STIGQter STIGQter: STIG Summary: Mainframe Product Security Requirements Guide Version: 1 Release: 4 Benchmark Date: 24 Jan 2020:

The Mainframe Product must generate audit records when successful/unsuccessful attempts to access privileges occur.

DISA Rule

SV-82681r1_rule

Vulnerability Number

V-68191

Group Title

SRG-APP-000091-MFP-000116

Rule Version

SRG-APP-000091-MFP-000116

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Mainframe Product to write to SMF and/or provide audit SAF call for the external security manager when successful/unsuccessful attempts to access privileges occur.

Check Contents

Examine the installation and configuration settings.

Verify that the Mainframe Product identifies privileged functions and writes to SMF and/or uses an external security manager to generate audit records when successful/unsuccessful attempts to access privileges occur.

If it does not, this is a finding.

Vulnerability Number

V-68191

Documentable

False

Rule Version

SRG-APP-000091-MFP-000116

Severity Override Guidance

Examine the installation and configuration settings.

Verify that the Mainframe Product identifies privileged functions and writes to SMF and/or uses an external security manager to generate audit records when successful/unsuccessful attempts to access privileges occur.

If it does not, this is a finding.

Check Content Reference

M

Target Key

3061

Comments