STIGQter STIGQter: STIG Summary: VMW vRealize Operations Manager 6.x PostgreSQL Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Sep 2018:

Security-relevant software updates to the vROps PostgreSQL DB must be installed within the time period directed by an authoritative source (e.g. IAVM, CTOs, DTMs, and STIGs).

DISA Rule

SV-98947r1_rule

Vulnerability Number

V-88297

Group Title

SRG-APP-000456-DB-000390

Rule Version

VROM-PG-000465

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Verify that patches and updates from an authoritative source are applied at least within 24 hours after they have been received and has been documented in the supporting documentation.

Check Contents

Obtain supporting documentation from the ISSO.

Review the policies and procedures used to ensure that all security-related upgrades are being installed within the configured time period directed by an authoritative source.

If all security-related upgrades are not being installed within the configured time period directed by an authoritative source, this is a finding.

Vulnerability Number

V-88297

Documentable

False

Rule Version

VROM-PG-000465

Severity Override Guidance

Obtain supporting documentation from the ISSO.

Review the policies and procedures used to ensure that all security-related upgrades are being installed within the configured time period directed by an authoritative source.

If all security-related upgrades are not being installed within the configured time period directed by an authoritative source, this is a finding.

Check Content Reference

M

Target Key

3445

Comments