Check: IBMZ-VM-000810
IBM zVM STIG:
IBMZ-VM-000810
(in version v1 r0.1)
Title
The IBM z/VM JOURNALING statement must be coded on the configuration file. (Cat II impact)
Discussion
If auditing is enabled late in the start-up process, the actions of some start-up processes may not be audited. Some audit systems also maintain state information only available if auditing is enabled before a given process is created.
Check Content
Examine the Product Configuration file. If the “JOURNALING” Statement does not specify “ON”, this is a finding.
Fix Text
Configure the System Configuration “JOURNALING” statement to “JOURNALING ON”.
Additional Identifiers
Rule ID:
Vulnerability ID: IBMZ-VM-000810
Group Title:
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
CCI-001464 |
The information system initiates session audits at system start-up. |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
AU-14 (1) |
System Start-Up |