IBM Support

CIS 8.1 Safeguards Fulfilled on AIX by Using PowerSC, ZTEA, and PCV

General Page

Hi everyone,

I am Stephen Dominguez, and I'm the author of this content. I work for IBM Expert Labs.

The Center for internet Security, Inc (CIS®) is a community-driven nonprofit, responsible for the CIS Controls® and CIS Benchmarks®, globally recognized best practices for securing IT systems and data. CIS leads a global community of IT professionals to continuously evolve these standards and provide products and services to proactively safeguard against emerging threats.

The intent of this website is to describe how IBM PowerSC can use functionality found in the following set of IBM products and offerings to fulfill CIS 8.1 Safeguards, when securing AIX:
1. IBM PowerSC (PowerSC)
2. IBM Zero Trust Execution for AIX (ZTEA)
3. IBM Power Cyber Vault for AIX (PCV)

This website is based on CIS Critical Security Controls v8.1 - March 2025

 

Control 2       
Inventory and Control of Software Assets
Safeguard NumberNameIG1IG2IG3PowerSCZTEAPCV
2.5Allowlist Authorized Software   
2.6Allowlist Authorized Libraries   
2.7Allowlist Authorized Scripts    
Control 3       
Data Protection
Safeguard NumberNameIG1IG2IG3PowerSCZTEAPCV
3.3Configure Data Access Control Lists 
3.14Log Sensitive Data Access    
Control 4       
Secure Configuration of Enterprise Assets and Software
Safeguard NumberNameIG1IG2IG3PowerSCZTEAPCV
4.3Configure Automatic Session Locking on Enterprise Assets  
4.6Securely Manage Enterprise Assets and Software  
4.7Manage Default Accounts on Enterprise Assets and Software  
4.8Uninstall or Disable Unnecessary Services on Enterprise Assets and Software   
Control 5       
Account Management
Safeguard NumberNameIG1IG2IG3PowerSCZTEAPCV
5.2Use Unique Passwords  
5.3Disable Dormant Accounts  
Control 6       
Access Control Management
Safeguard NumberNameIG1IG2IG3PowerSCZTEAPCV
6.4Require MFA for Remote Network Access  
6.5Require MFA for Administrative Access  
Control 7       
Continuous Vulnerability Management
Safeguard NumberNameIG1IG2IG3PowerSCZTEAPCV
7.3Perform Automated Operating System Patch Management  
7.5Perform Automated Vulnerability Scans of Internal Enterprise Assets   
7.7Remediate Detected Vulnerabilities   
Control 8       
Audit Log Management
Safeguard NumberNameIG1IG2IG3PowerSCZTEAPCV
8.2Collect Audit Logs  
8.5Collect Detailed Audit Logs   
8.8Collect Command-Line Audit Logs   
8.9Centralize Audit Logs   
8.12Collect Service Provider Logs    
Control 10       
Malware Defenses
Safeguard NumberNameIG1IG2IG3PowerSCZTEAPCV
10.1Deploy and Maintain Anti-Malware Software
10.2Configure Automatic Anti-Malware Signature Updates  
10.5Enable Anti-Exploitation Features   
10.6Centrally Manage Anti-Malware Software   
10.7Use Behavior-Based Anti-Malware Software   
Control 11       
Data Recovery
Safeguard NumberNameIG1IG2IG3PowerSCZTEAPCV
11.2Perform Automated Backups  
11.3Protect Recovery Data  
11.4Establish and Maintain an Isolated Instance of Recovery Data  
11.5Test Data Recovery   
Control 13       
Network Monitoring and Defense
Safeguard NumberNameIG1IG2IG3PowerSCZTEAPCV
13.1Centralize Security Event Alerting   
13.2Deploy a Host-Based Intrusion Detection Solution   
13.3Deploy a Network Intrusion Detection Solution   
13.7Deploy a Host-Based Intrusion Prevention Solution    
13.8Deploy a Network Intrusion Prevention Solution    
13.9Deploy Port-Level Access Control    

 

 

 

 

[{"Type":"MASTER","Line of Business":{"code":"LOB68","label":"Power HW"},"Business Unit":{"code":"BU070","label":"IBM Infrastructure"},"Product":{"code":"SSB2BD2","label":"IBM PowerSC"},"ARM Category":[{"code":"a8m3p000000UoK2AAK","label":"PowerSC Standard (PSC)"}],"Platform":[{"code":"PF002","label":"AIX"}],"Version":"2.0.0;2.1.0;2.2.0;2.3.0"}]

Document Information

Modified date:
11 June 2026

UID

ibm17274521