IBM z/OS BUFUSEWARN in the SMFPRMxx must be properly set.
DISA Rule
SV-223772r971542_rule
Vulnerability Number
V-223772
Group Title
SRG-OS-000343-GPOS-00134
Rule Version
RACF-OS-000160
Severity
CAT II
CCI(s)
- CCI-000139 - Alert organization-defined personnel or roles within an organization-defined time period in the event of an audit logging process failure.
- CCI-001855 - Provide a warning to organization-defined personnel, roles, and/or locations within an organization-defined time period when allocated audit log storage volume reaches an organization-defined percentage of repository maximum audit log storage capacity.
- CCI-001858 - Provide an alert in an organization-defined real-time-period to organization-defined personnel, roles, and/or locations when organization-defined audit failure events requiring real-time alerts occur.
Weight
10
Fix Recommendation
Configure the BUFUSEWARN statement in SMFPRMxx to "75" (75%) or less.
Check Contents
Refer to IEASYS00 member in SYS1.PARMLIB Concatenation. Determine proper SMFPRMxx member in SYS1.PARMLIB.
If BUFUSEWARN is set for "75" (75%) or less, this is not a finding.
Vulnerability Number
V-223772
Documentable
False
Rule Version
RACF-OS-000160
Severity Override Guidance
Refer to IEASYS00 member in SYS1.PARMLIB Concatenation. Determine proper SMFPRMxx member in SYS1.PARMLIB.
If BUFUSEWARN is set for "75" (75%) or less, this is not a finding.
Check Content Reference
M
Target Key
4101