OpenMic: Deploying and Using IBM Security and Compliance Management (SCM) (April 6th, 2016)

Announcing the following upcoming OpenMic event:

Deploying and Using IBM Security and Compliance Management (SCM)

Date/Time: April 6th, 2016 at 11:00 AM EDT (15:00 UTC/GMT, UTC-4 hours) for 60 minutes.
Presented by: Christian Castro from our IBM BigFix L2 Support organization along with a panel of other product experts arrayed from our product management, development, and services teams.

Please click here to view/accept the invitation.

Ahead of and after the OpenMic; please post any questions you would like to have answered either during the OpenMic or through this forum.

To receive email notifications for upcoming Security Support OpenMic web casts, send an e-mail to isssprt@us.ibm.com with the following in the subject line: ste subscribe Endpoint And Mobility Management.

2 Likes

I keep clicking HERE… but nothing happens :wink: (to view the invite)

It still needs to be published.

1 Like

@RaphaelWahl @Wouter

I had few questions that I can also bring up during the open mic

  1. Is there any documentation on how we can make fixlets report results to SCA?
  2. I could not find a way to create custom columns for checks. There is only one way to pass custom data to SCA and that is using measured values. So is it possible to change sometime in future to be able to create custom columns on the Reports->Checks page?

I have question about when the big Fix IBM Security and Compliance Management will allow for importing non-windows checklist that are OpenSCAP compliant?

Thanks for the invitation.
Can you pls address the following questions during tomorrow’s event -

  1. It has been recommended by the product team that Custom Sites be created and used for running the SCM scans. My question is do we have any feature available to Synchronize the IEM App Scanner and GTS CM Custom Contents with the External Sites whenever new updates are released ? The wizard “Synchronize Custom Checks” only supports synchronization of SCM content
  2. Is there any way we can get notifications about when new versions of the External Sites are released for SCM, IEM App Scanner & GTS CM Content ?
  3. I have noticed Fixlet Applicability Problem where the _Install*, _Run* and *GSDISeC Fixlets/Tasks are not applicable on all Subscribed Computers even though the Subsystem Scanner has detected the respective Subsystem onto the Subscribed Computers. What are the possible causes for this issue ?
  4. To take care of the Fixlet Applicability problem I was forced to use the OS and Middleware Relevance override settings. Is there any side effects of using these override settings ? If yes what are those ?
  5. I am using 3 types of contents namely SCM, IEM App Scanner & GCM. Would like to know the email ids of the respective team or individual whom I should approach in case I face any issue with these 3 type of contents.
  6. I have come across situations where, for a particular techspec parameter, few SCM Fixlets are asking the administrators to implement more settings than is being asked by the IBM Global Techspecs. I want to know the email id of the team or individual whom I can approach to discuss these cases in detail and get solutions.
  7. Which team or individual can be approached incase I want to get some SCM fixlets customized ?
  8. The external site IEM APP Scanner MySQL doesn’t download any content after activation although all other external sites are able to successfully download/synchronize contents. Is the IEM APP Scanner MySQL still under development ?
  9. The Unix SCM when run creates enough log files which clearly tells us what desired settings are required to be implemented at the OS level to make any parameter look Compliant. Is similar arrangement there for Windows ? If yes then where exactly the log files get created ?
  10. Can you pls share the full support escalation matrices of the 3 types of contents SCM, IEM App Scanner & GCM ?
1 Like

Hello debasishg,

Good questions.
The OpenMic is a limited time venue and we limit 1 to 2 questions per customer during an OpenMic to give time for all participants to ask their questions.
The OpenMic is not a troubleshooting session.

If after the OpenMic, you still have questions about the product refer to the product documentation site for the product will which be shared during the OpenMic. For other concerns contact support via the PMR process and we will assist. However, we can only assist you with 1 question per PMR at a time as per our support process.

Thank you,
Christian

Hello Ken,

Please make sure to give your name and contact information to the moderator. We will take your question to product management and provide details on this.

Thank you,
Christian

      Hello debasishg,

Good questions.
The OpenMic is a limited time venue and we limit 1
to 2 questions per customer during an OpenMic to give time for all
participants to ask their questions.
The OpenMic is not a troubleshooting session.

If after the OpenMic, you still have questions about the product
refer to the product documentation site for the product will which be
shared during the OpenMic. For other concerns contact support via the
PMR process and we will assist. However, we can only assist you with 1
question per PMR at a time as per our support process.

Thank you,
Christian

Question from one of our Federal Customers:

  1. In our environment, we are only requiring endpoints to meet compliance for CAT 1 checks for Server OS Checklists and all checks for Workstation OS checklists.Is there a way to customize the overview in SCA to reflect only the checks we need besides having to put in a bunch of exceptions?
  2. We have converted all of our external SCM sites into custom sites. Is there any additional configuration that needs to be done to have our custom sites show up in SCA?

jgordon,

sent you a reply on here. please check your messages on here.

-christian