UCF STIG Viewer Logo

The IAO/SA is not receiving Sun Ray security and patch notifications.


Overview

Finding ID Version Rule ID IA Controls Severity
V-16409 SUN0100 SV-17402r1_rule ECSC-1 Medium
Description
Organizations need to stay current with all applicable Sun Ray Server software updates that are released from Sun. In order to be aware of updates as they are released, Sun Ray system administrators will subscribe to Sun Ray Server vendor security notices, updates, and patches to ensure that all new vulnerabilities are known. New Sun Ray Server patches and updates should be reviewed for the Sun Ray Server before moving them into a production environment.
STIG Date
Sun Ray 4 Policy STIG 2015-04-02

Details

Check Text ( C-17277r1_chk )
Ask the IAO/SA to provide actual update notification or email to verify that they are on the subscription list. The email subscription for Sun is the SunSolve Patch Club Report and it is sent out weekly by Sun. If no emails or documentation can be provided, this is a finding.
Fix Text (F-16435r1_fix)
Access Sun Microsystem's website and update your profile by going to subscriptions and select the SunSolve Patch Club Report. This will ensure you get emails on all new and updated patches through SunSolve.