IBM z/VM must have access to an audit reduction tool that allows for central data review and analysis.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-237970
IBMZ-VM-002400
SV-237970r649750_rule
Medium
Description
Audit reduction is a process that manipulates collected audit information and organizes such information in a summary format that is more meaningful to analysts. Audit reduction and report generation capabilities do not always emanate from the same information system or from the same organizational entities conducting auditing activities. Audit reduction capability can include, for example, modern data mining techniques with advanced data filters to identify anomalous behavior in audit records. Audit records may at times be voluminous. Without a reduction tool crucial information may be overlooked.