The IBM z/OS systems requiring data at rest protection must properly employ IBM DS8880 or equivalent hardware solutions for full disk encryption.
DISA Rule
SV-251108r1028298_rule
Vulnerability Number
V-251108
Group Title
SRG-OS-000404-GPOS-00183
Rule Version
TSS0-OS-000320
Severity
CAT I
CCI(s)
- CCI-002476 - Implement cryptographic mechanisms to prevent unauthorized disclosure of organization-defined information at rest on organization-defined system components.
- CCI-001199 - Protects the confidentiality and/or integrity of organization-defined information at rest.
- CCI-002420 - Maintain the confidentiality and/or integrity of information during preparation for transmission.
- CCI-002445 - Distribute symmetric cryptographic keys using NIST FIPS-validated or NSA-approved key management technology and processes.
- CCI-002446 - Produces asymmetric cryptographic keys using: NSA-approved key management technology and processes; prepositioned keying material; DoD-approved or DoD-issued Medium Assurance PKI certificates; DoD-approved or DoD-issued Medium Hardware Assurance PKI certificates and hardware security tokens that protect the user's private key; or certificates issued in accordance with organization-defined requirements.
Weight
10
Fix Recommendation
Employ IBM's DS8880 hardware or equivalent hardware solutions to ensure full disk encryption.
Check Contents
Determine if IBM's DS880 Disks or equivalent hardware solutions are in use.
If IBMs DS880 Disks or equivalent hardware solutions are not in use for systems that require "data at rest", this is a finding.
Vulnerability Number
V-251108
Documentable
False
Rule Version
TSS0-OS-000320
Severity Override Guidance
Determine if IBM's DS880 Disks or equivalent hardware solutions are in use.
If IBMs DS880 Disks or equivalent hardware solutions are not in use for systems that require "data at rest", this is a finding.
Check Content Reference
M
Target Key
4102