IBM z/VM must employ a Session manager.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-237963SRG-OS-000480-GPOS-00227IBMZ-VM-002330SV-237963r649729_rule2022-08-312

Description

A session manager controls the semi-permanent interactive information interchange, also known as a dialogue, between a user and z/VM. Without the use of a session manager these semi-permanent interchanges can be open to compromise and attacks.

ℹ️ Check

Examine running systems. If access is gained to the z/VM system without going through a session manager, this is a finding.

✔️ Fix

Ensure that a session manager is in use with the system.