STIGQter STIGQter: STIG Summary:

Mainframe Product Security Requirements Guide

Version: 3

Release: 5 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-205439r960735_ruleThe Mainframe Product must limit the number of concurrent sessions to three for all accounts and/or account types.
SV-205440r960738_ruleThe Mainframe Product must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
SV-205441r960741_ruleThe Mainframe Product must initiate a session lock after a 15-minute period of inactivity.
SV-205442r982280_ruleThe Mainframe Product must provide the capability for users to directly initiate a session lock.
SV-205443r960747_ruleThe Mainframe Product must retain the session lock until the user reestablishes access using established identification and authentication procedures.
SV-205444r1043176_ruleThe Mainframe Product must use an external security manager for all account management functions.
SV-205445r960771_ruleThe Mainframe Product must automatically remove or disable temporary user accounts after 72 hours.
SV-205446r960774_ruleThe Mainframe Product must automatically disable accounts after 35 days of account inactivity.
SV-205447r960777_ruleThe Mainframe Product must automatically audit account creation.
SV-205448r960780_ruleThe Mainframe Product must automatically audit account modification.
SV-205449r960783_ruleThe Mainframe Product must automatically audit account disabling actions.
SV-205450r960786_ruleThe Mainframe Product must automatically audit account removal actions.
SV-205451r1137796_ruleThe Mainframe Product must enforce approved authorizations for logical access to sensitive information and system resources in accordance with applicable access control policies.
SV-205452r1137798_ruleThe Mainframe Product must enforce approved authorizations for security administrator access to sensitive information and system resources in accordance with applicable access control policies.
SV-205453r1137800_ruleThe Mainframe Product must enforce approved authorizations for system programmer access to sensitive information and system resources in accordance with applicable access control policies.
SV-205454r1137802_ruleThe Mainframe Product must enforce approved authorizations for controlling the flow of information within the system based on site security plan information flow control policies.
SV-205455r960840_ruleThe Mainframe Product must enforce the limit of three consecutive invalid logon attempts by a user during a 15 minute time period.
SV-205456r960852_ruleMainframe Products scanning for malicious code must scan all media used for system maintenance prior to use.
SV-205457r960864_ruleThe Mainframe Product must protect against an individual (or process acting on behalf of an individual) falsely denying having performed actions defined in the site security plan to be covered by non-repudiation.
SV-205458r960873_ruleFor Mainframe Products providing audit record aggregation, the Mainframe Product must compile audit records from mainframe components into a system-wide audit trail that is time-correlated with a tolerance for the relationship between time stamps of individual records in the audit trail in accordance with the site security plan.
SV-205459r960879_ruleThe Mainframe Product must provide audit record generation capability for DoD-defined auditable events within all application components.
SV-205460r960882_ruleThe Mainframe Product must allow only the information system security manager (ISSM) or individuals or roles appointed by the ISSM to select which auditable events are to be audited.
SV-205461r960885_ruleThe Mainframe Product must generate audit records when successful/unsuccessful attempts to access privileges occur.
SV-205462r960888_ruleThe Mainframe Product must initiate session auditing upon startup.
SV-205464r960891_ruleThe Mainframe Product must produce audit records containing information to establish what type of events occurred.
SV-205465r960894_ruleThe Mainframe Product must produce audit records containing information to establish when (date and time) the events occurred.
SV-205466r960897_ruleThe Mainframe Product must produce audit records containing information to establish where the events occurred.
SV-205467r960900_ruleThe Mainframe Product must produce audit records containing information to establish the source of the events.
SV-205468r960903_ruleThe Mainframe Product must produce audit records containing information to establish the outcome of the events.
SV-205469r960906_ruleThe Mainframe Product must generate audit records containing information to establish the identity of any individual or process associated with the event.
SV-205470r960909_ruleThe Mainframe Product must generate audit records containing the full-text recording of privileged commands or the individual identities of group account users.
SV-205471r960912_ruleThe Mainframe Product must alert the system administrator (SA) and information system security officer (ISSO) (at a minimum) in the event of an audit processing failure.
SV-205473r960918_ruleThe Mainframe Product must provide the capability to centrally review and analyze audit records from multiple components within the system.
SV-205474r960921_ruleThe Mainframe Product must prevent the execution of prohibited mobile code.
SV-205475r960924_ruleThe Mainframe Products must provide the capability to filter audit records for events of interest as defined in site security plan.
SV-205476r960927_ruleThe Mainframe Products must use internal system clocks to generate time stamps for audit records.
SV-205477r960930_ruleThe Mainframe Product must protect audit information from any type of unauthorized read access.
SV-205478r960933_ruleThe Mainframe Product must protect audit information from unauthorized modification.
SV-205479r960936_ruleThe Mainframe Product must protect audit information from unauthorized deletion.
SV-205480r960939_ruleThe Mainframe Product must protect audit tools from unauthorized access.
SV-205481r960942_ruleThe Mainframe Product must protect audit tools from unauthorized modification.
SV-205482r960945_ruleThe Mainframe Product must protect audit tools from unauthorized deletion.
SV-205483r982281_ruleThe Mainframe Product must prevent the installation of patches, service packs, or application components without verification that the software component has been digitally signed using a certificate that is recognized and approved by the organization.
SV-205484r960960_ruleThe Mainframe Product must limit privileges to change the Mainframe Product installation datasets to system programmers and authorized users in accordance with applicable access control policies.
SV-205485r960960_ruleThe Mainframe Product must limit privileges to change Mainframe Product started task and job datasets to system programmers and authorized users in accordance with applicable access control policies.
SV-205486r960960_ruleThe Mainframe Product must limit privileges to change Mainframe Product user datasets to authorized individuals.
SV-205487r960963_ruleThe Mainframe Product must be configured to disable non-essential capabilities.
SV-205488r1051115_ruleThe Mainframe Product must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
SV-205489r960972_ruleThe Mainframe Product must use multifactor authentication for network access to privileged accounts.
SV-205490r960975_ruleThe Mainframe Product must use multifactor authentication for network access to non-privileged accounts.
SV-205491r982283_ruleThe Mainframe Product must use multifactor authentication for local access to privileged accounts.
SV-205492r982286_ruleThe Mainframe Product must use multifactor authentication for local access to nonprivileged accounts.
SV-205493r982288_ruleThe Mainframe Product must verify users are authenticated with an individual authenticator prior to using a group authenticator.
SV-205494r982289_ruleThe Mainframe Product must enforce a minimum 15-character password length.
SV-205496r982292_ruleThe Mainframe Product must enforce password complexity by requiring that at least one uppercase character be used.
SV-205497r982293_ruleThe Mainframe Product must enforce password complexity by requiring that at least one lowercase character be used.
SV-205498r982294_ruleThe Mainframe Product must enforce password complexity by requiring that at least one numeric character be used.
SV-205499r982296_ruleThe Mainframe Product must enforce password complexity by requiring that at least one special character be used.
SV-205500r1043189_ruleThe Mainframe Product must require the change of at least eight of the total number of characters when passwords are changed.
SV-205501r982299_ruleThe Mainframe Product must store only cryptographically protected passwords.
SV-205502r1207665_ruleThe Mainframe Product must transmit only cryptographically protected passwords.
SV-205503r982300_ruleThe Mainframe Product must enforce 24 hours/1 day as the minimum password lifetime.
SV-205504r1043190_ruleThe Mainframe Product must enforce a 60-day maximum password lifetime restriction.
SV-205505r961038_ruleThe Mainframe Product, when using PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
SV-205506r961041_ruleThe Mainframe Product, when using PKI-based authentication, must enforce authorized access to the corresponding private key.
SV-205507r961044_ruleThe Mainframe Product must map the authenticated identity to the individual user or group account for PKI-based authentication.
SV-205508r961047_ruleThe Mainframe Product must obscure feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals.
SV-205509r961050_ruleThe Mainframe Product must use mechanisms meeting the requirements of applicable federal laws, Executive orders, directives, policies, regulations, standards, and guidance for authentication to a cryptographic module.
SV-205510r961053_ruleThe Mainframe Product must uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users).
SV-205511r961056_ruleThe Mainframe Product must provide an audit reduction capability that supports on-demand reporting requirements.
SV-205513r961083_ruleThe Mainframe Product must identify prohibited mobile code.
SV-205514r961086_ruleThe Mainframe Product must block, quarantine, and/or alert system administrators when prohibited mobile code is identified.
SV-205515r961089_ruleThe Mainframe Product must prevent the download of prohibited mobile code.
SV-205516r961092_ruleThe Mainframe Product must prevent the automatic execution of mobile code in, at a minimum, office applications, browsers, email clients, mobile code run-time environments, and mobile agent systems.
SV-205517r1137803_ruleThe Mainframe Product must separate user functionality (including user interface services) from information system management functionality.
SV-205518r961122_ruleThe Mainframe Product must fail to a secure state if system initialization fails, shutdown fails, or aborts fail.
SV-205519r961125_ruleIn the event of application failure, Mainframe Products must preserve any information necessary to determine the cause of failure and any information necessary to return to operations with the least disruption to mission processes.
SV-205520r961128_ruleThe Mainframe Product must protect the confidentiality and integrity of all information at rest.
SV-205521r961131_ruleThe Mainframe Product must isolate security functions from nonsecurity functions.
SV-205522r971528_ruleThe Mainframe Product must be configured such that emergency accounts are never automatically removed or disabled.
SV-205523r961158_ruleThe Mainframe Product must check the validity of all data inputs except those specifically identified by the organization.
SV-205524r961167_ruleThe Mainframe Product must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
SV-205525r961170_ruleThe Mainframe Product must reveal full-text detail error messages only to system programmers and/or security administrators.
SV-205526r982305_ruleThe Mainframe Product must update malicious code protection mechanisms whenever new releases are available in accordance with organizational configuration management policy.
SV-205527r961185_ruleThe Mainframe product must notify the system programmer and security administrator of failed security verification tests.
SV-205528r982308_ruleThe Mainframe Product must update malicious code protection mechanisms whenever new releases are available in accordance with organizational configuration management procedures.
SV-205529r961191_ruleThe Mainframe Product must configure malicious code protection mechanisms to perform periodic scans of the information system every seven days.
SV-205530r961206_ruleThe Mainframe Product must use cryptographic mechanisms to protect the integrity of audit tools.
SV-205531r982309_ruleThe Mainframe Product must notify system programmers and security administrators when accounts are created.
SV-205532r982310_ruleThe Mainframe Product must notify system programmers and security administrators when accounts are modified.
SV-205533r982311_ruleThe Mainframe Product must notify system programmers and security administrators for account disabling actions.
SV-205534r982312_ruleThe Mainframe Product must notify system programmers and security administrators for account removal actions.
SV-205535r1043182_ruleThe Mainframe Product must automatically terminate a user session after conditions, as defined in site security plan, are met or trigger events requiring session disconnect.
SV-205536r961224_ruleMainframe Products requiring user access authentication must provide a logoff capability for a user-initiated communication session.
SV-205537r961227_ruleThe Mainframe Product must display an explicit logoff message to users indicating the reliable termination of authenticated communications sessions.
SV-205538r961269_ruleThe Mainframe Product must associate types of security attributes having security attribute values as defined in site security plan with information in storage.
SV-205539r961272_ruleThe Mainframe Product must associate types of security attributes having security attribute values as defined in site security plan with information in process.
SV-205540r982313_ruleThe Mainframe Product must terminate shared/group account credentials when members leave the group.
SV-205541r961290_ruleThe Mainframe Product must automatically audit account enabling actions.
SV-205542r982314_ruleThe Mainframe Product must notify system programmers and security administrators of account enabling actions.
SV-205543r961317_ruleThe Mainframe Product must enforce organization-defined discretionary access control policies over defined subjects and objects.
SV-205544r961353_ruleThe Mainframe Product must prevent non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.
SV-205545r961359_ruleThe Mainframe Product must prevent software as identified in the site security plan from executing at higher privilege levels than users executing the software.
SV-205546r961362_ruleThe Mainframe Product must audit the execution of privileged functions.
SV-205547r961368_ruleThe Mainframe Product must automatically lock the account until the locked account is released by an administrator when three unsuccessful logon attempts in 15 minutes are exceeded.
SV-205553r961392_ruleThe mainframe product must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
SV-205554r961395_ruleThe Mainframe Product must off-load audit records onto a different system or media than the system being audited.
SV-205555r961398_ruleThe Mainframe Product must provide an immediate warning to the system programmer and security administrator (at a minimum) when allocated audit record storage volume reaches 75 percent of repository maximum audit record storage capacity.
SV-205556r961401_ruleThe Mainframe Product must provide an immediate real-time alert to the operations staff, system programmers, and/or security administrators, at a minimum, of all audit failure events requiring real-time alerts.
SV-205557r961413_ruleThe Mainframe Product must provide an audit reduction capability that supports on-demand audit review and analysis.
SV-205558r961416_ruleThe Mainframe Product must provide an audit reduction capability that supports after-the-fact investigations of security incidents.
SV-205559r961419_ruleThe Mainframe Product must provide a report generation capability that supports on-demand audit review and analysis.
SV-205560r961422_ruleThe Mainframe Product must provide a report generation capability that supports on-demand reporting requirements.
SV-205561r961425_ruleThe Mainframe Product must provide a report generation capability that supports after-the-fact investigations of security incidents.
SV-205562r961428_ruleThe Mainframe Product must provide an audit reduction capability that does not alter original content or time ordering of audit records.
SV-205563r961431_ruleThe Mainframe Product must provide a report generation capability that does not alter original content or time ordering of audit records.
SV-205564r982316_ruleThe Mainframe product must prohibit user installation of software without explicit privileged status.
SV-205565r961458_ruleThe Mainframe Product must implement organization-defined automated security responses if baseline configurations are changed in an unauthorized manner.
SV-205566r961461_ruleThe Mainframe Product must enforce access restrictions associated with changes to application configuration.
SV-205567r982317_ruleThe Mainframe Product must audit the enforcement actions used to restrict access associated with changes to the application.
SV-205570r961494_ruleThe Mainframe Product must accept Personal Identity Verification (PIV) credentials.
SV-205571r961497_ruleThe Mainframe Product must electronically verify Personal Identity Verification (PIV) credentials.
SV-205573r961521_ruleThe Mainframe Product must prohibit the use of cached authenticators after one hour.
SV-205574r961527_ruleThe Mainframe Product must accept Personal Identity Verification (PIV) credentials from other federal agencies.
SV-205575r961530_ruleThe Mainframe Product must electronically verify Personal Identity Verification (PIV) credentials from other federal agencies.
SV-205576r982321_ruleThe Mainframe Product must accept Federal Identity, Credential, and Access Management (FICAM)-approved third-party credentials.
SV-205577r982322_ruleThe Mainframe Product must conform to Federal Identity, Credential, and Access Management (FICAM)-issued profiles.
SV-205578r961548_ruleMainframe Products must audit nonlocal maintenance and diagnostic sessions audit events as defined in site security plan.
SV-205579r961554_ruleMainframe Products must implement cryptographic mechanisms to protect the integrity of nonlocal maintenance and diagnostic communications.
SV-205580r961557_ruleMainframe Products must implement cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications.
SV-205581r961560_ruleMainframe Products must verify remote disconnection at the termination of nonlocal maintenance and diagnostic sessions.
SV-205582r961563_ruleThe Mainframe Product must implement privileged access authorization to all information systems and infrastructure components for selected vulnerability scanning activities as defined in the site security plan.
SV-205584r1028317_ruleThe Mainframe Product must implement cryptographic mechanisms to prevent unauthorized modification of all information not cleared for public release at rest on system components outside of organization facilities.
SV-205585r1028318_ruleThe Mainframe Product must implement cryptographic mechanisms to prevent unauthorized disclosure of all information not cleared for public release at rest on system components outside of organization facilities.
SV-205586r1137804_ruleThe Mainframe Product must maintain a separate execution domain for each executing process.
SV-205587r961656_ruleThe Mainframe Product must behave in a predictable and documented manner that reflects organizational and system objectives when invalid inputs are received.
SV-205588r961665_ruleThe Mainframe Product must implement security safeguards to protect its memory from unauthorized code execution.
SV-205589r961677_ruleThe Mainframe Product must remove all upgraded/replaced software components that are no longer required for operation after updated versions have been installed.
SV-205590r1137810_ruleThe Mainframe Product must install security-relevant software updates within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, STIGs).
SV-205591r961731_ruleThe Mainframe Product performing organization-defined security functions must verify correct operation of security functions.
SV-205592r961734_ruleThe Mainframe Product must perform verification of the correct operation of security functions upon system startup and/or restart; upon command by a user with privileged access; and/or every 30 days.
SV-205593r961737_ruleThe Mainframe Product must either shut down, restart, and/or notify the appropriate personnel when anomalies in the operation of the security functions as defined in site security plan are discovered.
SV-205594r961740_ruleThe Mainframe product must perform an integrity check of all software from vendors/sources that provide cryptographic mechanisms to enable the validation of code authenticity and integrity at startup, at transitional states as defined in site security plan or security-relevant events, or annually.
SV-205595r961746_ruleThe Mainframe Product must perform an integrity check of information as defined in site security plan at startup, at transitional states as defined in site security plan or security-relevant events, or annually.
SV-205596r961755_ruleThe Mainframe Product must automatically shut down the information system, restart the information system, and/or implement security safeguards as conditions as defined in site security plan when integrity violations are discovered.
SV-205597r961767_ruleThe Mainframe Product must audit detected potential integrity violations.
SV-205598r961770_ruleThe Mainframe Product, upon detection of a potential integrity violation, must initiate one or more of the following actions: generate an audit record, alert the current user, alert personnel or roles as defined in the site security plan, and/or perform other actions as defined in the SSP.
SV-205599r961779_ruleThe Mainframe Product must prompt the user for action prior to executing mobile code.
SV-205600r961791_ruleThe Mainframe Product must generate audit records when successful/unsuccessful attempts to access security objects occur.
SV-205601r961794_ruleThe Mainframe Product must generate audit records when successful/unsuccessful attempts to access security levels occur.
SV-205602r961797_ruleThe Mainframe Product must generate audit records when successful/unsuccessful attempts to access categories of information (e.g., classification levels) occur.
SV-205603r961800_ruleThe Mainframe Product must generate audit records when successful/unsuccessful attempts to modify privileges occur.
SV-205604r961803_ruleThe Mainframe Product must generate audit records when successful/unsuccessful attempts to modify security objects occur.
SV-205605r961806_ruleThe Mainframe Product must generate audit records when successful/unsuccessful attempts to modify security levels occur.
SV-205606r961809_ruleThe Mainframe Product must generate audit records when successful/unsuccessful attempts to modify categories of information (e.g., classification levels) occur.
SV-205607r961812_ruleThe Mainframe Product must generate audit records when successful/unsuccessful attempts to delete privileges occur.
SV-205608r961815_ruleThe Mainframe Product must generate audit records when successful/unsuccessful attempts to delete security levels occur.
SV-205609r961818_ruleThe Mainframe Product must generate audit records when successful/unsuccessful attempts to delete security objects occur.
SV-205610r961821_ruleThe Mainframe Product must generate audit records when successful/unsuccessful attempts to delete categories of information (e.g., classification levels) occur.
SV-205611r961824_ruleThe Mainframe Product must generate audit records when successful/unsuccessful logon attempts occur.
SV-205612r961827_ruleThe Mainframe Product must generate audit records for privileged activities or other system-level access.
SV-205613r961830_ruleThe Mainframe Product must generate audit records showing starting and ending time for user access to the system.
SV-205614r961833_ruleThe Mainframe Product must generate audit records when concurrent logons from different workstations occur.
SV-205615r961836_ruleThe Mainframe Product must generate audit records when successful/unsuccessful accesses to objects occur.
SV-205616r961839_ruleThe Mainframe Product must generate audit records for all direct access to the information system.
SV-205617r961842_ruleThe Mainframe Product must generate audit records for all account creations, modifications, disabling, and termination events.
SV-205618r961845_ruleThe Mainframe Product must generate audit records for all kernel module load, unload, and restart events, and for all program initiations.
SV-205619r1137805_ruleThe Mainframe Product must implement NIST FIPS-validated cryptography to provision digital signatures in accordance with applicable federal laws, Executive orders, directives, policies, regulations, and standards.
SV-205620r1137806_ruleThe Mainframe Product must implement NIST FIPS-validated cryptography to generate and validate cryptographic hashes in accordance with applicable federal laws, Executive orders, directives, policies, regulations, and standards.
SV-205621r1137807_ruleThe Mainframe Product must implement NIST FIPS-validated cryptography to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive orders, directives, policies, regulations, and standards.
SV-205622r961863_ruleThe Mainframe Product must be configured in accordance with the security configuration settings based on DoD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs.
SV-219060r961863_ruleThe Mainframe Product must provide the capability for authorized users to select a user session to capture/record or view/hear.
SV-219061r961863_ruleThe Mainframe Product must provide the capability for authorized users to remotely view/hear, in real time, all content related to an established user session from a component separate from the Mainframe Product being monitored.
SV-253508r1117186_ruleThe Mainframe Product must implement NSA-approved cryptography to protect classified information in accordance with applicable federal laws, Executive orders, directives, policies, regulations, and standards.
SV-263669r982577_ruleThe Mainframe Product must disable accounts when the accounts have expired.
SV-263670r982579_ruleThe Mainframe Product must disable accounts when the accounts are no longer associated to a user.
SV-263671r982581_ruleThe Mainframe Product must implement the capability to centrally review and analyze audit records from multiple components within the system.
SV-263672r982583_ruleThe Mainframe Product must alert organization-defined personnel or roles upon detection of unauthorized access, modification, or deletion of audit information.
SV-263673r982337_ruleThe Mainframe Product must implement multifactor authentication for local; network; and/or remote access to privileged accounts; and/or nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access.
SV-263674r982585_ruleThe Mainframe Product must implement multifactor authentication for local; network; and/or remote access to privileged accounts; and/or nonprivileged accounts such that the device meets organization-defined strength of mechanism requirements.
SV-263675r982343_ruleThe Mainframe Product must, for password-based authentication, maintain a list of commonly used, expected, or compromised passwords on an organization-defined frequency.
SV-263676r982587_ruleThe Mainframe Product must, for password-based authentication, update the list of passwords on an organization-defined frequency.
SV-263677r982589_ruleThe Mainframe Product must, for password-based authentication, update the list of passwords when organizational passwords are suspected to have been compromised directly or indirectly.
SV-263678r982352_ruleThe Mainframe Product must, for password-based authentication, verify when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a).
SV-263679r982591_ruleThe Mainframe Product must, for password-based authentication, require immediate selection of a new password upon account recovery.
SV-263680r982593_ruleThe Mainframe Product must, for password-based authentication, allow user selection of long passwords and passphrases, including spaces and all printable characters.
SV-263681r982595_ruleThe Mainframe Product must, for password-based authentication, employ automated tools to assist the user in selecting strong password authenticators.
SV-263682r982364_ruleThe Mainframe Product must for public key-based authentication, implement a local cache of revocation data to support path discovery and validation.
SV-263683r982597_ruleThe Mainframe Product must protect nonlocal maintenance sessions by separating the maintenance session from other network sessions with the system by logically separated communications paths.
SV-263684r982599_ruleThe Mainframe Product must include only approved trust anchors in trust stores or certificate stores managed by the organization.
SV-263685r982601_ruleThe Mainframe Product must provide protected storage for cryptographic keys with organization-defined safeguards and/or hardware protected key store.
SV-263686r982603_ruleThe Mainframe Product must synchronize system clocks within and between systems or system components.
SV-263687r982605_ruleThe Mainframe Product must compare the internal system clocks on an organization-defined frequency with organization-defined authoritative time source.
SV-278990r1137813_ruleThe Mainframe Product must be a version supported by the vendor.