Security dashboard policies
A policy is a collection of security parameters and their defined expected values. A storage system can be associated with at most one security policy for its corresponding family type.
After receiving the full or mini probe data through Data Collector or Call Home with cloud services, the retrieved configurations (parameters) that align with the system’s security policy are considered as supported. The supported parameters are evaluated against policy's recommended values to generate system's security posture.
- Mini probe support:
- lssecurity : Supports firmware 9.1.2 and above for both data collector and Call Home with cloud services
- lssystem: Supports firmware 8.7.0 and above via data collector and firmware 8.5.3 via Call Home with cloud services
- lsmultifactorverify: No support
- IBM DS8000: No support
- When the device is connected through Call Home with cloud services, and the
censor_callhomeparameter is set toon, thelssecuritycommand's parameters will not be available for evaluation. Thelssecuritycommand's parameters includecli_timeout_mins,expiry_warning_days,gui_timeout_mins,min_password_length, andsshprotocol.
Creating and configuring security posture policy
A custom security posture policy enables you to monitor storage system parameters based on the assigned policy. For example, different policies can be assigned for different group of storage systems. You need admin access to customize the policy by selecting the number of parameters or by changing the parameters settings. You can then assign the storage systems to it for which you want to perform compliance monitoring.
You can create and configure a custom security posture policy. But, the default security posture policies are read-only, you cannot edit their parameter details.
To access, create or configure the security posture policy, navigate to .
If a storage system is added to a custom security posture policy and you delete that policy at any time, then the storage system is assigned to a default security posture policy. A default security posture policy is assigned to each storage system, if the storage system is not assigned to any custom security posture policy.
Total 16 parameters are supported for IBM Storage FlashSystem, IBM SAN Volume Controller, IBM Storwize, and IBM FlashSystem V840, out of which 13 parameters are included in the default security posture policy.
For IBM DS8000, 4 parameters are supported and all are included in the default security posture policy.
| Action | Procedure |
|---|---|
| Create custom security posture policy |
|
| Edit security parameters |
|
| Assign storage systems to the policy |
|
| Remove storage systems from the policy |
|
| Rename the policy |
|
| Delete the policy |
|
| Exclude system from monitoring |
|