STIGQter STIGQter: STIG Summary: z/OS BMC IOA for RACF Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 01 Oct 2025:

BMC IOA security exits are not installed or configured properly.

DISA Rule

SV-224415r1144853_rule

Vulnerability Number

V-224415

Group Title

SRG-OS-000018

Rule Version

ZIOA0060

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The system programmer responsible for the BMC IOA will review the BMC IOA operating environment. Ensure that the following security exit(s) is (are) installed properly. Determine if the site has modified the following security exit(s):

IOASE06
IOASE07
IOASE09
IOASE12
IOASE16
IOASE32
IOASE40
IOASE42

Ensure that the security exit(s) has (have) not been modified.

If the security exit(s) has (have) been modified, ensure the security exit(s) has (have) been checked as to not violate any security integrity within the system and approval documentation is on file.

Check Contents

Interview the systems programmer responsible for the BMC IOA. Determine if the site has modified the following security exit(s):

IOASE06
IOASE07
IOASE09
IOASE12
IOASE16
IOASE32
IOASE40
IOASE42

Verify the above security exit(s) has (have) not been modified.

If the above security exit(s) has (have) been modified, verify that the security exit(s) has (have) been approved by the site systems programmer and the approval is on file for examination.

Vulnerability Number

V-224415

Documentable

False

Rule Version

ZIOA0060

Severity Override Guidance

Interview the systems programmer responsible for the BMC IOA. Determine if the site has modified the following security exit(s):

IOASE06
IOASE07
IOASE09
IOASE12
IOASE16
IOASE32
IOASE40
IOASE42

Verify the above security exit(s) has (have) not been modified.

If the above security exit(s) has (have) been modified, verify that the security exit(s) has (have) been approved by the site systems programmer and the approval is on file for examination.

Check Content Reference

M

Target Key

4139