IBM z/OS must enforce a minimum eight character password length.
DISA Rule
SV-252705r1225873_rule
Vulnerability Number
V-252705
Group Title
SRG-OS-000481-GPOS-00481
Rule Version
ACF2-ES-000990
Severity
CAT II
CCI(s)
- CCI-004065 - For password-based authentication, employ automated tools to assist the user in selecting strong password authenticators.
- CCI-004066 - For password-based authentication, enforce organization-defined composition and complexity rules.
Weight
10
Fix Recommendation
Configure the Password option "MINPSWD" to "8".
Check Contents
From an ACF command screen enter:
SET CONTROL(GSO)
LIST PSWD
If "MINPSWD" is set to "8", this is not a finding.
Vulnerability Number
V-252705
Documentable
False
Rule Version
ACF2-ES-000990
Severity Override Guidance
From an ACF command screen enter:
SET CONTROL(GSO)
LIST PSWD
If "MINPSWD" is set to "8", this is not a finding.
Check Content Reference
M
Target Key
4100