UCF STIG Viewer Logo

IBM z/VM must have access to an audit reduction tool that allows for central data review and analysis.


Overview

Finding ID Version Rule ID IA Controls Severity
V-237970 IBMZ-VM-002400 SV-237970r649750_rule Medium
Description
Audit reduction is a process that manipulates collected audit information and organizes such information in a summary format that is more meaningful to analysts. Audit reduction and report generation capabilities do not always emanate from the same information system or from the same organizational entities conducting auditing activities. Audit reduction capability can include, for example, modern data mining techniques with advanced data filters to identify anomalous behavior in audit records. Audit records may at times be voluminous. Without a reduction tool crucial information may be overlooked.
STIG Date
IBM zVM Using CA VM:Secure Security Technical Implementation Guide 2021-06-16

Details

Check Text ( C-41180r649748_chk )
Ask the system administrator if there is an audit reduction tool available for use with IBM z/VM.

Determine if a process is established to route audit records to the tool.

If there is no audit tool available, this is a finding.

If a procedure for routing audit records to the tool is not documented and on file with the ISSM/ISSO, this is a finding.
Fix Text (F-41139r649749_fix)
Develop a process for routing audit records to an audit reduction tool.

Document the process and file with the ISSM/ISSO.