STIGQter STIGQter: STIG Summary: IBM zVM Using CA VM:Secure Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 27 Oct 2022:

IBM z/VM must be configured to disable non-essential capabilities.

DISA Rule

SV-237915r649585_rule

Vulnerability Number

V-237915

Group Title

SRG-OS-000095-GPOS-00049

Rule Version

IBMZ-VM-000560

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Develop a policy for a procedure to review and disable non-essential capabilities for z/VM.

Ensure that all identified non-essential capabilities are disabled.

Check Contents

Determine if the System administrator has a documented manual process to review and disable non-essential capabilities for z/VM.

If there is no policy and process to review and disable non-essential capabilities, this is a finding.

If capabilities identified in the policy are not disabled, this is a finding.

Vulnerability Number

V-237915

Documentable

False

Rule Version

IBMZ-VM-000560

Severity Override Guidance

Determine if the System administrator has a documented manual process to review and disable non-essential capabilities for z/VM.

If there is no policy and process to review and disable non-essential capabilities, this is a finding.

If capabilities identified in the policy are not disabled, this is a finding.

Check Content Reference

M

Target Key

5306