The IBM z/VM System administrator must develop routines and processes for notification in the event of audit failure.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-237967IBMZ-VM-002370SV-237967r649741_ruleCCI-000366medium
Description
Audit processing failures include, for example, software/hardware errors, failures in the audit capturing mechanisms, and audit storage capacity being reached or exceeded. Without proper notification vital audit records may be lost.
STIGDate
IBM zVM Using CA VM:Secure Security Technical Implementation Guide2022-08-31

Related Frameworks

4 paths across 3 frameworks
NIST 800-531 mapping
CM-6
1.00
  • DISA · V2R2 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
NIST 800-1712 mappings
3.4.1
1.00
  • DISA · V2R2 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
3.4.2
1.00
  • DISA · V2R2 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
CCI-000366
1.00
  • DISA · V2R2 · disa_xccdf · related

Details

Check Text (C-237967r649741_chk)

Ask the system administrator (SA) for documented routines and procures for notification in the event of audit failure. If there are no routines or procedures or they are not documented and filed with the ISSO, this is a finding.

Fix Text (F-41136r649740_fix)

Develop a procedure for notification in the event of audit failure.