Check: IBMZ-VM-000790
IBM zVM STIG:
IBMZ-VM-000790
(in version v1 r0.1)
Title
The IBM z/VM CA VM:Secure product must be installed and operating. (Cat II impact)
Discussion
When operating system accounts are removed, user accessibility is affected. Accounts are utilized for identifying individual users or for identifying the operating system processes themselves. In order to detect and respond to events affecting user accessibility and system processing, operating systems must audit account removal actions and, as required, notify the appropriate individuals so they can investigate the event. Such a capability greatly reduces the risk that operating system accessibility will be negatively affected for extended periods of time and provides logging that can be used for forensic purposes. To address access requirements, many operating systems can be integrated with enterprise-level authentication/access/auditing mechanisms that meet or exceed access control policy requirements.
Check Content
Verify that CA VM:Secure product is operational on the system by entering the following command: From the CMS Command line enter “VMSECURE VERSION”. If there is no response “VMSECURE” is not logged in, this is a finding.
Fix Text
CA VM:Secure product audits all commands. Ensure that CA VM:Secure product is installed and operational.
Additional Identifiers
Rule ID:
Vulnerability ID: IBMZ-VM-000790
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001405 |
The information system automatically audits account removal actions. |
Controls
Number | Title |
---|---|
AC-2 (4) |
Automated Audit Actions |