Spectrum recommends IBM Compliance Expert for AIX security…

By admin • December 18th, 2009

Highlights

* Easily set dozens of AIX security configuration settings to match external compliance standards
* Includes profiles with recommended system settings for the Payment Card Industry Data Security Standard and the US Department of Defense Security Technical Implementation Guide
* Simple command line interface minimizes training requirements and administrative workload
* Reports that simplify demonstrating compliance
* Support for AIX 6 and AIX V5.3

Insuring system compliance with third party security standards is often a labor intensive and time consuming process.

Compliance standards are typically long, complex documents that are difficult to translate into the appro-priate AIX operating system settings.

And, since standards often encom-pass many different area of operating system configuration, an admin-istrator frequently had to use several different administrative interfaces to configure a system to support standards compliance. The IBM Compliance Expert Ex-press Edition is designed to simplify the administrative effort associated with complying with two common ex-ternal standards.

The Compliance Expert Express Edition consists of a simple com-mand line interface and preconfig-ured compliance profiles for the Payment Card Industry Data Secu-rity Standard Version 2 (PCI DSS) and the US Department of Defense Security Technical Implementation Guide for UNIX (DoD STIG) stan-dards.

Administrators can use the IBM Compliance Expert Express Edition to set all relevant system parame-ters required by these standards.

The profiles include recommended settings for several areas of AIX configuration, including aspects such as minimum password length, password reuse, number of unsuc-cessful login attempts before lockout and other configuration aspects.

The administrator can run reports that show whether the system is configured to be compliant. These reports can alert the administrator to unauthorized parameter changes and to provide a foundation for compliance audits.

All external security standards in-clude aspects outside the realm of system configuration settings. The use of a tool like the IBM Compli-ance Expert Express Edition will not, by itself, insure standards compli-ance. The Compliance Expert is de-signed to simplify the management of systems configuration setting, al-lowing the administrators to focus on the other aspects of standards com-pliance.

Contact Spectrum for further information…

 

Leave a Comment

« | Home | »