STIGQter STIGQter: STIG Summary: CA IDMS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 01 Jul 2026:

IDMS must protect against the use of web-based applications that use generic IDs.

DISA Rule

SV-251597r960864_rule

Vulnerability Number

V-251597

Group Title

SRG-APP-000080-DB-000063

Rule Version

IDMS-DB-000170

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

For web-based applications using generic IDs, set the individual user ID (external identity) to be recorded in the journal.

For JDBC applications, use the "IdmsConnection setIdentity" method.

For ODBC applications, use the "SQLSetConnectAttr" function with the IDMS_ATTR_EXTERNAL_IDENTITY attribute type.

Run journal report "JREPORT 010" and" JREPORT 008" to audit the individual user ID.

Check Contents

If there are web-based applications to which individual users sign on, and a generic ID associated with the application is used to access back-end IDMS databases, this is a finding.

Vulnerability Number

V-251597

Documentable

False

Rule Version

IDMS-DB-000170

Severity Override Guidance

If there are web-based applications to which individual users sign on, and a generic ID associated with the application is used to access back-end IDMS databases, this is a finding.

Check Content Reference

M

Target Key

5418