The IBM z/VM System administrator must develop routines and processes for notification in the event of audit failure.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-237967 | IBMZ-VM-002370 | SV-237967r649741_rule | CCI-000366 | medium |
| Description | ||||
| Audit processing failures include, for example, software/hardware errors, failures in the audit capturing mechanisms, and audit storage capacity being reached or exceeded. Without proper notification vital audit records may be lost. | ||||
| STIG | Date | |||
| IBM zVM Using CA VM:Secure Security Technical Implementation Guide | 2022-08-31 | |||
Details
Check Text (C-237967r649741_chk)
Ask the system administrator (SA) for documented routines and procures for notification in the event of audit failure.
If there are no routines or procedures or they are not documented and filed with the ISSO, this is a finding.
Fix Text (F-41136r649740_fix)
Develop a procedure for notification in the event of audit failure.