Last week I have been at a customer working on a security assessment of their AIX setup. This customer was actually doing quite well compared to many I have reviewed. They had a security policy - and it had been recently updated. However, they were not using AIX Security Expert (aixpert) and that slowed down the process of updating their systems to the new/updated security policy.
Because they asked specifically about PCI compliance I did a little more reading (besides the PowerSC Overview). I went to the PCI site and downloaded the PCI_DSS_v2 guidelines.
I discovered that besides having a PCI.xml file (plus supporting scripts) for configuring systems according to the PCI DSS guidelines PowerSC has two components that will help greatly with satisfying PCI_DSS requirements: Trusted Logging for (more) tamper proof logs; Trusted Network Connection and Patch Management to assist OS fix and update maintenance.