STIGQter STIGQter: STIG Summary: IBM z/OS RACF Security Technical Implementation Guide Version: 8 Release: 3 Benchmark Date: 23 Apr 2021:

The IBM z/OS Policy Agent must contain a policy that manages excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial-of-service (DoS) attacks.

DISA Rule

SV-223793r604139_rule

Vulnerability Number

V-223793

Group Title

SRG-OS-000142-GPOS-00071

Rule Version

RACF-OS-000370

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Develop Policy application and Policy agent to manage excess capacity.

Check Contents

Examine the Policy Agent policy statements.

If it can be determined that there are policy statements that manages excess capacity, this is not a finding.

Vulnerability Number

V-223793

Documentable

False

Rule Version

RACF-OS-000370

Severity Override Guidance

Examine the Policy Agent policy statements.

If it can be determined that there are policy statements that manages excess capacity, this is not a finding.

Check Content Reference

M

Target Key

4101

Comments