IBM BigFix Compliance UPDATE: CIS Checklists for Windows 2008 DC, Windows 2008 R2 DC, Windows 2012 DC, Windows 2012 R2 DC and Windows 2016 DC published 2017-10-18

Product:
IBM BigFix Compliance

Title:
Relevance issue fix for Windows 2008 DC, Windows 2008 R2 DC, Windows 2012 DC, Windows 2012 R2 DC and Windows 2016 DC checklists.

Security Benchmark:
CIS Microsoft Windows Server 2008 DC Benchmark, v3.0.0
CIS Microsoft Windows Server 2008 R2 DC Benchmark, v3.0.0
CIS Microsoft Windows Server 2012 DC Benchmark, V2.0.0
CIS Microsoft Windows Server 2012 R2 DC Benchmark, V2.2.0
CIS Microsoft Windows Server 2016 DC Benchmark, v1.0.0

Published Sites:
CIS Checklist for Windows 2008 DC - RG03 site version 4
CIS Checklist for Windows 2008 R2 DC site version 6
CIS Checklist for Windows 2012 DC, site version 5
CIS Checklist for Windows 2012 R2 DC, site version 8
CIS Checklist for Windows 2016 DC site version 2
(The site version is provided for air-gap customers.)

Details:
Fixed and improved implementation for the following checks:

· xccdf_org.cisecurity.benchmarks_rule_2.3.1.1_L1_Ensure_Accounts_Administrator_account_status_is_set_to_Disabled.
· xccdf_org.cisecurity.benchmarks_rule_2.3.1.2_L1_Ensure_Accounts_Guest_account_status_is_set_to_Disabled
· xccdf_org.cisecurity.benchmarks_rule_2.3.1.3_L1_Ensure_Accounts_Guest_account_status_is_set_to_Disabled.

Relevance was unable to identify whether “Administrator” and “Guest” accounts are enabled or disabled when they are renamed. This was fixed by modifying the relevance to read SID of these accounts when they are renamed.

Actions to take:
· To subscribe to the above site, you can use the License Overview Dashboard to enable and gather the site. Note that you must be entitled to the BigFix Compliance product and you must be using IBM BigFix version 9.2 and later.
· If you use custom sites, update your custom sites accordingly to use the latest content. You can synchronize your content by using the Synchronize Custom Checks wizard. For more information, see https://ibm.biz/Bd4LBt.

More information:
To know more about IBM BigFix Compliance SCM checklists, please see
· IBM Developer Works:
https://www.ibm.com/developerworks/community/wikis/home?lang=en#!/wiki/Tivoli%20Endpoint%20Manager/page/SCM%20Checklists
· IBM BigFix Blog:
https://www.ibm.com/developerworks/community/blogs/a1a33778-88b7-452a-9133-c955812f8910?lang=en
· IBM BigFix Forum:
https://forum.bigfix.com/c/release-announcements/compliance

We hope you find this latest release of SCM content useful and effective. Thank you!

– The IBM BigFix Compliance team