| Checked | Name | Title |
|---|
| ☐ | SV-223419r1225652_rule | IBM z/OS Certificate Name Filtering must be implemented with appropriate authorization and documentation. |
| ☐ | SV-223420r1225653_rule | IBM z/OS must not use Expired Digital Certificates. |
| ☐ | SV-223421r1225654_rule | All IBM z/OS digital certificates in use must have a valid path to a trusted Certification authority. |
| ☐ | SV-223422r1225655_rule | CA-ACF2 OPTS GSO record must be set to ABORT mode. |
| ☐ | SV-223423r1225656_rule | The number of ACF2 users granted the special privilege PPGM must be justified. |
| ☐ | SV-223424r1225657_rule | The number of ACF2 users granted the special privilege OPERATOR must be kept to a strictly controlled minimum. |
| ☐ | SV-223425r1225658_rule | The number of ACF2 users granted the special privilege CONSOLE must be justified. |
| ☐ | SV-223426r1225659_rule | The number of ACF2 users granted the special privilege ALLCMDS must be justified. |
| ☐ | SV-223427r1225660_rule | IBM z/OS system commands must be properly protected. |
| ☐ | SV-223428r1225661_rule | IBM z/OS Sensitive Utility Controls must be properly defined and protected. |
| ☐ | SV-223429r1225662_rule | CA-ACF2 NJE GSO record value must indicate validation options that apply to jobs submitted through a network job entry subsystem (JES2, JES3, RSCS). |
| ☐ | SV-223430r1225663_rule | CA-ACF2 must protect Memory and privileged program dumps in accordance with proper security requirements. |
| ☐ | SV-223431r1225664_rule | CA-ACF2 must properly define users that have access to the CONSOLE resource in the TSOAUTH resource class. |
| ☐ | SV-223433r1225665_rule | CA-ACF2 must limit access to SYSTEM DUMP data sets to appropriate authorized users. |
| ☐ | SV-223434r1225666_rule | CA-ACF2 must limit access to SYS(x).TRACE to system programmers only. |
| ☐ | SV-223435r1225667_rule | CA-ACF2 allocate access to system user catalogs must be properly protected. |
| ☐ | SV-223436r1225668_rule | ACF2 Classes required to properly security the z/OS UNIX environment must be ACTIVE. |
| ☐ | SV-223437r1225669_rule | Access to IBM z/OS special privilege TAPE-LBL or TAPE-BLP must be limited and/or justified. |
| ☐ | SV-223438r1225670_rule | CA-ACF2 must limit access to System page data sets (i.e., PLPA, COMMON, and LOCALx) to system programmers. |
| ☐ | SV-223439r1225671_rule | IBM z/OS must protect dynamic lists in accordance with proper security requirements. |
| ☐ | SV-223440r1225672_rule | IBM z/OS Libraries included in the system REXXLIB concatenation must be properly protected. |
| ☐ | SV-223441r1225673_rule | CA-ACF2 must limit Write or greater access to SYS1.UADS To system programmers only and read and update access must be limited to system programmer personnel and/or security personnel. |
| ☐ | SV-223442r1225674_rule | CA-ACF2 must limit all system PROCLIB data sets to appropriate authorized users. |
| ☐ | SV-223443r1225675_rule | CA-ACF2 access to the System Master Catalog must be properly protected. |
| ☐ | SV-223444r1225676_rule | IBM z/OS MCS consoles access authorization(s) for CONSOLE resource(s) must be properly protected. |
| ☐ | SV-223445r1225677_rule | CA-ACF2 must limit Write or greater access to SYS1.NUCLEUS to system programmers only. |
| ☐ | SV-223446r1225678_rule | CA-ACF2 must limit Write or greater access to SYS1.LPALIB to system programmers only. |
| ☐ | SV-223447r1225679_rule | CA-ACF2 must limit Write or greater access to SYS1.IMAGELIB to system programmers. |
| ☐ | SV-223448r1225680_rule | CA-ACF2 must limit Write or greater access to Libraries containing EXIT modules to system programmers only. |
| ☐ | SV-223449r1225681_rule | CA-ACF2 must limit Write and Allocate access to all APF-authorized libraries to system programmers only. |
| ☐ | SV-223450r1225682_rule | CA-ACF2 must limit Write or greater access to all LPA libraries to system programmers only. |
| ☐ | SV-223451r1225683_rule | CA-ACF2 must limit Write and Allocate access to LINKLIST libraries to system programmers only. |
| ☐ | SV-223452r1225684_rule | CA-ACF2 must limit Write and allocate access to all system-level product installation libraries to system programmers only. |
| ☐ | SV-223453r1225685_rule | CA-ACF2 must limit Write or greater access to SYS1.SVCLIB to system programmers only. |
| ☐ | SV-223454r1225686_rule | CA-ACF2 Access to SYS1.LINKLIB must be properly protected. |
| ☐ | SV-223455r1225687_rule | CA-ACF2 must limit access to data sets used to back up and/or dump SMF collection files to appropriate users and/or batch jobs that perform SMF dump processing. |
| ☐ | SV-223456r1225688_rule | CA-ACF2 LOGONIDs must not be defined to SYS1.UADS for non-emergency use. |
| ☐ | SV-223457r1225689_rule | IBM z/OS IEASYMUP resource must be protected in accordance with proper security requirements. |
| ☐ | SV-223458r1225690_rule | CA-ACF2 must limit Update and Allocate access to system backup files to system programmers and/or batch jobs that perform DASD backups. |
| ☐ | SV-223459r1225691_rule | ACF2 PPGM GSO record value must specify protected programs that are only executed by privileged users. |
| ☐ | SV-223462r1225692_rule | The CA-ACF2 PSWD GSO record values for MAXTRY and PASSLMT must be properly set. |
| ☐ | SV-223463r1225693_rule | IBM z/OS SYS1.PARMLIB must be properly protected. |
| ☐ | SV-223464r1225694_rule | CA-ACF2 must be installed, functional, and properly configured. |
| ☐ | SV-223465r1225695_rule | CA-ACF2 must limit Write and allocate access to the JES2 System data sets (e.g., Spool, Checkpoint, and Initialization parameters) to system programmers only. |
| ☐ | SV-223466r1225696_rule | CA-ACF2 must limit Write or greater access to libraries that contain PPT modules to system programmers only. |
| ☐ | SV-223467r1225697_rule | The EXITS GSO record value must specify the module names of site written ACF2 exit routines. |
| ☐ | SV-223468r1225698_rule | The CA-ACF2 LOGONID with the REFRESH attribute must have procedures for utilization. |
| ☐ | SV-223469r1225699_rule | IBM z/OS TSO GSO record values must be set to the values specified. |
| ☐ | SV-223470r1225700_rule | IBM z/OS procedures must restrict ACF2 LOGONIDs with the READALL attribute to auditors and/or authorized users. |
| ☐ | SV-223471r1225701_rule | IBM z/OS must have the RULEVLD and RSRCVLD attributes specified for LOGONIDs with the SECURITY attribute. |
| ☐ | SV-223472r1225702_rule | IBM z/OS LOGONIDs with the AUDIT or CONSULT attribute must be properly scoped. |
| ☐ | SV-223473r1225703_rule | IBM z/OS LOGONID with the ACCTPRIV attribute must be restricted to the ISSO. |
| ☐ | SV-223474r1225704_rule | IBM z/OS batch jobs with restricted ACF2 LOGONIDs must have the PGM(xxxxxxxx) and SUBAUTH attributes or the SOURCE(xxxxxxxx) attribute assigned to the corresponding LOGONIDs. |
| ☐ | SV-223475r1225705_rule | CA-ACF2 RULEOPTS GSO record values must be set to the values specified. |
| ☐ | SV-223476r1225706_rule | The CA-ACF2 GSO OPTS record value must be properly specified. |
| ☐ | SV-223477r1225707_rule | CA-ACF2 must prevent the use of dictionary words for passwords. |
| ☐ | SV-223478r1225708_rule | CA-ACF2 database must be on a separate physical volume from its backup and recovery data sets. |
| ☐ | SV-223479r1225709_rule | CA-ACF2 database must be backed up on a scheduled basis. |
| ☐ | SV-223480r1225710_rule | ACF2 REFRESH attribute must be restricted to security administrators' LOGON ID only. |
| ☐ | SV-223481r1225711_rule | ACF2 maintenance LOGONIDs must have corresponding GSO MAINT records. |
| ☐ | SV-223482r1225712_rule | ACF2 LOGONIDs with the NON-CNCL attribute specified in the associated LOGONID record must be listed as trusted and must be specifically approved. |
| ☐ | SV-223483r1225713_rule | ACF2 LOGONIDs with the ACCOUNT, LEADER, or SECURITY attribute must be properly scoped. |
| ☐ | SV-223484r1225714_rule | ACF2 LOGONIDs associated with started tasks that have the MUSASS attribute and the requirement to submit jobs on behalf of its users must have the JOBFROM attribute as required. |
| ☐ | SV-223485r1225715_rule | IBM z/OS Started Tasks must be properly identified and defined to ACF2. |
| ☐ | SV-223486r1225716_rule | ACF2 emergency LOGONIDS with the REFRESH attribute must have the SUSPEND attribute specified. |
| ☐ | SV-223487r1225717_rule | ACF2 BACKUP GSO record must be defined with a TIME value specifies greater than 00 unless the database is shared and backed up on another system. |
| ☐ | SV-223488r1225718_rule | ACF2 APPLDEF GSO record if used must have supporting documentation indicating the reason it was used. |
| ☐ | SV-223489r1225719_rule | ACF2 MAINT GSO record value if specified must be restricted to production storage management user. |
| ☐ | SV-223490r1225720_rule | ACF2 LINKLST GSO record if specified must only contains trusted system data sets. |
| ☐ | SV-223491r1225721_rule | IBM z/OS must properly protect MCS console userid(s). |
| ☐ | SV-223492r1225722_rule | ACF2 BLPPGM GSO record must not be defined. |
| ☐ | SV-223493r1225723_rule | IBM z/OS UID(0) must be properly assigned. |
| ☐ | SV-223494r1225724_rule | IBM z/OS user account for the UNIX kernel (OMVS) must be properly defined to the security database. |
| ☐ | SV-223495r1225725_rule | IBM z/OS user account for the UNIX (RMFGAT) must be properly defined. |
| ☐ | SV-223496r1225726_rule | ACF2 LOGONIDs must be defined with the required fields completed. |
| ☐ | SV-223497r1225727_rule | CA-ACF2 defined user accounts must uniquely identify system users. |
| ☐ | SV-223498r1225728_rule | CA-ACF2 userids found inactive for more than 35 days must be suspended. |
| ☐ | SV-223499r1225729_rule | CA-ACF2 PWPHRASE GSO record must be properly defined. |
| ☐ | SV-223500r1225730_rule | CA-ACF2 must enforce password complexity by requiring that at least one special character be used. |
| ☐ | SV-223501r1225731_rule | ACF2 PSWD GSO record value must be set to require at least one uppercase character be used. |
| ☐ | SV-223502r1225732_rule | ACF2 PSWD GSO record value must be set to require at least one numeric character be used. |
| ☐ | SV-223503r1225733_rule | ACF2 PSWD GSO record value must be set to require at least one lowercase character be used. |
| ☐ | SV-223504r1225734_rule | ACF2 PSWD GSO record value must be set to require the change of at least 50 percent of the total number of characters when passwords are changed. |
| ☐ | SV-223505r1225735_rule | ACF2 must use NIST FIPS-validated cryptography to protect passwords in the security database. |
| ☐ | SV-223506r1225736_rule | ACF2 PSWD GSO record value must be set to require a 60-day maximum password lifetime restriction. |
| ☐ | SV-223507r1225737_rule | ACF2 PSWD GSO record value must be set to require 24 hours/one day as the minimum password lifetime. |
| ☐ | SV-223508r1225738_rule | ACF2 PSWD GSO record value must be set to prohibit password reuse for a minimum of five generations or more. |
| ☐ | SV-223509r1225739_rule | ACF2 TSOTWX GSO record values must be set to obliterate the logon password on TWX devices. |
| ☐ | SV-223510r1225740_rule | ACF2 TSOCRT GSO record values must be set to obliterate the logon to ASCII CRT devices. |
| ☐ | SV-223511r1225741_rule | ACF2 TSO2741 GSO record values must be set to obliterate the logon password on 2741 devices. |
| ☐ | SV-223512r1225742_rule | ACF2 SECVOLS GSO record value must be set to VOLMASK(). Any local changes are justified and documented with the ISSO. |
| ☐ | SV-223513r1225743_rule | ACF2 RESVOLS GSO record value must be set to Volmask(-). Any other setting requires documentation justifying the change. |
| ☐ | SV-223514r1225744_rule | ACF2 security data sets and/or databases must be properly protected. |
| ☐ | SV-223515r1225745_rule | ACF2 AUTOERAS GSO record value must be set to indicate that ACF2 is controlling the automatic physical erasure of VSAM or non VSAM data sets. |
| ☐ | SV-223517r1225746_rule | IBM z/OS SMF recording options for the FTP Server must be configured to write SMF records for all eligible events. |
| ☐ | SV-223518r1225747_rule | IBM z/OS data sets for the FTP Server must be properly protected. |
| ☐ | SV-223519r1225748_rule | IBM z/OS permission bits and user audit bits for HFS objects that are part of the FTP Server component must be properly configured. |
| ☐ | SV-223520r1225749_rule | IBM z/OS FTP.DATA configuration statements must have a proper BANNER statement with the Standard Mandatory DoD Notice and Consent Banner. |
| ☐ | SV-223522r1225750_rule | IBM z/OS FTP.DATA configuration statements for the FTP Server must specify the BANNER statement. |
| ☐ | SV-223523r1225751_rule | IBM z/OS FTP Control cards must be properly stored in a secure PDS file. |
| ☐ | SV-223525r1225752_rule | IBM z/OS FTP Server daemon must be defined with proper security parameters. |
| ☐ | SV-223526r1225753_rule | IBM z/OS startup parameters for the FTP Server must be defined in the SYSTCPD and SYSFTPD DD statements for configuration files. |
| ☐ | SV-223527r1225754_rule | IBM z/OS FTP.DATA configuration for the FTP Server must have INACTIVE statement properly set. |
| ☐ | SV-223528r1225755_rule | IBM z/OS JESTRACE and/or SYSLOG resources must be protected in accordance with security requirements. |
| ☐ | SV-223529r1225756_rule | IBM z/OS JESSPOOL resources must be protected in accordance with security requirements. |
| ☐ | SV-223530r1225757_rule | IBM z/OS JESNEWS resources must be protected in accordance with security requirements. |
| ☐ | SV-223531r1225758_rule | IBM z/OS JES2 system commands must be protected in accordance with security requirements. |
| ☐ | SV-223532r1225759_rule | IBM z/OS JES2 spool resources must be controlled in accordance with security requirements. |
| ☐ | SV-223533r1225760_rule | IBM z/OS JES2 output devices must be properly controlled for Classified Systems. |
| ☐ | SV-223534r1225761_rule | IBM z/OS JES2 output devices must be controlled in accordance with the proper security requirements. |
| ☐ | SV-223535r1225762_rule | IBM z/OS JES2 input sources must be controlled in accordance with the proper security requirements. |
| ☐ | SV-223536r1225763_rule | IBM z/OS Surrogate users must be controlled in accordance with proper security requirements. |
| ☐ | SV-223537r1225764_rule | The IBM z/OS BPX.SMF resource must be properly configured. |
| ☐ | SV-223539r1225765_rule | IBM z/OS Inapplicable PPT entries must be invalidated. |
| ☐ | SV-223540r1225766_rule | The IBM z/OS system administrator (SA) must develop a process notify appropriate personnel when accounts are removed. |
| ☐ | SV-223541r1225767_rule | The IBM z/OS system administrator (SA) must develop a process notify appropriate personnel when accounts are modified. |
| ☐ | SV-223542r1225768_rule | The IBM z/OS system administrator (SA) must develop a process notify appropriate personnel when accounts are deleted. |
| ☐ | SV-223543r1225769_rule | The IBM z/OS system administrator (SA) must develop a process notify appropriate personnel when accounts are created. |
| ☐ | SV-223544r1225770_rule | IBM z/OS Required SMF data record types must be collected. |
| ☐ | SV-223545r1225771_rule | IBM z/OS special privileges must be assigned on an as-needed basis to LOGONIDs associated with STCs and LOGONIDs that need to execute TSO in batch. |
| ☐ | SV-223546r1225772_rule | IBM z/OS must specify SMF data options to assure appropriate activation. |
| ☐ | SV-223547r1225773_rule | IBM z/OS SMF collection files (system MANx data sets or LOGSTREAM DASD) must have storage capacity to store at least one weeks worth of audit data. |
| ☐ | SV-223548r1225774_rule | IBM z/OS system administrators must develop an automated process to collect and retain SMF data. |
| ☐ | SV-223549r1225775_rule | IBM z/OS BUFUSEWARN in the SMFPRMxx must be properly set. |
| ☐ | SV-223550r1225776_rule | IBM z/OS NOBUFFS in SMFPRMxx must be properly set (Default is MSG). |
| ☐ | SV-223551r1225777_rule | IBM z/OS Time Protocol must be properly configured. |
| ☐ | SV-223552r1225778_rule | The IBM z/OS system must use a time protocol that syncs with an authoritative external time source. |
| ☐ | SV-223553r1225779_rule | IBM z/OS PARMLIB CLOCKxx must have the Accuracy PARM coded properly. |
| ☐ | SV-223554r1225780_rule | IBM z/OS SMF collection files (i.e., SYS1.MANx) access must be limited to appropriate users and/or batch jobs that perform SMF dump processing. |
| ☐ | SV-223556r1225781_rule | IBM z/OS PASSWORD data set and OS passwords must not be used. |
| ☐ | SV-223557r1225782_rule | IBM z/OS must configure system waittimes to protect resource availability based on site priorities. |
| ☐ | SV-223558r1225783_rule | IBM z/OS Emergency LOGONIDs must be properly defined. |
| ☐ | SV-223560r1225784_rule | IBM z/OS Policy Agent must employ a deny-all, allow-by-exception firewall policy for allowing connections to other systems. |
| ☐ | SV-223561r1225785_rule | Unsupported IBM z/OS system software must not be installed and/or active on the system. |
| ☐ | SV-223562r1225786_rule | IBM z/OS must not allow non-existent or inaccessible LINKLIST libraries. |
| ☐ | SV-223563r1225787_rule | IBM z/OS must not allow non-existent or inaccessible Link Pack Area (LPA) libraries. |
| ☐ | SV-223564r1225788_rule | IBM z/OS must not have inaccessible APF libraries defined. |
| ☐ | SV-223565r1225789_rule | IBM z/OS LNKAUTH=APFTAB must be specified in the IEASYSxx member(s) in the currently active parmlib data set(s). |
| ☐ | SV-223566r1225790_rule | Duplicated IBM z/OS sensitive utilities and/or programs must not exist in APF libraries. |
| ☐ | SV-223567r1225791_rule | IBM z/OS must properly configure CONSOLxx members. |
| ☐ | SV-223568r1225792_rule | IBM z/OS must use ICSF or SAF Key Rings for key management. |
| ☐ | SV-223569r1225793_rule | The IBM z/OS systems requiring data at rest protection must properly employ IBM DS8880 or equivalent hardware solutions for full disk encryption. |
| ☐ | SV-223570r1225794_rule | IBM z/OS sensitive and critical system data sets must not exist on shared DASD. |
| ☐ | SV-223571r1225795_rule | IBM z/OS Policy agent must contain a policy that protects against or limits the effects of Denial of Service (DoS) attacks by ensuring the operating system is implementing rate-limiting measures on impacted network interfaces. |
| ☐ | SV-223572r1225796_rule | IBM z/OS Policy agent must contain a policy that manages excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of Denial of Service (DoS) attacks. |
| ☐ | SV-223573r1225797_rule | IBM z/OS must employ a session manager to manage retaining a users session lock until that user reestablishes access using established identification and authentication procedures. |
| ☐ | SV-223574r1225798_rule | IBM z/OS system administrator must develop a procedure to notify designated personnel if baseline configurations are changed in an unauthorized manner. |
| ☐ | SV-223575r1225799_rule | IBM z/OS must employ a session manager that conceal, via the session lock, information previously visible on the display with a publicly viewable image. |
| ☐ | SV-223576r1225800_rule | IBM z/OS must employ a session manager to manage session lock after a 15-minute period of inactivity. |
| ☐ | SV-223577r1225801_rule | The IBM z/OS system administrator (SA) must develop a procedure to automatically remove or disable temporary user accounts after 72 hours. |
| ☐ | SV-223578r1225802_rule | IBM z/OS system administrator must develop a procedure to automatically remove or disable emergency accounts after the crisis is resolved or 72 hours. |
| ☐ | SV-223579r1225803_rule | IBM z/OS system administrator must develop a procedure to notify system administrators (SAs) and information system security officers (ISSOs) of account enabling actions. |
| ☐ | SV-223581r1225804_rule | IBM z/OS system administrator must develop a procedure to remove all software components after updated versions have been installed. |
| ☐ | SV-223582r1225805_rule | IBM z/OS system administrator must develop a procedure to shut down the information system, restart the information system, and/or notify the system administrator when anomalies in the operation of any security functions are discovered. |
| ☐ | SV-223583r1225806_rule | IBM z/OS must employ a session manager configured for users to directly initiate a session lock for all connection types. |
| ☐ | SV-223584r1225807_rule | ACF2 system administrator must develop a procedure to disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity. |
| ☐ | SV-223585r1225808_rule | IBM z/OS system administrator must develop a procedure to offload SMF files to a different system or media than the system being audited. |
| ☐ | SV-223586r1225809_rule | IBM z/OS SMF recording options for the SSH daemon must be configured to write SMF records for all eligible events. |
| ☐ | SV-223587r1225810_rule | IBM z/OS SSH daemon must be configured with the Department of Defense (DoD) logon banner. |
| ☐ | SV-223588r1225811_rule | IBM z/OS SSH daemon must be configured to only use the SSHv2 protocol. |
| ☐ | SV-223589r1225812_rule | IBM z/OS SSH daemon must be configured to use a FIPS 140-3-compliant cryptographic algorithm. |
| ☐ | SV-223590r1225813_rule | IBM z/OS permission bits and user audit bits for HFS objects that are part of the Syslog daemon component must be configured properly. |
| ☐ | SV-223591r1225814_rule | IBM z/OS Syslog daemon must be started at z/OS initialization. |
| ☐ | SV-223592r1225815_rule | IBM z/OS Syslog daemon must be properly defined and secured. |
| ☐ | SV-223593r1225816_rule | IBM z/OS DFSMS resource class(es) must be defined to the GSO CLASMAP record in accordance with security requirements. |
| ☐ | SV-223594r1225817_rule | IBM z/OS DFSMS Program Resources must be properly defined and protected. |
| ☐ | SV-223595r1225818_rule | IBM z/OS DFSMS control data sets must be protected in accordance with security requirements. |
| ☐ | SV-223596r1225819_rule | IBM z/OS DFMSM resource class(es)must be defined to the GSO SAFDEF record in accordance with security requirements. |
| ☐ | SV-223597r1225820_rule | IBM z/OS DFSMS resources must be protected in accordance with the proper security requirements. |
| ☐ | SV-223598r1225821_rule | IBM z/OS using DFSMS must properly specify SYS(x).PARMLIB(IGDSMSxx), SMS parameter settings. |
| ☐ | SV-223599r1225822_rule | IBM z/OS PROFILE.TCPIP configuration statements for the TCP/IP stack must be coded properly. |
| ☐ | SV-223600r1225823_rule | IBM z//OS must be configured to restrict all TCP/IP ports to ports, protocols, and/or services as defined in the PPSM CAL and vulnerability assessments. |
| ☐ | SV-223601r1225824_rule | IBM z/OS TCP/IP resources must be properly protected. |
| ☐ | SV-223602r1225825_rule | IBM z/OS permission bits and user audit bits for HFS objects that are part of the Base TCP/IP component must be configured properly. |
| ☐ | SV-223603r1225828_rule | IBM z/OS data sets for the Base TCP/IP component must be properly protected. |
| ☐ | SV-223604r1225831_rule | IBM z/OS Configuration files for the TCP/IP stack must be properly specified. |
| ☐ | SV-223605r1225832_rule | IBM z/OS Started tasks for the Base TCP/IP component must be defined in accordance with security requirements. |
| ☐ | SV-223608r1225833_rule | IBM z/OS PROFILE.TCPIP configuration INACTIVITY statement must be configured to 900 seconds. |
| ☐ | SV-223609r1225834_rule | IBM z/OS SMF recording options for the TN3270 Telnet Server must be properly specified. |
| ☐ | SV-223610r1225835_rule | IBM z/OS SSL encryption options for the TN3270 Telnet Server must be specified properly. |
| ☐ | SV-223611r1225836_rule | IBM z/OS TN3270 Telnet Server configuration statement MSG10 text must have the Standard Mandatory DoD Notice and Consent Banner. |
| ☐ | SV-223613r1225837_rule | IBM z/OS VTAM session setup controls for the TN3270 Telnet Server must be properly specified. |
| ☐ | SV-223615r1225838_rule | IBM z/OS TSOAUTH resources must be restricted to authorized users. |
| ☐ | SV-223616r1225839_rule | IBM z/OS UNIX SUPERUSER resource must be protected in accordance with guidelines. |
| ☐ | SV-223617r1225840_rule | IBM z/OS UNIX security parameters in etc/profile must be properly specified. |
| ☐ | SV-223618r1225841_rule | IBM z/OS UNIX security parameters in /etc/rc must be properly specified. |
| ☐ | SV-223619r1225842_rule | IBM z/OS UNIX resources must be protected in accordance with security requirements. |
| ☐ | SV-223620r1225843_rule | IBM z/OS UNIX MVS HFS directory(s) with other write permission bit set must be properly defined. |
| ☐ | SV-223621r1225844_rule | IBM z/OS BPX resource(s) must be protected in accordance with security requirements. |
| ☐ | SV-223622r1225845_rule | IBM z/OS UNIX SYSTEM FILE SECURITY SETTINGS must be properly protected or specified. |
| ☐ | SV-223623r1225846_rule | IBM z/OS UNIX MVS data sets with z/OS UNIX components must be properly protected. |
| ☐ | SV-223624r1225847_rule | IBM z/OS UNIX MVS data sets or HFS objects must be properly protected. |
| ☐ | SV-223625r1225848_rule | IBM z/OS UNIX HFS permission bits and audit bits for each directory must be properly protected. |
| ☐ | SV-223626r1225849_rule | IBM z/OS UNIX MVS data sets used as step libraries in /etc/steplib must be properly protected. |
| ☐ | SV-223629r1225850_rule | IBM z/OS UNIX OMVS parameters in PARMLIB must be properly specified. |
| ☐ | SV-223630r1225851_rule | IBM z/OS UNIX HFS MapName files security parameters must be properly specified. |
| ☐ | SV-223631r1225852_rule | IBM z/OS UNIX BPXPRMxx security parameters in PARMLIB must be properly specified. |
| ☐ | SV-223632r1225853_rule | IBM z/OS User exits for the FTP Server must not be used without proper approval and documentation. |
| ☐ | SV-223633r1225854_rule | IBM z/OS UNIX security parameters for restricted network service(s) in /etc/inetd.conf must be properly specified. |
| ☐ | SV-223634r1225855_rule | IBM z/OS user account for the z/OS UNIX SUPERSUSER userid must be properly defined. |
| ☐ | SV-223635r1225856_rule | IBM z/OS UNIX user accounts must be properly defined. |
| ☐ | SV-223636r1225857_rule | IBM z/OS UNIX groups must be defined with a unique GID. |
| ☐ | SV-223637r1225858_rule | IBM z/OS Attributes of z/OS UNIX user accounts must have a unique GID in the range of 1-99. |
| ☐ | SV-223638r1225859_rule | IBM z/OS Attributes of UNIX user accounts used for account modeling must be defined in accordance with security requirements. |
| ☐ | SV-223639r1225860_rule | IBM z/OS startup user account for the z/OS UNIX Telnet Server must be defined properly. |
| ☐ | SV-223640r1225861_rule | IBM z/OS HFS objects for the z/OS UNIX Telnet Server must be properly protected. |
| ☐ | SV-223641r1225864_rule | IBM z/OS UNIX Telnet Server etc/banner file must have the Standard Mandatory DoD Notice and Consent Banner. |
| ☐ | SV-223642r1225865_rule | IBM z/OS UNIX Telnet Server warning banner must be properly specified. |
| ☐ | SV-223643r1225866_rule | IBM z/OS UNIX Telnet Server Startup parameters must be properly specified to display the banner. |
| ☐ | SV-223644r1225867_rule | IBM z/OS System data sets used to support the VTAM network must be properly secured. |
| ☐ | SV-223645r1225868_rule | IBM z/OS VTAM USSTAB definitions must not be used for unsecured terminals. |
| ☐ | SV-245535r1225871_rule | IBM z/OS TCPIP.DATA configuration statement must contain the DOMAINORIGIN or DOMAIN specified for each TCP/IP defined. |
| ☐ | SV-252547r1225872_rule | IBM z/OS TCP/IP AT-TLS policy must be properly configured in Policy Agent. |
| ☐ | SV-252705r1225873_rule | IBM z/OS must enforce a minimum eight character password length. |
| ☐ | SV-255895r1225874_rule | IBM z/OS FTP.DATA configuration statements for the FTP Server must be specified in accordance with requirements. |
| ☐ | SV-255932r1225875_rule | IBM Integrated Crypto Service Facility (ICSF) Configuration parameters must be correctly specified. |
| ☐ | SV-255933r1225876_rule | IBM Integrated Crypto Service Facility (ICSF) install data sets must be properly protected. |
| ☐ | SV-255934r1225877_rule | IBM Integrated Crypto Service Facility (ICSF) Started Task name must be properly identified / defined to the system ACP. |
| ☐ | SV-255945r1225878_rule | IBM Integrated Crypto Service Facility (ICSF) STC data sets must be properly protected. |
| ☐ | SV-272873r1225879_rule | IBM z/OS DFSMS control data sets must reside on separate storage volumes. |
| ☐ | SV-272874r1225880_rule | IBM z/OS RJE workstations and NJE nodes must be defined to the FACILITY resource class. |
| ☐ | SV-275949r1225881_rule | zOSMF resource class(es) must be defined to the ACF2 GSO CLASMAP record in accordance with security requirements. |
| ☐ | SV-275951r1225882_rule | ICSF resources must be protected in accordance with security requirements. |
| ☐ | SV-275964r1225883_rule | zOSMF resources must be protected in accordance with security requirements. |
| ☐ | SV-275965r1225884_rule | ICSF resource class(es) must be defined to the ACF2 GSO CLASMAP record in accordance with security requirements. |
| ☐ | SV-285328r1225885_rule | IBM z/OS SSL options for the TN3270 Telnet Server must specufy a secure port. |