STIGQter STIGQter: STIG Summary: Mainframe Product Security Requirements Guide Version: 3 Release: 5 Benchmark Date: 01 Jul 2026:

The Mainframe Product must allow only the information system security manager (ISSM) or individuals or roles appointed by the ISSM to select which auditable events are to be audited.

DISA Rule

SV-205460r960882_rule

Vulnerability Number

V-205460

Group Title

SRG-APP-000090

Rule Version

SRG-APP-000090-MFP-000115

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Mainframe Product to restrict selection of auditable events to security administrators (or individuals or roles appointed by the ISSM).

Check Contents

Examine the configuration settings.

Verify the capability to select auditable events is restricted to security administrators (or individuals or roles appointed by the ISSM). If it is not, this is a finding.

Vulnerability Number

V-205460

Documentable

False

Rule Version

SRG-APP-000090-MFP-000115

Severity Override Guidance

Examine the configuration settings.

Verify the capability to select auditable events is restricted to security administrators (or individuals or roles appointed by the ISSM). If it is not, this is a finding.

Check Content Reference

M

Target Key

2906