STIGQter STIGQter: STIG Summary: Mainframe Product Security Requirements Guide Version: 3 Release: 5 Benchmark Date: 01 Jul 2026:

The Mainframe Product must automatically terminate a user session after conditions, as defined in site security plan, are met or trigger events requiring session disconnect.

DISA Rule

SV-205535r1043182_rule

Vulnerability Number

V-205535

Group Title

SRG-APP-000295

Rule Version

SRG-APP-000295-MFP-000006

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Mainframe Product to automatically terminate a user session after any conditions as defined in site security plan or trigger requiring disconnect.

Check Contents

If the Mainframe Product has no data screen capability, this requirement is not applicable.

Determine whether the Mainframe Product has capability to terminate user sessions according to conditions as defined in site security plan and triggers. If it cannot, this is a finding.

Examine Configuration settings to determine whether the Mainframe Product is configured to automatically terminate sessions. If it is not, this is a finding.

Vulnerability Number

V-205535

Documentable

False

Rule Version

SRG-APP-000295-MFP-000006

Severity Override Guidance

If the Mainframe Product has no data screen capability, this requirement is not applicable.

Determine whether the Mainframe Product has capability to terminate user sessions according to conditions as defined in site security plan and triggers. If it cannot, this is a finding.

Examine Configuration settings to determine whether the Mainframe Product is configured to automatically terminate sessions. If it is not, this is a finding.

Check Content Reference

M

Target Key

2906