The IBM z/OS systems requiring data-at-rest protection must properly employ IBM DS8880 or equivalent hardware solutions for full disk encryption.
DISA Rule
SV-223788r1028297_rule
Vulnerability Number
V-223788
Group Title
SRG-OS-000396-GPOS-00176
Rule Version
RACF-OS-000320
Severity
CAT I
CCI(s)
- CCI-001199 - Protects the confidentiality and/or integrity of organization-defined information at rest.
- CCI-002420 - Maintain the confidentiality and/or integrity of information during preparation for transmission.
- CCI-002445 - Distribute symmetric cryptographic keys using NIST FIPS-validated or NSA-approved key management technology and processes.
- CCI-002446 - Produces asymmetric cryptographic keys using: NSA-approved key management technology and processes; prepositioned keying material; DoD-approved or DoD-issued Medium Assurance PKI certificates; DoD-approved or DoD-issued Medium Hardware Assurance PKI certificates and hardware security tokens that protect the user's private key; or certificates issued in accordance with organization-defined requirements.
Weight
10
Fix Recommendation
Employ IBM's DS8880 hardware or equivalent hardware solutions to ensure full disk encryption.
Check Contents
Determine if IBM's DS8880 Disks or equivalent hardware solutions are in use.
If they are not in use for systems that require data at rest, this is a finding.
Vulnerability Number
V-223788
Documentable
False
Rule Version
RACF-OS-000320
Severity Override Guidance
Determine if IBM's DS8880 Disks or equivalent hardware solutions are in use.
If they are not in use for systems that require data at rest, this is a finding.
Check Content Reference
M
Target Key
4101