The VMM must notify the system administrator (SA) and information system security officer (ISSO) when accounts are modified.
DISA Rule
SV-207428r984225_rule
Vulnerability Number
V-207428
Group Title
SRG-OS-000275
Rule Version
SRG-OS-000275-VMM-000970
Severity
CAT II
CCI(s)
- CCI-000015 - Support the management of system accounts using (organization-defined automated mechanisms).
Weight
10
Fix Recommendation
Configure the VMM to notify the SA and ISSO when accounts are modified.
Check Contents
Verify the VMM notifies the SA and ISSO when accounts are modified.
If it does not, this is a finding.
Vulnerability Number
V-207428
Documentable
False
Rule Version
SRG-OS-000275-VMM-000970
Severity Override Guidance
Verify the VMM notifies the SA and ISSO when accounts are modified.
If it does not, this is a finding.
Check Content Reference
M
Target Key
2924