NIST Checklist Logo
NIST Security Configuration Checklists Repository
BETA
Browse Repository by
   Product Category
   Vendor
   Submitting
Organization

Our Sponsor
white space white space

VMS – OpenVMS VAX/ALPHA Security Readiness Review Security Checklist

Name

VMS – OpenVMS VAX/ALPHA Security Readiness Review Security Checklist, Version 2 Release 2

Version

Version 2 Release 2

Status

Final

Creation Date

Not available.

Revision Date

2005-01-28

Product Category

Operating System

Vendor

Compaq

Product

OpenVMS Operating System

Product Version

Versions 5.3 through 7.3

Product Role

Server

Checklist Summary

The VMS - OpenVMS SRR targets conditions that undermine the integrity of security, contribute to inefficient security operations and administration, or may lead to interruption of production operations.  Additionally, the review ensures the site has properly installed and implemented the VMS/OpenVMS environment and that it is being managed in a way that is secure, efficient, and effective.  The items reviewed are based on standards and requirements published by DISA in the Security Handbook and other DoD Policy and regulations.  (There is no available VMS – OpenVMS Security Technical Implementation Guide.) The results of the SRR scripts will coincide with the VMS-OpenVMS SRR Checklist with the following: F- Finding, N/F- Not A Finding, N/A- Not Applicable, MR -Manual Review, or NR – Not Reviewed.

DISA Field Security Operations has assigned a level of urgency to each finding based on Chief Information Officer (CIO) established criteria for certification and accreditation.  All findings are based on regulations and guidelines.  All findings require correction by the host organization. Category I findings are any vulnerabilities that provide an attacker immediate access into a machine, superuser access, or access that bypasses a firewall.  Category II findings are any vulnerabilities that provide information that has a high potential of giving access to an intruder.  Category III findings are any vulnerabilities that provide information that potentially could lead to compromise.  Category IV vulnerabilities, when resolved, will prevent the possibility of degraded security.

The VMS - OpenVMS Security Checklist is composed of five major sections and two appendices.  The major sections within this checklist are sections 2A and 3A. Section 2A, the “SRR Results Report”, is comprised of a matrix that allows the reviewer to manually document vulnerabilities discovered during the Security Readiness Review (SRR). Section 3A, “Checklist Procedures”, documents procedures to instruct reviewers about how to manually perform the SRR for each specific PDI.

Known Issues

Not available.

Target Audience

Developped for the DOD.
This document is intended for IAOs, SAs, IAMs, NSOs, and others who are responsible for the configuration, management, or support of information systems.  It assumes that the reader has knowledge of the OpenVMS operating system and is familiar with common computer terminology.

Target Operational Environment

Enterprise and Specialized Security-Limited Functionality.

Checklist Installation Tools

The scripts need to be unzipped (Windows) or untarred/uncompressed (Unix) and/or copied to the host system (Windows, Unix copy commands).

Rollback Capability

Not available.

Testing Information

Not available.

NIAP/CMVP Status

Not available.

Regulatory Compliance

DOD Directive 8500.

Comments, Warnings, Disclaimer, Miscellaneous

Please refer to the Checklist or the README.txt files provided with the scripts for any comments, warnings, or detailed instructions.

Disclaimer

Not available.

Product Support

It should be noted that FSO Support for the STIGs, Checklists, and Tools is only available to DOD Customers.

Submitting Organization/Authors

Defense Information Systems Agency

Point of Contact

Not available.

Sponsor

Not available.

Licensing

Not available.

Checklist Homepage

http://iase.disa.mil/stigs/checklist/index.html

Download Package

http://iase.disa.mil/stigs/checklist/
vms-openvms_srrchklst_v2r2-01jan2005.zip

Integrity

SHA1 Digest
(vms-openvms_srrchklst_v2r2-01jan2005.zip) =
b3d7468b4b756b790448f29bd4b9cf3137fc9883

SHA256 Digest
(vms-openvms_srrchklst_v2r2-01jan2005.zip) =
9de980d03031761020c7388928bb76a7e0de8a
950b2375d8478ac62c30d1c1bd

Change History

Version 2, Release 1: 2003-10-31
Version 2, Release 2: 2005-01-28

Dependency/Requirement

Not available.

References

Not available.

NIST Identifier

1080



NIST and the checklist submitter do not guarantee or warrant the checklist's accuracy or completeness. NIST is not responsible for loss, damage, or problems that may be caused by using the checklist.

Last updated: November 15, 2006
Page created: October 28, 2004

Disclaimer Notice & Privacy Statement / Security Notice
Send comments or suggestions to checklists@nist.gov
NIST is an Agency of the U.S. Commerce Department's Technology Administration