STIGQter STIGQter: STIG Summary: CA IDMS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 01 Jul 2026:

IDMS must reveal security-related messages only to authorized users.

DISA Rule

SV-251626r961170_rule

Vulnerability Number

V-251626

Group Title

SRG-APP-000267-DB-000163

Rule Version

IDMS-DB-000550

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

In the source for RHDCOPTF, add lines:

#DEFOPT OPT00051 <-for messages sent to user
#DEFOPT OPT00226 <-for messages sent to IDMS log

Then, reassemble and relink RHDCOPTF. Reload RHDCOPTF in the CV by issuing the following commands:

DCMT VARY NUCLEUS MODULE RHDCOPTF NEW COPY
DCMT VARY NUCLEUS RELOAD

Contact the security office to ensure that ADSOBPLG, the ADS print log utility, is secured via the ESM and assigned to the appropriate users, and that the ADS log file is secured from being read by others than ISSO, ISSM, SA, and DBA, also via the ESM.

Check Contents

Check that security messages from external security managers (ESMs) are sent only to the log which can be secured. Log on to IDMS DC system and issue "DCPROFIL". Scroll to the "OPTION FLAGS" screen.

If OPT00051 is not listed, this is a finding.

For IDMS LOG messages, if OPT00226 is not listed, this is a finding.

Contact the security office and verify that the user, groups, and roles are defined to the ESM so that DC log can only be viewed by Information System Security Officer (ISSO), Information System Security manager (ISSM), Systems Administrator (SA), and Database Administrator (DBA).

Vulnerability Number

V-251626

Documentable

False

Rule Version

IDMS-DB-000550

Severity Override Guidance

Check that security messages from external security managers (ESMs) are sent only to the log which can be secured. Log on to IDMS DC system and issue "DCPROFIL". Scroll to the "OPTION FLAGS" screen.

If OPT00051 is not listed, this is a finding.

For IDMS LOG messages, if OPT00226 is not listed, this is a finding.

Contact the security office and verify that the user, groups, and roles are defined to the ESM so that DC log can only be viewed by Information System Security Officer (ISSO), Information System Security manager (ISSM), Systems Administrator (SA), and Database Administrator (DBA).

Check Content Reference

M

Target Key

5418