| Checked | Name | Title |
|---|
| ☐ | SV-223871r998483_rule | All IBM z/OS digital certificates in use must have a valid path to a trusted Certification Authority (CA). |
| ☐ | SV-223872r958448_rule | Expired IBM z/OS digital certificates must not be used. |
| ☐ | SV-223873r958482_rule | IBM z/OS must have Certificate Name Filtering implemented with appropriate authorization and documentation. |
| ☐ | SV-223874r1137691_rule | CA-TSS Security control ACIDs must be limited to the administrative authorities authorized and that require these privileges to perform their job duties. |
| ☐ | SV-223875r1137691_rule | The number of CA-TSS ACIDs possessing the tape Bypass Label Processing (BLP) privilege must be limited. |
| ☐ | SV-223876r958362_rule | CA-TSS MODE Control Option must be set to FAIL. |
| ☐ | SV-223877r958388_rule | The CA-TSS NPWRTHRESH Control Option must be properly set. |
| ☐ | SV-223878r958388_rule | The CA-TSS NPPTHRESH Control Option must be properly set. |
| ☐ | SV-223879r1050764_rule | The CA-TSS PTHRESH Control Option must be set to 2. |
| ☐ | SV-223881r958434_rule | IBM z/OS must limit access for SMF collection files (i.e., SYS1.MANx) to appropriate users and/or batch jobs that perform SMF dump processing. |
| ☐ | SV-223882r998484_rule | IBM z/OS SYS1.PARMLIB must be properly protected. |
| ☐ | SV-223883r998485_rule | IBM z/OS for PKI-based authentication must use ICSF or the ESM to store keys. |
| ☐ | SV-223885r998486_rule | The CA-TSS NEWPHRASE and PPSCHAR Control Options must be properly set. |
| ☐ | SV-223886r998487_rule | The CA-TSS NEWPW control options must be properly set. |
| ☐ | SV-223887r998488_rule | IBM z/OS must use NIST FIPS-validated cryptography to protect passwords in the security database. |
| ☐ | SV-223888r1038967_rule | The CA-TSS PWEXP Control Option must be set to 60. |
| ☐ | SV-223889r1038967_rule | The CA-TSS PPEXP Control Option must be properly set. |
| ☐ | SV-223890r998491_rule | The CA-TSS PWHIST Control Option must be set to 10 or greater. |
| ☐ | SV-223891r998492_rule | The CA-TSS PPHIST Control Option must be properly set. |
| ☐ | SV-223893r1137691_rule | CA-TSS access to SYS1.LINKLIB must be properly protected. |
| ☐ | SV-223894r1137691_rule | CA-TSS must limit Write or greater access to SYS1.SVCLIB to system programmers only. |
| ☐ | SV-223895r1137691_rule | CA-TSS must limit Write or greater access to SYS1.IMAGELIB to system programmers only. |
| ☐ | SV-223896r1137691_rule | CA-TSS must limit Write or greater access to SYS1.LPALIB to system programmers only. |
| ☐ | SV-223897r1137691_rule | CA-TSS must limit WRITE or greater access to all APF-authorized libraries to system programmers only. |
| ☐ | SV-223898r1137691_rule | IBM z/OS libraries included in the system REXXLIB concatenation must be properly protected. |
| ☐ | SV-223899r1137691_rule | CA-TSS must limit Write or greater access to all LPA libraries to system programmers only. |
| ☐ | SV-223900r1137691_rule | CA-TSS must limit Write or greater access to SYS1.NUCLEUS to system programmers only. |
| ☐ | SV-223901r1137691_rule | CA-TSS must limit Write or greater access to libraries that contain PPT modules to system programmers only. |
| ☐ | SV-223902r1137691_rule | CA-TSS must limit WRITE or greater access to LINKLIST libraries to system programmers only. |
| ☐ | SV-223903r1137691_rule | CA-TSS security data sets and/or databases must be properly protected. |
| ☐ | SV-223904r1137691_rule | CA-TSS must limit access to the System Master Catalog to appropriate authorized users. |
| ☐ | SV-223905r1137691_rule | CA-TSS allocate access to system user catalogs must be limited to system programmers only. |
| ☐ | SV-223906r1137691_rule | CA-TSS must limit WRITE or greater access to all system-level product installation libraries to system programmers only. |
| ☐ | SV-223907r1137691_rule | CA-TSS must limit WRITE or greater access to the JES2 System data sets (e.g., Spool, Checkpoint, and Initialization parameters) to system programmers only. |
| ☐ | SV-223908r1137691_rule | CA-TSS must limit Write or greater access to SYS1.UADS to system programmers only, and Read and Update access must be limited to system programmer personnel and/or security personnel. |
| ☐ | SV-223909r1137691_rule | CA-TSS must limit access to data sets used to back up and/or dump SMF collection files to appropriate users and/or batch jobs that perform SMF dump processing. |
| ☐ | SV-223910r1137691_rule | CA-TSS must limit access to SYSTEM DUMP data sets to system programmers only. |
| ☐ | SV-223911r1137691_rule | CA-TSS WRITE or Greater access to System backup files must be limited to system programmers and/or batch jobs that perform DASD backups. |
| ☐ | SV-223912r1137691_rule | CA-TSS must limit access to SYS(x).TRACE to system programmers only. |
| ☐ | SV-223913r1137691_rule | CA-TSS must limit access to System page data sets (i.e., PLPA, COMMON, and LOCALx) to system programmers only. |
| ☐ | SV-223914r1137691_rule | CA-TSS must limit WRITE or greater access to libraries containing EXIT modules to system programmers only. |
| ☐ | SV-223915r958726_rule | CA-TSS must limit all system PROCLIB data sets to system programmers only and appropriate authorized users. |
| ☐ | SV-223916r1137691_rule | CA-TSS must protect memory and privileged program dumps in accordance with proper security requirements. |
| ☐ | SV-223917r1137691_rule | IBM z/OS must protect dynamic lists in accordance with proper security requirements. |
| ☐ | SV-223918r1137691_rule | IBM z/OS system commands must be properly protected. |
| ☐ | SV-223919r1137691_rule | IBM z/OS MCS consoles access authorization(s) for CONSOLE resource(s) must be properly protected. |
| ☐ | SV-223920r1137691_rule | CA-TSS must properly define users that have access to the CONSOLE resource in the TSOAUTH resource class. |
| ☐ | SV-223921r1137691_rule | IBM z/OS Operating system commands (MVS.) of the OPERCMDS resource class must be properly owned. |
| ☐ | SV-223922r1137691_rule | CA-TSS AUTH Control Option values specified must be set to (OVERRIDE,ALLOVER) or (MERGE,ALLOVER). |
| ☐ | SV-223923r1137691_rule | Access to the CA-TSS MODE resource class must be appropriate. |
| ☐ | SV-223924r1137691_rule | Data set masking characters must be properly defined to the CA-TSS security database. |
| ☐ | SV-223925r1137691_rule | CA-TSS Emergency ACIDs must be properly limited and must audit all resource access. |
| ☐ | SV-223926r1137691_rule | CA-TSS ACIDs must not have access to FAC(*ALL*). |
| ☐ | SV-223927r1137691_rule | The CA-TSS ALL record must have appropriate access to Facility Matrix Tables. |
| ☐ | SV-223928r1137691_rule | Data set masking characters allowing access to all data sets must be properly restricted in the CA-TSS security database. |
| ☐ | SV-223929r1137691_rule | IBM z/OS DASD Volume access greater than CREATE found in the CA-TSS database must be limited to authorized information technology personnel requiring access to perform their job duties. |
| ☐ | SV-223930r1137691_rule | IBM z/OS Sensitive Utility Controls must be properly defined and protected. |
| ☐ | SV-223931r991591_rule | IBM z/OS Started tasks must be properly defined to CA-TSS. |
| ☐ | SV-223932r991589_rule | The CA-TSS CANCEL Control Option must not be specified. |
| ☐ | SV-223933r991589_rule | The CA-TSS HPBPW Control Option must be set to three days maximum. |
| ☐ | SV-223934r991589_rule | The CA-TSS INSTDATA Control Option must be set to 0. |
| ☐ | SV-223935r991589_rule | The CA-TSS OPTIONS Control Option must include option 4 at a minimum. |
| ☐ | SV-223936r991589_rule | CA-TSS TEMPDS Control Option must be set to YES. |
| ☐ | SV-223937r991589_rule | The number of CA-TSS control ACIDs must be justified and properly assigned. |
| ☐ | SV-223938r991589_rule | The number of CA-TSS ACIDs with MISC9 authority must be justified. |
| ☐ | SV-223939r991589_rule | The CA-TSS LUUPDONCE Control Option value specified must be set to NO. |
| ☐ | SV-223940r991589_rule | The CA-TSS Automatic Data Set Protection (ADSP) Control Option must be set to NO. |
| ☐ | SV-223941r991589_rule | CA-TSS RECOVER Control Option must be set to ON. |
| ☐ | SV-223942r958480_rule | IBM z/OS must properly configure CONSOLxx members. |
| ☐ | SV-223943r958480_rule | IBM z/OS must properly protect MCS console userid(s). |
| ☐ | SV-223944r958482_rule | The CA-TSS CPFRCVUND Control Option value specified must be set to NO. |
| ☐ | SV-223945r958482_rule | The CA-TSS CPFTARGET Control Option value specified must be set to LOCAL. |
| ☐ | SV-223946r958482_rule | CA-TSS User ACIDs and Control ACIDs must have the NAME field completed. |
| ☐ | SV-223947r958482_rule | The CA-TSS PASSWORD(NOPW) option must not be specified for any ACID type. |
| ☐ | SV-223948r958482_rule | Interactive ACIDs defined to CA-TSS must have the required fields completed. |
| ☐ | SV-223950r958482_rule | CA-TSS Batch ACID(s) submitted through RJE and NJE must be sourced. |
| ☐ | SV-223951r958482_rule | IBM z/OS DASD management ACIDs must be properly defined to CA-TSS. |
| ☐ | SV-223952r998495_rule | CA-TSS user accounts must uniquely identify system users. |
| ☐ | SV-223953r998496_rule | CA-TSS security administrator must develop a process to suspend userids found inactive for more than 35 days. |
| ☐ | SV-223954r998497_rule | The CA-TSS INACTIVE Control Option must be properly set. |
| ☐ | SV-223955r1137695_rule | The CA-TSS AUTOERASE Control Option must be set to ALL for all systems. |
| ☐ | SV-223956r958550_rule | CA-TSS DOWN Control Option values must be properly specified. |
| ☐ | SV-223957r958808_rule | The CA-TSS Facility Control Option must specify the sub option of MODE=FAIL. |
| ☐ | SV-223958r998498_rule | CA-TSS ACID creation must use the EXP option. |
| ☐ | SV-223959r958730_rule | The CA-TSS SUBACID Control Option must be set to U,8. |
| ☐ | SV-223960r958730_rule | CA-TSS must use propagation control to eliminate ACID inheritance. |
| ☐ | SV-223961r958730_rule | IBM z/OS scheduled production batch ACIDs must specify the CA-TSS BATCH Facility, and the Batch Job Scheduler must be authorized to the Scheduled production CA-TSS batch ACID. |
| ☐ | SV-223962r958732_rule | CA-TSS ADMINBY Control Option must be set to ADMINBY. |
| ☐ | SV-223963r958732_rule | CA-TSS LOG Control Option must be set to (SMF,INIT, SEC9, MSG). |
| ☐ | SV-223964r958732_rule | CA-TSS MSCA ACID password changes must be documented in the change log. |
| ☐ | SV-223965r958726_rule | The IBM z/OS IEASYMUP resource must be protected in accordance with proper security requirements. |
| ☐ | SV-223966r958726_rule | CA-TSS Default ACID must be properly defined. |
| ☐ | SV-223967r958726_rule | The CA-TSS BYPASS attribute must be limited to trusted STCs only. |
| ☐ | SV-223968r958726_rule | CA-TSS MSCA ACID must perform security administration only. |
| ☐ | SV-223969r958726_rule | CA-TSS ACIDs granted the CONSOLE attribute must be justified. |
| ☐ | SV-223970r958726_rule | CA-TSS ACIDs defined as security administrators must have the NOATS attribute. |
| ☐ | SV-223972r958636_rule | CA-TSS VTHRESH Control Option values specified must be set to (10,NOT,CAN). |
| ☐ | SV-223973r1050767_rule | IBM z/OS FTP.DATA configuration statements must have a proper banner statement with the Standard Mandatory DOD Notice and Consent Banner. |
| ☐ | SV-223974r958406_rule | IBM z/OS SMF recording options for the FTP server must be configured to write SMF records for all eligible events. |
| ☐ | SV-223975r1196257_rule | CA-TSS permission bits and user audit bits for HFS objects that are part of the FTP server component must be properly configured. |
| ☐ | SV-223976r1137691_rule | IBM z/OS data sets for the FTP server must be properly protected. |
| ☐ | SV-223977r1130288_rule | IBM z/OS FTP Control cards must be properly stored in a secure PDS file. |
| ☐ | SV-223978r958480_rule | IBM z/OS user exits for the FTP server must not be used without proper approval and documentation. |
| ☐ | SV-223979r958482_rule | The IBM z/OS FTP server daemon must be defined with proper security parameters. |
| ☐ | SV-223980r970703_rule | IBM z/OS FTP.DATA configuration for the FTP server must have the INACTIVE statement properly set. |
| ☐ | SV-223981r970703_rule | IBM z/OS startup parameters for the FTP server must have the INACTIVE statement properly set. |
| ☐ | SV-223982r958586_rule | IBM z/OS FTP.DATA configuration statements for the FTP server must specify the Standard Mandatory DoD Notice and Consent Banner statement. |
| ☐ | SV-223985r1137691_rule | IBM z/OS JES2.** resource must be properly protected in the CA-TSS database. |
| ☐ | SV-223986r1137691_rule | IBM z/OS RJE workstations and NJE nodes must be controlled in accordance with STIG requirements. |
| ☐ | SV-223987r1137691_rule | IBM z/OS JES2 input sources must be controlled in accordance with the proper security requirements. |
| ☐ | SV-223988r1137691_rule | IBM z/OS JES2 input sources must be properly controlled. |
| ☐ | SV-223989r1137691_rule | IBM z/OS JES2 output devices must be controlled in accordance with the proper security requirements. |
| ☐ | SV-223990r1137691_rule | IBM z/OS JES2 output devices must be properly controlled for classified systems. |
| ☐ | SV-223991r1137691_rule | IBM z/OS JESSPOOL resources must be protected in accordance with security requirements. |
| ☐ | SV-223992r1137691_rule | IBM z/OS JESNEWS resources must be protected in accordance with security requirements. |
| ☐ | SV-223993r1137691_rule | IBM z/OS JESTRACE and/or SYSLOG resources must be protected in accordance with security requirements. |
| ☐ | SV-223994r1137691_rule | IBM z/OS JES2 spool resources must be controlled in accordance with security requirements. |
| ☐ | SV-223995r1137691_rule | IBM z/OS JES2 system commands must be protected in accordance with security requirements. |
| ☐ | SV-223996r1137691_rule | IBM z/OS Surrogate users must be controlled in accordance with proper security requirements. |
| ☐ | SV-223997r958478_rule | Duplicated IBM z/OS sensitive utilities and/or programs must not exist in APF libraries. |
| ☐ | SV-223998r998499_rule | IBM z/OS required SMF data record types must be collected. |
| ☐ | SV-223999r958402_rule | IBM z/OS Session manager must properly configure wait time limits. |
| ☐ | SV-224000r1130291_rule | The IBM z/OS BPX.SMF resource must be properly configured. |
| ☐ | SV-224001r958414_rule | IBM z/OS must specify SMF data options to ensure appropriate activation. |
| ☐ | SV-224002r958424_rule | IBM z/OS BUFUSEWARN in the SMFPRMxx must be properly set. |
| ☐ | SV-224003r991589_rule | IBM z/OS PASSWORD data set and OS passwords must not be used. |
| ☐ | SV-224004r991589_rule | The CA-TSS database must be on a separate physical volume from its backup and recovery data sets. |
| ☐ | SV-224005r991589_rule | The CA-TSS database must be backed up on a scheduled basis. |
| ☐ | SV-224006r991593_rule | The IBM z/OS Policy Agent must be configured to deny-all, allow-by-exception firewall policy for allowing connections to other systems. |
| ☐ | SV-224007r958478_rule | IBM z/OS must not have Inaccessible APF libraries defined. |
| ☐ | SV-224008r958478_rule | IBM z/OS inapplicable PPT entries must be invalidated. |
| ☐ | SV-224009r958478_rule | IBM z/OS LNKAUTH=APFTAB must be specified in the IEASYSxx member(s) in the currently active parmlib data set(s). |
| ☐ | SV-224010r1137695_rule | IBM z/OS sensitive and critical system data sets must not exist on shared DASD. |
| ☐ | SV-224011r958528_rule | The IBM z/OS Policy Agent must contain a policy that manages excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial-of-service (DoS) attacks. |
| ☐ | SV-224013r998500_rule | The IBM z/OS system administrator (SA) must develop a process to notify appropriate personnel when accounts are created. |
| ☐ | SV-224014r998501_rule | The IBM z/OS system administrator (SA) must develop a process to notify appropriate personnel when accounts are modified. |
| ☐ | SV-224015r998502_rule | The IBM z/OS system administrator (SA) must develop a process to notify appropriate personnel when accounts are deleted. |
| ☐ | SV-224016r998503_rule | The IBM z/OS system administrator (SA) must develop a process to notify appropriate personnel when accounts are removed. |
| ☐ | SV-224017r958804_rule | Unsupported IBM z/OS system software must not be installed and/or active on the system. |
| ☐ | SV-224018r958804_rule | IBM z/OS must not allow nonexistent or inaccessible Link Pack Area (LPA) libraries. |
| ☐ | SV-224019r958804_rule | IBM z/OS must not allow nonexistent or inaccessible LINKLIST libraries. |
| ☐ | SV-224020r958796_rule | CA-TSS must be installed and properly configured. |
| ☐ | SV-224021r958752_rule | IBM z/OS SMF collection files (system MANx data sets or LOGSTREAM DASD) must have storage capacity to store at least one weeks worth of audit data. |
| ☐ | SV-224022r958754_rule | IBM z/OS System Administrators must develop an automated process to collect and retain SMF data. |
| ☐ | SV-224023r1169905_rule | The IBM z/OS system must use a time protocol that syncs with an authoritative external time source. |
| ☐ | SV-224024r1174004_rule | IBM z/OS Time Protocol must be properly configured. IBM z/OS SNTP daemon (SNTPD) permission bits must be properly configured. |
| ☐ | SV-224025r998506_rule | IBM z/OS PARMLIB CLOCKxx must have the Accuracy PARM coded properly. |
| ☐ | SV-224026r958902_rule | The IBM z/OS Policy Agent must contain a policy that protects against or limits the effects of denial-of-service (DoS) attacks by ensuring IBM z/OS is implementing rate-limiting measures on impacted network interfaces. |
| ☐ | SV-224031r991589_rule | IBM z/OS must configure system wait times to protect resource availability based on site priorities. |
| ☐ | SV-224032r958404_rule | IBM z/OS must employ a session manager to conceal, via the session lock, information previously visible on the display with a publicly viewable image. |
| ☐ | SV-224034r958400_rule | IBM z/OS must employ a session manager to manage retaining a users session lock until that user reestablishes access using established identification and authentication procedures. |
| ☐ | SV-224035r998507_rule | IBM z/OS system administrator (SA) must develop a procedure to remove or disable temporary user accounts after 72 hours. |
| ☐ | SV-224036r998508_rule | IBM z/OS system administrator (SA) must develop a procedure to remove or disable emergency accounts after the crisis is resolved or 72 hours. |
| ☐ | SV-224037r998509_rule | IBM z/OS system administrator (SA) must develop a procedure to notify SAs and information system security officers (ISSOs) of account enabling actions. |
| ☐ | SV-224038r958794_rule | IBM z/OS system administrator must develop a procedure to notify designated personnel if baseline configurations are changed in an unauthorized manner. |
| ☐ | SV-224040r958936_rule | IBM z/OS system administrator must develop a procedure to remove all software components after updated versions have been installed. |
| ☐ | SV-224041r958948_rule | IBM z/OS system administrator must develop a procedure to shut down the information system, restart the information system, and/or notify the system administrator when anomalies in the operation of any security functions are discovered. |
| ☐ | SV-224042r959008_rule | IBM z/OS system administrator must develop a procedure to offload SMF files to a different system or media than the system being audited. |
| ☐ | SV-224043r998511_rule | IBM z/OS must employ a session manager for users to directly initiate a session lock for all connection types. |
| ☐ | SV-224044r1212331_rule | The SSH daemon must be configured to use a FIPS 140-3-compliant cryptographic algorithm. |
| ☐ | SV-224045r958480_rule | IBM z/OS SSH daemon must be configured to only use the SSHv2 protocol. |
| ☐ | SV-224046r1137691_rule | IBM z/OS permission bits and user audit bits for HFS objects that are part of the Syslog daemon component must be configured properly. |
| ☐ | SV-224047r958482_rule | The IBM z/OS Syslog daemon must not be started at z/OS initialization. |
| ☐ | SV-224048r958482_rule | The IBM z/OS Syslog daemon must be properly defined and secured. |
| ☐ | SV-224049r1137691_rule | IBM z/OS DFSMS resources must be protected in accordance with the proper security requirements. |
| ☐ | SV-224050r1137691_rule | IBM z/OS DFSMS Program Resources must be properly defined and protected. |
| ☐ | SV-224051r1137691_rule | IBM z/OS DFSMS control data sets must be protected in accordance with security requirements. |
| ☐ | SV-224052r991589_rule | IBM z/OS using DFSMS must properly specify SYS(x).PARMLIB(IGDSMSxx), SMS parameter settings. |
| ☐ | SV-224054r958406_rule | IBM z/OS SMF recording options for the SSH daemon must be configured to write SMF records for all eligible events. |
| ☐ | SV-224055r958586_rule | The IBM z/OS SSH daemon must be configured with the Standard Mandatory DoD Notice and Consent Banner. |
| ☐ | SV-224056r958406_rule | IBM z/OS PROFILE.TCPIP configuration statements for the TCP/IP stack must be properly coded. |
| ☐ | SV-224057r1137691_rule | IBM z/OS permission bits and user audit bits for HFS objects that are part of the Base TCP/IP component must be configured properly. |
| ☐ | SV-224058r1137691_rule | IBM z/OS TCP/IP resources must be properly protected. |
| ☐ | SV-224059r1137691_rule | IBM z/OS data sets for the Base TCP/IP component must be properly protected. |
| ☐ | SV-224060r991589_rule | IBM z/OS Configuration files for the TCP/IP stack must be properly specified. |
| ☐ | SV-224061r958482_rule | IBM z/OS started tasks for the Base TCP/IP component must be defined in accordance with security requirements. |
| ☐ | SV-224062r958672_rule | IBM z//OS must be configured to restrict all TCP/IP ports to ports, protocols, and/or services as defined in the PPSM CAL and vulnerability assessments. |
| ☐ | SV-224065r958390_rule | IBM z/OS TN3270 Telnet server configuration statement MSG10 text must have the Standard Mandatory DoD Notice and Consent Banner. |
| ☐ | SV-224066r958846_rule | IBM z/OS SMF recording options for the TN3270 Telnet server must be properly specified. |
| ☐ | SV-224067r1212334_rule | IBM z/OS SSL encryption options for the TN3270 Telnet Server must be specified properly. |
| ☐ | SV-224068r991589_rule | IBM z/OS VTAM session setup controls for the TN3270 Telnet server must be properly specified. |
| ☐ | SV-224069r970703_rule | IBM z/OS PROFILE.TCPIP configuration for the TN3270 Telnet server must have the INACTIVE statement properly specified. |
| ☐ | SV-224072r1137691_rule | IBM Z/OS TSOAUTH resources must be restricted to authorized users. |
| ☐ | SV-224073r958726_rule | CA-TSS LOGONIDs must not be defined to SYS1.UADS for non-emergency use. |
| ☐ | SV-224074r991589_rule | IBM z/OS UNIX HFS MapName file security parameters must be properly specified. |
| ☐ | SV-224075r1038966_rule | IBM z/OS NOBUFFS in SMFPRMxx must be properly set (default is MSG). |
| ☐ | SV-224076r1137691_rule | IBM z/OS BPX resource(s) must be protected in accordance with security requirements. |
| ☐ | SV-224077r1137691_rule | IBM z/OS UNIX resources must be protected in accordance with security requirements. |
| ☐ | SV-224078r1137691_rule | IBM z/OS UNIX SUPERUSER resources must be protected in accordance with guidelines. |
| ☐ | SV-224079r1137691_rule | IBM z/OS UNIX MVS data sets or HFS objects must be properly protected. |
| ☐ | SV-224080r1137691_rule | IBM z/OS UNIX MVS data sets with z/OS UNIX components must be properly protected. |
| ☐ | SV-224081r1137691_rule | IBM z/OS UNIX MVS data sets used as step libraries in /etc/steplib must be properly protected. |
| ☐ | SV-224082r1137691_rule | IBM z/OS UNIX HFS permission bits and audit bits for each directory must be properly protected. |
| ☐ | SV-224083r1137691_rule | IBM z/OS UNIX system file security settings must be properly protected or specified. |
| ☐ | SV-224084r1137691_rule | IBM z/OS UNIX MVS HFS directory(s) with OTHER write permission bit set must be properly defined. |
| ☐ | SV-224085r1137691_rule | The CA-TSS HFSSEC resource class must be defined with DEFPROT. |
| ☐ | SV-224086r991589_rule | IBM z/OS UNIX OMVS parameters in PARMLIB must be properly specified. |
| ☐ | SV-224087r991589_rule | IBM z/OS UNIX BPXPRMxx security parameters in PARMLIB must be properly specified. |
| ☐ | SV-224088r1137691_rule | IBM z/OS UNIX security parameters in etc/profile must be properly specified. |
| ☐ | SV-224089r1137691_rule | IBM z/OS UNIX security parameters in /etc/rc must be properly specified. |
| ☐ | SV-224090r991589_rule | IBM z/OS Default profiles must not be defined in TSS OMVS UNIX security parameters for classified systems. |
| ☐ | SV-224091r1195292_rule | IBM z/OS UNIX security parameters for restricted network service(s) in /etc/inetd.conf must be properly specified. |
| ☐ | SV-224092r958482_rule | IBM z/OS attributes of z/OS UNIX user accounts must have a unique GID in the range of 1-99. |
| ☐ | SV-224093r958482_rule | The IBM z/OS user account for the UNIX kernel (OMVS) must be properly defined to the security database. |
| ☐ | SV-224094r958482_rule | The IBM z/OS user account for the z/OS UNIX SUPERUSER userid must be properly defined. |
| ☐ | SV-224095r958482_rule | The IBM z/OS user account for the UNIX (RMFGAT) must be properly defined. |
| ☐ | SV-224096r958482_rule | IBM z/OS UID(0) must be properly assigned. |
| ☐ | SV-224097r958482_rule | IBM z/OS UNIX user accounts must be properly defined. |
| ☐ | SV-224098r958482_rule | IBM z/OS attributes of UNIX user accounts used for account modeling must be defined in accordance with security requirements. |
| ☐ | SV-224099r958392_rule | The IBM z/OS UNIX Telnet server etc/banner file must have the Standard Mandatory DoD Notice and Consent Banner. |
| ☐ | SV-224100r1137691_rule | The IBM z/OS startup user account for the z/OS UNIX Telnet server must be properly defined. |
| ☐ | SV-224101r1137691_rule | IBM z/OS HFS objects for the z/OS UNIX Telnet server must be properly protected. |
| ☐ | SV-224102r958586_rule | The IBM z/OS UNIX Telnet server Startup parameters must be properly specified. |
| ☐ | SV-224103r958586_rule | The IBM z/OS UNIX Telnet server warning banner must be properly specified. |
| ☐ | SV-224104r1137691_rule | IBM z/OS System data sets used to support the VTAM network must be properly secured. |
| ☐ | SV-224105r991560_rule | IBM z/OS VTAM USSTAB definitions must not be used for unsecured terminals. |
| ☐ | SV-245537r991589_rule | The IBM z/OS TCPIP.DATA configuration statement must contain the DOMAINORIGIN or DOMAIN specified for each TCP/IP defined. |
| ☐ | SV-251108r1028298_rule | The IBM z/OS systems requiring data at rest protection must properly employ IBM DS8880 or equivalent hardware solutions for full disk encryption. |
| ☐ | SV-252554r1212337_rule | IBM z/OS TCP/IP AT-TLS policy must be properly configured in Policy Agent. |
| ☐ | SV-255896r991589_rule | IBM z/OS FTP.DATA configuration statements for the FTP Server must be specified in accordance with requirements. |
| ☐ | SV-255940r991589_rule | IBM Integrated Crypto Service Facility (ICSF) Configuration parameters must be correctly specified. |
| ☐ | SV-255941r1137691_rule | IBM Integrated Crypto Service Facility (ICSF) install data sets are not properly protected. |
| ☐ | SV-255942r958482_rule | IBM Integrated Crypto Service Facility (ICSF) Started Task name is not properly identified / defined to the system ACP. |
| ☐ | SV-255943r958482_rule | IBM Integrated Crypto Service Facility (ICSF) Started task(s) must be properly defined to the Started Task Table ACID for Top Secret. |
| ☐ | SV-255944r991560_rule | IBM Integrated Crypto Service Facility (ICSF) STC data sets must be properly protected. |
| ☐ | SV-272878r1137691_rule | IBM z/OS DFSMS control data sets must reside on separate storage volumes. |
| ☐ | SV-275959r1137691_rule | zOSMF resource class(es) must be properly owned in accordance with security requirements. |
| ☐ | SV-275960r1169908_rule | zOSMF resources must be protected in accordance with security requirements. |
| ☐ | SV-275961r1169902_rule | ICSF resource class(es) must be properly owned in accordance with security requirements. |
| ☐ | SV-275962r1169904_rule | ICSF resources must be protected in accordance with security requirements. |
| ☐ | SV-285330r1212315_rule | IBM z/OS SSL options for the TN3270 Telnet Server must specify a secure port. |