The VMM must notify the system administrator (SA) and information system security officer (ISSO) when accounts are removed.
DISA Rule
SV-207430r984231_rule
Vulnerability Number
V-207430
Group Title
SRG-OS-000277
Rule Version
SRG-OS-000277-VMM-000990
Severity
CAT II
CCI(s)
- CCI-000015 - Support the management of system accounts using (organization-defined automated mechanisms).
Weight
10
Fix Recommendation
Configure the VMM to notify the SA and ISSO when accounts are removed.
Check Contents
Verify the VMM notifies the SA and ISSO when accounts are removed.
If it does not, this is a finding.
Vulnerability Number
V-207430
Documentable
False
Rule Version
SRG-OS-000277-VMM-000990
Severity Override Guidance
Verify the VMM notifies the SA and ISSO when accounts are removed.
If it does not, this is a finding.
Check Content Reference
M
Target Key
2924