(imported topic written by JHearnsberger)
Hey guys,
Thought I would pass this along, in hopes that someone else might get some use out of some of my headache with our implementation. I work for a fuel retailer and there are settings that we monitor and track that are outside of “normal” security and compliance checklists. One of these checklists I have put together is a checklist to monitor credit card discount settings when a card is used at the dispenser. Of course, there isn’t a 3rd party provider for this, such as DISA STIG and others - so I had to be creative.
Below are the steps I found that worked for creating a custom site, with custom relevance analysis, and have it report up to SCA / TEMA. I put this together to make sure my guys are following a standard with creating these sites, and I am sharing in hopes that it helps someone not get stuck on this.
IBM Endpoint Manager - Configuration Management Setup
- Go to Security Configuration domain
- Open the wizard “Create Custom Checklist”
- Name the checklist
- Check one of the DISA STIG checklist items - will be deleted later.
- Create Checklist
- Subscribe computers to the new custom checklist
- Navigate to your new custom site, and deactive the analysis from the DISA STIG checklist we added previously.
- Open the wizard “Create Custom Relevance SCM Checks”
- Select Site and Applicability fixlet
- Complete all fields in “Required Information” fields
- Put a description in for what the filxlet does
- Paste debugged relevance into “Compliance Relevance”
- Paste debugged relevance into “Analysis Relevance”, include desired values and a relevant title.
- Include remediation actionscript, if needed.
- Click Create Fixlet
- Go into the custom checklist again.
- Delete the DISA STIG fixlets, tasks, and analysis. DO NOT delete the applicability fixlet
- Change the applicability fixlet to: name ofoperating system = “Win7” orname ofoperating system = “WinXP”. This fixlet will incllude Windows XP systems until they are out of production.
- Ensure that the correct systems are subscribed, have started being analyzed, and are reporting back to the server.
- Go to the SCA dashboard and run a manual import
- Verify that the new checklist is reporting to the dashboard.