Security posture tenant dashboard

It provides the compliance overview of all the storage systems that are being monitored.

To navigate to this page, click Main menu > Security Posture. You can also navigate to this page by clicking View details on System protection widget of Overview dashboard.

Security overview dashboard has two tabs:

Overview

The Overview tab consists of the following widgets:
  • Compliance summary: It provides the compliance overview of all the storage systems being monitored. There is different percentage categorization for compliance level:
    • Least (0% to 10%)
    • Low (10% to 30%)
    • Moderate (30% to 70 %)
    • High (70% to 100 %)
    • Excluded systems

    Click View all systems to see the list of all storage systems along with their security compliance. It opens a Compliance by systems side pane. Alternatively, you can also click on any percentage category of the donut chart to directly open the Compliance by systems side pane.

    For more information, see View all systems.

    Note: Formula to calculate the compliance percentage for a system:

    Total supported compliant parameters for the system/Total supported parameter for the system * 100 = % compliant system (parameter)

  • Compliance by products: It provides the compliance overview of all the storage systems product wise, such as IBM SVC, IBM Storwize, and IBM DS8000. IBM FlashSystem and IBM FlashV family are displayed as FlashSystem on the widget.
  • Failed parameters: It displays the parameters that contribute to the non-compliance state of the storage system. It provides the actual insights of the parameters based on which you can take an action to make the storage system compliant. On each parameter, the total number of storage systems are also displayed which are non-compliant for that particular parameter.

    You can also view a particular failed parameter's status corresponding to the storage system by clicking on the chart. This filter functionality is enabled through interactive treemap charts, where you can click on it to explore further details.

    Click View all failed parameters to see the list of all failed parameters in a tabular form. It is sorted in descending order where the parameter on which most of the storage systems are non-compliant is displayed on the top.

  • Security categories: It provides the compliance overview of the storage systems based on the category how the systems are distributed, such as authentication and data access control, physical storage security, audit logging, data protection, administration access, and encryption.
    Note: Formula to calculate the compliance percentage by category:

    Total supported compliant parameters in a category for the system/Total supported parameter in a category for the system * 100 = % compliant system categories

Each widget has 3 buttons in the top-right corner:
  • Show as table - To display the widget details in the form of a table
  • Make fullscreen - To provide full screen view of the widget
  • i icon - To provide additional information about Failed parameters and Security categories widget
  • More options - To export the compliance summary in CSV, PNG, or JPG format
View systems

Clicking on View systems opens a Compliance by systems pane which displays the Total systems being monitored. Also, it displays the segregated number of storage systems in terms of Least, Low, Moderate, High compliant and also the number of Excluded systems. The count displayed for each category is clickable. On clicking it, the table is filtered to display the storage systems of that particular category.

There are 3 options displayed before the columns:
  • Text-based search field Text based search field: It enables you to type any text, which matches with the data values in visible text-based columns, and the matched records are filtered and displayed in the grid. Clearing the search field displays all the records again.
  • Filter icon button Filter icon: It opens a Filters panel to specify custom filters.
  • Text-based report button Text-based report button: It opens a submenu that has buttons for exporting the data grid contents in CSV, PDF, and HTML format. It enables you to export the table data in CSV, PDF, and HTML format.

It displays the Storage systems names, the Security compliance percentage, and Parameters on which the system is compliant and non- compliant. The table data is sorted based on the Security compliance column in ascending order (least to high).

Each row has a three dot menu which has 3 options:
  • Security details: Clicking on it opens the Overview tab of the individual security dashboard of that storage system.
  • Parameter details: Clicking on it opens the Security parameters tab of the individual security dashboard of that storage system.

Security parameters

You can directly view the parameters list by clicking Security parameters tab on the Security dashboard.

It displays the list of all security parameters on which all the storage systems are either compliant or non-compliant. The table has the following columns:
Table 1. Security parameters
Column name Description
Parameter Name of the parameter.
Category Category in which the parameter is defined, such as, security, data protection, audit logging, authentication and data access control, etc.
Non-compliant systems Number of storage systems which are non-compliant for that specific parameter. Clicking on it opens a side pane with details of that parameter. For more information, see Parameter details.
Compliant systems Number of storage systems which are compliant for that specific parameter. Clicking on it opens a side pane with details of that parameter. For more information, see Parameter details.
System family Category of system family to which the parameter belongs.

Below the tabs there are 3 options, Text-based search field, Filter icon button, and Text-based report button. For more information, see View systems.

Parameter details

The parameter names are clickable. On clicking the parameter name, the corresponding parameter details side pane opens.

It displays the Recommended state whether Enabled or Disabled, Description about the parameter and what can be the Impact if recommendation is not followed.

It has two tabs, Non-complaint and Compliant, each of which lists all the storage systems which are non-compliant and compliant, respectively. The Storage systems column lists the storage system names and Security compliance column displays the compliance percentage of the storage system.

Each row has a three dot menu which has 2 options, Security details and Parameter details. For more information, see View systems.

Note: The system security is evaluated after the full probe event is completed. The last time when the full probe event was completed can be seen on the top-right corner of the dashboard.