Best Practices for securing BMC TrueSight Server Automation


BMC recommends implementing the following best practices and security hardening measures for TrueSight Server Automation. The table following, later shows recommendations for securing various system components.

ComponentRecommendation
Remote Console Protocol (RCP) Security
  • Restrict Access: The RCP console should only be accessible from a terminal server, which provides and additional layer of authorization and allows the administrator to limit connectivity to the application servers.
  • Enforce Secure Communication: All RCP-to-app server connections must use TLS 1.2 to make sure encrypted communication. (bladsadmin EnabledSecureProtocols setting: Configuring the TLS protocol - BMC Documentation
TrueSight Server Automation User Authentication & Authorization
Remote System Call Daemon (RSCD) Security

 

Application Server

Use strong cryptographic ciphers and enforce TLS 1.2 for all connections. 

DatabaseEncrypting your database connection - BMC Documentation
Remote Site Access
  • Remote sites should use a SOCKS proxy as a single point of entry.
  • Consider implementing a repeater for payload caching.

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*

TrueSight Server Automation 25.2