UCF STIG Viewer Logo

The vAMI installation procedures must be capable of being rolled back to a last known good configuration.


Overview

Finding ID Version Rule ID IA Controls Severity
V-90215 VRAU-VA-000180 SV-100865r1_rule Medium
Description
Any changes to the components of the application server can have significant effects on the overall security of the system. In order to ensure a prompt response to failed application installations and application server upgrades, the application server must provide an automated rollback capability that allows the system to be restored to a previous known good configuration state prior to the application installation or application server upgrade.
STIG Date
VMW vRealize Automation 7.x vAMI Security Technical Implementation Guide 2018-10-12

Details

Check Text ( C-89907r1_chk )
Interview the ISSO and/or the SA.

Determine if there is a local procedure to revert to the last known good configuration in the event of failed installations and upgrades.

If a procedure does not exist or is not being followed, this is a finding.
Fix Text (F-96957r1_fix)
Develop and implement a site procedure to revert to the last known good configuration in the event of failed installations and upgrades.