CA VM:Secure product must be installed and operating.
DISA Rule
SV-237899r858927_rule
Vulnerability Number
V-237899
Group Title
SRG-OS-000004-GPOS-00004
Rule Version
IBMZ-VM-000030
Severity
CAT II
CCI(s)
- CCI-000018 - Automatically audit account creation actions.
- CCI-000067 - Employ automated mechanisms to monitor remote access methods.
- CCI-000130 - Ensure that audit records containing information that establishes what type of event occurred.
- CCI-000131 - Ensure that audit records containing information that establishes when the event occurred.
- CCI-000132 - Ensure that audit records containing information that establishes where the event occurred.
- CCI-000133 - Ensure that audit records containing information that establishes the source of the event.
- CCI-000134 - Ensure that audit records containing information that establishes the outcome of the event.
- CCI-000135 - Generate audit records containing the organization-defined additional information that is to be included in the audit records.
- CCI-000169 - Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2 a. on organization-defined information system components.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
- CCI-001403 - Automatically audit account modification actions.
- CCI-001404 - Automatically audit account disabling actions.
- CCI-001405 - Automatically audit account removal actions.
- CCI-001487 - Ensure that audit records containing information that establishes the identity of any individuals, subjects, or objects/entities associated with the event.
- CCI-002160 - Enforce organization-defined mandatory access control policy over all subjects and objects where the policy specifies that a subject that has been granted access to information is constrained from changing the rules governing access control.
- CCI-002264 - Provides the means to associate organization-defined types of security attributes having organization-defined security attribute values with information in transmission.
- CCI-002914 - Defines the credentials required for personnel to have unescorted access to the facility where the system resides.
Weight
10
Fix Recommendation
CA VM:Secure product audits all commands.
Ensure CA VM:Secure product is installed and operational.
Using CA VM:Secure product audit of all commands with z/VM standard journal record assures that all pertinent information is stored.
Check Contents
Verify the CA VM:Secure product is operational on the system by entering the following command.
From the "CMS" command line enter:
VMSECURE VERSION
If there is no response, "VMSECURE" is not logged in, this is a finding.
Vulnerability Number
V-237899
Documentable
False
Rule Version
IBMZ-VM-000030
Severity Override Guidance
Verify the CA VM:Secure product is operational on the system by entering the following command.
From the "CMS" command line enter:
VMSECURE VERSION
If there is no response, "VMSECURE" is not logged in, this is a finding.
Check Content Reference
M
Target Key
5306