STIGQter STIGQter: STIG Summary: zOS Front End Processor for TSS Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 01 Oct 2025:

An active log is not available to keep track of all hardware upgrades and software changes made to the FEP (Front End Processor).

DISA Rule

SV-224723r1145986_rule

Vulnerability Number

V-224723

Group Title

SRG-OS-000480

Rule Version

ZFEP0014

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The systems programmer will see that a a log of all hardware and software upgrades/changes has been created for auditing purposes and problem tracking. All changes and upgrades will be logged.

Check Contents

Review site documentation to validate that procedures are in place to protect the FEP service subsystem and diskette drive:

- All documents and procedures that apply to FEP operations including network management, FEP initialization, IPL, shutdown, NCP dumping, backup, and recovery.

If a log is in place to keep track of all hardware upgrades and software changes, this is not a finding.

Vulnerability Number

V-224723

Documentable

False

Rule Version

ZFEP0014

Severity Override Guidance

Review site documentation to validate that procedures are in place to protect the FEP service subsystem and diskette drive:

- All documents and procedures that apply to FEP operations including network management, FEP initialization, IPL, shutdown, NCP dumping, backup, and recovery.

If a log is in place to keep track of all hardware upgrades and software changes, this is not a finding.

Check Content Reference

M

Target Key

4193