| copyright |
|
||
|---|---|---|---|
| lastupdated | 2026-07-08 | ||
| keywords | Security and Compliance Center, SCC, Workload Protection, Workload Protection agent Linux, AIX, PowerVS SCC | ||
| subcollection | power-iaas |
{{site.data.keyword.attribute-definition-list}}
Integrating {{site.data.keyword.powerSys_notm}} with IBM Cloud Security and Compliance Center Workload Protection
{: #integrate-scc}
{{site.data.keyword.off-prem-fname}} in [{{site.data.keyword.off-prem}}]{: tag-blue}
{{site.data.keyword.sysdigsecure_full}} offers a comprehensive suite of security solutions to help your organization secure its cloud environments. {{site.data.keyword.compliance_short}} Workload Protection centrally manages your organization’s security, risk, and compliance with regulatory standards and industry benchmarks. For more information about {{site.data.keyword.compliance_short}} Workload Protection, see Getting started with IBM Cloud Security and Compliance Center Workload Protection{: external}.
In sectors such as financial services, continuous compliance in the cloud environment is crucial to protect customer and application data. Cloud Security Posture Management (CSPM) is one of the key features of the {{site.data.keyword.compliance_short}} {{site.data.keyword.sysdigsecure_short}} service. When this feature is enabled in your workspace, the CSPM ensures that automatic compliance checks are integrated in your development workflow to mitigate such risks on a daily basis.
{: #cspm}
CSPM accelerates hybrid platform adoption by verifying security and regulatory compliance with automated compliance checks for IBM Cloud Framework. The automated compliance checks for Financial Services, Digital Operational Resilience Act (DORA), CIS IBM Cloud Foundations Benchmark, PCI, and many other industry-related or best practice standards. For more information, see About IBM Cloud Security Posture Management (CSPM){: external}. CSPM helps with:
- Continuous validation of compliance
- Vulnerability prioritization
- Detection and response to runtime threats
- Forensics and incident response
You can enable the CSPM feature in your new and existing {{site.data.keyword.powerSys_notm}} workspaces. CSPM provides a unified platform to manage security and compliance across hybrid and multicloud environments and services.
{: #integrate-cspm}
To integrate {{site.data.keyword.powerSys_notm}} with Cloud Security and Compliance Center, enable Cloud Security Posture Management (CSPM) feature in your existing or new workspaces:
{: #enable-cspm-new}
To enable CSPM in a new Power Virtual Server workspace, complete the following steps:
- Log in to the IBM Cloud catalog with your credentials.
- In the search box, type Power Virtual Server and click the Power Virtual Server tile.
- Click Create a workspace.
- Select IBM data center as the location type.
- Select an IBM data center from the Location list and click Continue.
- In the Details section, provide a name for the workspace and select the resource group from the Resource group drop-down list. You can optionally provide User tags and Access management tags for the workspace.
- Click Continue. The selected workspace details are displayed on the Summary page.
- In the Integrations (Optional) section, the Cloud security posture management toggle switch is enabled by default. To disable CSPM, set Cloud security posture management to off.
- Click Finish. The selected workspace details are displayed on the Summary page.
- Select the I agree to the Terms and conditions checkbox and click Create.
Integration costs are based on usage and vary based on the hourly consumption for nodes and virtual machines. You can review the estimated cost on the Summary page. To review the cost associated with CSPM, see Security and Compliance Center Workload Protection{: external} in IBM Cloud catalog. {: important}
{: #enable-cspm-existing}
To enable Monitoring or CSPM in an existing Power Virtual Server workspace, complete the following steps:
-
Log in to the IBM Cloud Power Virtual Server user interface.
-
Click Workspaces in the left navigation menu.
-
Select the workspace for which you want to enable Monitoring or CSPM. The Workspace details pane is displayed.
-
To enable CSPM, click Add CSPM in the Integrations section. The Add cloud security posture management pane is displayed with the predefined SCC Workload Protection instance, Trusted profile, and App Configuration instance.
-
Click Edit to change the name, location, and plan for the CSPM instance, and click Save.
-
Click Create.
{{site.data.keyword.sysdigsecure_short}} agent in Linux® and AIX® on {{site.data.keyword.powerSys_notm}}
{: #wp-linux-AIX}
After you provision an instance of the {{site.data.keyword.compliance_short}} {{site.data.keyword.sysdigsecure_short}} service in IBM Cloud, you can deploy the {{site.data.keyword.sysdigsecure_short}} agent on your Linux or AIX hosts on {{site.data.keyword.powerSysFull}}. To provision an instance of {{site.data.keyword.sysdigsecure_short}}, see Managing the Workload Protection agent in Linux on Power Virtual Server{: external} or Managing the Workload Protection agent on AIX on Power Virtual Server{: external}.
{{site.data.keyword.sysdigsecure_short}} provides the following features to protect your stand-alone Linux or AIX hosts on {{site.data.keyword.powerSys_notm}}.
| Feature | On Linux hosts | On AIX hosts |
|---|---|---|
| Posture management | Scans host configuration files for compliance and benchmarks such as CIS Linux Benchmark | Scans host configuration files for compliance and benchmarks such as CIS AIX Benchmark |
| Host scanning | Scans host packages, detects associated vulnerabilities, and identifies the resolution priority based on available fixed versions and severity | - |
| Threat detection and response | Identifies threats and suspicious activity based on application, network, and host activity by processing syscall events and investigates with detailed system captures | - |
| {: caption="{{site.data.keyword.sysdigsecure_short}} agent features" caption-side="top"} |
For more information about managing and deploying the {{site.data.keyword.sysdigsecure_short}} agent on your Linux hosts, see Managing the Workload Protection agent in Linux on PowerVS{: external}.
For more information about managing and deploying the {{site.data.keyword.sysdigsecure_short}} agent on your AIX hosts, see Managing the Workload Protection agent in AIX on PowerVS{: external}.