For Mainframe Products providing audit record aggregation, the Mainframe Product must compile audit records from mainframe components into a system-wide audit trail that is time-correlated with a tolerance for the relationship between time stamps of individual records in the audit trail in accordance with the sites security plan.
From Mainframe Product Security Requirements Guide
Part of SRG-APP-000086-MFP-000110
Associated with:
CCI-000174
SV-82671r1_rule
For Mainframe Products providing audit record aggregation, the Mainframe Product must compile audit records from mainframe components into a system-wide audit trail that is time-correlated with a tolerance for the relationship between time stamps of individual records in the audit trail in accordance with the sites security plan.
Vulnerability discussion
Without the ability to collate records based on the time when the events occurred, the ability to perform forensic analysis and investigations across multiple components is significantly degraded.Audit trails are time-correlated if the time stamps in the individual audit records can be reliably related to the time stamps in other audit records to achieve a time ordering of the records within an organization-defined level of tolerance.This requirement applies only to Mainframe Products that provide the capability to compile system-wide audit records for multiple systems or system components.
Check content
If the Mainframe Product does not perform audit record aggregation, this is not applicable.
Examine configuration settings.
If the Mainframe Product settings do not use the operating system clock for time stamps, this is a finding.
Fix text
Configure the Mainframe Product to use the operating system clock for time stamps.
Pro Tips
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer