STIGQter STIGQter: STIG Summary: CA IDMS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 01 Jul 2026:

All installation-delivered IDMS USER-level tasks must be properly secured.

DISA Rule

SV-251586r1137654_rule

Vulnerability Number

V-251586

Group Title

SRG-APP-000033-DB-000084

Rule Version

IDMS-DB-000060

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The SRTT module must be coded to enable task-level security. When using an external security manager (ESM), this could be done in the following manner:

#SECRTT TYPE=ENTRY, X
RESTYPE=TASK, X
SECBY=EXTERNAL , X
EXTNAME=(RESTYPE,RESNAME), X
EXTCLS='CA@IDMS'

or to give access specifically to one or more tasks (in this case, to ADS):

#SECRTT TYPE=ENTRY, RESTYPE=TASK, X
SECBY=OFF, X
EXTNAME=(RESTYPE,RESNAME),EXTCLS='CA@IDMS'

with an OCCUR statement for each task:

#SECRTT TYPE=OCCUR,RESTYPE=TASK, X
SECBY=EXTERNAL, X
RESNAME='ADS'

Using the above examples, the ESM must be configured to grant access for resource name "TASK.task-name" to security group (or role) USER, for security class "CA@IDMS", where "task-name" is one of the user-level tasks listed. This grant must be repeated for each Task in the list. The appropriate ESM rules must then be given to the appropriate users. For instance, in Top Secret:
TSS PER(user_id) CA@IDMS(TASK.ADS)

In ACF2:
$KEY(TASK.ADS) TYPE(CA@IDMS)
UID(user_id) ALLOW

In RACF:
PERMIT TASK.ADS CLASS(CA@IDMS) ID(user_id) ACCESS(READ)

After making the above changes, assemble and link RHDCSRTT to create a new SRTT. To implement the new SRTT, either recycle any CVs that use the SRTT or issue these commands:

DCMT VARY NUCLEUS MODULE RHDCSRTT NEW COPY
DCMT VARY NUCLEUS RELOAD

Check Contents

Examine load module "RHDCSRTT" by executing CA IDMS utility "IDMSSRTD", or by issuing command "DCMT DISPLAY SRTT" while signed onto the CV, and reviewing the output.

Note: This requires PTFs SO07995 and SO09476.

Validate the following suggested user-level tasks are secured in the SRTT (included, for example, in the roles of DCADMIN-, DBADMIN-, and DEVELOPER-level security).

Note: USER, DEVELOPER, DBADMIN, and DCADMIN are suggested categories only.
ADS
OCF
OCFT
OCFX
OLP
OLQ
OLQNT
OLQT
OLQTNOTE

If "TASK" is not found as the resource type in any of the entries, this is a finding.

If "TASK" is secured internally, this is a finding.

If "TASK" is secured externally in the SRTT, review the SRTT entries to ensure that the above tasks are secured and review ESM for external class and external name format to verify the appropriate authorizations have been defined. If they have not, this is a finding.

Vulnerability Number

V-251586

Documentable

False

Rule Version

IDMS-DB-000060

Severity Override Guidance

Examine load module "RHDCSRTT" by executing CA IDMS utility "IDMSSRTD", or by issuing command "DCMT DISPLAY SRTT" while signed onto the CV, and reviewing the output.

Note: This requires PTFs SO07995 and SO09476.

Validate the following suggested user-level tasks are secured in the SRTT (included, for example, in the roles of DCADMIN-, DBADMIN-, and DEVELOPER-level security).

Note: USER, DEVELOPER, DBADMIN, and DCADMIN are suggested categories only.
ADS
OCF
OCFT
OCFX
OLP
OLQ
OLQNT
OLQT
OLQTNOTE

If "TASK" is not found as the resource type in any of the entries, this is a finding.

If "TASK" is secured internally, this is a finding.

If "TASK" is secured externally in the SRTT, review the SRTT entries to ensure that the above tasks are secured and review ESM for external class and external name format to verify the appropriate authorizations have been defined. If they have not, this is a finding.

Check Content Reference

M

Target Key

5418