|
The following measures are taken to harden the BMC Atrium Discovery appliance when it is built:
The appliance is equipped with its own baseline monitoring system (based on the open source Tripwire product) which can be configured to automatically take action in case of unauthorized changes, such as shutting down the appliance or disabling access. User managementBMC Atrium Discovery application's internal user management service offers all the features required to support ISO 17799 guidelines, specifically:
Many firms have invested in identity and access management solutions to centralize user management and the permissions to the applications they can access. BMC Atrium Discovery can also integrate with a corporate LDAP solution such as Active Directory so that user accounts and group permissions can be managed directly from the LDAP. LDAP groups can be [mapped] as desired to BMC Atrium Discovery groups to simplify overall administration. Appliance firewallThe appliance firewall is pre-configured to ensure only the following incoming traffic is allowed. Slave communication is always initiated from the appliance so is not listed here. The open ports listed below are incoming TCP ports to the appliance.
The appliance approach provides a known and understood system in which the interaction between components is designed; the firewall is one of those components. Consequently the appliance is expected to have full control over the firewall. Local Linux system administrators should not make any changes to the appliance firewall as this may compromise the appliance security and any changes will be lost when the it is upgraded. Where further monitoring or protection is required then it should be placed behind an additional firewall. Windows Slave hardeningWindows discovery requires a slave or proxy running on a Windows host to provide the methods (WMI, RCMD, RemCom and so forth) of accessing Windows systems. The slave host should be configured to allow the following incoming traffic. The ports given are incoming TCP ports to the Windows slave host.
Penetration testingTo ensure BMC Atrium Discovery data integrity and confidentiality, the BMC Quality Assurance group performs a thorough assessment on each major and minor release. UI penetration tests are made with IBM® AppScan®. System penetration tests are made with Tenable Nessus and Bastille Linux. Known false positives flagged by security scannersThe following security issues have been flagged in the past by some security scanners. In each case they can be shown as not being applicable to BMC Atrium Discovery.
|
