STIGQter STIGQter: STIG Summary: Mainframe Product Security Requirements Guide Version: 3 Release: 5 Benchmark Date: 01 Jul 2026:

The Mainframe Product must generate audit records when successful/unsuccessful attempts to access categories of information (e.g., classification levels) occur.

DISA Rule

SV-205602r961797_rule

Vulnerability Number

V-205602

Group Title

SRG-APP-000494

Rule Version

SRG-APP-000494-MFP-000119

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Mainframe Product to write to SMF and/or provide audit SAF to call when successful/unsuccessful attempts to access categories of information occur.

Check Contents

Examine installation and configuration settings.

Verify that the Mainframe Product identifies all security categories of information; writes to SMF and/or uses an external security manager to generate audit records when successful/unsuccessful attempts to access categories of information. If it does not, this is a finding.

Vulnerability Number

V-205602

Documentable

False

Rule Version

SRG-APP-000494-MFP-000119

Severity Override Guidance

Examine installation and configuration settings.

Verify that the Mainframe Product identifies all security categories of information; writes to SMF and/or uses an external security manager to generate audit records when successful/unsuccessful attempts to access categories of information. If it does not, this is a finding.

Check Content Reference

M

Target Key

2906