Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-237970 | IBMZ-VM-002400 | SV-237970r649750_rule | Medium |
Description |
---|
Audit reduction is a process that manipulates collected audit information and organizes such information in a summary format that is more meaningful to analysts. Audit reduction and report generation capabilities do not always emanate from the same information system or from the same organizational entities conducting auditing activities. Audit reduction capability can include, for example, modern data mining techniques with advanced data filters to identify anomalous behavior in audit records. Audit records may at times be voluminous. Without a reduction tool crucial information may be overlooked. |
STIG | Date |
---|---|
IBM zVM Using CA VM:Secure Security Technical Implementation Guide | 2022-08-31 |
Check Text ( C-41180r649748_chk ) |
---|
Ask the system administrator if there is an audit reduction tool available for use with IBM z/VM. Determine if a process is established to route audit records to the tool. If there is no audit tool available, this is a finding. If a procedure for routing audit records to the tool is not documented and on file with the ISSM/ISSO, this is a finding. |
Fix Text (F-41139r649749_fix) |
---|
Develop a process for routing audit records to an audit reduction tool. Document the process and file with the ISSM/ISSO. |