2.2 Ensure system Microcode Discovery Service (MDS) is performed regularly

Information

Microcode Discovery Service (MDS) is used to determine if microcode installed on your IBM POWER system is at the latest level.

MDS relies on an AIX utility called Inventory Scout. Inventory Scout is installed by default on all AIX 5 and later systems.

Note: on the current landing page for Microcode Discovery Service there is the following announcement:

This Web site is being migrated to the IBM Cloud. The functioning of this site will not be changed as a result of the move, but there will be a new URL. Initially there will be a redirect to the new site, which will be removed within a few months. There is no firm date set for the removal of the redirect.
The new cloud version is available at: https://esupport.ibm.com/customercare/mds

The steps below (in Audit) may need adjustment when the migration process is completed.

Firmware should be patched to address potential hardware and security vulnerabilities.

CIS recommends that hardware be no greater than N-2 levels behind.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Follow the procedure provided by the firmware update package(s) to update the firmware.

Impact:

This scan is most especially important on VIOS partitions because these partitions, by definition, manage different i/o adapters that may be in need of firmware updates.

See Also

https://workbench.cisecurity.org/benchmarks/19066

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-8b.

Plugin: Unix

Control ID: d8c02bc0892b402dd5bec16ef6e9465ad6246e5396436e1b44e0872cdfd3a97c