Check: SOL-11.1-090270
Solaris 11 x86 STIG:
SOL-11.1-090270
(in versions v2 r10 through v1 r10)
Title
The operating system must identify potentially security-relevant error conditions. (Cat II impact)
Discussion
Security functional testing involves testing the operating system for conformance to the operating system security function specifications, as well as for the underlying security model. The need to verify security functionality applies to all security functions. The conformance criteria state the conditions necessary for the operating system to exhibit the desired security behavior or satisfy a security property. For example, successful login triggers an audit entry.
Check Content
Ask the operator if DoD-approved SCAP compliance checking software is installed and run on a periodic basis. If DoD-approved SCAP compliance checking software is not installed and/or not run on a periodic basis, this is a finding.
Fix Text
Install, configure, and run DoD-approved SCAP compliance checking software on a periodic basis. Review the output of the software and document any out-of-compliance issues.
Additional Identifiers
Rule ID: SV-224673r854575_rule
Vulnerability ID: V-224673
Group Title: SRG-OS-000445
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001311 |
The information system identifies potentially security-relevant error conditions. |
CCI-002696 |
The information system verifies correct operation of organization-defined security functions. |
Controls
Number | Title |
---|---|
SI-6 |
Security Function Verification |