STIGQter STIGQter: STIG Summary: Mainframe Product Security Requirements Guide Version: 3 Release: 5 Benchmark Date: 01 Jul 2026:

The Mainframe Product must audit the enforcement actions used to restrict access associated with changes to the application.

DISA Rule

SV-205567r982317_rule

Vulnerability Number

V-205567

Group Title

SRG-APP-000381

Rule Version

SRG-APP-000381-MFP-000188

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Mainframe Product change management settings to audit the enforcement actions used to restrict access associated with changes to application configuration to appropriate users according to organizational change policies.

Check Contents

Examine Configuration settings.

Examine organization change management policies.

If the Mainframe Product does not audit the enforcement actions used to access restriction associated with changes to the application in accordance with change management policies using System Management Facility (SMF) or an external security manager audit, this is a finding.

Vulnerability Number

V-205567

Documentable

False

Rule Version

SRG-APP-000381-MFP-000188

Severity Override Guidance

Examine Configuration settings.

Examine organization change management policies.

If the Mainframe Product does not audit the enforcement actions used to access restriction associated with changes to the application in accordance with change management policies using System Management Facility (SMF) or an external security manager audit, this is a finding.

Check Content Reference

M

Target Key

2906