STIGQter STIGQter: STIG Summary: IBM zSecure Suite Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 02 Apr 2025:

IBM Security zSecure must implement organization-defined automated security responses if baseline zSecure configurations are changed in an unauthorized manner.

DISA Rule

SV-259735r961458_rule

Vulnerability Number

V-259735

Group Title

SRG-APP-000379-MFP-000186

Rule Version

ZSEC-00-000200

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The recipients of the SMF reports or alert messages must investigate whether the UPDATE is legitimate (e.g., is documented and approved in a change management request). If it is not, they must restore the original configuration setting.

Check Contents

Verify that a (daily) scheduled batch job is defined and used or a custom alert is configured and activated to inform appropriate personnel, such as auditors and compliance officers, about successful changes to the zSecure configuration data sets on their z/OS systems.

If SMF records regarding successful UPDATE(s) to zSecure configuration data sets are not reported to the information system security manager (ISSM), this is a finding.

Vulnerability Number

V-259735

Documentable

False

Rule Version

ZSEC-00-000200

Severity Override Guidance

Verify that a (daily) scheduled batch job is defined and used or a custom alert is configured and activated to inform appropriate personnel, such as auditors and compliance officers, about successful changes to the zSecure configuration data sets on their z/OS systems.

If SMF records regarding successful UPDATE(s) to zSecure configuration data sets are not reported to the information system security manager (ISSM), this is a finding.

Check Content Reference

M

Target Key

5574