STIGQter STIGQter: STIG Summary: IBM zVM Using CA VM:Secure Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 27 Oct 2022:

CA VM:Secure product Rules Facility must be restricted to appropriate personnel.

DISA Rule

SV-237962r649726_rule

Vulnerability Number

V-237962

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

IBMZ-VM-001280

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure the product Rules Facility is installed.

Ensure that authority to create system rules or rules that apply to other users is only granted to appropriate personnel.

Check Contents

Issue Command:

VMSECURE CONFIG AUTHORIZ

Inspect the "GRANT" statements.

If there are statements that grant the authority to create system rules or rules that apply to other users is only granted to appropriate personnel, this is not a finding.

Vulnerability Number

V-237962

Documentable

False

Rule Version

IBMZ-VM-001280

Severity Override Guidance

Issue Command:

VMSECURE CONFIG AUTHORIZ

Inspect the "GRANT" statements.

If there are statements that grant the authority to create system rules or rules that apply to other users is only granted to appropriate personnel, this is not a finding.

Check Content Reference

M

Target Key

5306