IBM z/VM must have access to an audit reduction tool that allows for central data review and analysis.

From IBM z/VM Using CA VM:Secure Security Technical Implementation Guide

Part of SRG-OS-000480-GPOS-00227

Associated with: CCI-000366

SV-93693r1_rule IBM z/VM must have access to an audit reduction tool that allows for central data review and analysis.

Vulnerability discussion

Audit reduction is a process that manipulates collected audit information and organizes such information in a summary format that is more meaningful to analysts. Audit reduction and report generation capabilities do not always emanate from the same information system or from the same organizational entities conducting auditing activities. Audit reduction capability can include, for example, modern data mining techniques with advanced data filters to identify anomalous behavior in audit records. Audit records may at times be voluminous. Without a reduction tool crucial information may be overlooked.

Check content

Ask the system administrator if there is an audit reduction tool available for use with IBM z/VM. Determine if a process is established to route audit records to the tool. If there is no audit tool available, this is a finding. If a procedure for routing audit records to the tool is not documented and on file with the ISSM/ISSO, this is a finding.

Fix text

Develop a process for routing audit records to an audit reduction tool. Document the process and file with the ISSM/ISSO.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer