forward.
Checklists that are already published will be updated during the next refresh.</span></i></p>

<p class="MsoNormal" style="margin:12pt 0in;line-height:115%;font-size:11pt;font-family:Arial,sans-serif"><b><span lang="EN">1. Persistent scan exclusions for the
Deploy and Run Scan task (Linux checklists)</span></b></p>

<p class="MsoNormal" style="margin:12pt 0in;line-height:115%;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN">For Linux checklists, you can now
configure and store scan exclusions directly on the endpoint, so they are
reused across scan runs without re-entering them each time. Two new tasks, Add
Scan Exclusions and Remove Scan Exclusions, let you manage exclusions for
directories, mount points, filesystem types, and the inode threshold. Saved
values are applied automatically on later scans, and the Take Action inputs are
used when no saved value exists.</span></p>

<p class="MsoNormal" style="margin:12pt 0in;line-height:115%;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN">For details, see <a href="https://help.hcl-software.com/bigfix/11.0/compliance/Compliance/SCM_Users_Guide/c_modify_filesystem_scan_option_linux.html">https://help.hcl-software.com/bigfix/11.0/compliance/Compliance/SCM_Users_Guide/c_modify_filesystem_scan_option_linux.html</a></span></p>

<p class="MsoNormal" style="margin:12pt 0in;line-height:115%;font-size:11pt;font-family:Arial,sans-serif"><b><span lang="EN">2. Corrected DISA STIG ID and DISA CCI
ID (STIG checklists)</span></b></p>

<p class="MsoNormal" style="margin:12pt 0in;line-height:115%;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN">We have corrected the DISA STIG ID and
DISA CCI ID metadata for STIG checklists. Previously, the DISA STIG ID showed
inaccurate data and the DISA CCI ID was blank, both in SCA and in the check
description in the console. This has been fixed so the values now reflect the
correct data from the DISA benchmark. In SCA, the DISA CCI ID column shows the
CCI ID, the DISA VulId (STIG ID) column shows the STIG ID, and the Source ID
column shows the Vulnerability ID. The same information is available in the
check description in the console. This makes it easier to cross-reference
findings against external scanners and DISA guidance.</span></p>

<p class="MsoNormal" style="margin:12pt 0in;line-height:115%;font-size:11pt;font-family:Arial,sans-serif"><b><span lang="EN">3. More reliable Environment Setup
task (Middleware and NIX checklists)</span></b></p>

<p class="MsoNormal" style="margin:12pt 0in;line-height:115%;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN">For Middleware and NIX checklists, the
Environment Setup task now uses an atomic results refresh. Previously, the task
removed the existing results before generating new ones, which could briefly
cause checks to report as Non-Compliant or Not Applicable if the client
evaluated during that window. The task now keeps the existing results until the
new results are fully generated, then swaps them in, so a valid set of results
is always available. Each result also carries a timestamp showing when it was
collected.</span></p>

<p class="MsoNormal" style="margin:12pt 0in;line-height:115%;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN">For details, see
<a href="https://help.hcl-software.com/bigfix/11.0/compliance/Compliance/SCM_Users_Guide/c_environment_setup-task_mw.html">https://help.hcl-software.com/bigfix/11.0/compliance/Compliance/SCM_Users_Guide/c_environment_setup-task_mw.html</a></span></p>

<p class="MsoNormal" style="margin:12pt 0in;line-height:115%;font-size:11pt;font-family:Arial,sans-serif"><b><span lang="EN">More information</span></b></p>

<p class="MsoNormal" style="margin:12pt 0in;line-height:115%;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN">To learn more about BigFix Compliance SCM
checklists, see the BigFix Forum:
<a href="https://forum.bigfix.com/c/release-announcements/scm-checklists/86">https://forum.bigfix.com/c/release-announcements/scm-checklists/86</a></span></p>

<p class="MsoNormal" style="margin:12pt 0in;line-height:115%;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN">We hope you find these improvements
useful, and we welcome your feedback.</span></p>

<p class="MsoNormal" style="margin:12pt 0in;line-height:115%;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN">The BigFix Compliance team</span></p>

<p class="MsoNormal" style="margin:0in;line-height:115%;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN"> </span></p></div>