STIGQter STIGQter: STIG Summary: CA IDMS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 01 Jul 2026:

IDMS must use the ESM to generate auditable records for resources when DOD-defined auditable events occur.

DISA Rule

SV-251599r1212353_rule

Vulnerability Number

V-251599

Group Title

SRG-APP-000089-DB-000064

Rule Version

IDMS-DB-000190

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If some of the resource types were not defined to the #SECRTT with SECBY=EXTERNAL, update the #SECRTT security module to include the appropriate definitions.

Access Actions such as login - Resource type SGON
Privileged system access - Resource types SYST, DB, DMCL, DBTB
Privileged object access - Resource types SLOD, SACC, QUEU
Privileged program access - Resource type TASK, SPGM

To update the #SECRTT entries, change any invalid definitions of SECBY=INTERNAL to SECBY=EXTERNAL for the resources listed above. If any of the resource types are missing, add them. Once the updates are complete, recompile the RHDCSRTT module. Confirm that the resource types are referenced appropriately by the external security manager.

Check Contents

Examine load module RHDCSRTT by executing CA IDMS utility IDMSSRTD or by issuing command "DCMT DISPLAY SRTT" while signed on to the CV and reviewing the output.

Note: This requires PTFs SO07995 and SO09476.

If the ESM specification does not match the RHDCSRTT entry, this is a finding.

Validate each of the following listed entries:
Access Actions such as login - Resource type SGON
Privileged system access - Resource types SYST, DB, DMCL, DBTB
Privileged object access - Resource types SLOD, SACC, QUEU
Privileged program access - Resource type TASK, SPGM

If any are not secured externally, this is a finding.

Vulnerability Number

V-251599

Documentable

False

Rule Version

IDMS-DB-000190

Severity Override Guidance

Examine load module RHDCSRTT by executing CA IDMS utility IDMSSRTD or by issuing command "DCMT DISPLAY SRTT" while signed on to the CV and reviewing the output.

Note: This requires PTFs SO07995 and SO09476.

If the ESM specification does not match the RHDCSRTT entry, this is a finding.

Validate each of the following listed entries:
Access Actions such as login - Resource type SGON
Privileged system access - Resource types SYST, DB, DMCL, DBTB
Privileged object access - Resource types SLOD, SACC, QUEU
Privileged program access - Resource type TASK, SPGM

If any are not secured externally, this is a finding.

Check Content Reference

M

Target Key

5418