STIGQter STIGQter: STIG Summary: CA IDMS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 01 Jul 2026:

The storage used for data collection by CA IDMS web services must be protected.

DISA Rule

SV-251647r961638_rule

Vulnerability Number

V-251647

Group Title

SRG-APP-000441-DB-000378

Rule Version

IDMS-DB-000830

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Use the following system generation parameters to enable the use of standard storage protection:

Set STORAGE KEY parameter of the SYSTEM statement to a value that is not "9". (The value other than 9 is dependent on how the z/OS parm AllowUserKeyCSA is set).

Set PROTECT/NOPROTECT parameter of the SYSTEM statement to "PROTECT".

Set PROTECT/NOPROTECT parameter of the PROGRAM statement to "PROTECT" for RHDCWSSP.

Generate and restart the system.

Check Contents

Log on to IDMS DC system and issue "DCPROFIL". If SYSTEM STORAGE PROTECTED: display is "NO", this is a finding.

Issue DCMT D PROGRAM RHDCWSSP. If Storage Prot is "NO", this is a finding.

Vulnerability Number

V-251647

Documentable

False

Rule Version

IDMS-DB-000830

Severity Override Guidance

Log on to IDMS DC system and issue "DCPROFIL". If SYSTEM STORAGE PROTECTED: display is "NO", this is a finding.

Issue DCMT D PROGRAM RHDCWSSP. If Storage Prot is "NO", this is a finding.

Check Content Reference

M

Target Key

5418