STIGQter STIGQter: STIG Summary:

IBM z/OS ACF2 Security Technical Implementation Guide

Version: 9

Release: 9 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-223419r1225652_ruleIBM z/OS Certificate Name Filtering must be implemented with appropriate authorization and documentation.
SV-223420r1225653_ruleIBM z/OS must not use Expired Digital Certificates.
SV-223421r1225654_ruleAll IBM z/OS digital certificates in use must have a valid path to a trusted Certification authority.
SV-223422r1225655_ruleCA-ACF2 OPTS GSO record must be set to ABORT mode.
SV-223423r1225656_ruleThe number of ACF2 users granted the special privilege PPGM must be justified.
SV-223424r1225657_ruleThe number of ACF2 users granted the special privilege OPERATOR must be kept to a strictly controlled minimum.
SV-223425r1225658_ruleThe number of ACF2 users granted the special privilege CONSOLE must be justified.
SV-223426r1225659_ruleThe number of ACF2 users granted the special privilege ALLCMDS must be justified.
SV-223427r1225660_ruleIBM z/OS system commands must be properly protected.
SV-223428r1225661_ruleIBM z/OS Sensitive Utility Controls must be properly defined and protected.
SV-223429r1225662_ruleCA-ACF2 NJE GSO record value must indicate validation options that apply to jobs submitted through a network job entry subsystem (JES2, JES3, RSCS).
SV-223430r1225663_ruleCA-ACF2 must protect Memory and privileged program dumps in accordance with proper security requirements.
SV-223431r1225664_ruleCA-ACF2 must properly define users that have access to the CONSOLE resource in the TSOAUTH resource class.
SV-223433r1225665_ruleCA-ACF2 must limit access to SYSTEM DUMP data sets to appropriate authorized users.
SV-223434r1225666_ruleCA-ACF2 must limit access to SYS(x).TRACE to system programmers only.
SV-223435r1225667_ruleCA-ACF2 allocate access to system user catalogs must be properly protected.
SV-223436r1225668_ruleACF2 Classes required to properly security the z/OS UNIX environment must be ACTIVE.
SV-223437r1225669_ruleAccess to IBM z/OS special privilege TAPE-LBL or TAPE-BLP must be limited and/or justified.
SV-223438r1225670_ruleCA-ACF2 must limit access to System page data sets (i.e., PLPA, COMMON, and LOCALx) to system programmers.
SV-223439r1225671_ruleIBM z/OS must protect dynamic lists in accordance with proper security requirements.
SV-223440r1225672_ruleIBM z/OS Libraries included in the system REXXLIB concatenation must be properly protected.
SV-223441r1225673_ruleCA-ACF2 must limit Write or greater access to SYS1.UADS To system programmers only and read and update access must be limited to system programmer personnel and/or security personnel.
SV-223442r1225674_ruleCA-ACF2 must limit all system PROCLIB data sets to appropriate authorized users.
SV-223443r1225675_ruleCA-ACF2 access to the System Master Catalog must be properly protected.
SV-223444r1225676_ruleIBM z/OS MCS consoles access authorization(s) for CONSOLE resource(s) must be properly protected.
SV-223445r1225677_ruleCA-ACF2 must limit Write or greater access to SYS1.NUCLEUS to system programmers only.
SV-223446r1225678_ruleCA-ACF2 must limit Write or greater access to SYS1.LPALIB to system programmers only.
SV-223447r1225679_ruleCA-ACF2 must limit Write or greater access to SYS1.IMAGELIB to system programmers.
SV-223448r1225680_ruleCA-ACF2 must limit Write or greater access to Libraries containing EXIT modules to system programmers only.
SV-223449r1225681_ruleCA-ACF2 must limit Write and Allocate access to all APF-authorized libraries to system programmers only.
SV-223450r1225682_ruleCA-ACF2 must limit Write or greater access to all LPA libraries to system programmers only.
SV-223451r1225683_ruleCA-ACF2 must limit Write and Allocate access to LINKLIST libraries to system programmers only.
SV-223452r1225684_ruleCA-ACF2 must limit Write and allocate access to all system-level product installation libraries to system programmers only.
SV-223453r1225685_ruleCA-ACF2 must limit Write or greater access to SYS1.SVCLIB to system programmers only.
SV-223454r1225686_ruleCA-ACF2 Access to SYS1.LINKLIB must be properly protected.
SV-223455r1225687_ruleCA-ACF2 must limit access to data sets used to back up and/or dump SMF collection files to appropriate users and/or batch jobs that perform SMF dump processing.
SV-223456r1225688_ruleCA-ACF2 LOGONIDs must not be defined to SYS1.UADS for non-emergency use.
SV-223457r1225689_ruleIBM z/OS IEASYMUP resource must be protected in accordance with proper security requirements.
SV-223458r1225690_ruleCA-ACF2 must limit Update and Allocate access to system backup files to system programmers and/or batch jobs that perform DASD backups.
SV-223459r1225691_ruleACF2 PPGM GSO record value must specify protected programs that are only executed by privileged users.
SV-223462r1225692_ruleThe CA-ACF2 PSWD GSO record values for MAXTRY and PASSLMT must be properly set.
SV-223463r1225693_ruleIBM z/OS SYS1.PARMLIB must be properly protected.
SV-223464r1225694_ruleCA-ACF2 must be installed, functional, and properly configured.
SV-223465r1225695_ruleCA-ACF2 must limit Write and allocate access to the JES2 System data sets (e.g., Spool, Checkpoint, and Initialization parameters) to system programmers only.
SV-223466r1225696_ruleCA-ACF2 must limit Write or greater access to libraries that contain PPT modules to system programmers only.
SV-223467r1225697_ruleThe EXITS GSO record value must specify the module names of site written ACF2 exit routines.
SV-223468r1225698_ruleThe CA-ACF2 LOGONID with the REFRESH attribute must have procedures for utilization.
SV-223469r1225699_ruleIBM z/OS TSO GSO record values must be set to the values specified.
SV-223470r1225700_ruleIBM z/OS procedures must restrict ACF2 LOGONIDs with the READALL attribute to auditors and/or authorized users.
SV-223471r1225701_ruleIBM z/OS must have the RULEVLD and RSRCVLD attributes specified for LOGONIDs with the SECURITY attribute.
SV-223472r1225702_ruleIBM z/OS LOGONIDs with the AUDIT or CONSULT attribute must be properly scoped.
SV-223473r1225703_ruleIBM z/OS LOGONID with the ACCTPRIV attribute must be restricted to the ISSO.
SV-223474r1225704_ruleIBM z/OS batch jobs with restricted ACF2 LOGONIDs must have the PGM(xxxxxxxx) and SUBAUTH attributes or the SOURCE(xxxxxxxx) attribute assigned to the corresponding LOGONIDs.
SV-223475r1225705_ruleCA-ACF2 RULEOPTS GSO record values must be set to the values specified.
SV-223476r1225706_ruleThe CA-ACF2 GSO OPTS record value must be properly specified.
SV-223477r1225707_ruleCA-ACF2 must prevent the use of dictionary words for passwords.
SV-223478r1225708_ruleCA-ACF2 database must be on a separate physical volume from its backup and recovery data sets.
SV-223479r1225709_ruleCA-ACF2 database must be backed up on a scheduled basis.
SV-223480r1225710_ruleACF2 REFRESH attribute must be restricted to security administrators' LOGON ID only.
SV-223481r1225711_ruleACF2 maintenance LOGONIDs must have corresponding GSO MAINT records.
SV-223482r1225712_ruleACF2 LOGONIDs with the NON-CNCL attribute specified in the associated LOGONID record must be listed as trusted and must be specifically approved.
SV-223483r1225713_ruleACF2 LOGONIDs with the ACCOUNT, LEADER, or SECURITY attribute must be properly scoped.
SV-223484r1225714_ruleACF2 LOGONIDs associated with started tasks that have the MUSASS attribute and the requirement to submit jobs on behalf of its users must have the JOBFROM attribute as required.
SV-223485r1225715_ruleIBM z/OS Started Tasks must be properly identified and defined to ACF2.
SV-223486r1225716_ruleACF2 emergency LOGONIDS with the REFRESH attribute must have the SUSPEND attribute specified.
SV-223487r1225717_ruleACF2 BACKUP GSO record must be defined with a TIME value specifies greater than 00 unless the database is shared and backed up on another system.
SV-223488r1225718_ruleACF2 APPLDEF GSO record if used must have supporting documentation indicating the reason it was used.
SV-223489r1225719_ruleACF2 MAINT GSO record value if specified must be restricted to production storage management user.
SV-223490r1225720_ruleACF2 LINKLST GSO record if specified must only contains trusted system data sets.
SV-223491r1225721_ruleIBM z/OS must properly protect MCS console userid(s).
SV-223492r1225722_ruleACF2 BLPPGM GSO record must not be defined.
SV-223493r1225723_ruleIBM z/OS UID(0) must be properly assigned.
SV-223494r1225724_ruleIBM z/OS user account for the UNIX kernel (OMVS) must be properly defined to the security database.
SV-223495r1225725_ruleIBM z/OS user account for the UNIX (RMFGAT) must be properly defined.
SV-223496r1225726_ruleACF2 LOGONIDs must be defined with the required fields completed.
SV-223497r1225727_ruleCA-ACF2 defined user accounts must uniquely identify system users.
SV-223498r1225728_ruleCA-ACF2 userids found inactive for more than 35 days must be suspended.
SV-223499r1225729_ruleCA-ACF2 PWPHRASE GSO record must be properly defined.
SV-223500r1225730_ruleCA-ACF2 must enforce password complexity by requiring that at least one special character be used.
SV-223501r1225731_ruleACF2 PSWD GSO record value must be set to require at least one uppercase character be used.
SV-223502r1225732_ruleACF2 PSWD GSO record value must be set to require at least one numeric character be used.
SV-223503r1225733_ruleACF2 PSWD GSO record value must be set to require at least one lowercase character be used.
SV-223504r1225734_ruleACF2 PSWD GSO record value must be set to require the change of at least 50 percent of the total number of characters when passwords are changed.
SV-223505r1225735_ruleACF2 must use NIST FIPS-validated cryptography to protect passwords in the security database.
SV-223506r1225736_ruleACF2 PSWD GSO record value must be set to require a 60-day maximum password lifetime restriction.
SV-223507r1225737_ruleACF2 PSWD GSO record value must be set to require 24 hours/one day as the minimum password lifetime.
SV-223508r1225738_ruleACF2 PSWD GSO record value must be set to prohibit password reuse for a minimum of five generations or more.
SV-223509r1225739_ruleACF2 TSOTWX GSO record values must be set to obliterate the logon password on TWX devices.
SV-223510r1225740_ruleACF2 TSOCRT GSO record values must be set to obliterate the logon to ASCII CRT devices.
SV-223511r1225741_ruleACF2 TSO2741 GSO record values must be set to obliterate the logon password on 2741 devices.
SV-223512r1225742_ruleACF2 SECVOLS GSO record value must be set to VOLMASK(). Any local changes are justified and documented with the ISSO.
SV-223513r1225743_ruleACF2 RESVOLS GSO record value must be set to Volmask(-). Any other setting requires documentation justifying the change.
SV-223514r1225744_ruleACF2 security data sets and/or databases must be properly protected.
SV-223515r1225745_ruleACF2 AUTOERAS GSO record value must be set to indicate that ACF2 is controlling the automatic physical erasure of VSAM or non VSAM data sets.
SV-223517r1225746_ruleIBM z/OS SMF recording options for the FTP Server must be configured to write SMF records for all eligible events.
SV-223518r1225747_ruleIBM z/OS data sets for the FTP Server must be properly protected.
SV-223519r1225748_ruleIBM z/OS permission bits and user audit bits for HFS objects that are part of the FTP Server component must be properly configured.
SV-223520r1225749_ruleIBM z/OS FTP.DATA configuration statements must have a proper BANNER statement with the Standard Mandatory DoD Notice and Consent Banner.
SV-223522r1225750_ruleIBM z/OS FTP.DATA configuration statements for the FTP Server must specify the BANNER statement.
SV-223523r1225751_ruleIBM z/OS FTP Control cards must be properly stored in a secure PDS file.
SV-223525r1225752_ruleIBM z/OS FTP Server daemon must be defined with proper security parameters.
SV-223526r1225753_ruleIBM z/OS startup parameters for the FTP Server must be defined in the SYSTCPD and SYSFTPD DD statements for configuration files.
SV-223527r1225754_ruleIBM z/OS FTP.DATA configuration for the FTP Server must have INACTIVE statement properly set.
SV-223528r1225755_ruleIBM z/OS JESTRACE and/or SYSLOG resources must be protected in accordance with security requirements.
SV-223529r1225756_ruleIBM z/OS JESSPOOL resources must be protected in accordance with security requirements.
SV-223530r1225757_ruleIBM z/OS JESNEWS resources must be protected in accordance with security requirements.
SV-223531r1225758_ruleIBM z/OS JES2 system commands must be protected in accordance with security requirements.
SV-223532r1225759_ruleIBM z/OS JES2 spool resources must be controlled in accordance with security requirements.
SV-223533r1225760_ruleIBM z/OS JES2 output devices must be properly controlled for Classified Systems.
SV-223534r1225761_ruleIBM z/OS JES2 output devices must be controlled in accordance with the proper security requirements.
SV-223535r1225762_ruleIBM z/OS JES2 input sources must be controlled in accordance with the proper security requirements.
SV-223536r1225763_ruleIBM z/OS Surrogate users must be controlled in accordance with proper security requirements.
SV-223537r1225764_ruleThe IBM z/OS BPX.SMF resource must be properly configured.
SV-223539r1225765_ruleIBM z/OS Inapplicable PPT entries must be invalidated.
SV-223540r1225766_ruleThe IBM z/OS system administrator (SA) must develop a process notify appropriate personnel when accounts are removed.
SV-223541r1225767_ruleThe IBM z/OS system administrator (SA) must develop a process notify appropriate personnel when accounts are modified.
SV-223542r1225768_ruleThe IBM z/OS system administrator (SA) must develop a process notify appropriate personnel when accounts are deleted.
SV-223543r1225769_ruleThe IBM z/OS system administrator (SA) must develop a process notify appropriate personnel when accounts are created.
SV-223544r1225770_ruleIBM z/OS Required SMF data record types must be collected.
SV-223545r1225771_ruleIBM z/OS special privileges must be assigned on an as-needed basis to LOGONIDs associated with STCs and LOGONIDs that need to execute TSO in batch.
SV-223546r1225772_ruleIBM z/OS must specify SMF data options to assure appropriate activation.
SV-223547r1225773_ruleIBM z/OS SMF collection files (system MANx data sets or LOGSTREAM DASD) must have storage capacity to store at least one weeks worth of audit data.
SV-223548r1225774_ruleIBM z/OS system administrators must develop an automated process to collect and retain SMF data.
SV-223549r1225775_ruleIBM z/OS BUFUSEWARN in the SMFPRMxx must be properly set.
SV-223550r1225776_ruleIBM z/OS NOBUFFS in SMFPRMxx must be properly set (Default is MSG).
SV-223551r1225777_ruleIBM z/OS Time Protocol must be properly configured.
SV-223552r1225778_ruleThe IBM z/OS system must use a time protocol that syncs with an authoritative external time source.
SV-223553r1225779_ruleIBM z/OS PARMLIB CLOCKxx must have the Accuracy PARM coded properly.
SV-223554r1225780_ruleIBM z/OS SMF collection files (i.e., SYS1.MANx) access must be limited to appropriate users and/or batch jobs that perform SMF dump processing.
SV-223556r1225781_ruleIBM z/OS PASSWORD data set and OS passwords must not be used.
SV-223557r1225782_ruleIBM z/OS must configure system waittimes to protect resource availability based on site priorities.
SV-223558r1225783_ruleIBM z/OS Emergency LOGONIDs must be properly defined.
SV-223560r1225784_ruleIBM z/OS Policy Agent must employ a deny-all, allow-by-exception firewall policy for allowing connections to other systems.
SV-223561r1225785_ruleUnsupported IBM z/OS system software must not be installed and/or active on the system.
SV-223562r1225786_ruleIBM z/OS must not allow non-existent or inaccessible LINKLIST libraries.
SV-223563r1225787_ruleIBM z/OS must not allow non-existent or inaccessible Link Pack Area (LPA) libraries.
SV-223564r1225788_ruleIBM z/OS must not have inaccessible APF libraries defined.
SV-223565r1225789_ruleIBM z/OS LNKAUTH=APFTAB must be specified in the IEASYSxx member(s) in the currently active parmlib data set(s).
SV-223566r1225790_ruleDuplicated IBM z/OS sensitive utilities and/or programs must not exist in APF libraries.
SV-223567r1225791_ruleIBM z/OS must properly configure CONSOLxx members.
SV-223568r1225792_ruleIBM z/OS must use ICSF or SAF Key Rings for key management.
SV-223569r1225793_ruleThe IBM z/OS systems requiring data at rest protection must properly employ IBM DS8880 or equivalent hardware solutions for full disk encryption.
SV-223570r1225794_ruleIBM z/OS sensitive and critical system data sets must not exist on shared DASD.
SV-223571r1225795_ruleIBM z/OS Policy agent must contain a policy that protects against or limits the effects of Denial of Service (DoS) attacks by ensuring the operating system is implementing rate-limiting measures on impacted network interfaces.
SV-223572r1225796_ruleIBM z/OS Policy agent must contain a policy that manages excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of Denial of Service (DoS) attacks.
SV-223573r1225797_ruleIBM z/OS must employ a session manager to manage retaining a users session lock until that user reestablishes access using established identification and authentication procedures.
SV-223574r1225798_ruleIBM z/OS system administrator must develop a procedure to notify designated personnel if baseline configurations are changed in an unauthorized manner.
SV-223575r1225799_ruleIBM z/OS must employ a session manager that conceal, via the session lock, information previously visible on the display with a publicly viewable image.
SV-223576r1225800_ruleIBM z/OS must employ a session manager to manage session lock after a 15-minute period of inactivity.
SV-223577r1225801_ruleThe IBM z/OS system administrator (SA) must develop a procedure to automatically remove or disable temporary user accounts after 72 hours.
SV-223578r1225802_ruleIBM z/OS system administrator must develop a procedure to automatically remove or disable emergency accounts after the crisis is resolved or 72 hours.
SV-223579r1225803_ruleIBM z/OS system administrator must develop a procedure to notify system administrators (SAs) and information system security officers (ISSOs) of account enabling actions.
SV-223581r1225804_ruleIBM z/OS system administrator must develop a procedure to remove all software components after updated versions have been installed.
SV-223582r1225805_ruleIBM z/OS system administrator must develop a procedure to shut down the information system, restart the information system, and/or notify the system administrator when anomalies in the operation of any security functions are discovered.
SV-223583r1225806_ruleIBM z/OS must employ a session manager configured for users to directly initiate a session lock for all connection types.
SV-223584r1225807_ruleACF2 system administrator must develop a procedure to disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.
SV-223585r1225808_ruleIBM z/OS system administrator must develop a procedure to offload SMF files to a different system or media than the system being audited.
SV-223586r1225809_ruleIBM z/OS SMF recording options for the SSH daemon must be configured to write SMF records for all eligible events.
SV-223587r1225810_ruleIBM z/OS SSH daemon must be configured with the Department of Defense (DoD) logon banner.
SV-223588r1225811_ruleIBM z/OS SSH daemon must be configured to only use the SSHv2 protocol.
SV-223589r1225812_ruleIBM z/OS SSH daemon must be configured to use a FIPS 140-3-compliant cryptographic algorithm.
SV-223590r1225813_ruleIBM z/OS permission bits and user audit bits for HFS objects that are part of the Syslog daemon component must be configured properly.
SV-223591r1225814_ruleIBM z/OS Syslog daemon must be started at z/OS initialization.
SV-223592r1225815_ruleIBM z/OS Syslog daemon must be properly defined and secured.
SV-223593r1225816_ruleIBM z/OS DFSMS resource class(es) must be defined to the GSO CLASMAP record in accordance with security requirements.
SV-223594r1225817_ruleIBM z/OS DFSMS Program Resources must be properly defined and protected.
SV-223595r1225818_ruleIBM z/OS DFSMS control data sets must be protected in accordance with security requirements.
SV-223596r1225819_ruleIBM z/OS DFMSM resource class(es)must be defined to the GSO SAFDEF record in accordance with security requirements.
SV-223597r1225820_ruleIBM z/OS DFSMS resources must be protected in accordance with the proper security requirements.
SV-223598r1225821_ruleIBM z/OS using DFSMS must properly specify SYS(x).PARMLIB(IGDSMSxx), SMS parameter settings.
SV-223599r1225822_ruleIBM z/OS PROFILE.TCPIP configuration statements for the TCP/IP stack must be coded properly.
SV-223600r1225823_ruleIBM z//OS must be configured to restrict all TCP/IP ports to ports, protocols, and/or services as defined in the PPSM CAL and vulnerability assessments.
SV-223601r1225824_ruleIBM z/OS TCP/IP resources must be properly protected.
SV-223602r1225825_ruleIBM z/OS permission bits and user audit bits for HFS objects that are part of the Base TCP/IP component must be configured properly.
SV-223603r1225828_ruleIBM z/OS data sets for the Base TCP/IP component must be properly protected.
SV-223604r1225831_ruleIBM z/OS Configuration files for the TCP/IP stack must be properly specified.
SV-223605r1225832_ruleIBM z/OS Started tasks for the Base TCP/IP component must be defined in accordance with security requirements.
SV-223608r1225833_ruleIBM z/OS PROFILE.TCPIP configuration INACTIVITY statement must be configured to 900 seconds.
SV-223609r1225834_ruleIBM z/OS SMF recording options for the TN3270 Telnet Server must be properly specified.
SV-223610r1225835_ruleIBM z/OS SSL encryption options for the TN3270 Telnet Server must be specified properly.
SV-223611r1225836_ruleIBM z/OS TN3270 Telnet Server configuration statement MSG10 text must have the Standard Mandatory DoD Notice and Consent Banner.
SV-223613r1225837_ruleIBM z/OS VTAM session setup controls for the TN3270 Telnet Server must be properly specified.
SV-223615r1225838_ruleIBM z/OS TSOAUTH resources must be restricted to authorized users.
SV-223616r1225839_ruleIBM z/OS UNIX SUPERUSER resource must be protected in accordance with guidelines.
SV-223617r1225840_ruleIBM z/OS UNIX security parameters in etc/profile must be properly specified.
SV-223618r1225841_ruleIBM z/OS UNIX security parameters in /etc/rc must be properly specified.
SV-223619r1225842_ruleIBM z/OS UNIX resources must be protected in accordance with security requirements.
SV-223620r1225843_ruleIBM z/OS UNIX MVS HFS directory(s) with other write permission bit set must be properly defined.
SV-223621r1225844_ruleIBM z/OS BPX resource(s) must be protected in accordance with security requirements.
SV-223622r1225845_ruleIBM z/OS UNIX SYSTEM FILE SECURITY SETTINGS must be properly protected or specified.
SV-223623r1225846_ruleIBM z/OS UNIX MVS data sets with z/OS UNIX components must be properly protected.
SV-223624r1225847_ruleIBM z/OS UNIX MVS data sets or HFS objects must be properly protected.
SV-223625r1225848_ruleIBM z/OS UNIX HFS permission bits and audit bits for each directory must be properly protected.
SV-223626r1225849_ruleIBM z/OS UNIX MVS data sets used as step libraries in /etc/steplib must be properly protected.
SV-223629r1225850_ruleIBM z/OS UNIX OMVS parameters in PARMLIB must be properly specified.
SV-223630r1225851_ruleIBM z/OS UNIX HFS MapName files security parameters must be properly specified.
SV-223631r1225852_ruleIBM z/OS UNIX BPXPRMxx security parameters in PARMLIB must be properly specified.
SV-223632r1225853_ruleIBM z/OS User exits for the FTP Server must not be used without proper approval and documentation.
SV-223633r1225854_ruleIBM z/OS UNIX security parameters for restricted network service(s) in /etc/inetd.conf must be properly specified.
SV-223634r1225855_ruleIBM z/OS user account for the z/OS UNIX SUPERSUSER userid must be properly defined.
SV-223635r1225856_ruleIBM z/OS UNIX user accounts must be properly defined.
SV-223636r1225857_ruleIBM z/OS UNIX groups must be defined with a unique GID.
SV-223637r1225858_ruleIBM z/OS Attributes of z/OS UNIX user accounts must have a unique GID in the range of 1-99.
SV-223638r1225859_ruleIBM z/OS Attributes of UNIX user accounts used for account modeling must be defined in accordance with security requirements.
SV-223639r1225860_ruleIBM z/OS startup user account for the z/OS UNIX Telnet Server must be defined properly.
SV-223640r1225861_ruleIBM z/OS HFS objects for the z/OS UNIX Telnet Server must be properly protected.
SV-223641r1225864_ruleIBM z/OS UNIX Telnet Server etc/banner file must have the Standard Mandatory DoD Notice and Consent Banner.
SV-223642r1225865_ruleIBM z/OS UNIX Telnet Server warning banner must be properly specified.
SV-223643r1225866_ruleIBM z/OS UNIX Telnet Server Startup parameters must be properly specified to display the banner.
SV-223644r1225867_ruleIBM z/OS System data sets used to support the VTAM network must be properly secured.
SV-223645r1225868_ruleIBM z/OS VTAM USSTAB definitions must not be used for unsecured terminals.
SV-245535r1225871_ruleIBM z/OS TCPIP.DATA configuration statement must contain the DOMAINORIGIN or DOMAIN specified for each TCP/IP defined.
SV-252547r1225872_ruleIBM z/OS TCP/IP AT-TLS policy must be properly configured in Policy Agent.
SV-252705r1225873_ruleIBM z/OS must enforce a minimum eight character password length.
SV-255895r1225874_ruleIBM z/OS FTP.DATA configuration statements for the FTP Server must be specified in accordance with requirements.
SV-255932r1225875_ruleIBM Integrated Crypto Service Facility (ICSF) Configuration parameters must be correctly specified.
SV-255933r1225876_ruleIBM Integrated Crypto Service Facility (ICSF) install data sets must be properly protected.
SV-255934r1225877_ruleIBM Integrated Crypto Service Facility (ICSF) Started Task name must be properly identified / defined to the system ACP.
SV-255945r1225878_ruleIBM Integrated Crypto Service Facility (ICSF) STC data sets must be properly protected.
SV-272873r1225879_ruleIBM z/OS DFSMS control data sets must reside on separate storage volumes.
SV-272874r1225880_ruleIBM z/OS RJE workstations and NJE nodes must be defined to the FACILITY resource class.
SV-275949r1225881_rulezOSMF resource class(es) must be defined to the ACF2 GSO CLASMAP record in accordance with security requirements.
SV-275951r1225882_ruleICSF resources must be protected in accordance with security requirements.
SV-275964r1225883_rulezOSMF resources must be protected in accordance with security requirements.
SV-275965r1225884_ruleICSF resource class(es) must be defined to the ACF2 GSO CLASMAP record in accordance with security requirements.
SV-285328r1225885_ruleIBM z/OS SSL options for the TN3270 Telnet Server must specufy a secure port.