CA VM:Secure product NORULE record in the SECURITY CONFIG file must be configured to REJECT.
DISA Rule
SV-237917r858969_rule
Vulnerability Number
V-237917
Group Title
SRG-OS-000080-GPOS-00048
Rule Version
IBMZ-VM-000600
Severity
CAT II
CCI(s)
- CCI-000213 - Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
- CCI-000366 - Implement the security configuration settings.
- CCI-000764 - Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.
- CCI-000804 - Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users.
- CCI-001804 - Defines the policies for governing the installation of software by users.
Weight
10
Fix Recommendation
Configure the "SECURITY CONFIG" file to include a "NORULE" record that is set to "REJECT".
Check Contents
Examine the "SECURITY CONFIG" file.
If a "NORULE" record exists and is set to "REJECT", this is not a finding.
Vulnerability Number
V-237917
Documentable
False
Rule Version
IBMZ-VM-000600
Severity Override Guidance
Examine the "SECURITY CONFIG" file.
If a "NORULE" record exists and is set to "REJECT", this is not a finding.
Check Content Reference
M
Target Key
5306