CA VM:Secure product audit records must offload audit records to a different system or media.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-237938IBMZ-VM-000940SV-237938r851946_ruleCCI-001851medium
Description
Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Off-loading is a common process in information systems with limited audit storage capacity.
STIGDate
IBM zVM Using CA VM:Secure Security Technical Implementation Guide2022-08-31

Details

Check Text (C-237938r851946_chk)

If there is no documented process for audit offload, this is a finding. Examine the documented user process for audit record offload. If the procedure does not offload to a different system or media, this is a finding.

Fix Text (F-41107r649653_fix)

Develop a user written procedure to offload audit records to a different system or media.