The IBM z/OS systems requiring data at rest protection must properly employ IBM DS8880 or equivalent hardware solutions for full disk encryption.
DISA Rule
SV-223569r1225793_rule
Vulnerability Number
V-223569
Group Title
SRG-OS-000185-GPOS-00079
Rule Version
ACF2-OS-000340
Severity
CAT I
CCI(s)
- CCI-001199 - Protects the confidentiality and/or integrity of organization-defined information at rest.
- CCI-002450 - Implement organization-defined types of cryptography for each specified cryptography use.
- CCI-002475 - Implement cryptographic mechanisms to prevent unauthorized modification of organization-defined information when at rest on organization-defined system components.
- CCI-002476 - Implement cryptographic mechanisms to prevent unauthorized disclosure of organization-defined information at rest on organization-defined system components.
Weight
10
Fix Recommendation
Employ IBM's DS8880 hardware or equivalent hardware solutions to ensure full disk encryption.
Check Contents
Determine if IBM's DS880 Disks or equivalent hardware solutions are in use.
If they are not in use for systems that require data at rest, this is a finding.
Vulnerability Number
V-223569
Documentable
False
Rule Version
ACF2-OS-000340
Severity Override Guidance
Determine if IBM's DS880 Disks or equivalent hardware solutions are in use.
If they are not in use for systems that require data at rest, this is a finding.
Check Content Reference
M
Target Key
4100