1) Ensure Cloud Object Storage encryption is enabled with BYOK
Ensure Cloud Object Storage encryption is enabled with KYOK
Ensure Block Storage is encrypted with BYOK
Ensure Block Storage is encrypted with KYOK
These 4 controls
Due to a flaw in the IBM scan, where it is configured to check for both BYOK and KYOK however, if only one of the methods is selected, the scan will highlight the other one as failed.
please look into this code change and enhancements support case is raised and team agreed there's an flaw and making code changes
2) Ensure OS disk is encrypted with customer managed keys
Ensure data disks are encrypted with customer managed keys
for these two controls Due to a design configuration in the IBM code, this is not possible for the already created Cloud Object Storage/OS Disks/data disks during initial steps
Scenario :
Scans are failing as they can only ignore resources at service level but not at the individual group level. Which means, if some groups need encryption and others don’t, we are unable to ‘ignore’ the ones that do not require hence, the scan throws an error even when encryption is not required on the Cloud Object Storage
the current setup should have an option to suppress the alerts/recommendations/vulnerabilities.
3)
Ensure no VPC access control lists allow ingress from 0.0.0.0/0 to SSH port
Ensure the default security group of every VPC restricts all traffic
Ensure no VPC security groups allow ingress from 0.0.0.0/0 to RDP port
Ensure no VPC security groups allow ingress from 0.0.0.0/0 to SSH port
Ensure no VPC access control lists allow ingress from 0.0.0.0/0 to RDP port
In VPC security groups, when we have a security group with multiple ports (allowed and not allowed ports), the rule should pass. Currently only port is checked. There should be allowed ports along with default ports for a rule to pass.
4)
The new version of CIS profile needed which needs to map updated COS rules
rule-9eb7b514-5c27-43ba-83fc-26d75e0bf695,
rule-ac203dbc-ff0d-49f7-bf11-c08af429cb86.
Map to the IBM CIS benchmark Scan controls [42 total ] as existing Rules has flaws
| Idea priority | Medium |
| Needed By | Week |
By clicking the "Post Comment" or "Submit Idea" button, you are agreeing to the IBM Ideas Portal Terms of Use.
Do not place IBM confidential, company confidential, or personal information into any field.