The VMM must off-load audit records onto a different system or media than the system being audited.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-207453SRG-OS-000342-VMM-001230SV-207453r958754_ruleCCI-001851medium
Description
Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Off-loading is a common process in VMMs with limited audit storage capacity.
STIGDate
Virtual Machine Manager Security Requirements Guide2024-12-06

Details

Check Text (C-207453r958754_chk)

Verify the VMM off-loads audit records onto a different system or media than the system being audited. If it does not, this is a finding.

Fix Text (F-7710r365764_fix)

Configure the VMM to off-load audit records onto a different system or media than the system being audited.