Skip to Main Content
Status Delivered
Workspace * IBM Cloud Ideas
Categories Storage
Created by Guest
Created on Jan 31, 2024

The Current IBM CIS Benchmark Scan has a bug/flaw in few of the Controls

1) Ensure Cloud Object Storage encryption is enabled with BYOK

Ensure Cloud Object Storage encryption is enabled with KYOK

Ensure Block Storage is encrypted with BYOK

Ensure Block Storage is encrypted with KYOK

These 4 controls

Due to a flaw in the IBM scan, where it is configured to check for both BYOK and KYOK however, if only one of the methods is selected, the scan will highlight the other one as failed.

please look into this code change and enhancements support case is raised and team agreed there's an flaw and making code changes

2) Ensure OS disk is encrypted with customer managed keys

Ensure data disks are encrypted with customer managed keys

for these two controls Due to a design configuration in the IBM code, this is not possible for the already created Cloud Object Storage/OS Disks/data disks during initial steps

Scenario :
Scans are failing as they can only ignore resources at service level but not at the individual group level. Which means, if some groups need encryption and others don’t, we are unable to ‘ignore’ the ones that do not require hence, the scan throws an error even when encryption is not required on the Cloud Object Storage

the current setup should have an option to suppress the alerts/recommendations/vulnerabilities.
3)
Ensure no VPC access control lists allow ingress from 0.0.0.0/0 to SSH port

Ensure the default security group of every VPC restricts all traffic

Ensure no VPC security groups allow ingress from 0.0.0.0/0 to RDP port

Ensure no VPC security groups allow ingress from 0.0.0.0/0 to SSH port

Ensure no VPC access control lists allow ingress from 0.0.0.0/0 to RDP port

In VPC security groups, when we have a security group with multiple ports (allowed and not allowed ports), the rule should pass. Currently only port is checked. There should be allowed ports along with default ports for a rule to pass.

4)
The new version of CIS profile needed which needs to map updated COS rules
rule-9eb7b514-5c27-43ba-83fc-26d75e0bf695,

rule-ac203dbc-ff0d-49f7-bf11-c08af429cb86.
Map to the IBM CIS benchmark Scan controls [42 total ] as existing Rules has flaws


Idea priority Medium
Needed By Week