STIGQter STIGQter: STIG Summary: IBM z/OS RACF Security Technical Implementation Guide Version: 8 Release: 3 Benchmark Date: 23 Apr 2021:

IBM FTP.DATA configuration for the FTP server must have the INACTIVE statement properly set.

DISA Rule

SV-223743r604139_rule

Vulnerability Number

V-223743

Group Title

SRG-OS-000163-GPOS-00072

Rule Version

RACF-FT-000110

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the FTP configuration to include an Inactive statement with a value between 1 and 900 (seconds).

Check Contents

Refer to the Data configuration file specified on the SYSFTPD DD statement in the FTP started task JCL.

If the INACTIVE statement is coded with a value between 1 and 900 (seconds), this is not a finding.

Vulnerability Number

V-223743

Documentable

False

Rule Version

RACF-FT-000110

Severity Override Guidance

Refer to the Data configuration file specified on the SYSFTPD DD statement in the FTP started task JCL.

If the INACTIVE statement is coded with a value between 1 and 900 (seconds), this is not a finding.

Check Content Reference

M

Target Key

4101

Comments