STIGQter STIGQter: STIG Summary: z/OS Front End Processor for ACF2 Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 01 Oct 2025:

An active log is not available to keep track of all hardware upgrades and software changes made to the FEP (Front End Processor).

DISA Rule

SV-230186r1144192_rule

Vulnerability Number

V-230186

Group Title

SRG-OS-000480

Rule Version

ZFEP0014

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The systems programmer will notice that a log of all hardware and software upgrades/changes has been created for auditing purposes and problem tracking. All changes and upgrades will be logged.

Check Contents

Review site documentation to validate that procedures are in place to protect the FEP service subsystem and diskette drive:

- All documents and procedures that apply to FEP operations including network management, FEP initialization, IPL, shutdown, NCP dumping, backup, and recovery.

If a log is in place to keep track of all hardware upgrades and software changes, this is not a finding.

Vulnerability Number

V-230186

Documentable

False

Rule Version

ZFEP0014

Severity Override Guidance

Review site documentation to validate that procedures are in place to protect the FEP service subsystem and diskette drive:

- All documents and procedures that apply to FEP operations including network management, FEP initialization, IPL, shutdown, NCP dumping, backup, and recovery.

If a log is in place to keep track of all hardware upgrades and software changes, this is not a finding.

Check Content Reference

M

Target Key

5235