Security dashboard policies

A policy is a collection of security parameters and their defined expected values. A storage system can be associated with at most one security policy for its corresponding family type.

After receiving the full or mini probe data through Data Collector or Call Home with cloud services, the retrieved configurations (parameters) that align with the system’s security policy are considered as supported. The supported parameters are evaluated against policy's recommended values to generate system's security posture.

Note:
  • Mini probe support:
    • lssecurity : Supports firmware 9.1.2 and above for both data collector and Call Home with cloud services
    • lssystem: Supports firmware 8.7.0 and above via data collector and firmware 8.5.3 via Call Home with cloud services
    • lsmultifactorverify: No support
    • IBM DS8000: No support
  • When the device is connected through Call Home with cloud services, and the censor_callhome parameter is set to on, the lssecurity command's parameters will not be available for evaluation. The lssecurity command's parameters include cli_timeout_mins, expiry_warning_days, gui_timeout_mins, min_password_length, and sshprotocol.

Creating and configuring security posture policy

A custom security posture policy enables you to monitor storage system parameters based on the assigned policy. For example, different policies can be assigned for different group of storage systems. You need admin access to customize the policy by selecting the number of parameters or by changing the parameters settings. You can then assign the storage systems to it for which you want to perform compliance monitoring.

You can create and configure a custom security posture policy. But, the default security posture policies are read-only, you cannot edit their parameter details.

To access, create or configure the security posture policy, navigate to Main menu > Administration > Security posture policies.

If a storage system is added to a custom security posture policy and you delete that policy at any time, then the storage system is assigned to a default security posture policy. A default security posture policy is assigned to each storage system, if the storage system is not assigned to any custom security posture policy.

Total 16 parameters are supported for IBM Storage FlashSystem, IBM SAN Volume Controller, IBM Storwize, and IBM FlashSystem V840, out of which 13 parameters are included in the default security posture policy.

For IBM DS8000, 4 parameters are supported and all are included in the default security posture policy.

Table 1. Actions that can be performed on custom security posture policy
Action Procedure
Create custom security posture policy
  1. Click Create Policy on the Security posture policy page.
  2. Enter a Name and select storage system family.
  3. (Optional) Add Description.
  4. Click Next.
  5. Add parameters and click Next.

    By default, 13 parameters are enabled, you can configure the remaining 3 parameters.

  6. (Optional) Assign the storage systems to the policy and click Next.
  7. Verify the security posture policy parameters and the storage systems that will use the policy. Click Create.
Edit security parameters
  1. Click the three dots menu of the policy and select Manage policy.
  2. Select the Security parameters tab.
  3. Select the category from the list or search the parameter name in the search box.
  4. Edit the parameter details as required.
  5. Click Save changes.
Assign storage systems to the policy
  1. Click the three dots menu of the policy and select Manage policy.
  2. Select the Assigned storage systems tab.
  3. Click Assign storage systems.

    It displays the list of all storage systems. It also has a side panel that lists the storage systems that are assigned to the policy.

  4. Select the storage systems that you want to associate with the policy and click Assign.
Remove storage systems from the policy
  1. Click the three dots menu of the policy and select Manage policy.
  2. Select the Assigned storage systems tab.
  3. Select one or more storage systems that you want to remove from the policy.
  4. Click Remove.
  5. Acknowledge the check box and click Remove on the pop-up.
    Note: When a storage system is removed from the custom security posture policy then it gets assigned to the default security posture policy.

    Storage systems cannot be removed from the default security posture policy, it can only be assigned to the custom security posture policy.

Rename the policy
  1. Open the custom security posture policy that you want to rename.
  2. Select Policy actions > Rename.
  3. Enter the new name and/or description of the policy.
  4. Click Save changes.
Delete the policy
  1. Open the custom security posture policy that you want to delete.
  2. Select Policy actions > Delete .
    Note: When the custom security posture policy is deleted, the assigned storage systems are moved to the default security posture policy of that storage system’s family.
Exclude system from monitoring
  1. Navigate to Main menu > Security Posture.
  2. Select Security actions > Exclude from monitoring.
  3. Click Exclude on the pop-up.

    You can resume monitoring anytime by clicking Resume monitoring on the security posture dashboard of the storage systems.