Questions on Restrict permissions for CMDB model hardening setting
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎07-01-2024 09:18 PM
Hello experts,
While browsing and investigating on the security hardening settings, it seems that the 'Restrict Permissions for CMDB Model' security center hardening is compliant even though there is nothing configured to it. See below:
When I also verified on the properties, I cannot find that property and the plugin mentioned is also not installed,
Do anyone of you know why does it show as compliant even though there is nothing configured?
I can see that this behavior is existing also in a number of PDI's
Regards,
Vaine
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎07-02-2024 02:58 AM
The recommendation is to set that property to true IF the plugin is active. If the plugin is not active, the property does not make any difference, so in that case you are compliant regardless of its existence and/or value.
Blog: https://sys.properties | Telegram: https://t.me/sys_properties | LinkedIn: https://www.linkedin.com/in/slava-savitsky/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎07-03-2024 12:43 AM
Hello,
But there is an instance in Vancouver PDI with SC in 1.2.0 version with that same setting, the plugin is not active and the property is not visible, it display as non-compliant.
Regards,
Vaine
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎07-03-2024 02:26 AM
Note that in this instance there is no IF clause in the description of the setting, which suggests it uses a different logic for evaluation of compliance/non-compliance. Is this instance on the same version as the other one?
Blog: https://sys.properties | Telegram: https://t.me/sys_properties | LinkedIn: https://www.linkedin.com/in/slava-savitsky/